You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: clients/client-acm-pca/README.md
+13-14
Original file line number
Diff line number
Diff line change
@@ -7,23 +7,22 @@
7
7
8
8
AWS SDK for JavaScript ACMPCA Client for Node.js, Browser and React Native.
9
9
10
-
<p>This is the <i>ACM Private CA API Reference</i>. It provides descriptions,
10
+
<p>This is the <i>Amazon Web Services Private Certificate Authority API Reference</i>. It provides descriptions,
11
11
syntax, and usage examples for each of the actions and data types involved in creating
12
-
and managing private certificate authorities (CA) for your organization.</p>
13
-
<p>The documentation for each action shows the Query API request parameters and the XML
14
-
response. Alternatively, you can use one of the AWS SDKs to access an API that's
15
-
tailored to the programming language or platform that you're using. For more
16
-
information, see <ahref="https://aws.amazon.com/tools/#SDKs">AWS
17
-
SDKs</a>.</p>
18
-
<p>Each ACM Private CA API operation has a quota that determines the number of times the operation
19
-
can be called per second. ACM Private CA throttles API requests at different rates depending
20
-
on the operation. Throttling means that ACM Private CA rejects an otherwise valid request
21
-
because the request exceeds the operation's quota for the number of requests per second.
22
-
When a request is throttled, ACM Private CA returns a <ahref="https://docs.aws.amazon.com/acm-pca/latest/APIReference/CommonErrors.html">ThrottlingException</a> error. ACM Private CA does not guarantee a minimum request
12
+
and managing a private certificate authority (CA) for your organization.</p>
13
+
<p>The documentation for each action shows the API request parameters and the JSON
14
+
response. Alternatively, you can use one of the Amazon Web Services SDKs to access an API that is
15
+
tailored to the programming language or platform that you prefer. For more information,
16
+
see <ahref="https://aws.amazon.com/tools/#SDKs">Amazon Web Services SDKs</a>.</p>
17
+
<p>Each Amazon Web Services Private CA API operation has a quota that determines the number of times the
18
+
operation can be called per second. Amazon Web Services Private CA throttles API requests at different rates
19
+
depending on the operation. Throttling means that Amazon Web Services Private CA rejects an otherwise valid
20
+
request because the request exceeds the operation's quota for the number of requests per
21
+
second. When a request is throttled, Amazon Web Services Private CA returns a <ahref="https://docs.aws.amazon.com/acm-pca/latest/APIReference/CommonErrors.html">ThrottlingException</a> error. Amazon Web Services Private CA does not guarantee a minimum request
23
22
rate for APIs. </p>
24
23
25
-
<p>To see an up-to-date list of your ACM Private CA quotas, or to request a quota increase,
26
-
log into your AWS account and visit the <ahref="https://console.aws.amazon.com/servicequotas/">Service Quotas</a>
24
+
<p>To see an up-to-date list of your Amazon Web Services Private CA quotas, or to request a quota increase,
25
+
log into your Amazon Web Services account and visit the <ahref="https://console.aws.amazon.com/servicequotas/">Service Quotas</a>
* <p>This is the <i>ACM Private CA API Reference</i>. It provides descriptions,
322
+
* <p>This is the <i>Amazon Web Services Private Certificate Authority API Reference</i>. It provides descriptions,
323
323
* syntax, and usage examples for each of the actions and data types involved in creating
324
-
* and managing private certificate authorities (CA) for your organization.</p>
325
-
* <p>The documentation for each action shows the Query API request parameters and the XML
326
-
* response. Alternatively, you can use one of the AWS SDKs to access an API that's
327
-
* tailored to the programming language or platform that you're using. For more
328
-
* information, see <a href="https://aws.amazon.com/tools/#SDKs">AWS
329
-
* SDKs</a>.</p>
330
-
* <p>Each ACM Private CA API operation has a quota that determines the number of times the operation
331
-
* can be called per second. ACM Private CA throttles API requests at different rates depending
332
-
* on the operation. Throttling means that ACM Private CA rejects an otherwise valid request
333
-
* because the request exceeds the operation's quota for the number of requests per second.
