AWS Certificate Manager Private Certificate Authority

eventNameDescriptionSampleRule
anyCatch-all entry for AWS Certificate Manager Private Certificate Authority rules that match the service but not a specific eventName.NN
CreateCertificateAuthorityCreates a root or subordinate private certificate authority (CA). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreateCertificateAuthorityAuditReportCreates an audit report that lists every time that your CA private key is used to issue a certificate. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
CreatePermissionGrants one or more permissions on a private CA to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeleteCertificateAuthorityDeletes a private certificate authority (CA). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeletePermissionRevokes permissions on a private CA granted to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DeletePolicyDeletes the resource-based policy attached to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
DescribeCertificateAuthorityLists information about your private certificate authority (CA) or one that has been shared with you. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
DescribeCertificateAuthorityAuditReportLists information about a specific audit report created by calling the CreateCertificateAuthorityAuditReport action. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GetCertificateRetrieves a certificate from your private CA or one that has been shared with you.YN
GetCertificateAuthorityCertificateRetrieves the certificate and certificate chain for your private certificate authority (CA) or one that has been shared with you. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetCertificateAuthorityCsrRetrieves the certificate signing request (CSR) for your private certificate authority (CA). Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GetPolicyRetrieves the resource-based policy attached to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ImportCertificateAuthorityCertificateImports a signed private CA certificate into Amazon Web Services Private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
IssueCertificateUses your private certificate authority (CA), or one that has been shared with you, to issue a client certificate. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListCertificateAuthoritiesLists the private certificate authorities that you created by using the CreateCertificateAuthority action. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
ListPermissionsList all permissions on a private CA, if any, granted to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
ListTagsLists the tags, if any, that are associated with your private CA or one that has been shared with you. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
PutPolicyAttaches a resource-based policy to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RestoreCertificateAuthorityRestores a certificate authority (CA) that is in the DELETED state. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
RevokeCertificateRevokes a certificate that was issued inside Amazon Web Services Private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
TagCertificateAuthorityAdds one or more tags to your private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UntagCertificateAuthorityRemove one or more tags from your private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
UpdateCertificateAuthorityUpdates the status or configuration of a private certificate authority (CA). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.NN
GenerateCRLGenerateCRL recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
GenerateOCSPResponseGenerateOCSPResponse recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
SignCertificateSignCertificate recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
SignCRLSignCRL recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN
SignOCSPResponseSignOCSPResponse recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.NN

any: AWS Certificate Manager Private Certificate Authority (catch-all)

#
Service
acm-pca

Description

Catch-all entry for AWS Certificate Manager Private Certificate Authority rules that match the service but not a specific eventName.

CreateCertificateAuthority

#
Service
acm-pca

Description

Creates a root or subordinate private certificate authority (CA). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreateCertificateAuthorityAuditReport

#
Service
acm-pca

Description

Creates an audit report that lists every time that your CA private key is used to issue a certificate. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

CreatePermission

#
Service
acm-pca

Description

Grants one or more permissions on a private CA to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeleteCertificateAuthority

#
Service
acm-pca

Description

Deletes a private certificate authority (CA). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeletePermission

#
Service
acm-pca

Description

Revokes permissions on a private CA granted to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DeletePolicy

#
Service
acm-pca

Description

Deletes the resource-based policy attached to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

DescribeCertificateAuthority

#
Service
acm-pca

Description

Lists information about your private certificate authority (CA) or one that has been shared with you. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "26db7888-6348-353b-b36e-94215660cebe",
  "eventSource": "acm-pca.amazonaws.com",
  "eventName": "DescribeCertificateAuthority",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "32ecf319-73ab-40b4-9757-eef066c9ab0a",
  "userAgent": "aws-sdk-go-v2/1.33.0 ua/2.1 os/linux lang/go#1.23.6 md/GOOS#linux md/GOARCH#amd64 api/acmpca#1.37.13 aws-privateca-issuer/v1.4.1",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::ACMPCA::CertificateAuthority",
      "ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
    }
  ]
}

DescribeCertificateAuthorityAuditReport

#
Service
acm-pca

Description

Lists information about a specific audit report created by calling the CreateCertificateAuthorityAuditReport action. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GetCertificate

#
Service
acm-pca

Description

Retrieves a certificate from your private CA or one that has been shared with you.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: acm-pca:GetCertificate on resource: arn:aws:acm-pca:us-west-2:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012 because no resource-based policy allows the acm-pca:GetCertificate action",
  "eventCategory": "Management",
  "eventID": "10e1548f-893e-46f6-852a-25a9f8cf93e1",
  "eventName": "GetCertificate",
  "eventSource": "acm-pca.amazonaws.com",
  "eventTime": "2024-08-18T09:21:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.09",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "20afe62c-0119-4a04-90b7-6c3ff6a44e71",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "0.0.0.0",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "acm-pca.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_60e9ab1e-1f65-4548-84ba-24f72371f174 cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#acm-pca.get-certificate",
  "userIdentity": {
    "accessKeyId": "AKIA****************",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/TrailDiscover",
    "principalId": "AROA****************:User",
    "type": "IAMUser",
    "userName": "TrailDiscover"
  }
}

References #

GetCertificateAuthorityCertificate

#
Service
acm-pca

Description

Retrieves the certificate and certificate chain for your private certificate authority (CA) or one that has been shared with you. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "87e07e08-e4ff-4e67-93f1-30f069415559",
  "eventSource": "acm-pca.amazonaws.com",
  "eventName": "GetCertificateAuthorityCertificate",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "61c63681-642e-4e7a-9b1f-a5119e20eb95",
  "userAgent": "aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/acmpca#1.44.1 m/E,i",
  "errorCode": "InvalidStateException",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "example.us-east-1.amazonaws.com"
  },
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::ACMPCA::CertificateAuthority",
      "ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
    }
  ]
}

