Cisco Identity Services Engine Certificates API

The Certificates API from Cisco Identity Services Engine — 16 operation(s) for certificates.

Documentation

Specifications

Other Resources

🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/ERS-Open-API/ERS_APIs.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/TrustSec.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/policy.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/exim.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/rbac.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/deployment.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/certificates.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/upgrade.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/5G.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/alarms.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/prometheus-alertmanager.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/pxgrid-direct.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/webhooks.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/licensing.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/duo-identity-sync.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/endpoints.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/ise-profiler.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/ipsec.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/oidc.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/mfa.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/BackupRestore.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/patch-hot-patch.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/Repository.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/custom-attributes.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/data-connect.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/pxgrid-cloud.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/api-sgt-reservation.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/System-Settings.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/endpoint-replication.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/lsd-settings.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Open-API/task-service.yaml
🔗
OpenAPI Source
https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/endpoints/Monitoring-Open-API/monitoring-open-api.yaml

OpenAPI Specification

cisco-ise-certificates-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Cisco ISE Certificates API
  version: 1.0.0
  x-provenance:
    method: harvested
    authored_by: Cisco
    harvested_by: API Evangelist
    harvested_on: '2026-08-19'
    first_party: true
    provider_published: true
    source_host: pubhub.devnetcloud.com
    note: 103 ISE API descriptions (1,490 operations; 32 OpenAPI 3.0.x + 71 Swagger 2.0) enumerated from Cisco's own DevNet project manifest and fetched anonymously. Byte-identity reconfirmed 2026-08-19 by SHA-256 against the live source.
  x-evidence:
  - type: source
    url: https://pubhub.devnetcloud.com/media/identity-services-engine-api-v1/docs/
  - type: source
    url: https://developer.cisco.com/docs/identity-services-engine/
servers:
- url: https://10.127.96.94:443
  description: Inferred Url
tags:
- name: Certificates
paths:
  /api/v1/certs/certificate-signing-request:
    get:
      tags:
      - Certificates
      summary: Get all Certificate Signing Requests from PAN
      description: '<p style="font-size: 15px;"> This API supports filtering, sorting and pagination. </p><br/> <p style="font-size: 14px;">Filtering and sorting are supported for the following attributes: </p>    <ul style="font-size: 14px;">        <li>friendlyName</li>        <li>subject</li>        <li>timeStamp</li>          <ul>            <li>Supported Date Format: yyyy-MM-dd HH:mm:ss.SSS</li>            <li>Supported Operators: EQ, NEQ, GT and LT</li>          </ul>      </ul> '
      operationId: getCSRs
      parameters:
      - name: page
        in: query
        description: Page number
        required: false
        style: form
        schema:
          type: integer
          format: int32
          exampleSetFlag: true
      - name: size
        in: query
        description: Number of objects returned per page
        required: false
        style: form
        schema:
          type: integer
          format: int32
          exampleSetFlag: true
      - name: sort
        in: query
        description: sort type - asc or desc
        required: false
        style: form
        schema:
          type: string
          exampleSetFlag: true
          enum:
          - asc
          - desc
      - name: sortBy
        in: query
        description: sort column by which objects needs to be sorted
        required: false
        style: form
        schema:
