-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathacm-secondary-ca.tf
32 lines (25 loc) · 1022 Bytes
/
acm-secondary-ca.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
resource "aws_acmpca_certificate_authority_certificate" "subordinate" {
certificate_authority_arn = aws_acmpca_certificate_authority.subordinate.arn
certificate = aws_acmpca_certificate.subordinate.certificate
certificate_chain = aws_acmpca_certificate.subordinate.certificate_chain
}
resource "aws_acmpca_certificate" "subordinate" {
certificate_authority_arn = aws_acmpca_certificate_authority.rootCA.arn
certificate_signing_request = aws_acmpca_certificate_authority.subordinate.certificate_signing_request
signing_algorithm = "SHA512WITHRSA"
template_arn = "arn:${data.aws_partition.current.partition}:acm-pca:::template/SubordinateCACertificate_PathLen0/V1"
validity {
type = "YEARS"
value = 10
}
}
resource "aws_acmpca_certificate_authority" "subordinate" {
type = "SUBORDINATE"
certificate_authority_configuration {
key_algorithm = "RSA_2048"
signing_algorithm = "SHA512WITHRSA"
subject {
common_name = "sub.${local.domain}"
}
}
}