Mods
AWS

IAM Role: AWS/ACM/Operator

PermissionGrant
acm-pca:CreateCertificateAuthorityAuditReportOperator
acm-pca:TagCertificateAuthorityOperator
acm-pca:UntagCertificateAuthorityOperator
acm:AddTagsToCertificateOperator
acm:RemoveTagsFromCertificateOperator
acm-pca:GetCertificateReadOnly
acm-pca:GetCertificateAuthorityCertificateReadOnly
acm-pca:GetCertificateAuthorityCsrReadOnly
acm-pca:GetPolicyMetadata
acm-pca:ListCertificateAuthoritiesMetadata
acm-pca:ListPermissionsMetadata
acm-pca:ListTagsMetadata
acm:DescribeCertificateMetadata
acm:GetAccountConfigurationMetadata
acm:GetCertificateMetadata
acm:ListCertificatesMetadata
acm:ListTagsForCertificateMetadata