Skip to main content

πŸ’Ό [PCA.1] AWS Private CA root certificate authority should be disabled

  • Contextual name: πŸ’Ό [PCA.1] AWS Private CA root certificate authority should be disabled
  • ID: /frameworks/aws-fsbp-v1.0.0/pca/01
  • Located in: πŸ’Ό Private Certificate Authority (CA)

Description​

With AWS Private CA, you can create a CA hierarchy that includes a root CA and subordinate CAs. You should minimize the use of the root CA for daily tasks, especially in production environments. The root CA should only be used to issue certificates for intermediate CAs. This allows the root CA to be stored out of harm's way while the intermediate CAs perform the daily task of issuing end-entity certificates.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CA-9(1) Internal System Connections _ Compliance Checks15
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2 Baseline Configuration713

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags