Workspaces with trusted device by AWS Private CA

0

Customer want to deploy a "secure" AWS workspaces by only trust "specific device" within their office environment. Based on the following link, we can use "certificate" to trust the device. While based on AWS CA hierarchy best practice, we should have at least two tier CA (root + subordinate).

https://docs.aws.amazon.com/workspaces/latest/adminguide/trusted-devices.html https://docs.aws.amazon.com/acm-pca/latest/userguide/ca-hierarchy.html

Thus, we have two questions:

  1. Can we only use "single" root CA to issue certificate for Workspace users? (i.e. no subordinate CA in the design)

  2. Although "Root + subordinate" CA provide better security, each AWS private CA costs US$400. Under this situation, should we charge 2 x $400 for two CA even it is under the "same" hierarchy?

1개 답변
0
수락된 답변
  1. Yes. Designing a CA hierarchy (as you mention) is following security best practices. but still, you can choose to have just one PCA in place for this project. As usual, customer is responsable for taking these decisions, knowing and accepting the risks.

  2. ACM-PCA pricing is based per PCA. So yes again, if you have a Root + Subordinate you will have to pay for both, regardless if they are or are not under same hierarchy.

AWS
전문가
답변함 4년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