All Downloads are FREE. Search and download functionalities are using the official Maven repository.

com.amazonaws.services.acmpca.package-info Maven / Gradle / Ivy

/*
 * Copyright 2014-2019 Amazon.com, Inc. or its affiliates. All Rights Reserved.
 * 
 * Licensed under the Apache License, Version 2.0 (the "License"). You may not use this file except in compliance with
 * the License. A copy of the License is located at
 * 
 * http://aws.amazon.com/apache2.0
 * 
 * or in the "license" file accompanying this file. This file is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR
 * CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions
 * and limitations under the License.
 */

/**
 * 

* You can use the ACM PCA API to create a private certificate authority (CA). You must first call the * CreateCertificateAuthority operation. If successful, the operation returns an Amazon Resource Name (ARN) for * your private CA. Use this ARN as input to the GetCertificateAuthorityCsr operation to retrieve the certificate * signing request (CSR) for your private CA certificate. Sign the CSR using the root or an intermediate CA in your * on-premises PKI hierarchy, and call the ImportCertificateAuthorityCertificate to import your signed private CA * certificate into ACM PCA. *

*

* Use your private CA to issue and revoke certificates. These are private certificates that identify and secure client * computers, servers, applications, services, devices, and users over SSLS/TLS connections within your organization. * Call the IssueCertificate operation to issue a certificate. Call the RevokeCertificate operation to * revoke a certificate. *

* *

* Certificates issued by your private CA can be trusted only within your organization, not publicly. *

*
*

* Your private CA can optionally create a certificate revocation list (CRL) to track the certificates you revoke. To * create a CRL, you must specify a RevocationConfiguration object when you call the * CreateCertificateAuthority operation. ACM PCA writes the CRL to an S3 bucket that you specify. You must * specify a bucket policy that grants ACM PCA write permission. *

*

* You can also call the CreateCertificateAuthorityAuditReport to create an optional audit report, which * enumerates all of the issued, valid, expired, and revoked certificates from the CA. *

* *

* Each ACM PCA API operation has a throttling limit which determines the number of times the operation can be called * per second. For more information, see API Rate Limits in ACM * PCA in the ACM PCA user guide. *

*
*/ package com.amazonaws.services.acmpca;




© 2015 - 2025 Weber Informatics LLC | Privacy Policy