Low
PCA
Regional
AWS Private CA certificate authorities should be tagged
Description
Flags AWS Private CA certificate authorities that have no user-defined tags. Tags help associate CAs with their owning team and trust hierarchy; untagged CAs are operationally opaque.
Remediation
Apply at least one user-defined tag to every Private CA certificate authority.
Steps
- Open the AWS Private CA console and select the CA.
- Choose the Tags tab.
- Add at least one tag with a non-aws: prefixed key.
- Save the changes.