1. 程式人生 > >Troubleshoot AWS Certificate Manager Import Errors

Troubleshoot AWS Certificate Manager Import Errors

You can import third-party SSL/TLS certificates, and you can integrate certificates with AWS services. If your certificate meets the Prerequisites for Importing Certificates, but you receive an error message when importing the certificate, see the troubleshooting steps for the following errors:

"You have reached the maximum number of certificates. Delete certificates that are not in use, or contact AWS Support to request an increase."

By default, you can import up to 100 certificates into ACM, but new AWS accounts might start with a lower limit. If you exceed this limit, contact AWS Support to request a limit increase.

If you receive this error message and you haven't exceeded 100 certificates for your account, you might have exceeded the limit for certificates that you can import in a year. By default, you can import twice your account limit per year. For example, if your limit is 100 certificates, you can import up to 200 certificates per year. This includes certificates that you imported and deleted within the last 365 days. If you reach this limit, contact AWS Support to request a limit increase. For more information, see

AWS Certificate Manager Limits.

"The certificate field contains more than one certificate. You can specify only one certificate in this field."

If you are importing a certificate, do not upload the complete certificate chain for the Certificate body field. If you receive a certificate bundle, it might contain the server certificate and the certificate chain from the certificate authority (CA). Separate each file (the certificate, the certificate chain with the intermediate and root certificates, and the private key) that is created at the time of the certificate signing request (CSR) generation from the bundle, change the file to a PEM format, and upload them individually to ACM. To convert a certificate bundle to a PEM format, see

Server Certificates Troubleshooting.

"Unable to validate certificate chain. The certificate chain must start with the immediate signing certificate, followed by any intermediaries in order. The index within the chain of the invalid certificate is: 0"

When importing a certificate into ACM, do not include the certificate in the certificate chain. The certificate chain should contain only the intermediate and root certificates, and the certificate chain must be in order—starting with the intermediate certificates, and then ending with the root certificate.

"Could not validate the certificate with the certificate chain."

If ACM is unable to match the certificate to the certificate chain provided, verify that the certificate chain is associated to your certificate. You might need to contact your certificate provider for further assistance.

"The private key length <key_length> is not supported for key algorithm."

When you create an x.509 certificate or certificate request, you specify the algorithm and the key bit size that must be used to create the private-public key pair. Be sure that your certificate key meets the Prerequisites for Importing Certificates. If your key does meet the requirements for key size or algorithm, reach out to your certificate provider to re-issue the certificate with a supported key size and algorithm.

"The certificate body/chain provided is not in a valid PEM format," "InternalFailure," or "Unable to parse certificate. Please ensure the certificate is in PEM format."

If the certificate body, private key, or certificate chain is not in the PEM format, or if the certificate file does not contain the appropriate certificate body, you must convert the file. To convert a certificate or certificate chain from DER to a PEM format, see Server Certificates Troubleshooting.

"The private key is not supported."

If you import a certificate into ACM using the AWS Command Line Interface (AWS CLI), you pass the contents of your certificate files (certificate body, private key, and certificate chain) as a string. You must specify the certificate, the certificate chain, and the private key by their file names preceded by file:// . For more information, see import-certificate.

Note: Be sure to use the file path "file://key.pem" for your key and "file://certificate.pem" for your certificate. If you don't include the file path, you might receive the following error messages: "The private key is not supported" or "The certificate is not valid."

