openapi: 3.2.0 info: title: Godaddy Customers API servers: - url: https://api.ote-godaddy.com tags: - name: Customers paths: /v2/customers/{customerId}/certificates: get: tags: - Customers parameters: - $ref: '#/components/parameters/customerId' - $ref: '#/components/parameters/offset' - $ref: '#/components/parameters/limit' responses: '200': description: Customer certificate information retrieved. content: application/json: schema: $ref: '#/components/schemas/CertificateSummariesV2' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '422': $ref: '#/components/responses/422' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' description: 'This method can be used to retrieve a list of certificates for a specified customer. **shopperId** is **not the same** as **customerId**. **shopperId** is a number of max length 10 digits (*ex:* 1234567890) whereas **customerId** is a UUIDv4 (*ex:* 295e3bc3-b3b9-4d95-aae5-ede41a994d13)' operationId: getCustomerCertificatesByCustomerId summary: Retrieve customer's certificates /v2/customers/{customerId}/certificates/{certificateId}: get: tags: - Customers parameters: - $ref: '#/components/parameters/customerId' - $ref: '#/components/parameters/certificateId' responses: '200': description: Certificate details retrieved content: application/json: schema: $ref: '#/components/schemas/CertificateDetailV2' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '422': $ref: '#/components/responses/422' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' description: 'Once the certificate order has been created, this method can be used to check the status of the certificate. This method can also be used to retrieve details of the certificate. **shopperId** is **not the same** as **customerId**. **shopperId** is a number of max length 10 digits (*ex:* 1234567890) whereas **customerId** is a UUIDv4 (*ex:* 295e3bc3-b3b9-4d95-aae5-ede41a994d13)' operationId: getCertificateDetailByCertIdentifier summary: Retrieve individual certificate details /v2/customers/{customerId}/certificates/{certificateId}/domainVerifications: get: tags: - Customers parameters: - $ref: '#/components/parameters/customerId' - $ref: '#/components/parameters/certificateId' responses: '200': description: Domain verification status list for specified certificateId. content: application/json: schema: type: array items: $ref: '#/components/schemas/DomainVerificationSummary' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '422': $ref: '#/components/responses/422' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' description: 'This method can be used to retrieve the domain verification status for a certificate request. **shopperId** is **not the same** as **customerId**. **shopperId** is a number of max length 10 digits (*ex:* 1234567890) whereas **customerId** is a UUIDv4 (*ex:* 295e3bc3-b3b9-4d95-aae5-ede41a994d13) "' operationId: getDomainInformationByCertificateId summary: Retrieve domain verification status /v2/customers/{customerId}/certificates/{certificateId}/domainVerifications/{domain}: get: tags: - Customers description: 'Retrieve detailed information for supplied domain, including domain verification details and Certificate Authority Authorization (CAA) verification details. **shopperId** is **not the same** as **customerId**. **shopperId** is a number of max length 10 digits (*ex:* 1234567890) whereas **customerId** is a UUIDv4 (*ex:* 295e3bc3-b3b9-4d95-aae5-ede41a994d13)' operationId: getDomainDetailsByDomain summary: Retrieve detailed information for supplied domain parameters: - $ref: '#/components/parameters/customerId' - $ref: '#/components/parameters/certificateId' - $ref: '#/components/parameters/domain' responses: '200': description: Retrieve detailed information for supplied domain, including domain verification details and Certificate Authority Authorization (CAA) verification details. content: application/json: schema: $ref: '#/components/schemas/DomainVerificationDetail' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '422': $ref: '#/components/responses/422' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' /v2/customers/{customerId}/certificates/acme/externalAccountBinding: get: tags: - Customers description: Use this endpoint to retrieve a key identifier and Hash-based Message Authentication Code (HMAC) key for Automated Certificate Management Environment (ACME) External Account Binding (EAB). These credentials can be used with an ACME client that supports EAB (ex. CertBot) to automate the issuance request and deployment of DV SSL certificates operationId: getAcmeExternalAccountBinding summary: Retrieves the external account binding for the specified customer parameters: - $ref: '#/components/parameters/customerId' responses: '200': description: Acme key identifier and HMAC key for the external account binding. Directory URI is also provided for making ACME requests. content: application/json: schema: $ref: '#/components/schemas/ExternalAccountBinding' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '404': $ref: '#/components/responses/404' '422': $ref: '#/components/responses/422' '429': $ref: '#/components/responses/429' '500': $ref: '#/components/responses/500' components: parameters: offset: name: offset required: false in: query description: Number of results to skip for pagination schema: type: integer format: integer-positive pattern: ^[0-9]+$ domain: in: path name: domain description: A valid domain name in the certificate request required: true schema: type: string format: domain certificateId: description: Certificate id to lookup in: path name: certificateId required: true schema: type: string limit: name: limit required: false in: query description: Maximum number of items to return schema: type: integer format: integer-positive pattern: ^[0-9]+$ customerId: name: customerId description: An identifier for a customer in: path required: true schema: type: string responses: '500': description: Internal server error x-error-codes: - INTERNAL_SERVER_ERROR content: application/json: schema: $ref: '#/components/schemas/Error' '422': description: Application-specific request error x-error-codes: - INVALID_INPUT content: application/json: schema: $ref: '#/components/schemas/Error' '429': description: Too many requests received within interval x-error-codes: - RATE_LIMITED content: application/json: schema: $ref: '#/components/schemas/ErrorLimit' '401': description: Authentication info not sent or is invalid x-error-codes: - UNAUTHORIZED content: application/json: schema: $ref: '#/components/schemas/Error' '404': description: Resource not found x-error-codes: - NOT_FOUND content: application/json: schema: $ref: '#/components/schemas/Error' '403': description: Authenticated user is not allowed access x-error-codes: - ACCESS_DENIED content: application/json: schema: $ref: '#/components/schemas/Error' schemas: CertificateOrganization: properties: address: $ref: '#/components/schemas/CertificateAddress' description: Organization presence address assumedName: description: Only for EVSSL. The DBA(does business as) name for the organization. type: string jurisdictionOfIncorporation: $ref: '#/components/schemas/JurisdictionOfIncorporation' description: Jurisdiction of Incorporation name: description: Name of organization that owns common name type: string phone: description: Phone number for organization type: string registrationAgent: description: Only for EVSSL. type: string registrationNumber: description: Only for EVSSL. type: string required: - name - phone - address ErrorLimit: x-error-model: true additionalProperties: false allOf: - type: object properties: retryAfterSec: format: integer-positive type: integer description: Number of seconds to wait before attempting a similar request required: - retryAfterSec - $ref: '#/components/schemas/Error' ExternalAccountBinding: properties: directoryUrl: description: ACME directory resource URL. format: url type: string keyId: description: EAB key identifier for the ACME account. type: string hmacKey: description: EAB HMAC key for the ACME account type: string required: - directoryUrl - keyId - hmacKey CertificateContact: properties: email: description: Email address of requestor contact type: string jobTitle: description: Only used for EVSSL. Job title of requestor contact type: string nameFirst: description: First name of requestor contact type: string nameLast: description: Last name of requestor contact type: string nameMiddle: description: Middle initial of requestor contact type: string phone: description: Phone number for requestor contact type: string suffix: description: Suffix of requestor contact type: string required: - nameFirst - nameLast - email - phone CertificateDetailV2: properties: certificateId: description: The unique identifier of the certificate request. Only present if no errors returned type: string commonName: description: Common name of certificate format: domain type: string period: description: Validity period of order. Specified in years type: integer type: description: "Certificate type: \n * `DV_SSL` - (Domain Validated Secure Sockets Layer) SSL certificate validated using domain name only\n * `DV_WILDCARD_SSL` - SSL certificate containing subdomains which is validated using domain name only\n * `EV_SSL` - (Extended Validation) SSL certificate validated using organization information, domain name, business legal status, and other factors\n * `OV_CODE_SIGNING` - Code signing SSL certificate used by software developers to digitally sign apps. Validated using organization information\n * `OV_DRIVER_SIGNING` - Driver signing SSL certificate request used by software developers to digitally sign secure code for Windows hardware drivers. Validated using organization information\n * `OV_SSL` - SSL certificate validated using organization information and domain name\n * `OV_WILDCARD_SSL` - SSL certificate containing subdomains which is validated using organization information and domain name\n * `UCC_DV_SSL` - (Unified Communication Certificate) Multi domain SSL certificate validated using domain name only\n * `UCC_EV_SSL` - Multi domain SSL certificate validated using organization information, domain name, business legal status, and other factors\n * `UCC_OV_SSL` - Multi