Low PrivateCA Regional

AWS Private CA root certificate authority should be disabled

NIST 800-53ISO 27001

Description

Flags enabled root certificate authorities in AWS Private CA. Root CAs should remain disabled except when issuing certificates to subordinate CAs, to minimize exposure.


Remediation

Disable root certificate authorities in AWS Private CA and use subordinate CAs for day-to-day operations.

Steps

  1. Open the AWS Private CA console.
  2. Select the root CA.
  3. Choose 'Disable' to disable the root CA.
  4. Use subordinate CAs for issuing end-entity certificates.

Compliance

NIST 800-53ISO 27001