AWS Private CA adds detailed issuance logs
📜 The new AWS Private CA CloudTrail IssueCertificateDetails event records full certificate content, issuing CA data, requester identity, and signing status for every issuance. It captures the complete TBS certificate with X.509 fields and convenience fields like subject, issuer, serial, validity, template, and algorithm. Events include both successful and failed issuances and identify the requester (account/IAM principal or service principal). Delivered automatically as a CloudTrail management event in supported Regions, it can be consumed in real time via EventBridge or queried with Athena at standard CloudTrail cost.
