AWSStatic-verified

ACM Private Certificate Authority

A root or subordinate CA with revocation configured, its certificate installed in the same apply, and ACM permitted to issue from it. Documents the two traps: a CA bills through its deletion window, and one without CRL or OCSP can issue certificates it can never revoke.

terraformAWSaws
aws-private-cavizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan pending (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-12 · how we verify

Use it from the registry

terraform · opentofu
module "private_ca" {
  source  = "www.iac-bazaar.com/iac-bazaar/aws-private-ca/aws"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

aws-private-ca

ACM Private CA: a root or subordinate certificate authority with revocation configured, its certificate installed, and ACM permitted to issue from it. Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.

Cost, before anything else. A private CA bills a flat monthly fee per CA on top of per-certificate charges, and deleting one does not stop the clock: it enters PENDING_DELETION for a restore window and bills until that window closes. Seven days is the minimum and the default here; the API's own default is thirty, which is three more weeks of a CA you thought you had removed.

Revocation is not really optional. A CA with neither a CRL nor OCSP can issue certificates it can never revoke. If a private key leaks, the only remedy left is to distrust the CA itself - which means replacing every certificate it ever issued.

Other things the module handles:

  • A root CA signs its own certificate, and until that is installed the CA exists and can issue nothing - a state regularly mistaken for a broken CA. install_certificate does it in the same apply
  • signing_algorithm is validated against the SHA-2 ECDSA and RSA variants, so a mismatch with the key family fails at plan rather than at issuance
  • allow_acm_issuance is what makes the CA usable by ALB, CloudFront and the rest without manual certificate handling

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules