Amazon Private CA API operations and permissions - Amazon Private Certificate Authority
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Amazon Private CA API operations and permissions

When you set up access control and permissions policies that you plan to attach to an IAM identity (identity-based policies), use the following table as a reference. The first column in the table lists each Amazon Private CA API operation. You specify actions in a policy's Action element. The remaining columns provide the additional information.

Amazon Private CA API operations Required permissions Resources

CreateCertificateAuthority

acm-pca:CreateCertificateAuthority

acm-pca:TagCertificateAuthority (Only required when creating a CA with tags.)

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

CreateCertificateAuthorityAuditReport

acm-pca:CreateCertificateAuthorityAuditReport

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

CreatePermission acm-pca:CreatePermission arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

DeleteCertificateAuthority

acm-pca:DeleteCertificateAuthority

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

DeletePermission acm-pca:DeletePermission arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566
DeletePolicy acm-pca:DeletePolicy arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

DescribeCertificateAuthority

acm-pca:DescribeCertificateAuthority

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

DescribeCertificateAuthorityAuditReport

acm-pca:DescribeCertificateAuthorityAuditReport

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

GetCertificate

acm-pca:GetCertificate

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

GetCertificateAuthorityCertificate

acm-pca:GetCertificateAuthorityCertificate

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

GetCertificateAuthorityCsr

acm-pca:GetCertificateAuthorityCsr

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

GetPolicy acm-pca:GetPolicy arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

ImportCertificateAuthorityCertificate

acm-pca:ImportCertificateAuthorityCertificate

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

IssueCertificate

acm-pca:IssueCertificate

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

ListCertificateAuthorities

acm-pca:ListCertificateAuthorities

N/A

ListPermissions acm-pca:ListPermissions arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

ListTags

acm-pca:ListTags

N/A

PutPolicy acm-pca:PutPolicy arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

RevokeCertificate

acm-pca:RevokeCertificate

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

TagCertificateAuthority

acm-pca:TagCertificateAuthority

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

UntagCertificateAuthority

acm-pca:UntagCertificateAuthority

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

UpdateCertificateAuthority

acm-pca:UpdateCertificateAuthority

arn:aws:acm-pca:us-east-1:111122223333:certificate-authority/11223344-1234-1122-2233-112233445566

To provide access, add permissions to your users, groups, or roles: