certificate-authorities

view the approved certificate authorities

Changed on
<h3>Administrator views the approved certificate authorities.</h3>
get/certificate-authorities

Request

  • Base URL: /api/v1 (relative, and the document was published on a file host, not at the API’s origin)
  • URL: /api/v1/certificate-authorities
  • Auth: API key in header Authorization

Query parameters

key_usage_type'AUTHENTICATION' | 'SIGNING' enum

intended usage for the key (signing or authentication)

Example:AUTHENTICATION

return only CAs suitable for this type of key usage

include_intermediate_casboolean

if true, include also intermediate CAs. Otherwise only top CAs are included. Default value is "false".

Response

list of approved certificate authorities

namestring text required

name of the CA, as defined in global conf. Used also as an identifier

subject_distinguished_namestring text required

subject distinguished name

issuer_distinguished_namestring text required

issuer distinguished name

ocsp_response'NOT_AVAILABLE' | 'OCSP_RESPONSE_UNKNOWN' | 'OCSP_RESPONSE_GOOD' | 'OCSP_RESPONSE_SUSPENDED' | 'OCSP_RESPONSE_REVOKED' enum required

certificate authority OCSP status

not_afterstring date-time required

certificate authority expires at

top_caboolean required

if the certificate authority is top CA (instead of intermediate)

pathstring text required

encoded path string from this CA to top CA

authentication_onlyboolean required

if certificate authority is limited for authentication use only

certificate_profile_infostring text

Fully qualified class name that was used to create the CSR. Implements the ee.ria.xroad.common.certificateprofile.CertificateProfileInfoProvider interface.

default_csr_format'PEM' | 'DER' enum

format of the certificate signing request (PEM or DER)

acme_capableboolean

if certificate authority supports ACME

acme_server_ip_addressesstring[]

ACME server IP address(es) that can be helpful in configuring the firewall rules.

Example response

[
  {
    "name": "X-Road Test CA CN",
    "subject_distinguished_name": "C=FI, O=X-Road Test, OU=X-Road Test CA OU, CN=X-Road Test CA CN",
    "issuer_distinguished_name": "C=FI, O=X-Road Test, OU=X-Road Test CA OU, CN=X-Road Test CA CN",
    "ocsp_response": "IN_USE",
    "not_after": "2099-12-15T00:00:00.001Z",
    "top_ca": true,
    "path": "C=FI, O=X-Road Test Intermediate, OU=X-Road Test CA OU, CN=X-Road Test CA CN Intermediate:C=FI, O=X-Road Test, OU=X-Road Test CA OU, CN=X-Road Test CA CN",
    "certificate_profile_info": "org.example.TestCertificateInfoProvider",
    "default_csr_format": "PEM",
    "acme_server_ip_addresses": [
      "12.34.5.6",
      "AB:cd:67::89"
    ],
    "ocsp_responders": [
      {
        "url": "http://dev.xroad.rocks:123",
        "cost_type": "FREE"
      }
    ]
  }
]

Changes