clients

get security server client certificates information

<h3>Administrator views the certificates for the client.</h3>
get/clients/{id}/sign-certificates

Request

  • Base URL: /api/v1 (relative, and the document was published on a file host, not at the API’s origin)
  • URL: /api/v1/clients/{id}/sign-certificates
  • Auth: API key in header Authorization

Path parameters

idstring text required

id of the client

Response

list of certificates

ocsp_status'DISABLED' | 'EXPIRED' | 'OCSP_RESPONSE_UNKNOWN' | 'OCSP_RESPONSE_GOOD' | 'OCSP_RESPONSE_SUSPENDED' | 'OCSP_RESPONSE_REVOKED' enum required

certificate status

owner_idstring text required

client id of the owner member, <instance_id>:<member_class>:<member_code>

activeboolean required

if the certificate is active

saved_to_configurationboolean required

if the certificate is saved to configuration

renewed_cert_hashstring text

hash of the newer version of the certificate that is in the process of registration

renewal_errorstring text

error message thrown during the certificate automatic renewal process

ocsp_verify_before_activation_errorstring text

error message thrown when verifying ocsp responses before the certificate activation

next_automatic_renewal_timestring date-time

next planned automatic renewal time

status'SAVED' | 'REGISTRATION_IN_PROGRESS' | 'REGISTERED' | 'DELETION_IN_PROGRESS' | 'GLOBAL_ERROR' enum required

certificate status

possible_actionsPossibleAction[]

array containing the possible actions that can be done for this item

Example response

[
  {
    "ocsp_status": "IN_USE",
    "owner_id": "FI:GOV:123",
    "active": true,
    "saved_to_configuration": true,
    "certificate_details": {
      "issuer_distinguished_name": "issuer123",
      "issuer_common_name": "domain.com",
      "subject_distinguished_name": "subject123",
      "subject_common_name": "domain.com",
      "not_before": "2018-12-15T00:00:00.001Z",
      "not_after": "2018-12-15T00:00:00.001Z",
      "serial": "123456789",
      "version": 3,
      "signature_algorithm": "sha256WithRSAEncryption",
      "signature": "30af2fdc1780...",
      "public_key_algorithm": "sha256WithRSAEncryption",
      "rsa_public_key_modulus": "c44421d601...",
      "rsa_public_key_exponent": 65537,
      "ec_public_parameters": "secp256r1(1.2.840.10045.3.1.7)",
      "ec_public_key_point": "c44421d601...",
      "hash": "1234567890ABCDEF",
      "key_usages": [
        "NON_REPUDIATION"
      ],
      "subject_alternative_names": "DNS:*.example.org"
    },
    "status": "IN_USE",
    "possible_actions": [
      "DELETE"
    ]
  }
]

Changes

No recorded changes to this operation across all 50 revisions of this API.