ACM Private Certificate Authority
A root or subordinate CA with revocation configured, its certificate installed in the same apply, and ACM permitted to issue from it. Documents the two traps: a CA bills through its deletion window, and one without CRL or OCSP can issue certificates it can never revoke.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan pending (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-12 · how we verify
Use it from the registry
terraform · opentofumodule "private_ca" {
source = "www.iac-bazaar.com/iac-bazaar/aws-private-ca/aws"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
aws-private-ca
ACM Private CA: a root or subordinate certificate authority with revocation
configured, its certificate installed, and ACM permitted to issue from it.
Works with Terraform and OpenTofu (>= 1.6), AWS provider
>= 6.0, < 7.0.
Cost, before anything else. A private CA bills a flat monthly fee per CA on
top of per-certificate charges, and deleting one does not stop the clock: it
enters PENDING_DELETION for a restore window and bills until that window
closes. Seven days is the minimum and the default here; the API's own default
is thirty, which is three more weeks of a CA you thought you had removed.
Revocation is not really optional. A CA with neither a CRL nor OCSP can issue certificates it can never revoke. If a private key leaks, the only remedy left is to distrust the CA itself - which means replacing every certificate it ever issued.
Other things the module handles:
- A root CA signs its own certificate, and until that is installed the CA
exists and can issue nothing - a state regularly mistaken for a broken CA.
install_certificatedoes it in the same apply signing_algorithmis validated against the SHA-2 ECDSA and RSA variants, so a mismatch with the key family fails at plan rather than at issuanceallow_acm_issuanceis what makes the CA usable by ALB, CloudFront and the rest without manual certificate handling
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
aws-acm
Requests a public, DNS-validated ACM TLS certificate that ACM auto-renews forever, outputting the validation records to publish - CT logging on, wildcards and SANs supported.
aws-kms
Customer-managed KMS keys with sane key policies, aliases, rotation, and multi-region replicas.
aws-ssm-parameter-store
Map-driven SSM Parameter Store parameters - String, StringList, and SecureString - created from a single map, with SecureString always KMS-encrypted and the free Standard tier by default.
aws-secrets-manager
Secrets with versioning, resource policies, replication, and optional Lambda rotation scaffolding.