          type: string
          exampleSetFlag: true
      - name: filter
        in: query
        description: '<div> <style type="text/css" scoped> .apiServiceTable td, .apiServiceTable th { padding: 5px 10px !important; text-align: left; } </style> <span> <b>Simple filtering</b> should be available through the filter query string parameter. The structure of a filter is a triplet of field operator and value separated with dots. More than one filter can be sent. The logical operator common to ALL filter criteria will be by default AND, and can be changed by using the <i>"filterType=or"</i> query string parameter. Each resource Data model description should specify if an attribute is a filtered field. </span> <br /> <table class="apiServiceTable"> <thead> <tr> <th>OPERATOR</th> <th>DESCRIPTION</th> </tr> </thead> <tbody> <tr> <td>EQ</td> <td>Equals</td> </tr> <tr> <td>NEQ</td> <td>Not Equals</td> </tr> <tr> <td>GT</td> <td>Greater Than</td> </tr> <tr> <td>LT</td> <td>Less Then</td> </tr> <tr> <td>STARTSW</td> <td>Starts With</td> </tr> <tr> <td>NSTARTSW</td> <td>Not Starts With</td> </tr> <tr> <td>ENDSW</td> <td>Ends With</td> </tr> <tr> <td>NENDSW</td> <td>Not Ends With</td> </tr> <tr> <td>CONTAINS</td> <td>Contains</td> </tr> <tr> <td>NCONTAINS</td> <td>Not Contains</td> </tr> </tbody> </table> </div>'
        required: false
        style: form
        explode: true
        schema:
          type: string
          exampleSetFlag: true
      - name: filterType
        in: query
        description: The logical operator common to ALL filter criteria will be by default AND, and can be changed by using the parameter
        required: false
        style: form
        schema:
          type: string
          exampleSetFlag: true
          enum:
          - AND
          - OR
      responses:
        '200':
          description: Paged array of Certificate Signing Requests.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CSRGetAllRsp'
                exampleSetFlag: false
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
      security:
      - BasicAuth: []
    post:
      tags:
      - Certificates
      summary: Generate a Certificate Signing Request (CSR)
      description: ' <style type="text/css" scoped> .certTable td , .certTable th { padding: 5px 10px !important; text-align: left;} </style> <h3>Generate a certificate signing request for Multi-Use, Admin, EAP Authentication, RADIUS DTLS, PxGrid, SAML, Portal and IMS Services.</h3> Following parameters are present in the POST request body<br> <table class="certTable"> <thead> <tr> <th>PARAMETER</th> <th>DESCRIPTION</th> <th>EXAMPLE</th> </tr> </thead> <tbody> <tr> <td>hostnames</td> <td>List of Cisco ISE node hostnames for which CSRs should be generated</td> <td>"hostnames": ["ise-host1", "ise-host2"]</td> </tr> <tr> <td>allowWildCardCert</td> <td>Allow use of wildCards in certificates</td> <td>"allowWildCardCert": false</td> </tr> <tr> <td>keyLength<sup><font color=red>*required</font></sup></td> <td>Length of the key used for CSR generation.</td> <td>"keyLength": "512"</td> </tr> <tr> <td>keyType<sup><font color=red>*required</font></sup></td> <td>Type of key used for CSR generation either RSA or ECDSA.</td> <td>"keyType": "RSA"</td> </tr> <tr> <td>digestType<sup><font color=red>*required</font></sup></td> <td>Hash algorithm used for signing CSR.</td> <td>"digestType": "SHA-256"</td> </tr> <tr> <td>usedFor<sup><font color=red>*required</font></sup></td> <td>Certificate usage.</td> <td>"usedFor": "MULTI-USE"</td> </tr> <tr> <td>certificatePolicies</td> <td>Certificate policy OID or list of OIDs that the certificate should conform to. Use comma or space to separate the OIDs. </td> <td>"certificatePolicies": "Certificate Policies"</td> </tr> <tr> <td>subjectCommonName<sup><font color=red>*required</font></sup></td> <td>Certificate common name (CN).</td> <td>"subjectCommonName": "$FQDN$"</td> </tr> <tr> <td>subjectOrgUnit</td> <td>Certificate organizational unit (OU).</td> <td>"subjectOrgUnit": "Engineering"</td> </tr> <tr> <td>subjectOrg</td> <td>Certificate organization (O).</td> <td>"subjectOrg": "Cisco"</td> </tr> <tr> <td>subjectCity</td> <td>Certificate city or locality (L).</td> <td>"subjectCity": "San Jose"</td> </tr> <td>subjectState</td> <td>Certificate state (ST).</td> <td>"subjectState": "California"</td> </tr> <tr> <td>subjectCountry</td> <td>Certificate country (C).</td> <td>"subjectCountry": "US"</td> </tr> <tr> <td>sanDNS</td> <td>Array of SAN (Subject Alternative Name) DNS entries (optional).</td> <td>"sanDNS": ["ise.example.com"]</td> </tr> <td>sanIP</td> <td>Array of SAN IP entries (optional).</td> <td>"sanIP": ["1.1.1.1"]</td> </tr> <tr> <td>sanURI</td> <td>Array of SAN URI entries (optional).</td> <td>"sanURI": ["https://1.1.1.1"]</td> </tr> <tr> <td>sanDir</td> <td>Array of SAN DIR entries (optional).</td> <td>"sanDir": ["CN=AAA,DC=COM,C=IL"]</td> </tr> <tr> <td>portalGroupTag</td> <td>Portal Group Tag when using certificate for PORTAL service</td> <td>"portalGroupTag": "Default Portal Certificate Group"</td> </tr> </tbody> </table></br> <b>NOTE: </b>For <b>allowWildCardCert</b> to be false, the following parameter is mandatory:</br> <b>- hostnames </b></br> <p>When certificate is selected to be used for Portal Service, the following parameter is mandatory:</br> <b>- portalGroupTag</b></br></p> <hr/> '
