Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Certificate storage attributes

Focus mode
Certificate storage attributes - AWS CloudHSM

The following table lists the supported certificate object attributes and their values:

Attribute

Default value

Description

CKA_CLASS

Required

Must be CKO_CERTIFICATE.

CKA_TOKEN

True

Must be True.

CKA_MODIFIABLE

True

Must be True.

CKA_PRIVATE

False

Must be False.

CKA_LABEL

Empty

Limit 127 characters.

CKA_COPYABLE

False

Must be False.

CKA_DESTROYABLE

True

Must be True.

CKA_CERTIFICATE_TYPE

Required

Must be CKC_X_509.

CKA_TRUSTED

False

Must be False.

CKA_CERTIFICATE_CATEGORY

CK_CERTIFICATE_CATEGORY_UNSPECIFIED

Must be CK_CERTIFICATE_CATEGORY_UNSPECIFIED.

CKA_CHECK_VALUE

Derived from CKA_VALUE

Automatically set based on CKA_VALUE.

CKA_START_DATE

Empty

The certificate 'not before' date.

CKA_END_DATE

Empty

The certificate 'not after' date.

CKA_PUBLIC_KEY_INFO

Empty

Maximum size is 16 kilobytes.

CKA_SUBJECT

Required

The certificate subject.

CKA_ID

Empty

Maximum size is 128 bytes. Uniqueness isn't enforced.

CKA_ISSUER

Empty

The certificate issuer.

CKA_SERIAL_NUMBER

Empty

The certificate serial number.

CKA_VALUE

Required

Maximum size is 32 kilobytes.

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.