Low
PrivateCA
Regional
AWS Private CA root certificate authority should be disabled
NIST 800-53ISO 27001
Description
Flags enabled root certificate authorities in AWS Private CA. Root CAs should remain disabled except when issuing certificates to subordinate CAs, to minimize exposure.
Remediation
Disable root certificate authorities in AWS Private CA and use subordinate CAs for day-to-day operations.
Steps
- Open the AWS Private CA console.
- Select the root CA.
- Choose 'Disable' to disable the root CA.
- Use subordinate CAs for issuing end-entity certificates.
Compliance
NIST 800-53ISO 27001