AWS::ACMPCA::CertificateAuthority CrlDistributionPointExtensionConfiguration - Amazon CloudFormation
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

AWS::ACMPCA::CertificateAuthority CrlDistributionPointExtensionConfiguration

Contains configuration information for the default behavior of the CRL Distribution Point (CDP) extension in certificates issued by your CA. This extension contains a link to download the CRL, so you can check whether a certificate has been revoked. To choose whether you want this extension omitted or not in certificates issued by your CA, you can set the OmitExtension parameter.


To declare this entity in your Amazon CloudFormation template, use the following syntax:


{ "OmitExtension" : Boolean }


OmitExtension: Boolean



Configures whether the CRL Distribution Point extension should be populated with the default URL to the CRL. If set to true, then the CDP extension will not be present in any certificates issued by that CA unless otherwise specified through CSR or API passthrough.


Only set this if you have another way to distribute the CRL Distribution Points for certificates issued by your CA, such as the Matter Distributed Compliance Ledger.

This configuration cannot be enabled with a custom CNAME set.

Required: Yes

Type: Boolean

Update requires: No interruption