openapi: 3.0.1
info:
title: FlashArray REST Active Directory Certificates API
version: '2.52'
description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos
or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by
mapping identities across the NFS and SMB protocols by using LDAP queries.
'
servers:
- url: /
tags:
- name: Certificates
description: 'Purity//FA creates a self-signed certificate and private key when you start the system for the
first time. You can use the default certificate, change the certificate attributes, create a new
self-signed certificate, or import an SSL certificate signed by a certificate authority.
'
paths:
/api/2.52/certificates:
get:
tags:
- Certificates
summary: Pure Storage List Certificate Attributes
description: 'Displays certificate attributes.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Sort'
- $ref: '#/components/parameters/Total_item_count'
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateGetResponse'
post:
tags:
- Certificates
summary: Pure Storage Create Certificate
description: 'Creates a certificate object and specifies the valid time period and organization
details of the certificate. A certificate can be imported or manually configured.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CertificatePost'
required: true
x-codegen-request-body-name: certificate
responses:
'200':
description: Returns the newly created certificate object.
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateResponse'
x-codegen-request-body-name: certificate
delete:
tags:
- Certificates
summary: Pure Storage Delete Certificate
description: 'Deletes a specific certificate object.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Names'
responses:
'200':
description: OK
content: {}
patch:
tags:
- Certificates
summary: Pure Storage Modify Certificates
description: 'Modifies certificate attributes. Modifying self-signed certificate attributes
replaces the existing certificate with a new one, generated by Purity//FA,
using the specified attributes.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Generate_new_key'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CertificatePost'
required: true
x-codegen-request-body-name: certificate
responses:
'200':
description: Returns the newly updated certificate object.
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateResponse'
x-codegen-request-body-name: certificate
/api/2.52/certificates/certificate-groups:
get:
tags:
- Certificates
summary: Pure Storage List Certificates and Certificate-groups
description: 'Lists membership associations between groups and certificates.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Certificate_group_ids'
- $ref: '#/components/parameters/Certificate_group_names'
- $ref: '#/components/parameters/Certificate_ids'
- $ref: '#/components/parameters/Certificate_names'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Sort'
- $ref: '#/components/parameters/Total_item_count'
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateCertificateGroupGetResponse'
post:
tags:
- Certificates
summary: Pure Storage Create Certificates Orcertificate-groups
description: 'Creates one or more certificates to one or more certificate groups.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Certificate_group_ids'
- $ref: '#/components/parameters/Certificate_group_names'
- $ref: '#/components/parameters/Certificate_ids'
- $ref: '#/components/parameters/Certificate_names'
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateCertificateGroupResponse'
delete:
tags:
- Certificates
summary: Pure Storage Deletes Certificates/certificate-groups
description: 'Deletes one or more certificates from one or more certificate groups.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Certificate_group_ids'
- $ref: '#/components/parameters/Certificate_group_names'
- $ref: '#/components/parameters/Certificate_ids'
- $ref: '#/components/parameters/Certificate_names'
responses:
'200':
description: OK
content: {}
/api/2.52/certificates/uses:
get:
tags:
- Certificates
summary: Pure Storage List Certificates Uses
description: 'Displays the usage and associations of certificates.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Sort'
- $ref: '#/components/parameters/Total_item_count'
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateUseGetResponse'
/api/2.52/certificates/certificate-signing-requests:
post:
tags:
- Certificates
summary: Pure Storage Create Certificate-signing-requests
description: 'Creates a certificate signing request using a specified certificate and parameters.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateSigningRequestPost'
required: true
x-codegen-request-body-name: certificate
responses:
'200':
description: Returns the newly created certificate object.
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateSigningRequestResponse'
x-codegen-request-body-name: certificate
/api/2.26/certificates:
get:
tags:
- Certificates
summary: Pure Storage GET Certificates
description: List array certificates and their attributes.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset_2'
- $ref: '#/components/parameters/Sort_2'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateGetResponse'
post:
tags:
- Certificates
summary: Pure Storage POST Certificates
description: 'Either upload a CA certificate to the array, upload a new appliance certificate with
a private key, or generate a new self-signed certificate with a new private key and
the specified attributes.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CertificatePost_2'
required: true
x-codegen-request-body-name: certificate
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateResponse_2'
x-codegen-request-body-name: certificate
delete:
tags:
- Certificates
summary: Pure Storage DELETE Certificates
description: Delete a CA certificate from the array.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content: {}
patch:
tags:
- Certificates
summary: Pure Storage PATCH Certificates
description: 'Modify SSL certificate attributes such as importing a new certificate
and private key, or change intermediate certificate chains.
