https://docs.aws.amazon.com/whitepapers/latest/access-workspaces-with-access-cards/update-default-domain-policy-with-third-party-root-cas.html