Skip to content

Compatible with account required

AWS Private CA

AWS Private CA inventory, issuance, GetCertificate polling, revocation and optional ACM import are implemented with SigV4 and role assumption.

Verification: test_verified. Connection: unknown. Credentials: none. Live E2E: no.

AWS account with ACM Private CA and a scoped IAM role is not configured.

What sslcertificates.io can do

AWS Private CA inventory, issuance, GetCertificate polling, revocation and optional ACM import are implemented with SigV4 and role assumption. Capabilities: list_cas, issue, revoke, acm_handoff. Authentication uses iam_role.

Required permissions

acm-pca:ListCertificateAuthorities, IssueCertificate, GetCertificate, RevokeCertificate on selected CA ARNs. External ID required for cross-account roles.

Setup

Open Dashboard → Integrations → AWS Private CA. Enter the credentials described on this page. Values are encrypted at rest and never shown again. Run Test connection. Discovery runs only after authentication succeeds. Select a discovered resource. Do not paste opaque IDs unless the provider cannot enumerate them. Perform the certificate or notification action, then confirm the external system matches. Disconnect removes stored credentials and owned test resources created by sslcertificates.io.

Known limitations

Private CA is a paid AWS service. Live E2E needs an AWS account with ACM PCA enabled.

Official sources

Fact checked 2026-09-20. https://docs.aws.amazon.com/privateca/latest/userguide/PcaWelcome.html AWS Private CA is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.

Capabilities

list_cas issue revoke acm_handoff

Connect

Create an account to connect

AWS Private CA is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.