ACM Private CA now supports custom subject names, extensions, and name constraints
Share
Services
[AWS Certificate Manager (ACM) Private Certificate Authority (CA)](/certificate-manager/private-certificate-authority/) now supports customizable certificate subject names. Security and public key infrastructure (PKI) administrators, builders, and developers now have greater control over the types of certificate subject names they can create using ACM Private CA. For example, it’s now possible to represent your organization’s directory structure in certificates by including multiple organizational units (OUs) in your certificate subject names. It’s also possible to create subject names representing Internet of Things (IoT) product and vendor identifiers such as those conforming to [Matter](https://csa-iot.org/all-solutions/matter/), a new industry standard for secure and reliable home automation devices.
This launch also provides customers with the ability to include special purpose extensions in certificates. This includes the name constraint extension in CA certificates. Name constraints are rules for allowing or preventing subject names in certificates. For example, an organization can now create a name-constrained CA for their cloud infrastructure, separate from their on-premises CAs, and require all certificates to use the subject name “.cloud.example.com”. ACM Private CA now also supports any custom extension for end-user certificates. This includes the Qualified Certificate extension used with [Qualified Web Authentication Certificates](https://en.wikipedia.org/wiki/Qualified%5Fwebsite%5Fauthentication%5Fcertificate) (QWAC), which are a specific EU form of website certificate.
For more information about these features, visit ACM Private CA documentation to see how to [Issue a certificate with Custom Subject Names](https://docs.aws.amazon.com/acm-pca/latest/userguide/PcaIssueCert.html#custom-subject-1) or [Issue a certificate with Custom Extensions](https://docs.aws.amazon.com/acm-pca/latest/userguide/PcaIssueCert.html#custom-subject-2). For Java code examples, visit [Java API Custom Subject Names](https://docs.aws.amazon.com/acm-pca/latest/userguide/JavaApi-CustomAttributes.html) or [Java API Custom Extensions](https://docs.aws.amazon.com/acm-pca/latest/userguide/JavaApi-CustomExtensions.html). To learn more about using ACM Private CA, visit the [product page](/certificate-manager/private-certificate-authority/).
What else is happening at Amazon Web Services?
Amazon AppStream 2.0 users can now save their user preferences between streaming sessions
December 13th, 2024
Services
Share
AWS Elemental MediaConnect Gateway now supports source-specific multicast
December 13th, 2024
Services
Share
Amazon EC2 instances support bandwidth configurations for VPC and EBS
December 13th, 2024
Services
Share
AWS announces new AWS Direct Connect location in Osaka, Japan
December 13th, 2024
Services
Share
Amazon DynamoDB announces support for FIPS 140-3 interface VPC and Streams endpoints
December 13th, 2024
Services
Share