More Info:

Ensure that all the requests made during SSL/TLS certificate issue or renewal process are validated. These requests are managed within your account by the Amazon Certificate Manager (ACM), an AWS service that lets you provision, deploy and maintain SSL/TLS certificates for use with other AWS resources such as ELB load balancers, CloudFront distributions or APIs via Amazon API Gateway.

Risk Level

Medium

Address

Security

Compliance Standards

NIST

Triage and Remediation

Check Cause

  1. Sign in to the AWS Management Console and open the API Gateway console at https://console.aws.amazon.com/apigateway/.

  2. In the navigation pane, choose ‘APIs’.

  3. In the APIs pane, choose the API you want to check.

  4. In the API details pane, choose ‘Custom Domain Names’. This will display a list of custom domain names associated with the API.

  5. For each custom domain name, check the ‘ACM Certificate’ column. If the certificate is not valid, it will be indicated here.

Additional Reading: