Amazon wants to be your SSL certificate provider, applies to be a root Certificate Authority
Todd Bishop / GeekWire : Tweets: @digiphile . Thanks: @kevinlisota Tweets: Alex Howard / @digiphile : @Techmeme Tangentially related: @WhiteHouse mandates federal government websites move to HTTPS by default http://www.huffingtonpost.com/ ... tip tip tip Thanks: @kevinlisota
Context & Ripple Effects
Amazon's application to become a root Certificate Authority extends a security build-out that was already underway across AWS — from default S3 encryption to the AWS Shield DDoS protection service that followed a year later. Owning a place in the browser trust stores would let Amazon issue SSL certificates directly instead of routing that layer through third parties.
The move lands in a certificate market already being reshaped by Let's Encrypt's free automated certificates, and by trust questions the ecosystem itself raised when an investigation tied root CA TrustCor Systems to US intelligence connections. A hyperscaler with audited infrastructure entering the root program raises both the competitive bar and the stakes of who gets to vouch for the web.
First-order effects
- AWS customers gain a native path to certificates issued inside their existing cloud relationship, displacing revenue that today flows to incumbent CAs like Symantec and DigiCert.
- Amazon's own endpoints — retail, Prime, AWS console — no longer depend on external providers for the encryption chain underpinning them.
Second-order effects
- Incumbent CAs face price compression on commodity domain-validation certificates, following the pressure Let's Encrypt's free model already applied.
- Certificate issuance starts bundling with cloud contracts the way AWS bundled DDoS protection into Shield, making trust a feature of platform lock-in rather than a standalone purchase.
Third-order effects
- If the pattern holds, root-of-trust authority concentrates among a handful of cloud operators whose infrastructure scale makes them default auditors — raising the governance question of whether commercial cloud vendors should hold that power, the same question TrustCor's intel ties forced on the browser vendors.
- The browser trust-store model drifts from independent CAs toward vertically integrated platforms, with security posture becoming a differentiator between hyperscalers.
The trend: Web encryption is consolidating from a market of independent certificate authorities into an infrastructure layer owned by the cloud platforms themselves.