GetCertificateAuthorityCsr

#
Service
acm-pca

Description

Retrieves the certificate signing request (CSR) for your private certificate authority (CA). Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "7db93282-7952-408a-8965-3e3969705d1b",
  "eventSource": "acm-pca.amazonaws.com",
  "eventName": "GetCertificateAuthorityCsr",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "fbf109a4-3ba0-4498-9991-856df44534bc",
  "userAgent": "config.amazonaws.com",
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::ACMPCA::CertificateAuthority",
      "ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
    }
  ]
}

GetPolicy

#
Service
acm-pca

Description

Retrieves the resource-based policy attached to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ImportCertificateAuthorityCertificate

#
Service
acm-pca

Description

Imports a signed private CA certificate into Amazon Web Services Private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

IssueCertificate

#
Service
acm-pca

Description

Uses your private certificate authority (CA), or one that has been shared with you, to issue a client certificate. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "fe13a563-42ed-3f7b-b7a8-857abc6ada2e",
  "eventSource": "acm-pca.amazonaws.com",
  "eventName": "IssueCertificate",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "011852aa-ba13-47f3-8823-f1221f2adf0e",
  "userAgent": "pca-connector-scep.amazonaws.com",
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::ACMPCA::CertificateAuthority",
      "ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
    }
  ]
}

ListCertificateAuthorities

#
Service
acm-pca

Description

Lists the private certificate authorities that you created by using the CreateCertificateAuthority action. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "13417707-2f65-423f-910e-4df089437644",
  "eventSource": "acm-pca.amazonaws.com",
  "eventName": "ListCertificateAuthorities",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "5b9820d4-a26d-44b3-9310-67340cffbbb0",
  "userAgent": "resource-explorer-2.amazonaws.com"
}

ListPermissions

#
Service
acm-pca

Description

List all permissions on a private CA, if any, granted to the Certificate Manager (ACM) service principal (acm.amazonaws.com). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

ListTags

#
Service
acm-pca

Description

Lists the tags, if any, that are associated with your private CA or one that has been shared with you. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

PutPolicy

#
Service
acm-pca

Description

Attaches a resource-based policy to a private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RestoreCertificateAuthority

#
Service
acm-pca

Description

Restores a certificate authority (CA) that is in the DELETED state. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

RevokeCertificate

#
Service
acm-pca

Description

Revokes a certificate that was issued inside Amazon Web Services Private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

TagCertificateAuthority

#
Service
acm-pca

Description

Adds one or more tags to your private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UntagCertificateAuthority

#
Service
acm-pca

Description

Remove one or more tags from your private CA. Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

UpdateCertificateAuthority

#
Service
acm-pca

Description

Updates the status or configuration of a private certificate authority (CA). Model-derived from the AWS SDK operation catalog (botocore); the eventSource is inferred from the SDK endpoint prefix and no CloudTrail sample confirms it yet.

GenerateCRL

#
Service
acm-pca

Description

GenerateCRL recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "14e90dd6-c5f1-40e0-a6a6-c60e414ed050",
  "eventSource": "acm-pca.amazonaws.com",
  "eventName": "GenerateCRL",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "acm-pca.amazonaws.com",
  "resources": [
    {
      "type": "AWS::ACMPCA::CertificateAuthority",
      "ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
    }
  ]
}

GenerateOCSPResponse

#
Service
acm-pca

Description

GenerateOCSPResponse recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.10",
  "eventID": "67631226-0712-458b-a559-3ef9699a4518",
  "eventSource": "acm-pca.amazonaws.com",
  "eventName": "GenerateOCSPResponse",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "acm-pca.amazonaws.com",
  "resources": [
    {
      "type": "AWS::ACMPCA::Certificate",
      "ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
    }
  ]
}

SignCertificate

#
Service
acm-pca

Description

SignCertificate recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.10",
  "eventID": "7927e189-8825-44f9-bc20-fa6087a24293",
  "eventSource": "acm-pca.amazonaws.com",
  "eventName": "SignCertificate",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "acm-pca.amazonaws.com",
  "resources": [
    {
      "type": "AWS::ACMPCA::Certificate",
      "ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
    },
    {
      "type": "AWS::ACMPCA::CertificateAuthority",
      "ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
    }
  ]
}

SignCRL

#
Service
acm-pca

Description

SignCRL recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.10",
  "eventID": "7c7cd4a0-4d47-4df2-aa2a-1a0e9624191e",
  "eventSource": "acm-pca.amazonaws.com",
  "eventName": "SignCRL",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "acm-pca.amazonaws.com",
  "resources": [
    {
      "type": "AWS::ACMPCA::CertificateAuthority",
      "ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
    }
  ]
}

SignOCSPResponse

#
Service
acm-pca

Description

SignOCSPResponse recorded by CloudTrail for AWS Certificate Manager Private Certificate Authority. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. Operation catalog is model-derived from the AWS SDK (botocore); this (eventSource, eventName) pair is confirmed by an observed CloudTrail record.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.10",
  "eventID": "af5a6f75-37be-491b-a31d-b7d7f1433bd5",
  "eventSource": "acm-pca.amazonaws.com",
  "eventName": "SignOCSPResponse",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "acm-pca.amazonaws.com",
  "resources": [
    {
      "type": "AWS::ACMPCA::Certificate",
      "ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
    },
    {
      "type": "AWS::ACMPCA::CertificateAuthority",
      "ARN": "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/EXAMPLE"
    }
  ]
}