domain SSL certificate validated using organization information and domain name\n" enum: - DV_SSL - DV_WILDCARD_SSL - EV_SSL - OV_CODE_SIGNING - OV_DRIVER_SIGNING - OV_SSL - OV_WILDCARD_SSL - UCC_DV_SSL - UCC_EV_SSL - UCC_OV_SSL type: string status: description: "Certificate status (if issued or revoked): \n * `CANCELED` - Certificate request was canceled by customer\n * `DENIED` - Certificate request was denied by customer\\n * `EXPIRED` - Issued certificate has exceeded the valid end date\n * `ISSUED` - Certificate has been issued and is within validity period\n * `PENDING_ISSUANCE` - Certificate request has completed domain verification and is in the process of being issued\n * `PENDING_REKEY` - Previously issued certificate was rekeyed by customer and is in the process of being reissued\n * `PENDING_REVOCATION` - Previously issued certificate is in the process of being revoked\n * `REVOKED` - Issued certificate has been revoked\\n * `UNUSED` - Certificate in an error state\n" enum: - PENDING_ISSUANCE - ISSUED - REVOKED - CANCELED - DENIED - PENDING_REVOCATION - PENDING_REKEY - UNUSED - EXPIRED type: string createdAt: description: The date the certificate was ordered. format: iso-datetime type: string completedAt: description: The date the certificate request completed processing. format: iso-datetime type: string validEndAt: description: The end date of the certificate's validity (if issued or revoked). format: iso-datetime type: string validStartAt: description: The start date of the certificate's validity (if issued or revoked). format: iso-datetime type: string revokedAt: description: The revocation date of certificate (if revoked). format: iso-datetime type: string renewalAvailable: description: Only returned when a renewal is available. type: boolean serialNumber: description: Serial number of certificate (if issued or revoked) type: string serialNumberHex: description: Hexadecmial format for Serial number of certificate(if issued or revoked) type: string slotSize: description: "Number of subject alternative names (SAN) to be included in certificate (if UCC): \n * `FIVE` - Five slot UCC request\n * `TEN` - Ten slot UCC request\n * `FIFTEEN` - Fifteen slot UCC request\n * `TWENTY` - Twenty slot UCC request\n * `THIRTY` - Thirty slot UCC request\n * `FOURTY` - Fourty slot UCC request\n * `FIFTY` - Fifty slot UCC request\n * `ONE_HUNDRED` - One hundred slot UCC request\n" enum: - FIVE - TEN - FIFTEEN - TWENTY - THIRTY - FOURTY - FIFTY - ONE_HUNDRED type: string subjectAlternativeNames: description: Subject Alternative names. Collection of subjectAlternativeNames to be included in certificate. items: format: domain type: string type: array uniqueItems: true contact: $ref: '#/components/schemas/CertificateContact' organization: $ref: '#/components/schemas/CertificateOrganization' csr: description: Certificate signing request (if present) in PEM format type: string rootType: description: "Root type: \n * `GODADDY_SHA_1` - GoDaddy (Secure Hash Algorithm 1) SHA-1 root type\n * `GODADDY_SHA_2` - GoDaddy (Secure Hash Algorithm 2) SHA-2 root type\n * `STARFIELD_SHA_1` - Starfield SHA-1 root type\n * `STARFIELD_SHA_2` - Starfield SHA-2 root type\n" enum: - GODADDY_SHA_1 - GODADDY_SHA_2 - STARFIELD_SHA_1 - STARFIELD_SHA_2 type: string deniedReason: description: Only present if certificate order has been denied type: string progress: description: Percentage of completion for certificate vetting type: integer required: - certificateId - commonName - period - type - status - createdAt - contact CertificateSummaryV2: properties: certificateId: description: The unique identifier of the certificate request. type: string commonName: description: Common name for the certificate request. format: domain type: string period: description: Validity period of order. Specified in years. type: integer type: description: "Certificate type: \n * `DV_SSL` - (Domain Validated Secure Sockets Layer) SSL certificate validated using domain name only\n * `DV_WILDCARD_SSL` - SSL certificate containing subdomains which is validated using domain name only\n * `EV_SSL` - (Extended Validation) SSL certificate validated using organization information, domain name, business legal status, and other factors\n * `OV_CODE_SIGNING` - Code signing SSL certificate used by software developers to digitally sign apps. Validated using organization information\n * `OV_DRIVER_SIGNING` - Driver signing SSL certificate request used by software developers to digitally sign secure code for Windows hardware drivers. Validated using organization information\n * `OV_SSL` - SSL certificate validated using organization information and domain name\n * `OV_WILDCARD_SSL` - SSL certificate containing subdomains which is validated using organization information and domain name\n * `UCC_DV_SSL` - (Unified Communication Certificate) Multi domain SSL certificate validated using domain name only\n * `UCC_EV_SSL` - Multi domain SSL certificate validated using organization information, domain name, business legal status, and other factors\n * `UCC_OV_SSL` - Multi domain SSL certificate validated