Mods
AWS

IAM Role: AWS/ACM/Admin

PermissionGrant
acm-pca:CreateCertificateAuthorityAdmin
acm-pca:CreatePermissionAdmin
acm-pca:DeleteCertificateAuthorityAdmin
acm-pca:DeletePermissionAdmin
acm-pca:DeletePolicyAdmin
acm-pca:DescribeCertificateAuthorityAdmin
acm-pca:DescribeCertificateAuthorityAuditReportAdmin
acm-pca:ImportCertificateAuthorityCertificateAdmin
acm-pca:IssueCertificateAdmin
acm-pca:PutPolicyAdmin
acm-pca:RestoreCertificateAuthorityAdmin
acm-pca:RevokeCertificateAdmin
acm-pca:UpdateCertificateAuthorityAdmin
acm:DeleteCertificateAdmin
acm:ExportCertificateAdmin
acm:ImportCertificateAdmin
acm:PutAccountConfigurationAdmin
acm:RenewCertificateAdmin
acm:RequestCertificateAdmin
acm:ResendValidationEmailAdmin
acm:UpdateCertificateOptionsAdmin
acm-pca:CreateCertificateAuthorityAuditReportOperator
acm-pca:TagCertificateAuthorityOperator
acm-pca:UntagCertificateAuthorityOperator
acm:AddTagsToCertificateOperator
acm:RemoveTagsFromCertificateOperator
acm-pca:GetCertificateReadOnly
acm-pca:GetCertificateAuthorityCertificateReadOnly
acm-pca:GetCertificateAuthorityCsrReadOnly
acm-pca:GetPolicyMetadata
acm-pca:ListCertificateAuthoritiesMetadata
acm-pca:ListPermissionsMetadata
acm-pca:ListTagsMetadata
acm:DescribeCertificateMetadata
acm:GetAccountConfigurationMetadata
acm:GetCertificateMetadata
acm:ListCertificatesMetadata
acm:ListTagsForCertificateMetadata