334
-
* When a request is throttled, ACM Private CA returns a <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/CommonErrors.html">ThrottlingException</a> error. ACM Private CA does not guarantee a minimum request
324
+
* and managing a private certificate authority (CA) for your organization.</p>
325
+
* <p>The documentation for each action shows the API request parameters and the JSON
326
+
* response. Alternatively, you can use one of the Amazon Web Services SDKs to access an API that is
327
+
* tailored to the programming language or platform that you prefer. For more information,
328
+
* see <a href="https://aws.amazon.com/tools/#SDKs">Amazon Web Services SDKs</a>.</p>
329
+
* <p>Each Amazon Web Services Private CA API operation has a quota that determines the number of times the
330
+
* operation can be called per second. Amazon Web Services Private CA throttles API requests at different rates
331
+
* depending on the operation. Throttling means that Amazon Web Services Private CA rejects an otherwise valid
332
+
* request because the request exceeds the operation's quota for the number of requests per
333
+
* second. When a request is throttled, Amazon Web Services Private CA returns a <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/CommonErrors.html">ThrottlingException</a> error. Amazon Web Services Private CA does not guarantee a minimum request
335
334
* rate for APIs. </p>
336
335
*
337
-
* <p>To see an up-to-date list of your ACM Private CA quotas, or to request a quota increase,
338
-
* log into your AWS account and visit the <a href="https://console.aws.amazon.com/servicequotas/">Service Quotas</a>
336
+
* <p>To see an up-to-date list of your Amazon Web Services Private CA quotas, or to request a quota increase,
337
+
* log into your Amazon Web Services account and visit the <a href="https://console.aws.amazon.com/servicequotas/">Service Quotas</a>
* <p>Creates an audit report that lists every time that your CA private key is used. The
32
-
* report is saved in the Amazon S3 bucket that you specify on input.
33
-
*
34
-
* The <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_IssueCertificate.html">IssueCertificate</a> and <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_RevokeCertificate.html">RevokeCertificate</a> actions use
31
+
* <p>Creates an audit report that lists every time that your CA private key is used. The report
32
+
* is saved in the Amazon S3 bucket that you specify on input. The <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_IssueCertificate.html">IssueCertificate</a> and <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_RevokeCertificate.html">RevokeCertificate</a> actions use
35
33
* the private key. </p>
36
-
* <note>
34
+
* <note>
37
35
* <p>Both PCA and the IAM principal must have permission to write to
38
36
* the S3 bucket that you specify. If the IAM principal making the call
39
37
* does not have permission to write to the bucket, then an exception is
40
-
* thrown. For more information, see <a href="https://docs.aws.amazon.com/acm-pca/latest/userguide/PcaAuthAccess.html">Configure
41
-
* Access to ACM Private CA</a>.</p>
42
-
* </note>
43
-
*
44
-
* <p>ACM Private CA assets that are stored in Amazon S3 can be protected with encryption.
38
+
* thrown. For more information, see <a href="https://docs.aws.amazon.com/acm-pca/latest/userguide/crl-planning.html#s3-policies">Access
39
+
* policies for CRLs in Amazon S3</a>.</p>
40
+
* </note>
41
+
* <p>Amazon Web Services Private CA assets that are stored in Amazon S3 can be protected with encryption.
45
42
* For more information, see <a href="https://docs.aws.amazon.com/acm-pca/latest/userguide/PcaAuditReport.html#audit-report-encryption">Encrypting Your Audit
46
43
* Reports</a>.</p>
44
+
* <note>
45
+
* <p>You can generate a maximum of one report every 30 minutes.</p>
46
+
* </note>
47
47
* @example
48
48
* Use a bare-bones client and the command you need to make an API call.
* <p>Grants one or more permissions on a private CA to the AWS Certificate Manager (ACM) service
25
+
* <p>Grants one or more permissions on a private CA to the Certificate Manager (ACM) service
26
26
* principal (<code>acm.amazonaws.com</code>). These permissions allow ACM to issue and
27
-
* renew ACM certificates that reside in the same AWS account as the CA.</p>
27
+
* renew ACM certificates that reside in the same Amazon Web Services account as the CA.</p>
28
28
* <p>You can list current permissions with the <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_ListPermissions.html">ListPermissions</a> action and
29
29
* revoke them with the <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_DeletePermission.html">DeletePermission</a> action.</p>
* To do this, call the <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_UpdateCertificateAuthority.html">UpdateCertificateAuthority</a> action and set the <b>CertificateAuthorityStatus</b> parameter to <code>DISABLED</code>. </p>
34
34
* <p>Additionally, you can delete a CA if you are waiting for it to be created (that is,
35
35
* the status of the CA is <code>CREATING</code>). You can also delete it if the CA has
36
-
* been created but you haven't yet imported the signed certificate into ACM Private CA (that is,
37
-
* the status of the CA is <code>PENDING_CERTIFICATE</code>). </p>
36
+
* been created but you haven't yet imported the signed certificate into Amazon Web Services Private CA (that
37
+
* is, the status of the CA is <code>PENDING_CERTIFICATE</code>). </p>
38
38
* <p>When you successfully call <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_DeleteCertificateAuthority.html">DeleteCertificateAuthority</a>, the CA's status changes to
39
39
* <code>DELETED</code>. However, the CA won't be permanently deleted until the restoration
40
40
* period has passed. By default, if you do not set the
* <p>Revokes permissions on a private CA granted to the AWS Certificate Manager (ACM) service principal
25
+
* <p>Revokes permissions on a private CA granted to the Certificate Manager (ACM) service principal
26
26
* (acm.amazonaws.com). </p>
27
27
* <p>These permissions allow ACM to issue and renew ACM certificates that reside in the
28
-
* same AWS account as the CA. If you revoke these permissions, ACM will no longer
28
+
* same Amazon Web Services account as the CA. If you revoke these permissions, ACM will no longer
29
29
* renew the affected certificates automatically.</p>
30
30
* <p>Permissions can be granted with the <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_CreatePermission.html">CreatePermission</a> action and
31
31
* listed with the <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_ListPermissions.html">ListPermissions</a> action. </p>
* <p>Deletes the resource-based policy attached to a private CA. Deletion will remove any
26
26
* access that the policy has granted. If there is no policy attached to the private CA,
27
27
* this action will return successful.</p>
28
-
* <p>If you delete a policy that was applied through AWS Resource Access Manager (RAM), the
29
-
* CA will be removed from all shares in which it was included. </p>
30
-
* <p>The AWS Certificate Manager Service Linked Role that the policy supports is not affected when you
28
+
* <p>If you delete a policy that was applied through Amazon Web Services Resource Access Manager (RAM),
29
+
* the CA will be removed from all shares in which it was included. </p>
30
+
* <p>The Certificate Manager Service Linked Role that the policy supports is not affected when you
31
31
* delete the policy. </p>
32
32
* <p>The current policy can be shown with <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_GetPolicy.html">GetPolicy</a> and updated with <a href="https://docs.aws.amazon.com/acm-pca/latest/APIReference/API_PutPolicy.html">PutPolicy</a>.</p>
33
33
* <p class="title">
34
34
* <b>About Policies</b>
35
35
* </p>
36
36
* <ul>
37
37
* <li>
38
-
* <p>A policy grants access on a private CA to an AWS customer account, to AWS Organizations, or to
39
-
* an AWS Organizations unit. Policies are under the control of a CA administrator. For more information,
40
-
* see <a href="https://docs.aws.amazon.com/acm-pca/latest/userguide/pca-rbp.html">Using a Resource Based Policy with ACM Private CA</a>.</p>
38
+
* <p>A policy grants access on a private CA to an Amazon Web Services customer account, to Amazon Web Services Organizations, or to
39
+
* an Amazon Web Services Organizations unit. Policies are under the control of a CA administrator. For more information,
40
+
* see <a href="https://docs.aws.amazon.com/acm-pca/latest/userguide/pca-rbp.html">Using a Resource Based Policy with Amazon Web Services Private CA</a>.</p>
41
41
* </li>
42
42
* <li>
43
-
* <p>A policy permits a user of AWS Certificate Manager (ACM) to issue ACM certificates
43
+
* <p>A policy permits a user of Certificate Manager (ACM) to issue ACM certificates
44
44
* signed by a CA in another account.</p>
45
45
* </li>
46
46
* <li>
47
47
* <p>For ACM to manage automatic renewal of these certificates,
48
48
* the ACM user must configure a Service Linked Role (SLR). The SLR allows
49
49
* the ACM service to assume the identity of the user, subject to confirmation against the
50
-
* ACM Private CA policy. For more information, see
50
+
* Amazon Web Services Private CA policy. For more information, see
51
51
* <a href="https://docs.aws.amazon.com/acm/latest/userguide/acm-slr.html">Using a
52
52
* Service Linked Role with ACM</a>.</p>
53
53
* </li>
54
54
* <li>
55
-
* <p>Updates made in AWS Resource Manager (RAM) are reflected in policies. For more information,
55
+
* <p>Updates made in Amazon Web Services Resource Manager (RAM) are reflected in policies. For more information,
56
56
* see <a href="https://docs.aws.amazon.com/acm-pca/latest/userguide/pca-ram.html">Attach a Policy for Cross-Account
0 commit comments