相關推薦

Troubleshoot AWS Certificate Manager Import Errors

You can import third-party SSL/TLS certificates, and you can integrate certificates with AWS services. If your certificate meets the Prerequisi

Resend Validation Email from AWS Certificate Manager

Confirm that the certificate's status is "Pending validation", and then resend the validation email. To resend the validation email, the certif

AWS Certificate Manager(SSL/TLS 証明書を無料で作成)

AWS Certificate Manager は、AWS のサービスとお客様の內部接続リソースで使用するパブリックとプライベートの Secure Sockets Layer/Transport Layer Security (SSL/TLS) 証明書のプロビジョニング、管理、デプロイを簡単

AWS Systems Manager Features

AWS Systems Manager allows you to centralize operational data from multiple AWS services and automate tasks across your AWS resources. You can cr

AWS Certificate Manger

AWS Certificate Manager is integrated with other AWS services, so you can provision an SSL/TLS certificate and deploy it with your Elastic Load B

AWS Case Study: Import.io

Amazon Web Services is Hiring. Amazon Web Services (AWS) is a dynamic, growing business unit within Amazon.com. We are currently hiring So

AWS Systems Manager FAQs

Q: What is the difference between Secrets Manager and Parameter Store? AWS Secrets Manager is a service to manage the lifecycle for the secret

AWS Systems Manager Pricing

Automation, a Systems Manager feature, allows you to safely automate common and repetitive IT operations and management tasks across AWS resource

AWS Systems Manager雲資源管理器_雲平臺管理系統

AWS Systems Manager 可以根據您的修補、配置和自定義策略來掃描例項,從而幫助您保持安全性與合規性。您可以定義補丁基準,應用最新的防病毒定義並實施防火牆策略。您還可以大規模遠端管理伺服器,而無需手動登入到每個伺服器。Systems Manager 還提供一個集中式儲存來

AWS Systems Manager Partners

REAN Cloud's AWS Systems Manager practice has been validated as part of the AWS Service Delivery Program. REAN Cloud was one of th

AWS Systems Manager の特徴

AWS Systems Manager を使用することで、複數の AWS のサービスの運用データを一元化し、AWS リソース全體のタスクを自動化できます。アプリケーション、アプリケーションスタックのさまざまなレイヤー、本番環境と開発環境といったリソースの論理グループを作成できます。Syst

AWS Systems Manager Getting Started

Amazon Web Services is Hiring. Amazon Web Services (AWS) is a dynamic, growing business unit within Amazon.com. We are currently hiring So

AWS Systems Manager の料金

AWS Systems Manager に追加料金はかかりません。AWS Systems Manager によって管理または作成される基盤の AWS リソース (Amazon EC2 インスタンスまたは Amazon CloudWatch メトリクスなど) を実際に使用した分に対してのみ料金

AWS Systems Manager: получайте операционную аналитику и принимайте меры

AWS Systems Manager помогает поддерживать безопасность и соответствие требованиям, проверяя, соответствуют ли инстансы существующим политикам и

Возможности AWS Systems Manager 

AWS Systems Manager позволяет выполнять централизованный сбор операционных данных из различных сервисов AWS и автоматизировать задачи по всем исп

新功能 – AWS Systems Manager Session Manager 支援通過 Shell 訪問 EC2 例項

當今這個時代對於企業 IT 管理員來說非常有趣。一方面,開發人員在探討(並著手實施)基礎設施即程式碼的美好未來,將伺服器和其他資源視之如敝履。另一方面,仍需將舊版系統視之如愛寵,需要手動或藉助有限的自動化進行設定和維護。與我交流過的許多客戶都在快速向未來邁進,但卻困囿於眼下的環境。例如,他們

Tarification : AWS Certificate Manger : Amazon Web Services (AWS)

Exemple 3 : combinaison de gratuit et de payant Une CA privée dans la région USA Est (Virginie du Nord) émet un total de 5 000 nouveaux ce

Начало работы с AWS Systems Manager 

Amazon Web Services приглашает на работу. Amazon Web Services (AWS) – динамично растущее подразделение в составе Amazon.com. В настоящее в

AWS Firewall Manager 雲防火牆管理_Web防火牆規則

AWS Firewall Manager 能夠確保現有和新建的資源自動符合一組強制性的安全策略。該服務可以在跨帳戶建立時發現新的 Application Load Balancer 或 Amazon CloudFront 資源。例如,如果您需要符合美國財政部外國資產控制辦公室 (OFA