      operationId: generateCSR
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CSRRequest'
              exampleSetFlag: false
      responses:
        '200':
          description: Generated CSR
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenerateCSRRespPayload'
                exampleSetFlag: false
        '201':
          description: Created
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
        '405':
          description: Invalid Input
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
      security:
      - BasicAuth: []
  /api/v1/certs/certificate-signing-request/export/{hostname}/{id}:
    get:
      tags:
      - Certificates
      summary: Export a CSR for a given CSR ID and hostname
      description: Response of this API carries a CSR corresponding to the requested ID.
      operationId: exportCSR
      parameters:
      - name: hostname
        in: path
        description: Hostname to which the CSR belongs.
        required: true
        style: simple
        schema:
          type: string
          exampleSetFlag: true
      - name: id
        in: path
        description: ID of the CSR to be exported.
        required: true
        style: simple
        schema:
          type: string
          exampleSetFlag: true
      responses:
        '200':
          description: Exported CSR successfully
          content:
            application/octet-stream:
              schema:
                $ref: '#/components/schemas/Resource'
                exampleSetFlag: false
            application/json:
              schema:
                $ref: '#/components/schemas/Resource'
                exampleSetFlag: false
        '400':
          description: Bad Request
          content:
            application/octet-stream:
              schema:
                $ref: '#/components/schemas/ExportCSRFailRespPayload'
                exampleSetFlag: false
            application/json:
              schema:
                $ref: '#/components/schemas/ExportCSRFailRespPayload'
                exampleSetFlag: false
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
      security:
      - BasicAuth: []
  /api/v1/certs/certificate-signing-request/intermediate-ca:
    post:
      tags:
      - Certificates
      summary: Generate an intermediate CA CSR (certificate signing request)
      description: CSR generation for Intermediate Certificates.
      operationId: generateIntermediateCACsr
      responses:
        '200':
          description: Generated Cisco ISE Intermediate CA CSR
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GenerateIntermediateCACsrRespPayload'
                exampleSetFlag: false
        '201':
          description: Created
        '401':
          description: Unauthorized
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
        '404':
          description: Not Found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
      security:
      - BasicAuth: []
  /api/v1/certs/certificate-signing-request/{hostName}/{id}:
    get:
      tags:
      - Certificates
      summary: Get the certificate signing request for a given ID
      description: This API displays details of a certificate signing request of a particular node for a given hostname and ID.
      operationId: getCSRById
      parameters:
      - name: hostName
        in: path
        description: Name of the host of which CSR's should be returned
        required: true
        style: simple
        schema:
          type: string
          exampleSetFlag: true
      - name: id
        in: path
        description: ID of the Certificate Signing Request returned
        required: true
        style: simple
        schema:
          type: string
          exampleSetFlag: true
      responses:
        '200':
          description: Returns the CSR of given ID.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CSRGetByIdRsp'
                exampleSetFlag: false
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
      security:
      - BasicAuth: []
    delete:
      tags:
      - Certificates
      summary: Delete the certificate signing request for a given ID
      description: This API deletes the certificate signing request of a particular node based on a given hostname and ID.
