AWS Private CA Issuer Review
SkillCloud & infraUse this skill when reviewing AWS ACM Private CA (Private Certificate Authority) issuer configurations for cert-manager. Trigger on any request to audit AWSPCAIssuer, AWSPCAClusterIssuer, IRSA policy for cert-manager, certificate template ARNs, CRL configuration, or cross-account PCA usage.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the AWS Private CA Issuer Review skill
What this skill tells your AI
The instructions your AI receives, as published by vincentchuwaichow/vanguard-frontier-agentic in skills/aws/aws-private-ca-issuer-review/SKILL.md and read by ahel’s review.
Purpose
Review AWS ACM Private Certificate Authority configurations used by the cert-manager aws-privateca-issuer plugin. Identify CA hierarchy misconfigurations, overly permissive certificate templates, excessive IRSA permissions, unsafe validity periods, CRL reachability gaps, and cross-account PCA setup risks.
Lean operating rules
- Flag any
AWSPCAIssuerreferencing a ROOT CA ARN directly as CRITICAL — only a SUBORDINATE CA should be active for cert-manager issuance. - Check
spec.template.arn: flag any SubordinateCACertificate template as CRITICAL (allows cert-manager to mint sub-CAs). Correct template isEndEntityCertificate/V1. - Review IRSA role policy: required actions are
acm-pca:IssueCertificate,acm-pca:GetCertificate,acm-pca:DescribeCertificateAuthority. Flagacm-pca:DeleteCertificateAuthorityoracm-pca:CreateCertificateAuthorityas HIGH. - Review
spec.durationin Certificate resources; flag durations > 365d for workload certs as MEDIUM; best practice is <= 90d. - Check CRL S3 bucket reachability from within the VPC; flag unreachable CRL distribution points as HIGH (revocation disabled).
- For cross-account PCA (RAM-shared CA): verify minimum issuance-only permissions in the security account.
- Label all claims as live evidence, documentation-based, or inference.
References
Load these only when needed:
- Workflow and output contract
- Safety checklist
- Official sources
- Private CA Issuer Trust Boundaries Guide — use for domain-specific failure modes, safe workflow, verification targets, and pushback criteria.
Response minimum
- Severity-labeled findings list (CRITICAL / HIGH / MEDIUM / LOW)
- Evidence source for each finding
- Specific resource name or field path
- Recommended remediation with example policy or YAML snippet
- Overall PKI trust posture verdict
Signals
- GitHub stars
- 22
- Forks
- 3
- Last commit
- Sep 2026
ahel review
S4info
community integration — published by vincentchuwaichow, not aws
Automated review, not a security audit. Ruleset v1+k2.
Advanced
- Catalog kind
- skill
- Gateway key
aws-private-ca-issuer-review- Source
- github.com/vincentchuwaichow/vanguard-frontier-agentic