Alternatively, generate a new self-signed certificate with specified properties
to overwrite an existing certificate, and optionally generate a new private key.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Generate_new_key'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CertificatePatch'
required: true
x-codegen-request-body-name: certificate
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateResponse_2'
x-codegen-request-body-name: certificate
/api/2.26/certificates/certificate-groups:
get:
tags:
- Certificates
summary: Pure Storage GET Certificates/certificate-groups
description: List membership associations between groups and certificates.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Certificate_group_ids'
- $ref: '#/components/parameters/Certificate_group_names'
- $ref: '#/components/parameters/Certificate_ids'
- $ref: '#/components/parameters/Certificate_names_2'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Offset_2'
- $ref: '#/components/parameters/Sort_2'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateCertificateGroupGetResp'
post:
tags:
- Certificates
summary: Pure Storage POST Certificates/certificate-groups
description: Add one or more certificates to one or more certificate groups.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Certificate_group_ids'
- $ref: '#/components/parameters/Certificate_group_names'
- $ref: '#/components/parameters/Certificate_ids'
- $ref: '#/components/parameters/Certificate_names_2'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateCertificateGroupResponse_2'
delete:
tags:
- Certificates
summary: Pure Storage DELETE Certificates/certificate-groups
description: Remove one or more certificates from one or more certificate groups.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Certificate_group_ids'
- $ref: '#/components/parameters/Certificate_group_names'
- $ref: '#/components/parameters/Certificate_ids'
- $ref: '#/components/parameters/Certificate_names_2'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content: {}
/api/2.26/certificates/certificate-signing-requests:
post:
tags:
- Certificates
summary: Pure Storage Create Certificate-signing-requests
description: 'Creates a certificate signing request using a specified certificate and parameters.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateSigningRequestPost_2'
required: true
x-codegen-request-body-name: certificate
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateSigningRequestResponse_2'
x-codegen-request-body-name: certificate
/api/2.26/certificates/uses:
get:
tags:
- Certificates
summary: Pure Storage GET Certificates/uses
description: List how certificates are being used and by what.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset_2'
- $ref: '#/components/parameters/Sort_2'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/CertificateUseGetResponse'
components:
schemas:
CertificatePatch:
allOf:
- $ref: '#/components/schemas/_certificateBase_2'
- type: object
properties:
days:
description: 'The number of days that the self-signed certificate is valid. Defaults to 3650.
This field can only be specified when creating a new self-signed certificate.
'
type: integer
format: int32
example: 3650
passphrase:
description: 'The passphrase used to encrypt `private_key`.
This field can only be specified when importing a certificate and key pair.
'
type: string
private_key:
description: 'The text of the private key.
This field can only be specified when importing a certificate and key pair.
'
type: string
_builtIn_2:
type: object
properties:
id:
description: 'A non-modifiable, globally unique ID chosen by the system.
'
type: string
readOnly: true
name:
description: Name of the object (e.g., a file system or snapshot).
type: string
readOnly: true
Member:
type: object
properties:
group:
description: 'A reference to a group object that has the referenced member object
as a member.
'
title: Reference
allOf:
- $ref: '#/components/schemas/_reference_2'
member:
description: 'A reference to an object that is a member of the referenced group.
'
title: Reference
allOf:
- $ref: '#/components/schemas/_reference_2'
_referenceNoId:
type: object
properties:
name:
description: 'The resource name, such as volume name, pod name, snapshot name, and so on.
'
type: string
_certificateBase_2:
allOf:
- $ref: '#/components/schemas/_realmsReference'
- type: object
properties:
certificate:
description: The text of the certificate.
type: string
certificate_type:
description: 'The type of certificate. Possible values are `appliance` and
`external`.
Certificates of type `appliance` are used by the array to verify
its identity to clients. Certificates of type `external` are used
by the array to identify external servers to which it is configured
to communicate.
