Mods
AWS

IAM Role: AWS/ACM/ReadOnly

PermissionGrant
acm-pca:GetCertificateReadOnly
acm-pca:GetCertificateAuthorityCertificateReadOnly
acm-pca:GetCertificateAuthorityCsrReadOnly
acm-pca:GetPolicyMetadata
acm-pca:ListCertificateAuthoritiesMetadata
acm-pca:ListPermissionsMetadata
acm-pca:ListTagsMetadata
acm:DescribeCertificateMetadata
acm:GetAccountConfigurationMetadata
acm:GetCertificateMetadata
acm:ListCertificatesMetadata
acm:ListTagsForCertificateMetadata