      operationId: deleteCSR
      parameters:
      - name: hostName
        in: path
        description: Name of the host of which CSR's should be deleted
        required: true
        style: simple
        schema:
          type: string
          exampleSetFlag: true
      - name: id
        in: path
        description: ID of the Certificate Signing Request to be deleted
        required: true
        style: simple
        schema:
          type: string
          exampleSetFlag: true
      responses:
        '200':
          description: Deleted CSR of the given ID.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/DeleteCSRRespPayload'
                exampleSetFlag: false
        '204':
          description: No Content
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
      security:
      - BasicAuth: []
  /api/v1/certs/ise-root-ca/regenerate:
    post:
      tags:
      - Certificates
      summary: Regenerate entire internal CA certificate chain including root CA on the primary PAN and subordinate CAs on the PSNs (Applicable only for internal CA service)
      description: This API initiates regeneration of Cisco ISE root CA certificate chain. The response contains an ID which can be used to track the status. <br>  Setting "removeExistingISEIntermediateCSR" to true removes existing Cisco ISE Intermediate CSR.
      operationId: regenerateISERootCA
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RegenerateRootCA'
              exampleSetFlag: false
      responses:
        '200':
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
        '201':
          description: Created
        '202':
          description: Regeneration of Cisco ISE Root CA is initiated. Please use status API to get the status.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RegenerateRootCaRespPayload'
                exampleSetFlag: false
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '405':
          description: Invalid Input
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
      security:
      - BasicAuth: []
  /api/v1/certs/renew-certificate:
    post:
      tags:
      - Certificates
      summary: Renew certificates of OCSP responder and Cisco ISE Messaging Service
      description: This API initiates regeneration of certificates. The response contains an ID which can be used to track the status.
      operationId: renewCerts
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RenewCertificates'
              exampleSetFlag: false
      responses:
        '200':
          description: unexpected error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
        '201':
          description: Created
        '202':
          description: Regeneration of Certificate is initiated. Please use the status API to get the status.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RenewCertRespPayload'
                exampleSetFlag: false
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
        '405':
          description: Invalid Input
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
      security:
      - BasicAuth: []
  /api/v1/certs/signed-certificate/bind:
    post:
      tags:
      - Certificates
      summary: Bind CA Signed Certificate
      description: ' <style type="text/css" scoped> .certTable td , .certTable th { padding: 5px 10px !important; text-align: left;} </style> <h3>Bind CA Signed Certificate.</h3> <b>NOTE: </b>This API requires an existing certificate signing request, and the root certificate must already be trusted.<br> <b>NOTE: </b>The certificate may have a validity period greater than 398 days. It may be untrusted by many browsers.<br> <b>NOTE: </b>Request parameters accepting True and False as input can be replaced by 1 and 0 respectively.<br> <h4>Following parameters are used in the POST body</h4> <table class="certTable"> <thead> <tr> <th>PARAMETER</th> <th>DESCRIPTION</th> <th>EXAMPLE</th> </tr> </thead> <tbody> <tr> <td>name</td> <td>Friendly name of the certificate.</td> <td>"name": "CA Signed Certificate"</td> </tr> <tr> <td>data<sup><font color=red>*required</font></sup></td> <td> Plain-text contents of the certificate file. Every space needs to be replaced with a newline escape sequence (\n).