AWS Private CA API operations and permissions - AWS Private Certificate Authority
Services or capabilities described in AWS documentation might vary by Region. To see the differences applicable to the AWS European Sovereign Cloud Region, see the AWS European Sovereign Cloud User Guide.

AWS Private CA API operations and permissions

When you set up access control and permissions policies that you plan to attach to an IAM identity (identity-based policies), use the following table as a reference. The first column in the table lists each AWS Private CA API operation. You specify actions in a policy's Action element. The remaining columns provide the additional information.

AWS Private CA API operations Required permissions Resources

CreateCertificateAuthority

acm-pca:CreateCertificateAuthority

acm-pca:TagCertificateAuthority (Only required when creating a CA with tags.)

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

CreateCertificateAuthorityAuditReport

acm-pca:CreateCertificateAuthorityAuditReport

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

CreatePermission acm-pca:CreatePermission arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

DeleteCertificateAuthority

acm-pca:DeleteCertificateAuthority

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

DeletePermission acm-pca:DeletePermission arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566
DeletePolicy acm-pca:DeletePolicy arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

DescribeCertificateAuthority

acm-pca:DescribeCertificateAuthority

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

DescribeCertificateAuthorityAuditReport

acm-pca:DescribeCertificateAuthorityAuditReport

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

GetCertificate

acm-pca:GetCertificate

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

GetCertificateAuthorityCertificate

acm-pca:GetCertificateAuthorityCertificate

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

GetCertificateAuthorityCsr

acm-pca:GetCertificateAuthorityCsr

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

GetPolicy acm-pca:GetPolicy arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

ImportCertificateAuthorityCertificate

acm-pca:ImportCertificateAuthorityCertificate

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

IssueCertificate

acm-pca:IssueCertificate

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

ListCertificateAuthorities

acm-pca:ListCertificateAuthorities

N/A

ListPermissions acm-pca:ListPermissions arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

ListTags

acm-pca:ListTags

N/A

PutPolicy acm-pca:PutPolicy arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

RevokeCertificate

acm-pca:RevokeCertificate

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

TagCertificateAuthority

acm-pca:TagCertificateAuthority

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

UntagCertificateAuthority

acm-pca:UntagCertificateAuthority

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

UpdateCertificateAuthority

acm-pca:UpdateCertificateAuthority

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

To provide access, add permissions to your users, groups, or roles: