All integration guides
DIRECT AWS INTEGRATION · MANAGED SETUP

Deploy your QWAC on AWS CloudFront

Connect your AWS account and issuer. QWAC.com imports your certificate, attaches it to CloudFront, and keeps issued replacements in sync.

Connect an AWS role, distribution, and issuer•Reviewed October 9, 2026
Check compatibility first

Use an enabled standard distribution with one custom hostname and SNI. Multiple aliases, wildcard names, staging distributions, and continuous deployment need a coverage review. Certificates must be imported in US East (N. Virginia), even if your origin is elsewhere.

Before you start

This integration connects your website to verified organization identity—a foundation for your SEO and AEO strategy. See how QWAC fits into search and AI discovery.

  • An AWS account with a working CloudFront distribution and one custom hostname
  • An administrator who can create an IAM role for certificate management
  • Your enabled DigiCert Europe or Sectigo account and completed business verification
  • Access to your DNS provider and an active QWAC.com managed service
What you’re setting up

Your certificate is imported into AWS Certificate Manager (ACM) in us-east-1 and selected as the distribution’s viewer certificate. Reissues reuse that ACM certificate ARN. QWAC.com confirms the certificate served to visitors after propagation.

Account setup time does not include provider identity checks, certificate issuance, or managed-service activation.

01

Check your distribution

WHERE TO GOAWS console → CloudFront → Distributions
  1. Choose the distribution serving your website. Check its alternate domain name and verify the site loads over HTTPS.
  2. Use a standard distribution with exactly one custom hostname, SNI, and no staging or continuous deployment policy.
  3. Keep your current working certificate. QWAC.com creates a dedicated imported certificate for this website; it does not overwrite an unrelated ACM certificate.
✓
You’re ready for the next step when…

The distribution and its hostname are ready.

02

Connect your AWS role

WHERE TO GOQWAC.com → Add website → AWS CloudFront
  1. Enter the 12-digit AWS account ID.
  2. Select Get AWS role setup. Give your AWS administrator the generated trust policy and the permissions example linked below.
  3. Replace YOUR_AWS_ACCOUNT_ID and YOUR_DISTRIBUTION_ID in the permissions example. Create an IAM role using those permissions and the exact generated trust policy, including its external ID.
  4. Paste the role ARN into QWAC.com and select Connect AWS CloudFront. Select your distribution and hostname.
QWAC.com AWS CloudFront setup with AWS account ID and role setup button
Start with your AWS account ID. Get AWS role setup provides the trust policy for your administrator. Click image to enlarge
Before you continue

No customer AWS access keys are pasted into QWAC.com. The external ID binds role access to your QWAC.com account. You can revoke the role whenever needed.

✓
You’re ready for the next step when…

QWAC.com can assume the approved role and read your distribution.

03

Authorize your issuer

WHERE TO GOWebsite setup → Certificate provider
  1. Connect your own DigiCert Europe API account or enabled Sectigo ACME account.
  2. Choose We host the key for automatic ACM import, or Bring your key and CSR for manual installation.
  3. Select your purchased QWAC or EV product and review issuer fees before authorizing the request.
Before you continue

Hosted keys use envelope encryption with AWS KMS and are decrypted in memory for import into ACM. ACM stores the imported key for CloudFront. Cloudflare-generated keys are not used.

✓
You’re ready for the next step when…

The selected certificate request is authorized.

04

Complete domain and business checks

WHERE TO GOWebsite setup → DNS validation and your issuer account
  1. Add the TXT record shown in QWAC.com at your authoritative DNS provider, then select Check DNS.
  2. Complete the issuer’s business verification or authorized representative approval.
  3. Follow the new instructions whenever reissue validation is required; email alerts accompany dashboard actions.
Before you continue

DNS updates are manual in this integration, including for Route 53. Your hosting role does not receive DNS write access.

✓
You’re ready for the next step when…

The issuer approves and issues the certificate.

05

Import, deploy, and verify

WHERE TO GOWebsite setup → Deployment status
  1. For hosted keys, QWAC.com imports the certificate and matching key into ACM in US East (N. Virginia). It then updates only the distribution’s viewer certificate settings.
  2. For your own CSR, import the downloaded certificate and key into ACM yourself, then attach it to the distribution.
  3. Allow CloudFront to finish deployment. Select Sync; Active requires the expected certificate to be visible over public TLS.
  4. Replacements are reimported into the dedicated ACM certificate ARN, preserving the CloudFront association.
Before you continue

AWS does not automatically renew imported certificates. Resolve renewal alerts before expiry; an expired certificate can break HTTPS.

✓
You’re ready for the next step when…

CloudFront serves the issued certificate and renewal is tracked.

Bring your key and CSR

Keep your private key on your own system. QWAC.com needs only the public certificate signing request (CSR). Ask your administrator to generate an RSA-3072 key and a CSR for exactly your website hostname.

Example commands for your administrator
umask 077
openssl req -new -newkey rsa:3072 -nodes   -keyout example.com.key -out example.com.csr   -subj "/CN=example.com" -addext "subjectAltName=DNS:example.com"

Replace example.com with your selected hostname. Keep the .key file private and backed up. Only select the .csr file in QWAC.com.

  1. Choose your issuer, then Bring your key and CSR.
  2. Paste or select the public CSR. Connect your issuer account for the selected QWAC or EV product and authorize the request.
  3. When notified, download the issued certificate from your workspace.
  4. In AWS Certificate Manager, select US East (N. Virginia), then import the issued certificate, its matching private key, and intermediate CA chain. Attach that certificate to your CloudFront distribution. For reissues, reimport into the same ACM certificate ARN.
  5. Return to QWAC.com and select Verify AWS CloudFront installation. Repeat installation after every reissue.

Your key is uploaded directly to AWS CloudFront, which holds it for TLS serving. QWAC.com never receives it. This option does not use Keyless SSL.

AWS CloudFront installation instructions ↗
IF SOMETHING DOESN’T LOOK RIGHT

Troubleshooting

AWS role setup is unavailable

QWAC.com’s operator must configure its AWS delivery role before a customer trust policy can be generated. Contact onboarding; no certificate order has been placed.

Connection was denied

Check the account ID, role ARN, principal, external ID, and attached permissions. The trust policy must match the one generated for your account.

My distribution needs review

Only enabled standard distributions with one exact custom hostname and SNI are supported automatically. Multiple aliases need matching certificate coverage before replacement.

The certificate is not available in CloudFront

Check that it was imported into ACM in US East (N. Virginia), in the distribution’s AWS account, and covers the exact hostname.

A deployment is still propagating

An ACM import does not immediately change every edge location. We wait for CloudFront deployment and check public TLS before reporting Active.

An import response was lost

Contact support before importing again. Support can recover the matching, tagged ACM certificate and resume the saved deployment without creating duplicates.

Official references

Provider screens and requirements change. These links are the source of truth for their platform settings.

CloudFront certificate requirementsImport a certificate into ACMReimport into the same ACM certificateAWS role external IDs

Keep this guide handy.

Start with your hosting account, then choose your issuer and how to manage your key.

Register your interest