<br/> Use the command <cmd>awk &apos;NF {sub(/\r/, ""); printf "%s\\n",$0;}&apos; &lt;&lt;your .pem file&gt;&gt;</cmd> to extract data from certificate file. </td> <td>"data": "Plain-text contents of the certificate file."</td> </tr> <tr> <td>allowExtendedValidity<sup><font color=red>*required</font></sup></td> <td>Allow the certificates with validity greater than 398 days.</td> <td>"allowExtendedValidity": true</td> </tr> <tr> <td>allowOutOfDateCert<sup><font color=red>*required</font></sup></td> <td> Allow out of date certificates.</br> <b>SECURITY ALERT: </b>We recommend to set the parameter the parameter <b>allowOutOfDateCert</b> as <b>false</b> to avoid binding of expired certificates (not secure). </td> <td>"allowOutOfDateCert": true</td> </tr> <tr> <td>allowReplacementOfCertificates<sup><font color=red>*required</font></sup></td> <td>Allow Replacement of certificates.</td> <td>"allowReplacementOfCertificates": true</td> </tr> <tr> <td>allowReplacementOfPortalGroupTag<sup><font color=red>*required</font></sup></td> <td>Allow Replacement of Portal Group Tag.</td> <td>"allowReplacementOfPortalGroupTag": true</td> </tr> <td>admin</td> <td>Use certificate to authenticate the Cisco ISE Admin Portal</td> <td>"admin": false</td> </tr> <tr> <td>eap</td> <td>Use certificate for EAP protocols that use SSL/TLS tunneling</td> <td>"eap": false</td> </tr> <tr> <td>radius</td> <td>Use certificate for RADSec server</td> <td>"radius": false</td> </tr> <tr> <td>pxgrid</td> <td>Use certificate for the pxGrid Controller</td> <td>"pxgrid": false</td> </tr> <tr> <td>ims</td> <td>Use certificate for the Cisco ISE Messaging Service</td> <td>"ims": false</td> </tr> <tr> <td>saml</td> <td>Use certificate for SAML Signing</td> <td>"saml": false</td> </tr> <tr> <td>portal</td> <td>Use certificate for portal</td> <td>"portal": false</td> </tr> <tr> <td>portalGroupTag</td> <td>Portal Group Tag for using certificate with portal role</td> <td>"portalGroupTag": "Default Portal Certificate Group"</td> </tr> <tr> <td>validateCertificateExtensions</td> <td>Validate Certificate Extensions</td> <td>"validateCertificateExtensions": false</td> </tr> </tbody> </table> <br/> <h4>Following roles can be used in any combinations</h4> <table class="certTable"> <thead> <tr> <th>ROLE</th> <th>DEFAULT</th> <th>WARNING</th> </tr> </thead> <tbody> <tr> <td>Admin</td> <td>False</td> <td>Enabling admin role for this certificate causes an application server restart on the selected node.<br/><b>Note:</b> Make sure that the required certificate chain is imported under Trusted Certificates.</td> </tr> <tr> <td>EAP Authentication</td> <td>False</td> <td>Only one system certificate can be used for EAP. Assigning EAP to this certificate removes the assignment from another certificate.<br/><b>Note:</b> Make sure that the required certificate chain is imported under Trusted Certificates.</td> </tr> <tr> <td>RADIUS DTLS</td> <td>False</td> <td>Only one system certificate can be used for DTLS. Assigning DTLS to this certificate removes the assignment from another certificate.<br/><b>Note:</b> Make sure that the required certificate chain is imported under Trusted Certificates</td> </tr> <tr> <td>SAML</td> <td>False</td> <td>SAML cannot be used with other Usage. Enabling SAML unchecks all other Usage.</br><b>Note:</b> Make sure that the required certificate chain is imported under Trusted Certificates.</td> </tr> </tbody> </table> '
      operationId: bindCSR
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/BindCSRRequest'
              exampleSetFlag: false
      responses:
        '200':
          description: CSR Binded Successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BindCSRRespPayload'
                exampleSetFlag: false
        '201':
          description: Created
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
        '404':
          description: Not Found
      security:
      - BasicAuth: []
  /api/v1/certs/system-certificate/export:
    post:
      tags:
      - Certificates
      summary: Export a system certificate with a given a certificate ID
