You can rotate the certificates on the tunnel endpoints on the AWS side by using the Amazon VPC console. When a tunnel endpoint’s certificate is close to expiration, AWS automatically rotates the certificate using the service-linked role. For more information, see Service-linked roles for Site-to-Site VPN.
To rotate the Site-to-Site VPN tunnel endpoint certificate using the console
Open the Amazon VPC console at https://console.aws.amazon.com/vpc/
. In the navigation pane, choose Site-to-Site VPN connections.
Select the Site-to-Site VPN connection, and then choose Actions, Modify VPN tunnel certificate.
Select the tunnel endpoint.
Choose Save.
To rotate the Site-to-Site VPN tunnel endpoint certificate using the AWS CLI
Use the modify-vpn-tunnel-certificate