Certificate Authorities (iam/v2)

Create a Certificate Authority

General Availability

Make a request to create a certificate authority.

post/iam/v2/certificate-authorities

Request body

api_version'iam/v2'

APIVersion defines the schema version of this representation of a resource.

kind'CreateCertRequest'

Kind defines the object this REST resource represents.

idstring

ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object kinds or objects of the same kind within a different scope/namespace ("space").

display_namestring

The human-readable name of the certificate authority.

descriptionstring

A description of the certificate authority.

certificate_chainstring

The PEM encoded string containing the signing certificate chain used to validate client certs.

certificate_chain_filenamestring

The name of the certificate file.

crl_urlstring uri

The url from which to fetch the CRL for the certificate authority if crl_source is URL.

crl_chainstring

The PEM encoded string containing the CRL for this certificate authority. Defaults to this over crl_url if available.

require_crl_on_client_certificateboolean

Whether to require CRL validation on client certificates. If require_crl_on_client_certificate is true, then a CRL must be configured. At time of mTLS auth, if the client certificate is revoked in the CRL or the client issuer does not match the CRL issuer, certificate verification will fail even if TLS handshake is successful (OpenSSL -crl_check default behavior). If require_crl_on_client_certificate is false, this mTLS identity provider cannot configure a new CRL.

Example request

{
  "id": "dlz-f3a90de",
  "metadata": {
    "self": "https://api.confluent.cloud/iam/v2/create-cert-requests/ccr-12345",
    "resource_name": "crn://confluent.cloud/organization=9bb441c4-edef-46ac-8a41-c49e44a3fd9a/create-cert-request=ccr-12345",
    "created_at": "2006-01-02T15:04:05-07:00",
    "updated_at": "2006-01-02T15:04:05-07:00",
    "deleted_at": "2006-01-02T15:04:05-07:00"
  },
  "display_name": "My Certificate Authority",
  "description": "Sample description text",
  "certificate_chain": "-----BEGIN CERTIFICATE-----\nMIIDdTCCAl2gAwIBAgILBAAAAAABFUtaw5QwDQYJKoZIhvcNAQEFBQAwVzELMAkGA1UEBhMCQkUx\nGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jvb3QgQ0ExGzAZBgNVBAMTEkds\nb2JhbFNpZ24gUm9vdCBDQTAeFw05ODA5MDExMjAwMDBaFw0yODAxMjgxMjAwMDBaMFcxCzAJBgNV\nBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMRAwDgYDVQQLEwdSb290IENBMRswGQYD\nVQQDExJHbG9iYWxTaWduIFJvb3QgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDa\nDuaZjc6j40+Kfvvxi4Mla+pIH/EqsLmVEQS98GPR4mdmzxzdzxtIK+6NiY6arymAZavpxy0Sy6sc\nTHAHoT0KMM0VjU/43dSMUBUc71DuxC73/OlS8pF94G3VNTCOXkNz8kHp1Wrjsok6Vjk4bwY8iGlb\nKk3Fp1S4bInMm/k8yuX9ifUSPJJ4ltbcdG6TRGHRjcdGsnUOhugZitVtbNV4FpWi6cgKOOvyJBNP\nc1STE4U6G7weNLWLBYy5d4ux2x8gkasJU26Qzns3dLlwR5EiUWMWea6xrkEmCMgZK9FGqkjWZCrX\ngzT/LCrBbBlDSgeF59N89iFo7+ryUp9/k5DPAgMBAAGjQjBAMA4GA1UdDwEB/wQEAwIBBjAPBgNV\nHRMBAf8EBTADAQH/MB0GA1UdDgQWBBRge2YaRQ2XyolQL30EzTSo//z9SzANBgkqhkiG9w0BAQUF\nAAOCAQEA1nPnfE920I2/7LqivjTFKDK1fPxsnCwrvQmeU79rXqoRSLblCKOzyj1hTdNGCbM+w6Dj\nY1Ub8rrvrTnhQ7k4o+YviiY776BQVvnGCv04zcQLcFGUl5gE38NflNUVyRRBnMRddWQVDf9VMOyG\nj/8N7yy5Y0b2qvzfvGn9LhJIZJrglfCm7ymPAbEVtQwdpf5pLGkkeB6zpxxxYu7KyJesF12KwvhH\nhm4qxFYxldBniYUr+WymXUadDKqC5JlR3XC321Y9YeRq4VzW9v493kHMB65jUr9TU/Qr6cf9tveC\nX4XSQRjbgbMEHMUfpIBvFSDJ3gyICh3WZlXi/EjJKSZp4A==\n-----END CERTIFICATE-----",
  "certificate_chain_filename": "certificate.pem",
  "crl_chain": "-----BEGIN X509 CRL-----\nMIICNTCCAR0CAQEwDQYJKoZIhvcNAQELBQAwgbExCzAJBgNVBAYTAlVTMQswCQYD\nVQQIDAJDQTEWMBQGA1UEBwwNTW91bnRhaW4gVmlldzESMBAGA1UECgwJQ29uZmx1\nZW50MRMwEQYDVQQLDApzZWN1cml0eS0xMSYwJAYDVQQDDB1tdGxzMS5zZWN1cml0\neS0xLmNvbmZsdWVudC5pbzEsMCoGCSqGSIb3DQEJARYdbXRsczFAc2VjdXJpdHkt\nMS5jb25mbHVlbnQuaW8XDTI0MDgyNTE3NTYyNloXDTI0MTEyMzE3NTYyNlowJzAl\nAhQERu3UxH2q3eUglbdeQY8y0vT7rRcNMjQwODI1MTc1NTE2WqAOMAwwCgYDVR0U\nBAMCAQEwDQYJKoZIhvcNAQELBQADggEBAGvmflwxVAnqZbRx8njb2t6yXqeIOBaX\nCKhMq5CUWrWhMX/JrV5NhVfzeB2tgCCfM4J7gbKSArOKqjYpQBFL+r5eCjPBBcG4\nxqh1J60l5DDsiUcXQM5FtlWTBBZFxvvvWsLP4qA/0meYRY69YQNqgEQgQ65l0Ehl\ngIUx8WkEo82A8MDY/t91PaFHufnffPKu4CxFtcpGwuvA2n9mpxB2TsSTiV8THsfE\njatuFwYgumI6t5wIWb71j/1oqQDYtbgpgUvX9gD+g7HlCC4u6Dynd0q8lsimrbf6\ncGf5Vs3JfMcr1kYNruT7kg4f4hc3p4CcuWtxYmHOcWNyZbi+W9Fdakg=\n-----END X509 CRL-----",
  "require_crl_on_client_certificate": true
}