This field may only be specified at certificate creation time.
If not specified at creation time, defaults to `external`.
'
type: string
common_name:
description: The common name field listed in the certificate.
type: string
country:
description: The country field listed in the certificate.
type: string
example: Canada
email:
description: The email field listed in the certificate.
type: string
example: tcrisp@example.com
intermediate_certificate:
description: Intermediate certificate chains.
type: string
issued_by:
description: Who issued this certificate.
type: string
readOnly: true
example: Example Incorporated
issued_to:
description: Who this certificate was issued to.
type: string
readOnly: true
example: Pure Storage, Inc.
key_algorithm:
description: 'The key algorithm used to generate the certificate.
This field can only be specified when creating a new self-signed certificate.
Defaults to `rsa` if not specified. Valid values when creating a new self-signed
certificate only include `rsa`, `ec`, `ed448` and `ed25519`.
'
type: string
example: rsa
key_size:
description: 'The size (in bits) of the private key for the certificate. Default is 2048 bits
for `rsa` key_algorithm, 256 for `ec` and `ed25519`. The `ed448` default key
size is 456. This field can only be specified when creating a new self-signed
certificate.
'
type: integer
format: int32
example: 2048
locality:
description: The locality field listed in the certificate.
type: string
example: Toronto
organization:
description: The organization field listed in the certificate.
type: string
example: Veridian Dynamics
organizational_unit:
description: The organizational unit field listed in the certificate.
type: string
example: Research & Development
state:
description: The state/province field listed in the certificate.
type: string
example: Ontario
status:
description: 'The type of certificate.
Valid values are `self-signed` and `imported`.
'
type: string
readOnly: true
subject_alternative_names:
description: 'The alternative names that are secured by this certificate.
Alternative names may be IP addresses, DNS names, or URIs.
'
type: array
items:
type: string
example: otherdnsname.mydomain.com
valid_from:
description: 'The date when the certificate starts being valid.
'
type: integer
format: int64
readOnly: true
example: 1491070899000
valid_to:
description: 'The date when the certificate stops being valid.
'
type: integer
format: int64
readOnly: true
example: 152424849000
_memberWithType:
type: object
properties:
group:
$ref: '#/components/schemas/_referenceWithType'
member:
$ref: '#/components/schemas/_referenceWithType'
CertificateCertificateGroupResponse_2:
type: object
properties:
items:
description: 'A list of certificate and certificate group relationships.
'
type: array
items:
$ref: '#/components/schemas/Member'
_reference:
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified.
'
type: string
name:
description: 'The resource name, such as volume name, pod name,
snapshot name, and so on.
'
type: string
x-aliases:
- _referenceWithoutType
_fixedReferenceWithoutType:
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified.
'
type: string
readOnly: true
name:
description: 'The resource name, such as volume name, file system name,
snapshot name, and so on.
'
type: string
readOnly: true
x-readOnly: true
CertificateCertificateGroupGetResponse:
allOf:
- $ref: '#/components/schemas/PageInfo'
- $ref: '#/components/schemas/CertificateCertificateGroupResponse'
_referenceWithType:
allOf:
- $ref: '#/components/schemas/_reference'
- type: object
properties:
resource_type:
description: 'Type of the object (full name of the endpoint).
Valid values are `hosts`, `host-groups`, `network-interfaces`, `pods`,
`ports`, `pod-replica-links`, `subnets`, `volumes`, `volume-snapshots`,
`volume-groups`, `directories`, `policies/nfs`, `policies/smb`, and
`policies/snapshot`, etc.
'
type: string
x-aliases:
- _reference
CertificateSigningRequest:
description: 'SSL certificate managed by Purity//FA.
'
type: object
properties:
certificate_signing_request:
description: 'The text of a new certificate signing request.
'
type: string
CertificateSigningRequest_2:
description: 'SSL certificate managed by Purity.
'
type: object
properties:
certificate_signing_request:
description: 'The text of a new certificate signing request.
'
type: string
_fixedReferenceWithType:
allOf:
- $ref: '#/components/schemas/_fixedReference'
- type: object
properties:
resource_type:
description: 'Type of the object (full name of the endpoint).
Valid values are the unique part of the resource''s REST endpoint.
