Palo Alto Networks Certificate Policy API
APIs for Certificate Policy.
APIs for Certificate Policy.
openapi: 3.2.0
info:
title: TLS Protect Cloud API for Strata Cloud Manager Certificate Policy API
description: Use the TLS Protect Cloud APIs to manage certificates, certificate requests, applications, machine identities, users, teams, event logs, and more. This Open API spec file was created on June 04, 2026. © 2026 Palo Alto Networks, Inc. Palo Alto Networks is a registered trademark of Palo Alto Networks. A list of our trademarks can be found at https://www.paloaltonetworks.com/company/trademarks.html. All other marks mentioned herein may be trademarks of their respective companies.
version: 1.0.0
license:
name: MIT
url: https://opensource.org/license/mit
servers:
- url: https://api.strata.paloaltonetworks.com/ngts
description: Strata Cloud Manager API
security:
- scmToken: []
tags:
- name: Certificate Policy
description: APIs for Certificate Policy.
paths:
/v1/certificateissuingtemplates:
get:
description: Retrieves the details of issuing templates ordered by `priority` and `certificateAuthority`.
operationId: certificateissuingtemplate_getAll
parameters:
- description: UUID of a Certificate Authority Account.
in: query
name: certificateAuthorityAccountId
schema:
format: uuid
type: string
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateIssuingTemplateResponse'
description: Details of Issuing Templates in response body.
'400':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Incomplete or malformed request.
'412':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Incomplete or malformed request.
summary: Get the details of issuing templates
tags:
- Certificate Policy
post:
description: Creates an issuing template.
operationId: certificateissuingtemplate_create
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateIssuingTemplateRequest'
responses:
'201':
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateIssuingTemplateResponse'
description: Issuing Template was created; details in response body.
'400':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Incomplete or malformed request.
'404':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Issuing Template not found.
'409':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Issuing Template already exists.
'412':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Incomplete or malformed request.
summary: Add an issuing template
tags:
- Certificate Policy
/v1/certificateissuingtemplates/{id}:
get:
description: Retrieve the details of the issuing template that has the specified `id`.
operationId: certificateissuingtemplate_getById
parameters:
- description: UUID of an Issuing Template.
in: path
name: id
required: true
schema:
description: UUID of an Issuing Template.
format: uuid
type: string
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateIssuingTemplateInformation'
description: Issuing Template was found; details in response body.
'400':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Incomplete or malformed request.
'404':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Issuing Template not found.
'412':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Incomplete or malformed request.
summary: Get an issuing template details
tags:
- Certificate Policy
put:
description: Updates all the details of the issuing template that has the specified `id`.
operationId: certificateissuingtemplate_update
parameters:
- description: UUID of an Issuing Template.
in: path
name: id
required: true
schema:
description: UUID of an Issuing Template.
format: uuid
type: string
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateIssuingTemplateRequest'
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateIssuingTemplateInformation'
description: Issuing Template was updated; details in response body.
'202':
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateIssuingTemplateInformation'
description: Issuing Template exists.
'400':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Request Conditions Failed
'404':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Issuing Template not found.
'412':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Incomplete or malformed request.
summary: Overwrite an issuing template details
tags:
- Certificate Policy
delete:
description: Deletes the issuing template that has the specified `id`.
operationId: certificateissuingtemplate_delete
parameters:
- description: UUID of an Issuing Template.
in: path
name: id
required: true
schema:
description: UUID of an Issuing Template.
format: uuid
type: string
responses:
'204':
description: Issuing Template was deleted
'400':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Incomplete or malformed request.
'404':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Issuing Template not found.
'412':
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorResponse2'
description: Incomplete or malformed request.
summary: Remove an issuing template
tags:
- Certificate Policy
/v1/certificateissuingtemplates/domainssynchronization:
post:
description: Loads domain list from CA and updates the issuing templates with it
operationId: domainssynchronization
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/IssuingTemplatesDomainsSyncRequest'
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/IssuingTemplateDomainsSyncResponse'
description: List with the information about the status of the sync of every issuing template
summary: Synchronize issuing templates domains with CA
tags:
- Certificate Policy
components:
schemas:
AnyValue2:
description: Can be any value - string, number, boolean, array or object.
