Importing a certificate - AWS Certificate Manager

Importing a certificate

You can import an externally obtained certificate (that is, one provided by a third-party trust services provider) into ACM by using the AWS Management Console, the AWS CLI, or the ACM API. The following topics show you how to use the AWS Management Console and the AWS CLI. Procedures for obtaining a certificate from a non-AWS issuer are outside the scope of this guide.


Your selected signature algorithm must meet the Prerequisites for importing certificates.

Import (console)

The following example shows how to import a certificate using the AWS Management Console.

  1. Open the ACM console at If this is your first time using ACM, look for the AWS Certificate Manager heading and choose the Get started button under it.

  2. Choose Import a certificate.

  3. Do the following:

    1. For Certificate body, paste the PEM-encoded certificate to import. It should begin with -----BEGIN CERTIFICATE----- and end with -----END CERTIFICATE-----.

    2. For Certificate private key, paste the certificate's PEM-encoded, unencrypted private key. It should begin with -----BEGIN PRIVATE KEY----- and end with -----END PRIVATE KEY-----.

    3. (Optional) For Certificate chain, paste the PEM-encoded certificate chain.

  4. Choose Review and import.

  5. On the Review and import page, check the displayed metadata about your certificate to ensure that it is what you intended. The fields include:

    • Domains — A list of fully qualified domain names (FQDN) authenticated by the certificate

    • Expires in — The number of days until the certificate expires

    • Public key info — The cryptographic algorithm used to generate the key pair

    • Signature algorithm — The cryptographic algorithm used to create the certificate's signature

    • Can be used with — A list of ACM integrated services that support the type of certificate you are importing

    If everything is correct, choose Import.

Import (AWS CLI)

The following example shows how to import a certificate using the AWS Command Line Interface (AWS CLI). The example assumes the following:

  • The PEM-encoded certificate is stored in a file named Certificate.pem.

  • The PEM-encoded certificate chain is stored in a file named CertificateChain.pem.

  • The PEM-encoded, unencrypted private key is stored in a file named PrivateKey.pem.

To use the following example, replace the file names with your own and type the command on one continuous line. The following example includes line breaks and extra spaces to make it easier to read.

$ aws acm import-certificate --certificate fileb://Certificate.pem \ --certificate-chain fileb://CertificateChain.pem \ --private-key fileb://PrivateKey.pem

If the import-certificate command is successful, it returns the Amazon Resource Name (ARN) of the imported certificate.