# Linkerd Certificate Management with AWS Private CA Issuer

**URL:** <https://linkerd.buoyant.io/t/linkerd-certificate-management-with-aws-private-ca-issuer/796>\
**Category:** Linkerd General Discussion\
**Tags:** certificates\
**Created:** [July 29, 2025, 6:21am UTC](https://linkerd.buoyant.io/t/linkerd-certificate-management-with-aws-private-ca-issuer/796 "2025-07-29T06:21:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![joebowbeer](https://yyz1.discourse-cdn.com/flex029/user_avatar/linkerd.buoyant.io/joebowbeer/32/241_2.png) [@joebowbeer](https://linkerd.buoyant.io/u/joebowbeer)\
**Post date:** [July 29, 2025, 6:21am UTC](https://linkerd.buoyant.io/t/linkerd-certificate-management-with-aws-private-ca-issuer/796/1 "2025-07-29T06:21:16Z")

</div>

Related to an earlier blog post and question:

1. [Workshop Recap: Linkerd Certificate Management with Vault | Linkerd](https://linkerd.io/2024/02/06/linkerd-certificates-with-vault/)
2. [Security and operational considerations when setting intermediate CA cert expiries (cert-manager)](https://linkerd.buoyant.io/t/security-and-operational-considerations-when-setting-intermediate-ca-cert-expiries-cert-manager/280)

I’m looking for a workshop/blog similar to “Linkerd Certificate Management with Vault”, except for AWS Private CA Issuer.

cert-manager/aws-privateca-issuer

Does this exist?

If not, how different would it be from the Vault version?

Is the short-lived (7-day) AWS Issuer mode a candidate for this application?

---

<div class="post-metadata">

**Author:** ![joebowbeer](https://yyz1.discourse-cdn.com/flex029/user_avatar/linkerd.buoyant.io/joebowbeer/32/241_2.png) [@joebowbeer](https://linkerd.buoyant.io/u/joebowbeer)\
**Post date:** [August 5, 2025, 5:02am UTC](https://linkerd.buoyant.io/t/linkerd-certificate-management-with-aws-private-ca-issuer/796/2 "2025-08-05T05:02:42Z")

</div>

> [@joebowbeer](#):
>
> Is the short-lived (7-day) AWS Issuer mode a candidate for this application?

Answer: Yes, according to this article:

[https://aws.amazon.com/blogs/security/how-to-use-aws-private-certificate-authority-short-lived-certificate-mode/](https://aws.amazon.com/blogs/security/how-to-use-aws-private-certificate-authority-short-lived-certificate-mode/)

---

<div class="post-metadata">

**Author:** ![Flynn](https://yyz1.discourse-cdn.com/flex029/user_avatar/linkerd.buoyant.io/flynn/32/41_2.png) [@Flynn](https://linkerd.buoyant.io/u/Flynn)\
**Post date:** [August 5, 2025, 3:04pm UTC](https://linkerd.buoyant.io/t/linkerd-certificate-management-with-aws-private-ca-issuer/796/3 "2025-08-05T15:04:35Z")

</div>

There’s a [cert-manager extension](https://github.com/cert-manager/aws-privateca-issuer) for the AWS Private CA Issuer. I would expect that if you use that extension for your cert-manager (Cluster)Issuers in our normal instructions about certificate management with LInkerd, then it will work. As always, the main thing to be aware of at present is the need for restarts after rotating the trust anchor.
