Configure Amazon ACM Private Key Exportability in Policy Central

Use this procedure to enroll Amazon ACM certificates with exportable private-key options from Policy Central in KUBE.

  • Amazon CA integration is configured in KUBE.
  • A Policy Central cluster policy exists with an Amazon ACM issuance template.
  • You have permission to create or run certificate enrollment from KUBE.
  1. Go to menu > KUBE > GROUPS & POLICIES > Cluster Policy.
    The Cluster Policy inventory page is displayed.
  2. Create a new Policy Central cluster policy or edit an existing one, then open its certificate enrollment or issuance template details for Amazon ACM.
    The enrollment fields for Amazon ACM are displayed.
  3. Enable privateKeyExportable to request the certificate in AWS ACM with an exportable private key.
    The request is configured to create an exportable private key for that certificate enrollment.
  4. (Optional) Enable retrievePrivateKey to have AppViewX retrieve the private key after issuance and store it for certificate lifecycle operations.
    Private key retrieval is configured for completed enrollments.
  5. Complete the remaining enrollment fields and submit the enrollment request.
    The certificate request is submitted to Amazon ACM with the selected private-key behavior.
  6. After issuance, verify the certificate details in KUBE to confirm the enrollment completed with the configured private-key options.
    The certificate is available in KUBE according to the selected Policy Central settings.

Policy Central enrollment for Amazon ACM uses explicit private-key exportability and retrieval settings, aligned with your certificate lifecycle requirements.