Configure sslTrus CaaS for AWS ACM
Prerequisites
Before you start configuration, make sure you have completed the following preparations:
- Purchase the sslTrus CaaS service: Complete the CaaS subscription purchase first. For detailed purchase instructions, refer to sslTrus CaaS Purchase Guide.
- Apply for an SSL certificate: Make sure you have successfully requested and had the certificate issued. For the detailed request process, refer to sslTrus CaaS Certificate Request.
Configure Installation Point — Certificate Update (AWS ACM)
Configure the AWS ACM Management Interface
Prerequisite
Prepare the AK/SK of the AWS account used to manage ACM in advance.
- Go to the console backend > Asset Management > Vendor Management, select Amazon Web Services, and click Manage.

- Click Add Account.

- Enter the account name and the AccessKey and SecretKey of the AWS ACM management account, then click Save.

Permission Description
The AK/SK for AWS ACM must have the following permissions enabled:
- GetCertificate
- ImportCertificate
- ListCertificates
- Go to Asset Management and click Add Asset.

- Enter the asset name, select Amazon ACM, select the account you just created, enter the Region ID (obtained from AWS), and click Confirm to save.

Configure CaaS
- Go to Console > sslTrus CaaS Service, select the corresponding service, and click Details to enter the CaaS management backend.

- Switch to the Installation Point tab, click Add Installation Node, enter the node name, select Amazon ACM for Service Type, select the asset created in the previous step for Asset Name, enter the Certificate ARN (obtained from AWS), and click Confirm to save.

- After configuration, you can manage the node. Click Scan Now to start monitoring the node.

- After a new certificate is issued, click Push Certificate, and the system will push the new certificate to AWS ACM. You can see the certificate is updated to the latest version in backend monitoring.
