Restores a certificate authority (CA) that is in the DELETED state. You
can restore a CA during the period that you defined in the PermanentDeletionTimeInDays parameter of the DeleteCertificateAuthority action. Currently, you can specify 7 to 30 days.
If you did not specify a PermanentDeletionTimeInDays
value, by default you can restore the CA at any time in a 30 day period. You can check
the time remaining in the restoration period of a private CA in the DELETED
state by calling the DescribeCertificateAuthority or ListCertificateAuthorities actions. The status of a restored CA is set to
its pre-deletion status when the RestoreCertificateAuthority action returns. To change its status to
ACTIVE, call the UpdateCertificateAuthority action. If the private CA was in the
PENDING_CERTIFICATE state at deletion, you must use the ImportCertificateAuthorityCertificate action to import a certificate
authority into the private CA before it can be activated. You cannot restore a CA after
the restoration period has ended.
Example
Use a bare-bones client and the command you need to make an API call.
Restores a certificate authority (CA) that is in the
DELETED
state. You can restore a CA during the period that you defined in the PermanentDeletionTimeInDays parameter of the DeleteCertificateAuthority action. Currently, you can specify 7 to 30 days. If you did not specify a PermanentDeletionTimeInDays value, by default you can restore the CA at any time in a 30 day period. You can check the time remaining in the restoration period of a private CA in theDELETED
state by calling the DescribeCertificateAuthority or ListCertificateAuthorities actions. The status of a restored CA is set to its pre-deletion status when the RestoreCertificateAuthority action returns. To change its status toACTIVE
, call the UpdateCertificateAuthority action. If the private CA was in thePENDING_CERTIFICATE
state at deletion, you must use the ImportCertificateAuthorityCertificate action to import a certificate authority into the private CA before it can be activated. You cannot restore a CA after the restoration period has ended.Example
Use a bare-bones client and the command you need to make an API call.
See
input
shape.response
shape.config
shape.Throws
InvalidArnException (client fault)
The requested Amazon Resource Name (ARN) does not refer to an existing resource.
Throws
InvalidStateException (client fault)
The state of the private CA does not allow this action to occur.
Throws
ResourceNotFoundException (client fault)
A resource such as a private CA, S3 bucket, certificate, audit report, or policy cannot be found.