📣 Send us your press release
Site updates every 15 minutes
Technology

AWS Private Certificate Authority Simplifies Certificate Issuance for IAM Roles Anywhere

Amazon Web Services (AWS) has introduced a new integration enabling AWS Private Certificate Authority to issue certificates for use with IAM Roles Anywhere. This enhances security and management for external applications accessing AWS.

2 October 2026
AWS Private Certificate Authority Simplifies Certificate Issuance for IAM Roles Anywhere

Amazon Web Services (AWS) has introduced a new method to integrate AWS Private Certificate Authority (PCA) with IAM Roles Anywhere, streamlining the issuance of X.509 certificates. This new capability is designed to improve security and management for applications running outside of AWS environments that require access to AWS resources.

Traditionally, systems operating outside AWS have faced challenges in managing long-lived credentials, such as access keys. IAM Roles Anywhere addresses this by enabling the use of X.509 certificates for role-based access. With this update, AWS PCA can now be directly utilized to create and issue these certificates, combining AWS's Public Key Infrastructure services with the functionality of IAM Roles Anywhere.

The solution allows systems running outside of AWS to authenticate themselves to AWS by using X.509 certificates. These certificates enable the systems to assume an IAM role and obtain temporary IAM credentials from AWS Security Token Service (AWS STS). This reduces the reliance on long-lived credentials like access keys, thereby minimizing security risks associated with their potential exposure.

This new feature promotes more consistent management across hybrid and multi-cloud environments by leveraging the same IAM policies and roles used within AWS. The validity period of the certificates is defined at the time of request, adding an extra layer of security through time-limited trust. Organizations can further enhance security by using PKCS #11-compatible hardware security modules for storing private keys.

Original source: aws.amazon.com