RecommendedSettingsKeyTypeParameter:
properties:
curve:
enum:
- P256
- P384
- P521
- ED25519
- UNKNOWN
type: string
length:
format: int32
type: integer
type:
enum:
- RSA
- EC
type: string
type: object
CertificateIssuingTemplateResponse:
properties:
certificateIssuingTemplates:
items:
$ref: '#/components/schemas/CertificateIssuingTemplateInformation'
type: array
type: object
RecommendedSettingsRequest:
properties:
key:
$ref: '#/components/schemas/RecommendedSettingsKeyTypeParameter'
keyGeneratedBy:
type: string
sanRegexes:
items:
type: string
type: array
subjectCNRegexes:
items:
type: string
type: array
subjectCValue:
pattern: ^(([A-Z]{2})|(\.\*))$
type: string
subjectLValue:
pattern: '[^\*]*'
type: string
subjectOUValue:
pattern: '[^\*]*'
type: string
subjectOValue:
pattern: '[^\*]*'
type: string
subjectSTValue:
pattern: '[^\*]*'
type: string
type: object
IssuingTemplateDomainsSyncInformation:
properties:
error:
$ref: '#/components/schemas/ErrorInformation2'
issuingTemplateId:
format: uuid
type: string
status:
enum:
- COMPLETED
- FAILED
type: string
type: object
CertificateAuthorityProductInformation:
description: Product specific for external certificate authority
discriminator:
propertyName: certificateAuthority
properties:
certificateAuthority:
type: string
certificateType:
enum:
- OTHER
- DOMAIN_VALIDATED_SSL
type: string
hashAlgorithm:
enum:
- MD5
- SHA1
- MD2
- SHA224
- SHA256
- SHA384
- SHA512
- UNKNOWN
- GOSTR3411_94
- SHA3_224
- SHA3_256
- SHA3_384
- SHA3_512
- RIPEMD128
- RIPEMD160
- RIPEMD256
- SHA512_224
- SHA512_256
- SM3
- GOSTR3411_2012_256
- GOSTR3411_2012_512
- SHAKE128
- SHAKE256
type: string
productName:
type: string
productTypes:
items:
enum:
- SSL
- CODESIGN
type: string
readOnly: true
type: array
validityPeriod:
description: ISO8601 Period Format
example: PnYnMnDTnHnMnS
type: string
required:
- certificateAuthority
type: object
ErrorResponse2:
properties:
errors:
items:
$ref: '#/components/schemas/ErrorInformation2'
type: array
type: object
ErrorInformation2:
properties:
args:
items:
$ref: '#/components/schemas/AnyValue2'
type: array
code:
format: int32
type: integer
message:
type: string
type: object
TrackingDataInformation:
discriminator:
propertyName: certificateAuthority
properties:
certificateAuthority:
type: string
required:
- certificateAuthority
type: object
IssuingTemplatesDomainsSyncRequest:
properties:
action:
enum:
- REPLACE
type: string
certificateAuthorityAccountId:
format: uuid
type: string
issuingTemplatesIds:
description: Set of UUIDs of the issuing templates
example:
- 265f6d30-a0bb-11ed-aee0-89fe7e5f5d0c
items:
description: Set of UUIDs of the issuing templates
format: uuid
type: string
minItems: 1
type: array
uniqueItems: true
required:
- action
- certificateAuthorityAccountId
- issuingTemplatesIds
type: object
CertificateIssuingTemplateRequest:
properties:
certificateAuthority:
enum:
- MOCKCA
- DIGICERT
- GLOBALSIGN
- BUILTIN
- ENTRUST
- MICROSOFT
- ACME
- ZTPKI
- GLOBALSIGNMSSL
- TPP
- CONNECTOR
type: string
certificateAuthorityProductOptionId:
format: uuid
type: string
consumerTsgIds:
items:
type: string
type: array
uniqueItems: true
csrUploadAllowed:
type: boolean
description:
maxLength: 1024
type: string
driverGeneratedCsr:
type: boolean
driverId:
format: uuid
type: string
everyoneIsConsumer:
type: boolean
extendedKeyUsageValues:
items:
enum:
- SERVER
- CLIENT
type: string
type: array
uniqueItems: true
keyGeneratedByVenafiAllowed:
type: boolean
keyPairId:
format: uuid
type: string
keyReuse:
type: boolean
keyTypes:
items:
$ref: '#/components/schemas/KeyTypeParameters1'
type: array
locationId:
format: uuid
type: string
name:
maxLength: 64
type: string
priority:
format: int32
type: integer
product:
$ref: '#/components/schemas/CertificateAuthorityProductInformation'
recommendedSettings:
$ref: '#/components/schemas/RecommendedSettingsRequest'
resourceConsumerTeamIds:
items:
format: uuid
type: string
type: array
uniqueItems: true
resourceConsumerUserIds:
items:
format: uuid
type: string
type: array
uniqueItems: true
sanIpAddressRegexes:
items:
type: string
type: array
sanRegexes:
items:
type: string
type: array
sanRfc822NameRegexes:
items:
type: string
type: array
sanUniformResourceIdentifierRegexes:
items:
type: string
type: array
shareWithAll:
type: boolean
subjectCNRegexes:
items:
type: string
type: array
subjectCValues:
items:
type: string
type: array
subjectLRegexes:
items:
type: string
type: array
subjectORegexes:
items:
type: string
type: array
subjectOURegexes:
items:
type: string
type: array
subjectSTRegexes:
items:
type: string
type: array
trackingData:
$ref: '#/components/schemas/TrackingDataInformation'
required:
- certificateAuthority
- certificateAuthorityProductOptionId
- keyReuse
- keyTypes
- name
- product
type: object
RecommendedSettingsKeyTypeInformation:
properties:
curve:
enum:
- P256
- P384
- P521
- ED25519
- UNKNOWN
type: string
length:
format: int32
type: integer
type:
enum:
- RSA
- EC
type: string
type: object
RecommendedSettingsInformation:
properties:
key:
$ref: '#/components/schemas/RecommendedSettingsKeyTypeInformation'
keyGeneratedBy:
type: string
sanRegexes:
items:
type: string
type: array
subjectCNRegexes:
items:
type: string
type: array
subjectCValue:
type: string
subjectLValue:
type: string
subjectOUValue:
type: string
subjectOValue:
type: string
subjectSTValue:
type: string
type: object
KeyTypeInformation:
discriminator:
propertyName: keyType
properties:
keyType:
type: string
type: object
KeyTypeParameters1:
properties:
keyCurves:
items:
enum:
- P256
- P384
- P521
- ED25519
- UNKNOWN
type: string
type: array
keyLengths:
items:
format: int32
type: integer
type: array
keyType:
enum:
- RSA
- EC
type: string
required:
- keyType
type: object
CertificateIssuingTemplateInformation:
properties:
certificateAuthority:
enum:
- MOCKCA
- DIGICERT
- GLOBALSIGN
- BUILTIN
- ENTRUST
- MICROSOFT
- ACME
- ZTPKI
- GLOBALSIGNMSSL
- TPP
- CONNECTOR
type: string
certificateAuthorityAccountId:
format: uuid
type: string
certificateAuthorityProductOptionId:
format: uuid
type: string
companyId:
format: uuid
type: string
consumerTsgIds:
items:
type: string
type: array
uniqueItems: true
creationDate:
format: date-time
type: string
csrUploadAllowed:
type: boolean
description:
type: string
driverGeneratedCsr:
type: boolean
driverId:
format: uuid
type: string
everyoneIsConsumer:
type: boolean
extendedKeyUsageValues:
items:
enum:
- SERVER
- CLIENT
type: string
type: array
uniqueItems: true
id:
format: uuid
type: string
keyGeneratedByVenafiAllowed:
type: boolean
keyPairId:
format: uuid
type: string
keyReuse:
type: boolean
keyTypes:
items:
$ref: '#/components/schemas/KeyTypeInformation'
type: array
locationId:
format: uuid
type: string
modificationDate:
format: date-time
type: string
name:
type: string
priority:
format: int32
type: integer
product:
$ref: '#/components/schemas/CertificateAuthorityProductInformation'
reason:
type: string
recommendedSettings:
$ref: '#/components/schemas/RecommendedSettingsInformation'
referencingApplicationIds:
items:
format: uuid
type: string
type: array
resourceConsumerTeamIds:
items:
format: uuid
type: string
type: array
uniqueItems: true
resourceConsumerUserIds:
items:
format: uuid
type: string
type: array
uniqueItems: true
sanDnsNameRegexes:
items:
type: string
type: array
sanIpAddressRegexes:
items:
type: string
type: array
sanRegexes:
items:
type: string
type: array
sanRfc822NameRegexes:
items:
type: string
type: array
sanUniformResourceIdentifierRegexes:
items:
type: string
type: array
shareWithAll:
type: boolean
status:
enum:
- AVAILABLE
- UNAVAILABLE
type: string
subjectCNRegexes:
items:
type: string
type: array
subjectCValues:
items:
type: string
type: array
subjectLRegexes:
items:
type: string
type: array
subjectORegexes:
items:
type: string
type: array
subjectOURegexes:
items:
type: string
type: array
subjectSTRegexes:
items:
type: string
type: array
systemGenerated:
type: boolean
trackingData:
$ref: '#/components/schemas/TrackingDataInformation'
type: object
IssuingTemplateDomainsSyncResponse:
properties:
issuingTemplatesInformationList:
items:
$ref: '#/components/schemas/IssuingTemplateDomainsSyncInformation'
type: array
type: object
securitySchemes:
scmOAuth:
type: oauth2
description: 'Strata Cloud Manager APIs authenticate client requests using the OAuth 2.0 Client Credentials flow. Please use the `client_id`, `client_secret` values associated with an IAM service account along with a scope value of `tsg_id:XXXXXXXXXX`, where `XXXXXXXXXX` is the Tenant Service Group (TSG) ID. The resulting JWT access token should be attached to all API calls as a `Bearer` token in the `Authorization` header (ex. `Authorization: Bearer tokenstring`).'
flows:
clientCredentials:
tokenUrl: https://auth.apps.paloaltonetworks.com/oauth2/access_token
scopes: {}
scmToken:
type: http
description: 'Strata Cloud Manager APIs authenticate client requests using the OAuth 2.0 Client Credentials flow. Please use the `client_id`, `client_secret` values associated with an IAM service account along with a scope value of `tsg_id:XXXXXXXXXX`, where `XXXXXXXXXX` is the Tenant Service Group (TSG) ID. The resulting JWT access token should be attached to all API calls as a `Bearer` token in the `Authorization` header (ex. `Authorization: Bearer tokenstring`).'
scheme: bearer
bearerFormat: JWT