Response

A Certificate Authority was created.

api_version'iam/v2'

APIVersion defines the schema version of this representation of a resource.

kind'CertificateAuthority'

Kind defines the object this REST resource represents.

idstring

ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object kinds or objects of the same kind within a different scope/namespace ("space").

display_namestring required

The human-readable name of the certificate authority.

descriptionstring required

A description of the certificate authority.

fingerprintsstring[]

The fingerprints for each certificate in the certificate chain. These are SHA-1 encoded strings that act as unique identifiers for the certificates in the chain.

expiration_datesstring[]

The expiration dates of certificates in the chain.

serial_numbersstring[]

The serial numbers for each certificate in the certificate chain.

certificate_chain_filenamestring

The file name of the uploaded pem file for this certificate authority.

crl_sourcestring

The source specifies whether the Certificate Revocation List (CRL) is updated from either local file uploaded (LOCAL) or from url of CRL (URL).

crl_urlstring uri

The url from which to fetch the CRL for the certificate authority if crl_source is URL.

crl_updated_atstring date-time

The timestamp for when CRL was last updated.

statestring

The current state of the certificate authority.

require_crl_on_client_certificateboolean required

Whether to require CRL validation on client certificates. If require_crl_on_client_certificate is true, then a CRL must be configured. At time of mTLS auth, if the client certificate is revoked in the CRL or the client issuer does not match the CRL issuer, certificate verification will fail even if TLS handshake is successful (OpenSSL -crl_check default behavior). If require_crl_on_client_certificate is false, this mTLS identity provider cannot configure a new CRL.

Example response

{
  "id": "dlz-f3a90de",
  "metadata": {
    "self": "https://api.confluent.cloud/iam/v2/certificate-authorities/op-12345",
    "resource_name": "crn://confluent.cloud/organization=9bb441c4-edef-46ac-8a41-c49e44a3fd9a/identity-provider=op-12345",
    "created_at": "2006-01-02T15:04:05-07:00",
    "updated_at": "2006-01-02T15:04:05-07:00",
    "deleted_at": "2006-01-02T15:04:05-07:00"
  },
  "display_name": "My Certificate Authority",
  "description": "Sample description text",
  "fingerprints": [
    "B1BC968BD4f49D622AA89A81F2150152A41D829C"
  ],
  "expiration_dates": [
    "2017-07-21T17:32:28Z"
  ],
  "serial_numbers": [
    "219C542DE8f6EC7177FA4EE8C3705797"
  ],
  "certificate_chain_filename": "certificate.pem",
  "crl_source": "LOCAL",
  "crl_updated_at": "2017-07-21T17:32:28Z",
  "state": "ENABLED",
  "require_crl_on_client_certificate": true
}

Changes

No recorded changes to this endpoint across all 1 revision of this API.