Skip to content

aws.pca_connector_ad.get_template_group_access_control_entry

Example SQL Queries

SELECT * FROM
aws.pca_connector_ad.get_template_group_access_control_entry
WHERE
"group_security_identifier" = 'VALUE'
AND "template_arn" = 'VALUE';

Description

Retrieves the group access control entries for a template.

Table Definition

Column NameColumn Data Type
group_security_identifier Required Input Column

Security identifier (SID) of the group object from Active Directory. The SID starts with "S-".

VARCHAR
template_arn Required Input Column

The Amazon Resource Name (ARN) that was returned when you called CreateTemplate.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

access_control_entry

An access control entry allows or denies an Active Directory group from enrolling and/or autoenrolling with a template.

STRUCT(
"access_rights" STRUCT(
"auto_enroll" VARCHAR,
"enroll" VARCHAR
),
"created_at" TIMESTAMP_S,
"group_display_name" VARCHAR,
"group_security_identifier" VARCHAR,
"template_arn" VARCHAR,
"updated_at" TIMESTAMP_S
)
Show child fields
access_control_entry.access_rights

Permissions to allow or deny an Active Directory group to enroll or autoenroll certificates issued against a template.

Show child fields
access_control_entry.access_rights.auto_enroll

Allow or deny an Active Directory group from autoenrolling certificates issued against a template. The Active Directory group must be allowed to enroll to allow autoenrollment

access_control_entry.access_rights.enroll

Allow or deny an Active Directory group from enrolling certificates issued against a template.

access_control_entry.created_at

The date and time that the Access Control Entry was created.

access_control_entry.group_display_name

Name of the Active Directory group. This name does not need to match the group name in Active Directory.

access_control_entry.group_security_identifier

Security identifier (SID) of the group object from Active Directory. The SID starts with "S-".

access_control_entry.template_arn

The Amazon Resource Name (ARN) that was returned when you called CreateTemplate.

access_control_entry.updated_at

The date and time that the Access Control Entry was updated.