addInternalCertificate

The addInternalCertificate operation handles configuration related to InternalCertificate model. 

Data Parameters

Parameter Required Type Description
name False string A mandatory UTF string containing the name for the certificate. The string can be up to 128 characters. The name is used in the configuration as an object name only, it is not part of the certificate itself.
Field level constraints: cannot be null, length must be between 0 and 128 (inclusive), cannot have HTML, must match pattern ^[a-zA-Z0-9][a-zA-Z0-9.+-]*. (Note: Additional constraints might exist)
cert False string PEM formatted X.509v3 certificate.
privateKey False string PEM formatted private key. Only unencrypted keys are supported.
passPhrase False string Password used for encrypted private key. Encrypted keys are not supported yet.
Field level constraints: cannot have HTML. (Note: Additional constraints might exist)
issuerCommonName False string Common Name, typically product name/brand, of the Authority (issuer) that signed and issued the certificate. This is automatically extracted from the uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
issuerCountry False string An ISO3166 two character country code of the Authority (issuer) that signed and issued the certificate. This is automatically extracted from the uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
issuerLocality False string Locality, city name, of the Authority (issuer) that signed and issued the certificate. This is automatically extracted from the uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
issuerOrganization False string Organization, company name, of the Authority (issuer) that signed and issued the certificate. This is automatically extracted from the uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
issuerOrganizationUnit False string The Organization Unit, division or unit, of the Authority (issuer) that signed and issued the certificate. This is automatically extracted from the uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
issuerState False string State or the province of the Authority (issuer) that signed and issued the certificate. This is automatically extracted from the uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
subjectCommonName False string An Unicode alphanumeric string containing the Common Name, typically product name/brand, of the entity (subject) being certified or authenticated in the given certificate. This is mandatory input value for Self-Signed certificate and extracted from an uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
subjectCountry False string An ISO3166 two character country code of the Authority (issuer) that signed and issued the certificate. This is mandatory input value for Self-Signed certificate and extracted from an uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
subjectDistinguishedName False string A DN (Distinguished Name) defining the entity (subject) being certified or authenticated in the given certificate. For a root certificate the issuer and subject will be the same DN. This is automatically extracted from the uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
subjectLocality False string An Unicode alphanumeric string containing the locality, city name, of the entity (subject) being certified or authenticated in the given certificate. This is mandatory input value for Self-Signed certificate and extracted from an uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
subjectOrganization False string An Unicode alphanumeric string containing the organization, company name, of the entity (subject) being certified or authenticated in the given certificate. This is mandatory input value for Self-Signed certificate and extracted from an uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
subjectOrganizationUnit False string An Unicode alphanumeric string containing the Organization Unit, division or unit, of the entity (subject) being certified or authenticated in the given certificate. This is mandatory input value for Self-Signed certificate and extracted from an uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
subjectState False string An Unicode alphanumeric string containing the state or the province of the entity (subject) being certified or authenticated in the given certificate. This is mandatory input value for Self-Signed certificate and extracted from an uploaded certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
validityStartDate False string This is current date in UTC format for Self-Signed certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
validityEndDate False string This is set to five years in UTC format from the current date for Self-Signed certificate.
Field level constraints: cannot have HTML, must match pattern ^((?!;).)*$. (Note: Additional constraints might exist)
isSystemDefined False boolean A boolean value, TRUE and FALSE (the default). The TRUE value indicates that certificate is created by system and cannot be deleted. FALSE indicates that the certificate can be deleted.
certType False string An mandatory enum value that specifies the type of internal certificate. Values can be one of the following.
UPLOAD - Certificate is already defined and certificate and private string will be uploaded.
SELFSIGNED - Generate an internal certificate using the provided values.
type False string A UTF8 string, all letters lower-case, that represents the class-type. This corresponds to the class name.

Example

- name: Execute 'addInternalCertificate' operation
  ftd_configuration:
    operation: "addInternalCertificate"
    data:
        name: "{{ name }}"
        cert: "{{ cert }}"
        privateKey: "{{ private_key }}"
        passPhrase: "{{ pass_phrase }}"
        issuerCommonName: "{{ issuer_common_name }}"
        issuerCountry: "{{ issuer_country }}"
        issuerLocality: "{{ issuer_locality }}"
        issuerOrganization: "{{ issuer_organization }}"
        issuerOrganizationUnit: "{{ issuer_organization_unit }}"
        issuerState: "{{ issuer_state }}"
        subjectCommonName: "{{ subject_common_name }}"
        subjectCountry: "{{ subject_country }}"
        subjectDistinguishedName: "{{ subject_distinguished_name }}"
        subjectLocality: "{{ subject_locality }}"
        subjectOrganization: "{{ subject_organization }}"
        subjectOrganizationUnit: "{{ subject_organization_unit }}"
        subjectState: "{{ subject_state }}"
        validityStartDate: "{{ validity_start_date }}"
        validityEndDate: "{{ validity_end_date }}"
        isSystemDefined: "{{ is_system_defined }}"
        certType: "{{ cert_type }}"
        type: "{{ type }}"