More Info:

Ensure that your SSL/TLS certificates managed by AWS ACM are renewed 45 days before their validity period ends. Certificate Manager is the AWS service that lets you easily provision, manage, and deploy SSL/TLS certificates for use with other AWS resources such as Elastic Load Balancers, CloudFront distributions or APIs on Amazon API Gateway.

Risk Level

Medium

Address

Security

Compliance Standards

NIST

Triage and Remediation

Check Cause

  1. Log in to the AWS Management Console and navigate to the API Gateway service.
  2. In the API Gateway dashboard, select the APIs that you want to examine.
  3. In the API details page, select the “Stages” option from the left-hand side menu.
  4. In the Stages section, under the “SSL certificate” tab, check the expiration date of the ACM certificate. If the certificate is set to expire in less than 45 days, it indicates a misconfiguration.

Additional Reading: