ACMPCA / Client / delete_certificate_authority
delete_certificate_authority#
- ACMPCA.Client.delete_certificate_authority(**kwargs)#
Deletes a private certificate authority (CA). You must provide the Amazon Resource Name (ARN) of the private CA that you want to delete. You can find the ARN by calling the ListCertificateAuthorities action.
Note
Deleting a CA will invalidate other CAs and certificates below it in your CA hierarchy.
Before you can delete a CA that you have created and activated, you must disable it. To do this, call the UpdateCertificateAuthority action and set the CertificateAuthorityStatus parameter to
DISABLED
.Additionally, you can delete a CA if you are waiting for it to be created (that is, the status of the CA is
CREATING
). You can also delete it if the CA has been created but you haven’t yet imported the signed certificate into Amazon Web Services Private CA (that is, the status of the CA isPENDING_CERTIFICATE
).When you successfully call DeleteCertificateAuthority, the CA’s status changes to
DELETED
. However, the CA won’t be permanently deleted until the restoration period has passed. By default, if you do not set thePermanentDeletionTimeInDays
parameter, the CA remains restorable for 30 days. You can set the parameter from 7 to 30 days. The DescribeCertificateAuthority action returns the time remaining in the restoration window of a private CA in theDELETED
state. To restore an eligible CA, call the RestoreCertificateAuthority action.See also: AWS API Documentation
Request Syntax
response = client.delete_certificate_authority( CertificateAuthorityArn='string', PermanentDeletionTimeInDays=123 )
- Parameters:
CertificateAuthorityArn (string) –
[REQUIRED]
The Amazon Resource Name (ARN) that was returned when you called CreateCertificateAuthority. This must have the following form:
``arn:aws:acm-pca:region:account:certificate-authority/12345678-1234-1234-1234-123456789012 ``.
PermanentDeletionTimeInDays (integer) – The number of days to make a CA restorable after it has been deleted. This can be anywhere from 7 to 30 days, with 30 being the default.
- Returns:
None
Exceptions
ACMPCA.Client.exceptions.ConcurrentModificationException
ACMPCA.Client.exceptions.ResourceNotFoundException
ACMPCA.Client.exceptions.InvalidArnException
ACMPCA.Client.exceptions.InvalidStateException