Signers
Create a RICAL signer
/v1/ecosystems/certificates/rical-signersCreates a RICAL signer.
- Only available in implementations using unmanaged (external) DTS root CA certificates.
- A maximum of five RICAL signers can be created per tenant.
Provide either caId or intermediateCaId.
Roles
Analytics Events
Authorization
bearerAuth In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/ecosystems/certificates/rical-signers" \ -H "Content-Type: application/json" \ -d '{}'{ "id": "782f1885-c7c2-4459-8426-b6d7c111b0b1", "csrPem": "-----BEGIN CERTIFICATE REQUEST-----\nMIIDXTCCAkWgAwIBAgIJAL5...\n-----END CERTIFICATE REQUEST-----", "caId": "b0aae560-10e7-4247-8e96-7cdd3578a1e2", "intermediateCaId": "c1bbe671-21f8-5358-9537-eed4669b43f3", "active": false}Retrieve all RICAL signers
/v1/ecosystems/certificates/rical-signersRetrieves all RICAL signers.
Roles
Analytics Events
Authorization
bearerAuth In: header
Query Parameters
Range size of returned list.
1 <= value <= 1000100Starting point for the list of entries.
Response Body
application/json
application/json
application/json
curl -X GET "https://example.com/v1/ecosystems/certificates/rical-signers"{ "data": [ { "id": "782f1885-c7c2-4459-8426-b6d7c111b0b1", "active": true, "certificatePem": "-----BEGIN CERTIFICATE-----\nMIIDXTCCAkWgAwIBAgIJAL5...\n-----END CERTIFICATE-----", "certificateFingerprint": "f6cad6e579d70b3973efa60624af731a580d1a11a7579e70f2f10f059dc86172", "certificateData": { "commonName": "example.com", "country": "US", "notAfter": "2024-10-22T00:00:00Z", "notBefore": "2023-10-22T00:00:00Z" } } ], "nextCursor": "Y3JlYXRlZEF0PTIwMjAtMDgtMjVUMDY6NDY6MDkuNTEwWiZpZD1hNjZmZmVhNS04NDhlLTQzOWQtODBhNC1kZGE1NWY1M2UzNmM"}Retrieve a RICAL signer
/v1/ecosystems/certificates/rical-signers/{ricalSignerId}Retrieves a RICAL signer.
Roles
Analytics Events
Authorization
bearerAuth In: header
Path Parameters
Unique identifier of the RICAL signer.
uuidResponse Body
application/json
application/json
curl -X GET "https://example.com/v1/ecosystems/certificates/rical-signers/123e4567-e89b-12d3-a456-426614174000"{ "id": "782f1885-c7c2-4459-8426-b6d7c111b0b1", "active": true, "certificatePem": "-----BEGIN CERTIFICATE-----\nMIIDXTCCAkWgAwIBAgIJAL5...\n-----END CERTIFICATE-----", "certificateFingerprint": "f6cad6e579d70b3973efa60624af731a580d1a11a7579e70f2f10f059dc86172", "certificateData": { "commonName": "example.com", "country": "US", "notAfter": "2024-10-22T00:00:00Z", "notBefore": "2023-10-22T00:00:00Z" }}Update a RICAL signer
/v1/ecosystems/certificates/rical-signers/{ricalSignerId}Updates a RICAL signer by:
- Providing a RICAL Signer Certificate in PEM format that matches its Certificate Signing Request (CSR).
- Activating or deactivating the RICAL signer. Only RICAL signers with a valid
certificatePemcan be activated. - The
certificatePemfield becomes immutable after it's updated for the first time.
Roles
Analytics Events
Authorization
bearerAuth In: header
Path Parameters
Unique identifier of the RICAL signer.
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
curl -X PUT "https://example.com/v1/ecosystems/certificates/rical-signers/123e4567-e89b-12d3-a456-426614174000" \ -H "Content-Type: application/json" \ -d '{ "active": true }'{ "id": "782f1885-c7c2-4459-8426-b6d7c111b0b1", "active": true, "certificatePem": "-----BEGIN CERTIFICATE-----\nMIIDXTCCAkWgAwIBAgIJAL5...\n-----END CERTIFICATE-----", "certificateFingerprint": "f6cad6e579d70b3973efa60624af731a580d1a11a7579e70f2f10f059dc86172", "certificateData": { "commonName": "example.com", "country": "US", "notAfter": "2024-10-22T00:00:00Z", "notBefore": "2023-10-22T00:00:00Z" }}Delete a RICAL signer
/v1/ecosystems/certificates/rical-signers/{ricalSignerId}Deletes a RICAL signer.
Deleting a RICAL signer does not affect any RICALs it has already signed — those remain valid. It only means this signer can no longer be used to sign new RICALs.
Roles
Analytics Events
Authorization
bearerAuth In: header
Path Parameters
Unique identifier of the RICAL signer.
uuidResponse Body
application/json
application/json
curl -X DELETE "https://example.com/v1/ecosystems/certificates/rical-signers/123e4567-e89b-12d3-a456-426614174000"How would you rate this page?
Last updated on