-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathacm-root-ca.tf
40 lines (30 loc) · 1.01 KB
/
acm-root-ca.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
# Our CA
locals {
domain = "test.local"
}
resource "aws_acmpca_certificate_authority_certificate" "rootCA" {
certificate_authority_arn = aws_acmpca_certificate_authority.rootCA.arn
certificate = aws_acmpca_certificate.rootCA.certificate
certificate_chain = aws_acmpca_certificate.rootCA.certificate_chain
}
resource "aws_acmpca_certificate" "rootCA" {
certificate_authority_arn = aws_acmpca_certificate_authority.rootCA.arn
certificate_signing_request = aws_acmpca_certificate_authority.rootCA.certificate_signing_request
signing_algorithm = "SHA512WITHRSA"
template_arn = "arn:${data.aws_partition.current.partition}:acm-pca:::template/RootCACertificate/V1"
validity {
type = "YEARS"
value = 20
}
}
resource "aws_acmpca_certificate_authority" "rootCA" {
type = "ROOT"
certificate_authority_configuration {
key_algorithm = "RSA_4096"
signing_algorithm = "SHA512WITHRSA"
subject {
common_name = local.domain
}
}
}
data "aws_partition" "current" {}