Some certificates might become invalid and need dns validation. We need to create an script to automate dns validation of unverified certificates: https://docs.aws.amazon.com/acm/latest/userguide/dns-validation.html