More Info:

Ensure that all the expired Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates managed by AWS Certificate Manager are removed in order to adhere to Amazon Security Best Practices. Certificate Manager is the AWS service that lets you easily provision, manage, and deploy SSL/TLS certificates for use with other Amazon services such as Elastic Load Balancing and CloudFront.

Risk Level

High

Address

Security

Compliance Standards

NIST

Triage and Remediation

Check Cause

  1. Log in to the AWS Management Console and open the API Gateway console at https://console.aws.amazon.com/apigateway/.

  2. In the navigation pane, choose ‘APIs’.

  3. In the APIs pane, choose the API you want to check.

  4. In the API details pane, choose ‘Custom Domain Names’. This will display a list of custom domain names associated with the API.

  5. For each custom domain name, check the ‘ACM Certificate’ column. If the certificate is expired, the status will be ‘Expired’.

Additional Reading: