What is Amazon Private CA? - Amazon Private Certificate Authority
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

What is Amazon Private CA?

Amazon Private CA enables creation of private certificate authority (CA) hierarchies, including root and subordinate CAs, without the investment and maintenance costs of operating an on-premises CA. Your private CAs can issue end-entity X.509 certificates useful in scenarios including:

  • Creating encrypted TLS communication channels

  • Authenticating users, computers, API endpoints, and IoT devices

  • Cryptographically signing code

  • Implementing Online Certificate Status Protocol (OCSP) for obtaining certificate revocation status

Amazon Private CA operations can be accessed from the Amazon Web Services Management Console, using the Amazon Private CA API, or using the Amazon CLI.