SSL Auto Renewal

Summary

Bynder issues and automatically renews SSL/TLS certificates for all portals using AWS Certificate Manager (ACM), Amazon's managed certificate service. Once SSL auto-renewal is configured, certificates renew automatically on an ongoing basis with no manual follow-up required.

⚠️ Important: Auto-renewal requires you to keep the required DNS (CNAME) records permanently in place. If these records are removed or modified, auto-renewal will fail and your certificate will expire, causing downtime.

Note on terminology: AWS Certificate Manager (ACM) is the name of the Amazon Web Services product Bynder uses. Older documentation may refer to "automated certificate management" — this describes the same service. ACM should not be confused with ACME (Automated Certificate Management Environment), which is an unrelated industry protocol.

Who?

  • Customers with a custom portal URL. All domains hosted on Bynder require a valid SSL certificate. Bynder supplies a default URL and certificate; customers using a custom domain must have a certificate requested through ACM.
  • Domain administrators. A person with access to your organization's DNS configuration is needed to add the required CNAME records.

Why?

  • No expiration risk. Certificate maximum validity has shortened over the years (from 5 years down to 6 months as of early 2026, with further reductions expected). Auto-renewal removes the need for manual follow-ups: ACM manages the lifecycle and renews the certificate automatically prior to expiration.
  • No cost. There is no charge for configuring SSL auto-renewal.
  • Secure key management. ACM generates and protects a key pair for each certificate using strong encryption and key management best practices. No one has access to the private keys.
  • Broad compatibility. ACM public certificates are trusted by most modern browsers, operating systems, and mobile devices.

How?

  1. Contact Bynder to begin the request:
    • If you are in the implementation phase, reach out to your Onboarding Manager.
    • If your portal is already live, contact Customer Support.
  2. Provide the subdomain(s) for which an SSL certificate should be requested.
    • The requested URL must be a subdomain.
    • Optional: Indicate whether you want a redirect from your old portal URL to the new custom URL.
  3. Bynder provides two DNS records per domain:
    • One CNAME record validates domain ownership and authorizes AWS to request and renew the SSL certificate on your behalf (DNS validation).
    • A second record points the domain name to the correct server.
  4. Add the DNS records in your domain provider's configuration panel.
    • Instructions are available from most registrars, including GoDaddy, Namecheap, and Netfirms.
  5. Once the domain is validated, configure your primary domain and redirects under Portal settings > Domain Management.
  6. Keep the CNAME records in place permanently.
    • Do not remove the CNAME records after validation. They must remain in your DNS configuration for both your custom URL and your default Bynder subdomain ({portal-name}.bynder.com) to keep working. Because both URLs share the same certificate, removing the CNAME record will cause auto-renewal to fail, and users will experience connection errors when accessing either URL.

Technical details to be aware of:

  • Certificates issued through ACM have a maximum validity of 6 months and renew automatically before expiration.

  • ACM may renew or rekey a certificate and replace the old one without prior notice.

  • By default, ACM-issued certificates use RSA 2048-bit keys with SHA-256.

Related Articles

How To Create A Portal Custom URL

Privacy and Security

Bynder Security and Compliance

Updated