This template sets up a CA hierarchy and permission. It creates a root CA using the AWS::ACMPCA::CertificateAuthority resource, issues a CA certificate using the AWS::ACMPCA::Certificate resource, activates the root CA using the AWS::ACMPCA::CertificateAuthorityActivation resource, and sets permissions using the AWS::ACMPCA::Permission resource. It also creates a subordinate CA, issues a CA certificate for the subordinate CA, activates the subordinate CA, and sets permissions for the subordinate CA.

RootCA
AWS::ACMPCA::CertificateAuthority


RevocationConfiguration
CrlConfiguration
OcspConfiguration
Subject *
CustomAttributes

RootCACertificate
AWS::ACMPCA::Certificate


Validity *

RootCAActivation
AWS::ACMPCA::CertificateAuthorityActivation


RootCAPermission
AWS::ACMPCA::Permission


Actions

SubordinateCAOne
AWS::ACMPCA::CertificateAuthority


Subject *
CustomAttributes

SubordinateCAOneCACertificate
AWS::ACMPCA::Certificate


Validity *

SubordinateCAOneActivation
AWS::ACMPCA::CertificateAuthorityActivation


SubordinateCAOnePermission
AWS::ACMPCA::Permission


Actions

SubordinateCATwo
AWS::ACMPCA::CertificateAuthority


Subject *
CustomAttributes
Tags

SubordinateCATwoCACertificate
AWS::ACMPCA::Certificate


Validity *

SubordinateCATwoActivation
AWS::ACMPCA::CertificateAuthorityActivation


SubordinateCATwoPermission
AWS::ACMPCA::Permission


Actions

EndEntityCertificate
AWS::ACMPCA::Certificate


Validity *

CloudFormation Template

Share Template