Issue Certificate

The API initiates a request to issue certificate.

Before you begin

Ensure the following before attempting to renew certificate from any CA through AppViewX:

Request Structure

Endpoint: v1/pki/ca/issue/cert
Type: POST
Sample URL:
https://<IP/HostName/TenantName>:<GWPORT>/avxapi/v1/pki/ca/issue/cert?gwsource=external

To understand the elements of the sample URL, click here.

Headers
Content-Type: application/json
Table 1. Input Parameters
Name Description
sessionId

Header

(Mandatory) Session Id received after login.

Type: String

Constraint: Required if username and password are not provided.

username

Header

(Mandatory) AppViewX login username.

Type: String

Constraint: Required if sessionId is not provided.

password

Header

(Mandatory) AppViewX login password.

Type: String

Constraint: Required if sessionId is not provided.

Payload

Table 2. Payload
Name Description
caName (Mandatory) Name of the Certificate Authority to issue the certificate from.

Type: String

templateName (Mandatory) The certificate template to use.

Type: String

validityUnit (Mandatory) Unit for the certificate's validity (e.g., months, years).

Type: String

validityUnitValue (Mandatory) Action to triggered with the request

Type: Integer

csrGenerationSource (Mandatory) Select the source for CSR generation.

Type: String

certificateDownloadFormat (Mandatory) Select the download format of the certificate.

Type: String

csrContent (Mandatory) Base64-encoded CSR (Certificate Signing Request)

Type: String

certificateType (Mandatory) Type of certificate to be issued (e.g., End Certificate, Client, etc.)

Type: String

pathLength (Optional) Specifies the maximum number of subordinate CAs allowed below this certificate in the chain. The selected value must be less than the root issuing CA's path length.

Type: String

Response Structure

Response returns string of type application/json with the following body parameters:

Table 3. Parameters
Name Description
response Contains the response attributes for the issue certificate request.
message Success message - Issue certificate action triggered successfully.

Type: String

appStatusCode Application specific status code for the response. It is a non-null value for a failure response.

Type: String

tags Additional information in case of failure response.

Status Codes

HTTP Code appStatusCode Response Message
200 Accepted null Issue certificate action has been triggered successfully.
401 Unauthorized AVX_GW_003 Authentication failed, reason - Invalid Credentials.

Remediation: Ensure that valid username and password or a valid sessionId is provided as header parameters.

417 Expectation Failed CA_CONFIG_NOT_FOUND Occurs when specified CA is not present.

Remediation: Ensure that specified CA is present.

500 Internal Server Error TEMPLATE_NAME_NOT_AVAILABLE_IN_DB Occurs when specified Template is not present.

Remediation: Ensure that specified template is present.

400 Bad Request VALIDATION_ERROR_0004 Occurs when csrContent field is not present.

Remediation: Ensure that csrContent field is present.

Sample Request/Response

Request Payload
{
        "caName": "RootCAAVX",
        "templateName": "SubCA_Default_copy",
        "validityUnit": "months",
        "validityUnitValue": 1,
        "csrGenerationSource": "uploadCSR",
        "certificateDownloadFormat": "crt",
        "csrContent": "<csrContent>",
        "certificateType": "CA Certificate",
        "pathLength":"None"
    }
Response
{
    "response": "<certificate file>",
    "message": null,
    "appStatusCode": null,
    "tags": {},
    "headers": null
}

References

Understanding the sample URL
  • IP/HostName/TenantName: Replace with the actual IP address, hostname, or tenant name based on the specific configuration in AppViewX.
    • IP: A unique identifier assigned to each device connected to a computer network that uses the Internet Protocol for communication

      The IP address will be included in the endpoint URL for an on-prem deployment.

    • HostName: A human-readable label assigned to a device (host) on a network

      The hostname will be included in the endpoint URL for an on-prem deployment.

    • TenantName: An identifier label for a tenant given to indicate which tenant's data the API request will access/modify

      The tenant name will be included in the endpoint URL for a SaaS deployment.

  • GWPORT: AppViewX gateway port

    A gateway port refers to a network port through which data is sent and received to communicate with a gateway in an on-prem deployment.

    Example: 31443

  • avxapi: Path parameter value (static) that is part of the endpoint's URL
  • Endpoint: Endpoint of the API, for example: execute-hook
  • gwsource: Source or origin of a gateway, for example: external.