Mods
AWS

IAM Role: AWS/ACM/Metadata

PermissionGrant
acm-pca:GetPolicyMetadata
acm-pca:ListCertificateAuthoritiesMetadata
acm-pca:ListPermissionsMetadata
acm-pca:ListTagsMetadata
acm:DescribeCertificateMetadata
acm:GetAccountConfigurationMetadata
acm:GetCertificateMetadata
acm:ListCertificatesMetadata
acm:ListTagsForCertificateMetadata