AWS Certificate Manager Private Certificate Authority
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for AWS Certificate Manager Private Certificate Authority rules that match the service but not a specific eventName. | N | N |
| Create | Creates a root or subordinate private certificate authority (CA). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Creates an audit report that lists every time that your CA private key is used to issue a certificate. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Create | Grants one or more permissions on a private CA to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes a private certificate authority (CA). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Revokes permissions on a private CA granted to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Delete | Deletes the resource-based policy attached to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Describe | Lists information about your private certificate authority (CA) or one that has been shared with you. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Describe | Lists information about a specific audit report created by calling the CreateCertificateAuthorityAuditReport action. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Get | Retrieves a certificate from your private CA or one that has been shared with you. | Y | N |
| Get | Retrieves the certificate and certificate chain for your private certificate authority (CA) or one that has been shared with you. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | Retrieves the certificate signing request (CSR) for your private certificate authority (CA). Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Get | Retrieves the resource-based policy attached to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Import | Imports a signed private CA certificate into Amazon Web Services Private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Issue | Uses your private certificate authority (CA), or one that has been shared with you, to issue a client certificate. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | Lists the private certificate authorities that you created by using the CreateCertificateAuthority action. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| List | List all permissions on a private CA, if any, granted to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| List | Lists the tags, if any, that are associated with your private CA or one that has been shared with you. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Put | Attaches a resource-based policy to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Restore | Restores a certificate authority (CA) that is in the DELETED state. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Revoke | Revokes a certificate that was issued inside Amazon Web Services Private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Tag | Adds one or more tags to your private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Untag | Remove one or more tags from your private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Update | Updates the status or configuration of a private certificate authority (CA). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet. | N | N |
| Generate | GenerateCRL recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Generate | GenerateOCSPResponse recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Sign | SignCertificate recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Sign | SignCRL recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
| Sign | SignOCSPResponse recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record. | N | N |
any: AWS Certificate Manager Private Certificate Authority (catch-all)
#Description
Catch-all entry for AWS Certificate Manager Private Certificate Authority rules that match the service but not a specific eventName.
CreatePermission
#Description
Grants one or more permissions on a private CA to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeletePermission
#Description
Revokes permissions on a private CA granted to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
DeletePolicy
#Description
Deletes the resource-based policy attached to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GetCertificate
#Description
Retrieves a certificate from your private CA or one that has been shared with you.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: acm-pca:GetCertificate on resource: arn:aws:acm-pca:us-west-2:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012 because no resource-based policy allows the acm-pca:GetCertificate action",
"eventCategory": "Management",
"eventID": "10e1548f-893e-46f6-852a-25a9f8cf93e1",
"eventName": "GetCertificate",
"eventSource": "acm-pca.amazonaws.com",
"eventTime": "2024-08-18T09:21:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.09",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "20afe62c-0119-4a04-90b7-6c3ff6a44e71",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "0.0.0.0",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "acm-pca.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_60e9ab1e-1f65-4548-84ba-24f72371f174 cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#acm-pca.get-certificate",
"userIdentity": {
"accessKeyId": "AKIA****************",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/TrailDiscover",
"principalId": "AROA****************:User",
"type": "IAMUser",
"userName": "TrailDiscover"
}
}
References #
GetPolicy
#Description
Retrieves the resource-based policy attached to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
IssueCertificate
#Description
Uses your private certificate authority (CA), or one that has been shared with you, to issue a client certificate. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "fe13a563-42ed-3f7b-b7a8-857abc6ada2e",
"eventSource": "acm-pca.amazonaws.com",
"eventName": "IssueCertificate",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "011852aa-ba13-47f3-8823-f1221f2adf0e",
"userAgent": "pca-connector-scep.amazonaws.com",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::ACMPCA::CertificateAuthority",
"ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
}
]
}
ListPermissions
#Description
List all permissions on a private CA, if any, granted to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
PutPolicy
#Description
Attaches a resource-based policy to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
RevokeCertificate
#Description
Revokes a certificate that was issued inside Amazon Web Services Private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.
GenerateCRL
#Description
GenerateCRL recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "14e90dd6-c5f1-40e0-a6a6-c60e414ed050",
"eventSource": "acm-pca.amazonaws.com",
"eventName": "GenerateCRL",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "acm-pca.amazonaws.com",
"resources": [
{
"type": "AWS::ACMPCA::CertificateAuthority",
"ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
}
]
}
GenerateOCSPResponse
#Description
GenerateOCSPResponse recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.10",
"eventID": "67631226-0712-458b-a559-3ef9699a4518",
"eventSource": "acm-pca.amazonaws.com",
"eventName": "GenerateOCSPResponse",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "acm-pca.amazonaws.com",
"resources": [
{
"type": "AWS::ACMPCA::Certificate",
"ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
}
]
}
SignCertificate
#Description
SignCertificate recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.10",
"eventID": "7927e189-8825-44f9-bc20-fa6087a24293",
"eventSource": "acm-pca.amazonaws.com",
"eventName": "SignCertificate",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "acm-pca.amazonaws.com",
"resources": [
{
"type": "AWS::ACMPCA::Certificate",
"ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
},
{
"type": "AWS::ACMPCA::CertificateAuthority",
"ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
}
]
}
SignCRL
#Description
SignCRL recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.10",
"eventID": "7c7cd4a0-4d47-4df2-aa2a-1a0e9624191e",
"eventSource": "acm-pca.amazonaws.com",
"eventName": "SignCRL",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "acm-pca.amazonaws.com",
"resources": [
{
"type": "AWS::ACMPCA::CertificateAuthority",
"ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
}
]
}
SignOCSPResponse
#Description
SignOCSPResponse recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.10",
"eventID": "af5a6f75-37be-491b-a31d-b7d7f1433bd5",
"eventSource": "acm-pca.amazonaws.com",
"eventName": "SignOCSPResponse",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "acm-pca.amazonaws.com",
"resources": [
{
"type": "AWS::ACMPCA::Certificate",
"ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
},
{
"type": "AWS::ACMPCA::CertificateAuthority",
"ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
}
]
}