      description: ' <style type="text/css" scoped> .certTable td , .certTable th { padding: 5px 10px !important; text-align: left;} </style> <h3>Export System Certificate.</h3> Following parameters are used in the POST body <table class="certTable"> <thead> <tr> <th>PARAMETER</th> <th>DESCRIPTION</th> <th>EXAMPLE</th> </tr> </thead> <tbody> <tr> <td>id<sup><font color=red>*required</font></sup></td> <td>ID of a System Certificate.</td> <td>"id": "CERT-ID"</td> </tr> <tr> <td>hostName<sup><font color=red>*required</font></sup></td> <td>Name of the host for which the system certificate should be exported</td> <td>"hostName": "ise-node-001"</td> </tr> <tr> <td>export</td> <td> One of the following options is required: <ul> <li><b>"CERTIFICATE" :</b>Export only certificate without private key<br/></li> <li><b>"CERTIFICATE_WITH_PRIVATE_KEY" :</b>Export both certificate and private key (<b>"certificatePassword"</b> is required).</li> </ul> </td> <td>"export": "CERTIFICATE_WITH_PRIVATE_KEY"</td> </tr> <tr> <td>password<sup><font color=red>*required</font></sup></td> <td>Certificate password (required if <b>"export" : CERTIFICATE_WITH_PRIVATE_KEY</b>).</br> <b>Password constraints:</b> <ul> <li>Alphanumeric</li> <li>Minimum of 8 Characters</li> <li>Maximum of 100 Characters</li> </ul> </td> <td>"password": "certificate password"</td> </tr> </tbody> </table> <b>NOTE: </b>The response of this API carries a ZIP file containing the certificate and private key if  the request contains <b>"export" : "CERTIFICATE_WITH_PRIVATE_KEY"</b>. If the request body contains <b>"export" : "CERTIFICATE"</b>, the response carries a ZIP file containing only the certificate. <br/><br/> <b>WARNING: </b>Exporting a private key is not a secure operation. It could lead to possible exposure of the private key. <br/> '
      operationId: exportSystemCert
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ExportCertRequest'
              exampleSetFlag: false
      responses:
        '200':
          description: Exported certificate successfully
          content:
            application/octet-stream:
              schema:
                $ref: '#/components/schemas/Resource'
                exampleSetFlag: false
            application/json:
              schema:
                $ref: '#/components/schemas/Resource'
                exampleSetFlag: false
        '201':
          description: Created
        '400':
          description: Bad Request
          content:
            application/octet-stream:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
                exampleSetFlag: false
        '401':
          description: Unauthorized
        '403':
          description: Forbidden
        '404':
          description: Not Found
      security:
      - BasicAuth: []
  /api/v1/certs/system-certificate/generate-selfsigned-certificate:
    post:
      tags:
      - Certificates
      summary: Generate self-signed certificate in Cisco ISE
      description: ' <style type="text/css" scoped> .certTable td , .certTable th { padding: 5px 10px !important; text-align: left;} </style> <h3>Generate Self-signed Certificate</h3> <p><b>NOTE: </b>The certificate may have a validity period greater than 398 days. It may be untrusted by many browsers.<br> <b>NOTE: </b>Request parameters accepting True and False as input can be replaced by 1 and 0 respectively. <br> <b>NOTE: </b>Wildcard certificate and SAML certificate can be generated only on the primary PAN or a standalone node.<br></p> <br/> <h4>Following parameters are used in the POST body</h4> <table class="certTable"> <thead> <tr> <th>PARAMETER</th> <th>DESCRIPTION</th> <th>EXAMPLE</th> </tr> </thead> <tbody> <tr> <td>hostName<sup><font color=red>*required</font></sup></td> <td>Hostname or FQDN of the node in which the certificate needs to be created.</td> <td>"hostName": "ise-node-001"</td> </tr> <tr> <td>name</td> <td>Friendly name of the certificate.</td> <td>"name": "Self-signed System Certificate"</td> </tr> <tr> <td>subjectCommonName</td> <td> Certificate common name (CN)<br/> <b>NOTE: </b><ul><li>CN is Mandatory if SAN not configured.