keyStorageSecurityStandard
Specifies a cryptographic key management compliance standard for handling and protecting CA keys.
Default: FIPS_140_2_LEVEL_3_OR_HIGHER
Some Amazon Web Services Regions don't support the default value. When you create a CA in these Regions, you must use CCPC_LEVEL_1_OR_HIGHER
for the KeyStorageSecurityStandard
parameter. If you don't, the operation returns an InvalidArgsException
with this message: "A certificate authority cannot be created in this region with the specified security standard."
For information about security standard support in different Amazon Web Services Regions, see Storage and security compliance of Amazon Web Services Private CA private keys.