Palo Alto Networks · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Identity Services Certificate Profiles API
11 actions
11 updates
phrasing
extends
openapi/palo-alto-networks-certificate-profiles-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
What the actions change
x-apievangelist-phrasing
Targets 11
$.info
$.paths['/certificate-profiles'].get
$.paths['/certificate-profiles'].post
$.paths['/certificate-profiles/{id}'].get
$.paths['/certificate-profiles/{id}'].put
$.paths['/certificate-profiles/{id}'].delete
$.paths['/sse/config/v1/certificate-profiles'].get
$.paths['/sse/config/v1/certificate-profiles'].post
$.paths['/sse/config/v1/certificate-profiles/{id}'].get
$.paths['/sse/config/v1/certificate-profiles/{id}'].put
$.paths['/sse/config/v1/certificate-profiles/{id}'].delete
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Identity Services Certificate Profiles API
version: 1.0.0
extends: openapi/palo-alto-networks-certificate-profiles-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 10
- target: $.paths['/certificate-profiles'].get
update:
x-apievangelist-phrasing:
intent: List certificate profiles
effect: read
questions:
- Which certificate profiles are configured in a given folder?
- Can I find a certificate profile by name within a snippet or device?
instructions:
- text: List certificate profiles in folder {folder}.
slots:
folder: query.folder
- text: Find certificate profile {name} on device {device}.
slots:
name: query.name
device: query.device
method: generated
generated: '2026-09-26'
- target: $.paths['/certificate-profiles'].post
update:
x-apievangelist-phrasing:
intent: Create a certificate profile
effect: write
questions:
- How do I create a certificate profile with trusted CA certificates?
- Can a new certificate profile block expired or unknown certs and use OCSP?
instructions:
- text: Create certificate profile {name} with CA certificates {ca_certificates}.
slots:
name: requestBody.name
ca_certificates: requestBody.ca_certificates
- text: Add certificate profile {name} using CAs {ca_certificates} with OCSP {use_ocsp} and block expired {block_expired_cert}.
slots:
name: requestBody.name
ca_certificates: requestBody.ca_certificates
use_ocsp: requestBody.use_ocsp
block_expired_cert: requestBody.block_expired_cert
method: generated
generated: '2026-09-26'
- target: $.paths['/certificate-profiles/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a certificate profile
effect: read
questions:
- How do I view one certificate profile's settings by ID?
- What CA certificates and revocation checks does a specific certificate profile use?
instructions:
- text: Get certificate profile {id}.
slots:
id: path.id
- text: Show the revocation settings of certificate profile {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/certificate-profiles/{id}'].put
update:
x-apievangelist-phrasing:
intent: Update a certificate profile
effect: write
questions:
- How do I change the CA list or CRL settings on an existing certificate profile?
- Can I adjust the OCSP timeout on a certificate profile I already created?
instructions:
- text: Update certificate profile {id} named {name} to use CAs {ca_certificates}.
slots:
id: path.id
name: requestBody.name
ca_certificates: requestBody.ca_certificates
- text: Set OCSP receive timeout to {ocsp_receive_timeout} on existing profile {id} ({name}, CAs {ca_certificates}).
slots:
ocsp_receive_timeout: requestBody.ocsp_receive_timeout
id: path.id
name: requestBody.name
ca_certificates: requestBody.ca_certificates
method: generated
generated: '2026-09-26'
- target: $.paths['/certificate-profiles/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a certificate profile
effect: destructive
questions:
- How do I delete a certificate profile?
- Can I remove a certificate profile by its ID?
instructions:
- text: Delete certificate profile {id}.
slots:
id: path.id
- text: Remove the certificate profile with ID {id}.
slots:
id: path.id
method: generated
generated: '2026-09-26'
- target: $.paths['/sse/config/v1/certificate-profiles'].get
update:
x-apievangelist-phrasing:
intent: List certificate profiles
effect: read
questions:
- Which certificate profiles exist in a Prisma Access folder?
- Can I look up a certificate profile by name?
instructions:
- text: List certificate profiles in folder {folder} through the SSE config v1 path.
slots:
folder: query.folder
- text: Find the certificate profile named {name} in {folder}.
slots:
name: query.name
folder: query.folder
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/certificate-profiles'].post
update:
x-apievangelist-phrasing:
intent: Create a certificate profile
effect: write
questions:
- How do I create a certificate profile with my CA certificates?
- Can a new certificate profile block expired or unknown certificates?
instructions:
- text: Create certificate profile {name} in folder {folder} using CA certificates {ca_certificates}.
slots:
name: requestBody.name
folder: query.folder
ca_certificates: requestBody.ca_certificates
- text: Add cert profile {name} in {folder} with CAs {ca_certificates} and OCSP enabled {use_ocsp}.
slots:
name: requestBody.name
folder: query.folder
ca_certificates: requestBody.ca_certificates
use_ocsp: requestBody.use_ocsp
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/certificate-profiles/{id}'].get
update:
x-apievangelist-phrasing:
intent: Get a certificate profile
effect: read
questions:
- What CA certificates and revocation checks are in a certificate profile?
- Can I view one certificate profile by its ID?
instructions:
- text: Show certificate profile {id}.
slots:
id: path.id
- text: Get the settings of cert profile {id}.
slots:
id: path.id
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/certificate-profiles/{id}'].put
update:
x-apievangelist-phrasing:
intent: Modify a certificate profile
effect: write
questions:
- Can I change the CRL or OCSP settings on an existing certificate profile?
- How do I swap the CA certificates in a certificate profile I already have?
instructions:
- text: Modify certificate profile {id} via the SSE config v1 path, keeping name {name} and CAs {ca_certificates}.
slots:
id: path.id
name: requestBody.name
ca_certificates: requestBody.ca_certificates
- text: Turn on CRL checking ({use_crl}) for cert profile {id}, name {name}, CAs {ca_certificates}.
slots:
use_crl: requestBody.use_crl
id: path.id
name: requestBody.name
ca_certificates: requestBody.ca_certificates
method: generated
generated: '2026-10-01'
- target: $.paths['/sse/config/v1/certificate-profiles/{id}'].delete
update:
x-apievangelist-phrasing:
intent: Delete a certificate profile
effect: destructive
questions:
- Can I delete a certificate profile I no longer use?
- Is a certificate profile removed permanently when deleted?
instructions:
- text: Delete certificate profile {id} using the SSE config v1 endpoint.
slots:
id: path.id
- text: Remove cert profile {id}.
slots:
id: path.id
method: generated
generated: '2026-10-01'