Skip to main content

AWS Private CA

Link DigiCert​​®​​ Trust Lifecycle Manager to your AWS account to import, enroll, and manage certificates from AWS Private CA certificate authorities.

Before you begin

You need an active DigiCert sensor to establish and manage the connection to your Amazon AWS account. To learn more, see Deploy and manage sensors.

Manage AWS connector

To manage an AWS connector in your account:

  1. From the main menu, select Integrations > Connectors.

  2. Hover the connector name and open the actions menu on the right.

  3. Alternatively, select the connector by name to view the details and manage it from there.

Available management functions for the connector include:

  • Run now: Run the connector service, for example to import certificates from the linked account.

  • Test connection: Test connectivity to the linked account.

  • Delete: Unlink from the external account and delete the connector for it.

Issue certificates from AWS Private CAs

To start getting certificates from the private CAs in your AWS account, create a certificate profile based on the AWS Private CA server certificate template in DigiCert​​®​​ Trust Lifecycle Manager.

In the certificate profile, select from the following enrollment options based on how and where you want to install the AWS-issued certificates:

  • DigiCert agent: To install certificates on a web server using a DigiCert automation agent.

  • DigiCert sensor: To install certificates on a network appliance or cloud service using a DigiCert sensor.

  • 3rd-party ACME client: To install certificates on a web server using a third-party ACME client like Certbot.

Revoke AWS-issued certificates

To revoke certificates from AWS Private CAs, go the Inventory page in DigiCert​​®​​ Trust Lifecycle Manager. See Manage inventory.