List CA Policies

The List CA Policies API retrieves CA policies configured in AppViewX Native PKI, with support for filtering, searching, and pagination.

The response data array contains complete PKIaaSCAPolicy objects, including caConfiguration, cryptographicSettings with precomputed cipherSuites, csrAndKeyGeneration, revocationAndDistribution, and the requesting user’s accessMode.

To retrieve a single policy by exact name, set filter.policyName and maxSize to 1.

Before you Begin

Ensure the following before calling this API:
  • You have valid AppViewX credentials or an active session ID.
  • The AppViewX Native PKI module is enabled and accessible.

Request Structure

Endpoint: v1/pki/ca/policies/list
Type: POST
Sample URL:
https://<IP/HostName/TenantName>:<GWPORT>/avxapi/v1/pki/ca/policies/list?gwsource=external

To understand the elements of the sample URL, see References.

Headers
Content-Type: application/json
Table 1. Input Parameters
Name Description
sessionId

Header

(Mandatory) Session Id received after login.

Type: String

Constraint: Required if username and password are not provided.

username

Header

(Mandatory) AppViewX login username.

Type: String

Constraint: Required if sessionId is not provided.

password

Header

(Mandatory) AppViewX login password.

Type: String

Constraint: Required if sessionId is not provided.

Content-Type

Header

(Mandatory) Specifies the nature of the data in the payload.

Type: String

Constraint: Value of the parameter should be ‘application/json’

gwkey

Query

(Mandatory) Tenant Key. This is needed only in case of multi-tenant installations and can disregarded for other types of installations.

Type: String

gwsource

Query

(Mandatory) Source from which the request is triggered. (E.g. external)

Type: String

Payload

Body

Contains all the parameters to be included in the request body for the POST request.

Type: Payload

Payload Parameters

All parameters are optional. An empty request body returns all CA policies.
Parameter Description
startIndex Starting index for pagination.

Type: Integer. Example: 0.

maxSize Maximum number of results to return.

Type: Integer. Example: 50.

sortColumn Name of the field to sort results by.

Type: String. Example: policyName.

sortOrder Sort direction.

Type: String. Example: 1.

searchTextField Name of the field to apply the text search on.

Type: String. Example: policyName.

searchTextValue Text value to search for in the field specified by searchTextField.

Type: String. Example: Root.

filter Additional filter criteria.

Type: Array.

certificateAuthorityType Filter results by CA type.

Type: Array. Example: Root CA or Subordinate CA.

Response Structure

The response returns a string of type application/json with the following body parameters:

Parameter Description
response Contains the paginated result. Type: Array.
response.data List of CA policy summary objects matching the filter criteria. Type: Array of Objects. Each object contains policyName, description, certificateAuthorityType, and lastUpdatedTime.
response.totalCount Total number of CA policies matching the filter criteria, before pagination. Type: Integer.
message Success or error message. Type: String.
appStatusCode Application-specific status code for the response. Non-null for failure responses. Type: String.
tags Additional information in case of a failure response.

Status Codes

HTTP Status appStatusCode Description
200 OK null CA policies retrieved successfully.
400 Bad Request INVALID_SEARCH_TEXT_FIELD The value provided in searchTextField is not an allowed field.

Remediation: Use a valid field name for the search.

400 Bad Request INVALID_FILTER_FIELD An invalid field was provided in the filter object.

Remediation: Use a valid filter field.

400 Bad Request INVALID_SORT_FIELD An invalid field was provided in sortColumn.

Remediation: Use a valid sort column.

401 Unauthorized AVX_GW_003 Authentication failed — invalid credentials.

Remediation: Provide a valid username and password or a valid sessionId.

403 Forbidden USER_POLICY_ACCESS_RESTRICTED The authenticated user does not have access to CA policies.

Remediation: Contact your AppViewX administrator to grant the required permissions.

Sample Request/Response

Sample Request

{
  "startIndex": 0,
  "maxSize": 50,
  "sortColumn": "policyName",
  "sortOrder": "1",
  "searchTextField": "policyName",
  "searchTextValue": "Root",
  "filter": {
    "certificateAuthorityType": "Root CA"
  }
}

Sample Response

{
  "data": [
    {
      "policyName": "RootCAPolicy-RSA",
      "description": "Root CA policy with classical RSA key details",
      "createdBy": "admin",
      "accessMode": "RW",
      "caConfiguration": {
        "certificateAuthorityType": "Root CA",
        "validFor": [
          {
            "value": [
              1,
              5
            ],
            "unit": "Years"
          }
        ],
        "pathLengthConstraint": "0-4"
      },
      "cryptographicSettings": {
        "cryptoModel": "classical",
        "keyDetails": [
          {
            "keyDetailsType": "ClassicalKeyDetails",
            "classicalAlgorithm": "RSA",
            "padding": [
              "PKCS1"
            ],
            "bitLength": [
              "2048"
            ],
            "hashAlgorithm": [
              "SHA256"
            ]
          }
        ],
        "cipherSuites": [
          "RSA_PKCS1_2048_SHA256"
        ],
        "eku": [
          "serverAuth",
          "clientAuth"
        ],
        "ku": [
          "digitalSignature",
          "keyEncipherment",
          "crlSign"
        ]
      },
      "csrAndKeyGeneration": {
        "csrGeneration": "AppViewX"
      },
      "revocationAndDistribution": {
        "crlPublish": true,
        "crlDistributionPoints": [
          "HTTP"
        ],
        "defaultOcspSigningCertificate": "RSA",
        "defaultCsrGenerationForOcspSigningCertificate": "AppViewX"
      }
    }
  ],
  "iTotalDisplayRecords": 1
}

References

Understanding the sample URL
  • IP/HostName/TenantName: Replace with the actual IP address, hostname, or tenant name based on the specific configuration in AppViewX.
    • IP: A unique identifier assigned to each device connected to a computer network that uses the Internet Protocol for communication

      The IP address will be included in the endpoint URL for an on-prem deployment.

    • HostName: A human-readable label assigned to a device (host) on a network

      The hostname will be included in the endpoint URL for an on-prem deployment.

    • TenantName: An identifier label for a tenant given to indicate which tenant's data the API request will access/modify

      The tenant name will be included in the endpoint URL for a SaaS deployment.

  • GWPORT: AppViewX gateway port

    A gateway port refers to a network port through which data is sent and received to communicate with a gateway in an on-prem deployment.

    Example: 31443

  • avxapi: Path parameter value (static) that is part of the endpoint's URL
  • Endpoint: Endpoint of the API, for example: execute-hook
  • gwsource: Source or origin of a gateway, for example: external.