Low PCA Regional

AWS Private CA certificate authorities should be tagged

Description

Flags AWS Private CA certificate authorities that have no user-defined tags. Tags help associate CAs with their owning team and trust hierarchy; untagged CAs are operationally opaque.


Remediation

Apply at least one user-defined tag to every Private CA certificate authority.

Steps

  1. Open the AWS Private CA console and select the CA.
  2. Choose the Tags tab.
  3. Add at least one tag with a non-aws: prefixed key.
  4. Save the changes.