Why Letβs Encrypt?
We use Letβs Encrypt instead of Amazon ACM because:- Universal compatibility: Letβs Encrypt is allowed by ALL DNS providers
- No CAA conflicts: Some providers (Vercel, Netlify) have CAA records that block Amazon
- Fast issuance: Certificates are issued in seconds after DNS verification
Path Parameters
Example Request
Example Response
Response Fields
What Happens Next
- User adds the TXT record via Entri
- Frontend calls
/complete-certificateto validate and issue the cert - Certificate is imported to ACM and attached to CloudFront
- User can then switch their www CNAME to CloudFront (zero downtime!)