All Services

Security & IAM

AWS Private Certificate Authority

AWS Private Certificate Authority operates hosted private root or subordinate certificate authorities that issue and revoke private X.509 certificates for workloads, devices, users, and supported AWS service integrations.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Private Certificate Authority.

AWS Private Certificate Authority pricing and cost programs

Pricing model: Private CA and certificate usage

On-Demand
Available
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: CA operation · Certificates issued · Short-lived certificate mode

Programs and modes: General-purpose CAs · Short-lived certificate CAs · Private certificates

CA mode and certificate volume determine charges.

Free Tier: Service-specific — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement AWS Private Certificate Authority?

  • Provides managed CA key protection and certificate issuance APIs without operating on-premises CA servers and HSM-backed signing infrastructure.
  • Supports root and subordinate hierarchies, external parent CAs, templates, ACM integrations, revocation through CRLs or OCSP, and cross-account use.
  • Scales certificate issuance for private TLS, mutual TLS, devices, service meshes, Kubernetes, and enterprise identity systems.

How to implement AWS Private Certificate Authority

  1. Create a certificate policy and practices statement covering trust scope, hierarchy, namespaces, algorithms, validity, path length, issuance, revocation, audit, succession, compromise, and CA deletion.
  2. Place the root CA in a dedicated account, keep it offline from routine issuance, create constrained subordinate CAs for workloads, separate administrators from issuers, and limit templates and IAM permissions.
  3. Configure OCSP or private CRLs, distribute trust anchors safely, inventory issued certificates, monitor CloudTrail and expiry, rehearse revocation and CA succession, and delete unused CAs to stop charges.

AWS Private Certificate Authority best practices

  • Minimize root CA use, place it in its own protected account, use it primarily to sign intermediates, and require MFA and separation of duties for CA administration.
  • Constrain subordinate purpose and path length, use short end-entity validity where operations allow, implement revocation, keep CRL buckets private, and document every trust relationship.
  • Plan CA key rotation and succession well before expiry because replacing a CA changes its ARN and trust anchors; test application renewal and revocation behavior instead of assuming clients enforce it.

AWS Private Certificate Authority use cases and server impact

  • Private TLS and mutual TLS
  • Device and workload identity certificates
  • Enterprise and Kubernetes private PKI

Replaces hosted CA signing servers and much PKI infrastructure, while trust design, issuance policy, certificate inventory, revocation, client behavior, and incident response remain customer responsibilities.

Official implementation resources

Commonly paired AWS services