Amazon Certificate Manager (ACM)

Overview

HPE Morpheus Software integrates with Amazon Certificate Manager (ACM) to manage SSL/TLS certificates for AWS resources. This integration allows HPE Morpheus Software to provision and manage certificates within AWS, leveraging ACM’s automatic renewal and validation capabilities.

ACM certificates managed through HPE Morpheus Software can be used with AWS services including:

  • Elastic Load Balancers (ALB, NLB, CLB)

  • Amazon CloudFront distributions

  • Amazon API Gateway endpoints

  • AWS Elastic Beanstalk environments

Prerequisites

  • An active AWS Cloud integration in HPE Morpheus Software

  • IAM permissions for the ACM service:

    • acm:RequestCertificate

    • acm:DescribeCertificate

    • acm:ListCertificates

    • acm:DeleteCertificate

    • acm:ImportCertificate

    • acm:GetCertificate

  • For DNS validation: Route 53 permissions or access to the domain’s DNS

Configuration

ACM integration is available automatically when an AWS Cloud is configured in HPE Morpheus Software. No additional integration setup is required beyond the AWS Cloud configuration.

Requesting ACM Certificates

To request a new certificate through ACM:

  1. Navigate to |InfTruCer|

  2. Click + ADD

  3. Select the ACM certificate type

  4. Complete the request fields:

    • NAME: A name for the certificate in HPE Morpheus Software

    • AWS CLOUD: Select the AWS Cloud integration

    • REGION: AWS region for the certificate

    • DOMAIN NAME: Primary domain for the certificate (e.g., example.com)

    • ADDITIONAL NAMES: Subject Alternative Names (SANs) for additional domains

    • VALIDATION METHOD: DNS Validation (recommended) or Email Validation

  5. Click REQUEST

HPE Morpheus Software submits the certificate request to ACM. The certificate status will show as “Pending Validation” until domain ownership is verified.

Domain Validation

ACM provides a CNAME record that must be added to your domain’s DNS:

  • If the domain is managed in Route 53 through HPE Morpheus Software, validation can be completed automatically

  • For external DNS, add the provided CNAME record to your DNS zone

  • DNS validation records can remain in place for automatic renewal

Email Validation

ACM sends validation emails to domain contacts:

  • admin@example.com

  • administrator@example.com

  • hostmaster@example.com

  • postmaster@example.com

  • webmaster@example.com

Follow the link in the validation email to approve the certificate request.

Importing Existing Certificates to ACM

To import a third-party certificate into ACM through HPE Morpheus Software:

  1. Navigate to |InfTruCer|

  2. Click + ADD

  3. Select ACM Import type

  4. Provide:

    • CERTIFICATE BODY: PEM-encoded certificate

    • PRIVATE KEY: PEM-encoded private key

    • CERTIFICATE CHAIN: PEM-encoded intermediate certificates

  5. Click IMPORT

Note

Imported certificates are not automatically renewed by ACM. Only certificates requested through ACM receive automatic renewal.

Certificate Renewal

Certificates requested through ACM are automatically renewed by AWS:

  • ACM begins renewal 60 days before expiration

  • DNS-validated certificates renew automatically if the CNAME record is still in place

  • Email-validated certificates require re-approval via email

  • HPE Morpheus Software syncs the renewed certificate data automatically

Certificate Synchronization

HPE Morpheus Software synchronizes ACM certificate inventory from AWS:

  • Certificates created directly in the AWS Console appear in HPE Morpheus Software after sync

  • Certificate status (Issued, Pending, Expired, Revoked) is kept current

  • Association with AWS resources (ELBs, CloudFront) is tracked

Deleting ACM Certificates

To delete an ACM certificate:

  1. Navigate to |InfTruCer|

  2. Select the ACM certificate

  3. Click DELETE from the Actions menu

  4. Confirm deletion

Warning

ACM certificates cannot be deleted while in use by AWS services (load balancers, CloudFront, etc.). Remove the certificate association from all services before deletion.