</li><li>>Subject can contain a multi-valued CN. For multi-valued RDNs, follow the format "CN=value1, CN=value2"</li></ul> </td> <td>"subjectCommonName": "$FQDN$"</td> </tr> <tr> <td>subjectOrgUnit</td> <td> Certificate organizational unit (OU)<br/> <b>NOTE: </b>Subject can contain a multi-valued OU. For multi-valued RDNs, follow the format "OU=value1, OU=value2" </td> <td>"subjectOrgUnit": "Engineering"</td> </tr> <tr> <td>subjectOrg</td> <td> Certificate organization (O)<br/> <b>NOTE: </b>Subject can contain multi-valued O fields. For multi-valued RDNs, follow the format "O=value1, O=value2" </td> <td>"subjectOrg": "Cisco"</td> </tr> <tr> <td>subjectCity</td> <td>Certificate city or locality (L)</td> <td>"subjectCity": "San Jose"</td> </tr> <tr> <td>subjectState</td> <td>Certificate state (ST)</td> <td>"subjectState": "California"</td> </tr> <tr> <td>subjectCountry</td> <td>Certificate country (C)</td> <td>"subjectCountry": "US"</td> </tr> <tr> <td>sanDNS</td> <td>Array of SAN (Subject Alternative Name) DNS entries</td> <td>"sanDNS": ["ise.example.com"]</td> </tr> <tr> <td>sanIP</td> <td>Array of SAN IP address entries</td> <td>"sanIP": ["1.1.1.1"]</td> </tr> <tr> <td>sanURI</td> <td>Array of SAN URI entries</td> <td>"sanURI": ["https://1.1.1.1"]</td> </tr> <tr> <td>keyType<sup><font color=red>*required</font></sup></td> <td>Algorithm to use for certificate public key creation.</td> <td>"keyType": "RSA"</td> </tr> <tr> <td>keyLength<sup><font color=red>*required</font></sup></td> <td>Bit size of the public key.</td> <td>"keyLength": "4096"</td> </tr> <tr> <td>digestType<sup><font color=red>*required</font></sup></td> <td>Digest to sign with.</td> <td>"digestType": "SHA-384"</td> </tr> <tr> <td>certificatePolicies</td> <td>Certificate policy OID or list of OIDs that the certificate should conform to. Use comma or space to separate the OIDs. </td> <td>"certificatePolicies": "Certificate Policies"</td> </tr> <tr> <td>expirationTTL<sup><font color=red>*required</font></sup></td> <td> Certificate expiration value.<br/> <b>NOTE: </b>Expiration TTL should be within Unix time limit </td> <td>"expirationTTL": 2</td> </tr> <tr> <td>expirationTTLUnit<sup><font color=red>*required</font></sup></td> <td>Certificate expiration unit.</td> <td>"expirationTTLUnit": "years"</td> </tr> <tr> <td>admin</td> <td>Use certificate to authenticate the Cisco ISE Admin Portal</td> <td>"admin": false</td> </tr> <tr> <td>eap</td> <td>Use certificate for EAP protocols that use SSL/TLS tunneling</td> <td>"eap": false</td> </tr> <tr> <td>radius</td> <td>Use certificate for RADSec server</td> <td>"radius": false</td> </tr> <tr> <td>pxgrid</td> <td>Use certificate for the pxGrid controller</td> <td>"pxgrid": false</td> </tr> <tr> <td>saml</td> <td>Use certificate for SAML Signing</td> <td>"saml": false</td> </tr> <tr> <td>portal</td> <td>Use certificate for portal</td> <td>"portal": false</td> </tr> <tr> <td>portalGroupTag</td> <td>Portal Group Tag for using certificate with portal role</td> <td>"portalGroupTag": "Default Portal Certificate Group"</td> </tr> <tr> <td>allowReplacementOfPortalGroupTag<sup><font color=red>*required</font></sup></td> <td>Allow Replacement of Portal Group Tag.</td> <td>"allowReplacementOfPortalGroupTag": true</td> </tr> <tr> <td>allowWildCardCertificates</td> <td>Allow use of WildCards in certificates</td> <td>"allowWildCardCertificates": false</td> </tr> <tr> <td>allowReplacementOfCertificates<sup><font color=red>*required</font></sup></td> <td>Allow replacement of certificates.</td> <td>"allowReplacementOfCertificates": true</td> </tr> <tr> <td>allowExtendedValidity<sup><font color=red>*required</font></sup></td> <td>Allow generation of self-signed certificate with validity greater than 398 days.</td> <td>"allowExtendedValidity": true</td> </tr> <tr> <td>allowRoleTransferForSameSubject<sup><font color=red>*required</font></sup></td> <td>Allow the transfer of roles to certificates with same subject.<br/> If the matching certificate on Cisco ISE has either admin or portal role and if the request has admin or portal role selected along with <b>allowRoleTransferForSameSubject</b> parameter as true, a self-signed certificate would be generated with both admin and portal role enabled.</td> <td>"allowRoleTransferForSameSubject": true</td> </tr> <tr> <td>allowPortalTagTransferForSameSubject<sup><font color=red>*required</font></sup></td> <td>Acquire the group tag of the matching certificate.</br> If the request portal groug tag is different from the group tag of the matching certificate (If matching certificate in Cisco ISE has portal role enabled), a self-signed certificate would be generated by acquiring the group tag of the matching certificate if the <b>allow

# --- truncated at 32 KB (135 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cisco-ise/refs/heads/main/openapi/cisco-ise-certificates-api-openapi.yml