For example, a reference to a file system would have a
`resource_type` of `file-systems`.
'
type: string
readOnly: true
x-aliases:
- _fixedReference
CertificateSigningRequestPost:
description: SSL Certificate managed by Purity//FA.
type: object
properties:
certificate:
$ref: '#/components/schemas/_referenceNoId'
common_name:
description: The common name field listed in the certificate.
type: string
example: Pure Storage Inc.
country:
description: Two-letter country (ISO) code listed in the certificate.
type: string
example: CA
email:
description: The email field listed in the certificate.
type: string
example: tcrisp@veridiandynamics.com
locality:
description: The locality field listed in the certificate.
type: string
example: Toronto
organization:
description: The organization field listed in the certificate.
type: string
example: Veridian Dynamics
organizational_unit:
description: The organizational unit field listed in the certificate.
type: string
example: Research & Development
state:
description: The state/province field listed in the certificate.
type: string
example: Ontario
subject_alternative_names:
description: 'The alternative names that are secured by this certificate.
Alternative names include IP addresses, DNS names, or URIs.
'
type: array
items:
type: string
example: otherdnsname.mydomain.com
Certificate_2:
allOf:
- description: SSL Certificate managed by Purity.
- $ref: '#/components/schemas/_builtIn_2'
- $ref: '#/components/schemas/_certificateBase_2'
CertificateResponse:
type: object
properties:
items:
type: array
items:
$ref: '#/components/schemas/Certificate'
CertificateCertificateGroupGetResp:
allOf:
- $ref: '#/components/schemas/PageInfo_2'
- $ref: '#/components/schemas/CertificateCertificateGroupResponse_2'
CertificatePost_2:
allOf:
- $ref: '#/components/schemas/_certificateBase_2'
- type: object
properties:
days:
description: 'The number of days that the self-signed certificate is valid. Defaults to 3650.
This field can only be specified when creating a new self-signed certificate.
'
type: integer
format: int32
example: 3650
passphrase:
description: 'The passphrase used to encrypt `private_key`.
This field can only be specified when importing a certificate and key pair.
'
type: string
private_key:
description: 'The text of the private key.
This field can only be specified when importing a certificate and key pair.
'
type: string
_builtIn:
description: 'A built-in resource. Many are singletons predefined by Purity (e.g., support
settings). Some correspond to a piece of software, like an app, or hardware,
like a controller. Others are created by the system in response to some event
(e.g., alerts, audit records).
Typically, a user can''t create, delete or rename a built-in resource. A few
can be created or deleted, but not renamed because the names are meaningful
to Purity (e.g., VIFs).
'
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified and cannot refer to another resource.
'
type: string
readOnly: true
name:
description: 'A locally unique, system-generated name. The name cannot be modified.
'
type: string
readOnly: true
CertificateUse:
allOf:
- $ref: '#/components/schemas/_builtIn'
- type: object
properties:
group:
description: 'A reference to the certificate group that is being used, if any, where
this certificate is a member of the certificate-group.
Returns `null` if the referenced user object is not associated
with a group and is directly using this certificate.
'
title: FixedReferenceWithType
allOf:
- $ref: '#/components/schemas/_fixedReferenceWithType'
use:
description: A reference to an object using this certificate.
title: FixedReferenceWithType
allOf:
- $ref: '#/components/schemas/_fixedReferenceWithType'
Certificate:
allOf:
- $ref: '#/components/schemas/_builtIn'
- $ref: '#/components/schemas/_certificateBase'
- type: object
CertificatePost:
allOf:
- $ref: '#/components/schemas/_certificateBase'
- type: object
properties:
days:
description: 'The number of days that the self-signed certificate is valid. Defaults to 3650.
This field can only be specified when creating a new self-signed certificate.
'
type: integer
format: int32
example: 3650
key:
description: 'The text of the private key.
This field can only be specified when importing a certificate and key pair.
'
type: string
passphrase:
description: 'The passphrase used to encrypt `key`.
This field can only be specified when importing a certificate and key pair.
'
type: string
CertificateResponse_2:
type: object
properties:
items:
description: A list of certificate objects.
type: array
items:
# --- truncated at 32 KB (51 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/openapi/pure-storage-certificates-api-openapi.yml