1. Packages
  2. AWS
  3. API Docs
  4. acmpca
  5. getCertificate
AWS v7.10.0 published on Friday, Oct 24, 2025 by Pulumi

aws.acmpca.getCertificate

Get Started
aws logo
AWS v7.10.0 published on Friday, Oct 24, 2025 by Pulumi

    Get information on a Certificate issued by a AWS Certificate Manager Private Certificate Authority.

    Example Usage

    import * as pulumi from "@pulumi/pulumi";
    import * as aws from "@pulumi/aws";
    
    const example = aws.acmpca.getCertificate({
        arn: "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012/certificate/1234b4a0d73e2056789bdbe77d5b1a23",
        certificateAuthorityArn: "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012",
    });
    
    import pulumi
    import pulumi_aws as aws
    
    example = aws.acmpca.get_certificate(arn="arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012/certificate/1234b4a0d73e2056789bdbe77d5b1a23",
        certificate_authority_arn="arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012")
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/acmpca"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		_, err := acmpca.LookupCertificate(ctx, &acmpca.LookupCertificateArgs{
    			Arn:                     "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012/certificate/1234b4a0d73e2056789bdbe77d5b1a23",
    			CertificateAuthorityArn: "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012",
    		}, nil)
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Aws = Pulumi.Aws;
    
    return await Deployment.RunAsync(() => 
    {
        var example = Aws.Acmpca.GetCertificate.Invoke(new()
        {
            Arn = "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012/certificate/1234b4a0d73e2056789bdbe77d5b1a23",
            CertificateAuthorityArn = "arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012",
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.aws.acmpca.AcmpcaFunctions;
    import com.pulumi.aws.acmpca.inputs.GetCertificateArgs;
    import java.util.List;
    import java.util.ArrayList;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            final var example = AcmpcaFunctions.getCertificate(GetCertificateArgs.builder()
                .arn("arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012/certificate/1234b4a0d73e2056789bdbe77d5b1a23")
                .certificateAuthorityArn("arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012")
                .build());
    
        }
    }
    
    variables:
      example:
        fn::invoke:
          function: aws:acmpca:getCertificate
          arguments:
            arn: arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012/certificate/1234b4a0d73e2056789bdbe77d5b1a23
            certificateAuthorityArn: arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/12345678-1234-1234-1234-123456789012
    

    Using getCertificate

    Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.

    function getCertificate(args: GetCertificateArgs, opts?: InvokeOptions): Promise<GetCertificateResult>
    function getCertificateOutput(args: GetCertificateOutputArgs, opts?: InvokeOptions): Output<GetCertificateResult>
    def get_certificate(arn: Optional[str] = None,
                        certificate_authority_arn: Optional[str] = None,
                        region: Optional[str] = None,
                        opts: Optional[InvokeOptions] = None) -> GetCertificateResult
    def get_certificate_output(arn: Optional[pulumi.Input[str]] = None,
                        certificate_authority_arn: Optional[pulumi.Input[str]] = None,
                        region: Optional[pulumi.Input[str]] = None,
                        opts: Optional[InvokeOptions] = None) -> Output[GetCertificateResult]
    func LookupCertificate(ctx *Context, args *LookupCertificateArgs, opts ...InvokeOption) (*LookupCertificateResult, error)
    func LookupCertificateOutput(ctx *Context, args *LookupCertificateOutputArgs, opts ...InvokeOption) LookupCertificateResultOutput

    > Note: This function is named LookupCertificate in the Go SDK.

    public static class GetCertificate 
    {
        public static Task<GetCertificateResult> InvokeAsync(GetCertificateArgs args, InvokeOptions? opts = null)
        public static Output<GetCertificateResult> Invoke(GetCertificateInvokeArgs args, InvokeOptions? opts = null)
    }
    public static CompletableFuture<GetCertificateResult> getCertificate(GetCertificateArgs args, InvokeOptions options)
    public static Output<GetCertificateResult> getCertificate(GetCertificateArgs args, InvokeOptions options)
    
    fn::invoke:
      function: aws:acmpca/getCertificate:getCertificate
      arguments:
        # arguments dictionary

    The following arguments are supported:

    Arn string
    ARN of the certificate issued by the private certificate authority.
    CertificateAuthorityArn string
    ARN of the certificate authority.
    Region string
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    Arn string
    ARN of the certificate issued by the private certificate authority.
    CertificateAuthorityArn string
    ARN of the certificate authority.
    Region string
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    arn String
    ARN of the certificate issued by the private certificate authority.
    certificateAuthorityArn String
    ARN of the certificate authority.
    region String
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    arn string
    ARN of the certificate issued by the private certificate authority.
    certificateAuthorityArn string
    ARN of the certificate authority.
    region string
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    arn str
    ARN of the certificate issued by the private certificate authority.
    certificate_authority_arn str
    ARN of the certificate authority.
    region str
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    arn String
    ARN of the certificate issued by the private certificate authority.
    certificateAuthorityArn String
    ARN of the certificate authority.
    region String
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.

    getCertificate Result

    The following output properties are available:

    Arn string
    Certificate string
    PEM-encoded certificate value.
    CertificateAuthorityArn string
    CertificateChain string
    PEM-encoded certificate chain that includes any intermediate certificates and chains up to root CA.
    Id string
    The provider-assigned unique ID for this managed resource.
    Region string
    Arn string
    Certificate string
    PEM-encoded certificate value.
    CertificateAuthorityArn string
    CertificateChain string
    PEM-encoded certificate chain that includes any intermediate certificates and chains up to root CA.
    Id string
    The provider-assigned unique ID for this managed resource.
    Region string
    arn String
    certificate String
    PEM-encoded certificate value.
    certificateAuthorityArn String
    certificateChain String
    PEM-encoded certificate chain that includes any intermediate certificates and chains up to root CA.
    id String
    The provider-assigned unique ID for this managed resource.
    region String
    arn string
    certificate string
    PEM-encoded certificate value.
    certificateAuthorityArn string
    certificateChain string
    PEM-encoded certificate chain that includes any intermediate certificates and chains up to root CA.
    id string
    The provider-assigned unique ID for this managed resource.
    region string
    arn str
    certificate str
    PEM-encoded certificate value.
    certificate_authority_arn str
    certificate_chain str
    PEM-encoded certificate chain that includes any intermediate certificates and chains up to root CA.
    id str
    The provider-assigned unique ID for this managed resource.
    region str
    arn String
    certificate String
    PEM-encoded certificate value.
    certificateAuthorityArn String
    certificateChain String
    PEM-encoded certificate chain that includes any intermediate certificates and chains up to root CA.
    id String
    The provider-assigned unique ID for this managed resource.
    region String

    Package Details

    Repository
    AWS Classic pulumi/pulumi-aws
    License
    Apache-2.0
    Notes
    This Pulumi package is based on the aws Terraform Provider.
    aws logo
    AWS v7.10.0 published on Friday, Oct 24, 2025 by Pulumi
      Meet Neo: Your AI Platform Teammate