Skip to content

AWS Private CA

Integrate AWS Certificate Manager Private Certificate Authority (ACM PCA) with SSL-CLM to:

  • Issue private certificates for AWS and hybrid workloads
  • Renew certificates automatically
  • Revoke certificates
  • Sync certificate inventory from AWS

AWS Private CA integrates via the AWS SDK. No agent is required.


SSL-CLM Platform
│
│ (AWS SDK / HTTPS)
▼
AWS ACM Private CA
│
▼
Private Certificate Authority (your CA)

  • AWS account with ACM Private CA created and active
  • IAM user or role with permissions for acm-pca:IssueCertificate, acm-pca:GetCertificate, acm-pca:RevokeCertificate, acm-pca:ListCertificateAuthorities
  • CA ARN (Amazon Resource Name)
  • Network access from SSL-CLM backend to AWS API endpoints

Create an IAM user (or role) with the following policy:

{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"acm-pca:IssueCertificate",
"acm-pca:GetCertificate",
"acm-pca:GetCertificateAuthorityCertificate",
"acm-pca:RevokeCertificate",
"acm-pca:ListCertificateAuthorities",
"acm-pca:DescribeCertificateAuthority",
"acm-pca:ListTags"
],
"Resource": "arn:aws:acm-pca:*:*:certificate-authority/*"
}
]
}

Generate access keys for the IAM user.


Step 2 — Create Certificate Authority in SSL-CLM

Section titled “Step 2 — Create Certificate Authority in SSL-CLM”
  1. Navigate to Infrastructure → Certificate Authorities
  2. Click + Add CA
  3. Select AWS Private CA from the type cards
  4. Fill in the configuration:
FieldDescriptionExample
NameFriendly nameAWS PCA Production
RegionAWS region of the PCAus-east-1
CA ARNARN of the private CAarn:aws:acm-pca:us-east-1:123456789012:certificate-authority/abc-def-123
Access Key IDIAM access keyAKIAIOSFODNN7EXAMPLE
Secret Access KeyIAM secret key(stored encrypted)
Signing AlgorithmCertificate signing algorithmSHA256WITHRSA
Template ARN(Optional) ACM PCA templatearn:aws:acm-pca:::template/EndEntityCertificate/V1
Discovery IntervalHours between inventory syncs24
  1. Click Test Connection to verify
  2. Click Save

  1. Navigate to Certificates → + New Certificate
  2. Select Issue from CA
  3. Choose the AWS PCA CA
  4. Fill in subject and SAN details
  5. Set validity period
  6. Submit

SSL-CLM will:

  1. Generate a CSR
  2. Call acm-pca:IssueCertificate with the CSR and parameters
  3. Poll acm-pca:GetCertificate until the certificate is available
  4. Store the issued certificate in inventory

When revocation is requested:

  1. SSL-CLM calls acm-pca:RevokeCertificate with the serial number and reason
  2. AWS PCA updates its CRL
  3. SSL-CLM updates the certificate status to REVOKED

AlgorithmKey Type
SHA256WITHRSARSA
SHA384WITHRSARSA
SHA512WITHRSARSA
SHA256WITHECDSAECDSA
SHA384WITHECDSAECDSA
SHA512WITHECDSAECDSA

AWS PCA provides built-in templates:

TemplateUse Case
EndEntityCertificate/V1Standard end-entity (server/client) certs
SubordinateCACertificate_PathLen0/V1Subordinate CA with no further sub-CAs
CodeSigningCertificate/V1Code signing
OCSPSigningCertificate/V1OCSP responder

Leave the template ARN empty to use the default end-entity template.


AWS Private CA pricing:

  • Monthly fee: $400/month per CA (prorated)
  • Per-certificate fee: $0.75/cert (general), $0.058/cert (short-lived <7 days)

Plan your usage accordingly and leverage short-lived certificates where possible.


IssuePossible CauseResolution
Access deniedInsufficient IAM permissionsReview IAM policy, ensure all required actions are allowed
CA not foundWrong region or ARNVerify region matches CA location, check ARN
Certificate pendingCA busy or slow responseSSL-CLM retries automatically; check AWS PCA status
Signing algorithm errorAlgorithm not supported by CA key typeMatch signing algorithm to CA’s key type