tokens

add a new key and generate a csr for it

<h3>Administrator adds a new key and generates a csr for it.</h3>
post/tokens/{id}/keys-with-csrs

Request

  • Base URL: /api/v1 (relative, and the document was published on a file host, not at the API’s origin)
  • URL: /api/v1/tokens/{id}/keys-with-csrs
  • Auth: API key in header Authorization

Path parameters

idstring text required

id of the token

Request body

key_labelstring text required

label for the new key

Example request

{
  "key_label": "My new key",
  "csr_generate_request": {
    "key_usage_type": "AUTHENTICATION",
    "ca_name": "X-Road Test CA CN",
    "csr_format": "PEM",
    "member_id": "FI:GOV:123"
  }
}

Response

key created for the token

csr_idstring text required

CSR id

Example response

{
  "key": {
    "id": "0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF",
    "name": "friendly name",
    "label": "key label",
    "certificates": [
      {
        "ocsp_status": "IN_USE",
        "owner_id": "FI:GOV:123",
        "active": true,
        "saved_to_configuration": true,
        "certificate_details": {
          "issuer_distinguished_name": "issuer123",
          "issuer_common_name": "domain.com",
          "subject_distinguished_name": "subject123",
          "subject_common_name": "domain.com",
          "not_before": "2018-12-15T00:00:00.001Z",
          "not_after": "2018-12-15T00:00:00.001Z",
          "serial": "123456789",
          "version": 3,
          "signature_algorithm": "sha256WithRSAEncryption",
          "signature": "30af2fdc1780...",
          "public_key_algorithm": "sha256WithRSAEncryption",
          "rsa_public_key_modulus": "c44421d601...",
          "rsa_public_key_exponent": 65537,
          "ec_public_parameters": "secp256r1(1.2.840.10045.3.1.7)",
          "ec_public_key_point": "c44421d601...",
          "hash": "1234567890ABCDEF",
          "key_usages": [
            "NON_REPUDIATION"
          ],
          "subject_alternative_names": "DNS:*.example.org"
        },
        "status": "IN_USE",
        "possible_actions": [
          "DELETE"
        ]
      }
    ],
    "certificate_signing_requests": [
      {
        "id": "0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF",
        "owner_id": "FI:GOV:123",
        "certificate_profile": "org.example.TestCertificateInfoProvider",
        "possible_actions": [
          "DELETE"
        ]
      }
    ],
    "usage": "AUTHENTICATION",
    "available": true,
    "saved_to_configuration": true,
    "possible_actions": [
      "DELETE"
    ],
    "key_algorithm": "RSA"
  },
  "csr_id": "0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF"
}

Changes

No recorded changes to this operation across all 50 revisions of this API.