AWS Private CA
AWS Private CA Integration
Section titled “AWS Private CA Integration”Integrate AWS Certificate Manager Private Certificate Authority (ACM PCA) with SSL-CLM to:
- Issue private certificates for AWS and hybrid workloads
- Renew certificates automatically
- Revoke certificates
- Sync certificate inventory from AWS
AWS Private CA integrates via the AWS SDK. No agent is required.
Architecture
Section titled “Architecture”SSL-CLM Platform││ (AWS SDK / HTTPS)▼AWS ACM Private CA│▼Private Certificate Authority (your CA)Prerequisites
Section titled “Prerequisites”- AWS account with ACM Private CA created and active
- IAM user or role with permissions for
acm-pca:IssueCertificate,acm-pca:GetCertificate,acm-pca:RevokeCertificate,acm-pca:ListCertificateAuthorities - CA ARN (Amazon Resource Name)
- Network access from SSL-CLM backend to AWS API endpoints
Step 1 — Create IAM Credentials
Section titled “Step 1 — Create IAM Credentials”Create an IAM user (or role) with the following policy:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "acm-pca:IssueCertificate", "acm-pca:GetCertificate", "acm-pca:GetCertificateAuthorityCertificate", "acm-pca:RevokeCertificate", "acm-pca:ListCertificateAuthorities", "acm-pca:DescribeCertificateAuthority", "acm-pca:ListTags" ], "Resource": "arn:aws:acm-pca:*:*:certificate-authority/*" } ]}Generate access keys for the IAM user.
Step 2 — Create Certificate Authority in SSL-CLM
Section titled “Step 2 — Create Certificate Authority in SSL-CLM”- Navigate to Infrastructure → Certificate Authorities
- Click + Add CA
- Select AWS Private CA from the type cards
- Fill in the configuration:
| Field | Description | Example |
|---|---|---|
| Name | Friendly name | AWS PCA Production |
| Region | AWS region of the PCA | us-east-1 |
| CA ARN | ARN of the private CA | arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/abc-def-123 |
| Access Key ID | IAM access key | AKIAIOSFODNN7EXAMPLE |
| Secret Access Key | IAM secret key | (stored encrypted) |
| Signing Algorithm | Certificate signing algorithm | SHA256WITHRSA |
| Template ARN | (Optional) ACM PCA template | arn:aws:acm-pca:::template/EndEntityCertificate/V1 |
| Discovery Interval | Hours between inventory syncs | 24 |
- Click Test Connection to verify
- Click Save
Step 3 — Issue Certificates
Section titled “Step 3 — Issue Certificates”- Navigate to Certificates → + New Certificate
- Select Issue from CA
- Choose the AWS PCA CA
- Fill in subject and SAN details
- Set validity period
- Submit
SSL-CLM will:
- Generate a CSR
- Call
acm-pca:IssueCertificatewith the CSR and parameters - Poll
acm-pca:GetCertificateuntil the certificate is available - Store the issued certificate in inventory
Step 4 — Revoke Certificates
Section titled “Step 4 — Revoke Certificates”When revocation is requested:
- SSL-CLM calls
acm-pca:RevokeCertificatewith the serial number and reason - AWS PCA updates its CRL
- SSL-CLM updates the certificate status to REVOKED
Supported Signing Algorithms
Section titled “Supported Signing Algorithms”| Algorithm | Key Type |
|---|---|
SHA256WITHRSA | RSA |
SHA384WITHRSA | RSA |
SHA512WITHRSA | RSA |
SHA256WITHECDSA | ECDSA |
SHA384WITHECDSA | ECDSA |
SHA512WITHECDSA | ECDSA |
Template ARNs
Section titled “Template ARNs”AWS PCA provides built-in templates:
| Template | Use Case |
|---|---|
EndEntityCertificate/V1 | Standard end-entity (server/client) certs |
SubordinateCACertificate_PathLen0/V1 | Subordinate CA with no further sub-CAs |
CodeSigningCertificate/V1 | Code signing |
OCSPSigningCertificate/V1 | OCSP responder |
Leave the template ARN empty to use the default end-entity template.
Pricing Consideration
Section titled “Pricing Consideration”AWS Private CA pricing:
- Monthly fee: $400/month per CA (prorated)
- Per-certificate fee: $0.75/cert (general), $0.058/cert (short-lived <7 days)
Plan your usage accordingly and leverage short-lived certificates where possible.
Troubleshooting
Section titled “Troubleshooting”| Issue | Possible Cause | Resolution |
|---|---|---|
| Access denied | Insufficient IAM permissions | Review IAM policy, ensure all required actions are allowed |
| CA not found | Wrong region or ARN | Verify region matches CA location, check ARN |
| Certificate pending | CA busy or slow response | SSL-CLM retries automatically; check AWS PCA status |
| Signing algorithm error | Algorithm not supported by CA key type | Match signing algorithm to CA’s key type |