How Amazon's Event Notification Service Uses X.509 Certificates for Security
Amazon ENS now requires each seller to register a single X.509 certificate (PEM format) with a matching private key; uploading a new certificate automatically revokes the previous one. SSL is enforced for all calls and WS‑Security signing is mandatory, with certificates typically expiring after 1 year.
Overview
Amazon’s Event Notification Service (ENS) secures every data exchange with X.509 digital certificates. The mechanism, introduced to protect seller‑specific information, requires sellers to register a certificate before ENS can deliver order, inventory, or account alerts. Proper handling of these certificates is critical because any lapse can halt notifications and affect downstream operations.
Key Points
- Certificate prerequisite — Sellers must upload a valid X.509 certificate and its matching private key to AWS before ENS will accept any request, acting as the digital passport for the integration.
- Single certificate limit — Only one X.509 certificate can be linked to a seller account at a time; adding a new certificate automatically revokes the previous one, forcing an immediate update of all dependent systems.
- SSL encryption enforced — Every ENS call travels over Secure Sockets Layer (SSL), ensuring that payloads cannot be intercepted or altered while moving between the seller’s endpoint and Amazon’s servers.
- Private key is non‑recoverable — When AWS generates a certificate, the private key is displayed only once; after the page is closed the key is discarded permanently, so sellers must store it securely right away.
- WS‑Security signing required — ENS messages must be signed following the WS‑Security specification, using the public portion of the X.509 certificate for identity and the private key for a cryptographic signature that Amazon validates on receipt.
How Authentication Works
- Certificate registration — The seller’s public key is stored in AWS and tied to the seller’s unique identifier. For example, when a seller uploads a PEM‑encoded certificate, AWS records the public key and associates it with the seller’s Marketplace ID.
- Request signing — Before sending an ENS request, the seller’s application creates a digital signature with the private key. If the request is to fetch order notifications, the payload is hashed and encrypted with the private key, producing a signature that Amazon can later verify.
Analysis & Recommendations
Why This Matters
If a seller's X.509 certificate expires or is revoked, ENS rejects all order, inventory, and account notifications, leading to missed orders and inventory mismatches. The 1‑year certificate lifespan and single‑certificate limit force timely rotation and precise configuration updates across all downstream systems.
Key Takeaways
- Only one X.509 certificate can be linked to a seller account; adding a new one revokes the old certificate instantly.
- Certificates are typically valid for 1 year, requiring proactive rotation at least 30 days before expiry.
- ENS requests must be signed using WS‑Security with the private key, and all traffic is forced over SSL.
- Private keys are shown only once during generation and must be stored securely (e.g., AWS Secrets Manager).
Recommended Actions
- →In Seller Central, go to Security Credentials > X.509 Certificates, upload or generate a new PEM‑encoded certificate and immediately store the priv...
- →Set a CloudWatch alarm for the certificate’s expiry date (usually 1 year from issue) and schedule rotation 30 days prior.
- →Update all ENS client configurations to reference the new certificate identifier (e.g., replace “cert‑old123” with “cert‑new456”) and test a sandbo...
Comments
Join the discussion
Log in or create an account to share your thoughts on this update.
No comments yet. Be the first to share your thoughts!