aws-quickstart / quickstart-microsoft-pki

AWS Quick Start Team
Apache License 2.0
8 stars 8 forks source link

Allow Subordinate Enterprise CA instances to launch in a Public Subnet #57

Open fjleon1980 opened 2 years ago

fjleon1980 commented 2 years ago

Right now, the template is forcing the subordinate enterprise CA instance to launch in a private subnet. This is wrong, because in some cases, you need to make the CA reachable over the internet. For example, if you need to support smart card authentication for WorkSpaces, your AD Connector needs to be able to reach the OCSP URL via HTTP over the internet.

CaServerSubnet: !GetAtt VPCStack.Outputs.PrivateSubnet1AID

This line needs to be modified, and a new parameter needs to be selected by the user