Sign Sub Csr
- Print
- PDF
Sign Sub Csr
- Print
- PDF
Article summary
Did you find this summary helpful?
Thank you for your feedback
Available in Classic and VPC
Issue a certificate to perform the role of an intermediate CA using a CA certificate.
Request
The following describes the request format for the endpoint. The request format is as follows:
Method | URI |
---|---|
POST | /ca/{caTag}/sub/sign |
Request headers
For headers common to all Private CA APIs, see Common Private CA headers.
Request path parameters
The following describes the parameters.
Field | Type | Required | Description |
---|---|---|---|
caTag | String | Required | CA tag value
|
Request body
The following describes the request body.
Field | Type | Required | Description |
---|---|---|---|
period | String | Required | Validity period (days)
|
csrPem | String | Required | CSR (PEM)
|
Request example
The following is a sample request.
curl --location --request POST 'https://pca.apigw.ntruss.com/api/v1/ca/********-********/sub/sign' \
--header 'x-ncp-apigw-timestamp: {Timestamp}' \
--header 'x-ncp-iam-access-key: {Access Key}' \
--header 'x-ncp-apigw-signature-v2: {API Gateway Signature}' \
--header 'Content-Type: application/json' \
--data '{
"period": "10",
"csrPem": "-----BEGIN CERTIFICATE REQUEST-----\n{CSR}\n-----END CERTIFICATE REQUEST-----"
}'
Response
The following describes the response format.
Response body
The following describes the response body.
Field | Type | Required | Description |
---|---|---|---|
certificate | String | - | CA certificate (PEM) |
caChain | Array | - | Certificate chain (PEM) |
ocspResponder | String | - | Online Certificate Status Protocol (OCSP) URL |
issuer | String | - | Issuing CA (PEM) |
serialNo | String | - | Certificate serial number |
Response status codes
For response status codes common to all Private CA APIs, see Private CA response status codes.
Response example
The following is a sample example.
{
"code": "SUCCESS",
"msg": "Success",
"data": {
"certificate": "-----BEGIN CERTIFICATE-----\n{Certificate}\n-----END CERTIFICATE-----",
"caChain": [
"-----BEGIN CERTIFICATE-----\n{CA Chain}\n-----END CERTIFICATE-----",
"-----BEGIN CERTIFICATE-----\n{CA Chain}\n-----END CERTIFICATE-----",
"-----BEGIN CERTIFICATE-----\n{CA Chain}\n-----END CERTIFICATE-----"
],
"ocspResponder": "",
"issuer": "-----BEGIN CERTIFICATE-----\n{CA}\n-----END CERTIFICATE-----",
"serialNo": "**:**:**:**:**:**:**:**:**:**:**:**:**:**:**:**:**:**:**:**"
}
}
Was this article helpful?