Configure Amazon ACM Private Key Exportability in Policy Central
Use this procedure to enroll Amazon ACM certificates with exportable private-key options from Policy Central in KUBE.
- Amazon CA integration is configured in KUBE.
- A Policy Central cluster policy exists with an Amazon ACM issuance template.
- You have permission to create or run certificate enrollment from KUBE.
-
Go to menu > KUBE >
GROUPS & POLICIES >
Cluster Policy.
The Cluster Policy inventory page is displayed.
-
Create a new Policy Central cluster policy or edit an existing one, then open
its certificate enrollment or issuance template details for Amazon ACM.
The enrollment fields for Amazon ACM are displayed.
-
Enable privateKeyExportable to request the certificate
in AWS ACM with an exportable private key.
The request is configured to create an exportable private key for that certificate enrollment.
-
(Optional) Enable retrievePrivateKey to have AppViewX
retrieve the private key after issuance and store it for certificate lifecycle
operations.
Private key retrieval is configured for completed enrollments.
-
Complete the remaining enrollment fields and submit the enrollment request.
The certificate request is submitted to Amazon ACM with the selected private-key behavior.
-
After issuance, verify the certificate details in KUBE to confirm the
enrollment completed with the configured private-key options.
The certificate is available in KUBE according to the selected Policy Central settings.
Policy Central enrollment for Amazon ACM uses explicit private-key exportability and retrieval settings, aligned with your certificate lifecycle requirements.