using organization information and domain name\n" enum: - DV_SSL - DV_WILDCARD_SSL - EV_SSL - OV_CODE_SIGNING - OV_DRIVER_SIGNING - OV_SSL - OV_WILDCARD_SSL - UCC_DV_SSL - UCC_EV_SSL - UCC_OV_SSL type: string status: description: "Certificate status (if issued or revoked): \n * `CANCELED` - Certificate request was canceled by customer\n * `DENIED` - Certificate request was denied by customer\n * `EXPIRED` - Issued certificate has exceeded the valid end date\n * `ISSUED` - Certificate has been issued and is within validity period\n * `PENDING_ISSUANCE` - Certificate request has completed domain verification and is in the process of being issued\n * `PENDING_REKEY` - Previously issued certificate was rekeyed by customer and is in the process of being reissued\n * `PENDING_REVOCATION` - Previously issued certificate is in the process of being revoked\n * `REVOKED` - Issued certificate has been revoked\n * `UNUSED` - Certificate in an error state\n" enum: - ISSUED - CANCELED - DENIED - EXPIRED - PENDING_ISSUANCE - PENDING_REKEY - PENDING_REVOCATION - REVOKED - UNUSED type: string createdAt: description: Date that the certificate request was received. format: iso-datetime type: string completedAt: description: The date the certificate request completed processing (if issued or revoked). format: iso-datetime type: string validEndAt: description: The end date of the certificate's validity (if issued or revoked). format: iso-datetime type: string validStartAt: description: The start date of the certificate's validity (if issued or revoked). format: iso-datetime type: string revokedAt: description: The revocation date of certificate (if revoked). format: iso-datetime type: string renewalAvailable: description: Only returned when a renewal is available. type: boolean serialNumber: description: Serial number of certificate (if issued or revoked). type: string slotSize: description: "Number of subject alternative names (SAN) to be included in certificate (if UCC): \n * `FIVE` - Five slot UCC request\n * `TEN` - Ten slot UCC request\n * `FIFTEEN` - Fifteen slot UCC request\n * `TWENTY` - Twenty slot UCC request\n * `THIRTY` - Thirty slot UCC request\n * `FOURTY` - Fourty slot UCC request\n * `FIFTY` - Fifty slot UCC request\n * `ONE_HUNDRED` - One hundred slot UCC request\n" enum: - FIVE - TEN - FIFTEEN - TWENTY - THIRTY - FOURTY - FIFTY - ONE_HUNDRED type: string subjectAlternativeNames: description: Subject Alternative names (if UCC). Collection of subjectAlternativeNames to be included in certificate. format: domain items: type: string type: array uniqueItems: true required: - certificateId - commonName - period - type - createdAt - status DomainVerificationSummary: properties: domain: description: Domain name format: domain type: string domainEntityId: description: A unique identifier that can be leveraged for retrieving domain verification related information. Primarily used when troubleshooting a request type: integer dceToken: description: DCE verification type token (if DCE verification type). type: string status: description: "Domain verification status: \n * `AWAITING` - Verification pending customer input\n * `INVALID` - SAN connected to a cancelled request\n * `COMPLETED` - Verification completed\n * `FAILED_VERIFICATION` - Verification failed\n * `PENDING_POSSIBLE_FRAUD` - Flagged for a system level fraud review\n * `VERIFIED_POSSIBLE_FRAUD` - Fraud detection reviewed but verified\n * `DROPPED` - SAN dropped from request\n * `REVOKED_CERT` - Certificate revoked\n * `DROPPED_GOOGLE_SAFE_BROWSING` - SAN dropped from request due to Google Safe Browsing check\n * `DROPPED_CERTIFICATE_AUTHORITY_AUTHORIZATION` - SAN dropped from request due to Certificate Authorization Authority DNS record check\n" enum: - COMPLETED - FAILED_VERIFICATION - VERIFIED_POSSIBLE_FRAUD - DROPPED - DROPPED_CERTIFICATE_AUTHORITY_AUTHORIZATION - DROPPED_GOOGLE_SAFE_BROWSING - INVALID - AWAITING - PENDING_POSSIBLE_FRAUD - REVOKED_CERTIFICATE type: string createdAt: description: Timestamp indicating when the domain verification process was started format: iso-datetime type: string modifiedAt: description: Timestamp indicating when the domain verification process was last updated format: iso-datetime type: string type: description: "Domain verification type: \n * `AUTO_GENERATED_DOMAIN_ACCESS_EMAIL_ADMIN` - Domain verified using domain control verification email sent to admin@\n * `AUTO_GENERATED_DOMAIN_ACCESS_EMAIL_ADMINSTRATOR` - Domain verified using domain control verification email sent to administrator@\n * `AUTO_GENERATED_DOMAIN_ACCESS_EMAIL_HOST_MASTER` - Domain verified using domain control verification email sent to hostmaster@\n * `AUTO_GENERATED_DOMAIN_ACCESS_EMAIL_POST_MASTER` - Domain verified using domain control verification email sent to postmaster@\n * `AUTO_GENERATED_DOMAIN_ACCESS_EMAIL_WEB_MASTER` - Domain verified using domain control verification email sent to webmaster@\n * `DOMAIN_ACCESS_EMAIL` - Domain verified using a domain access email\n * `DOMAIN_ACCESS_LETTER` - Customer completed a domain access letter which was used for domain verification\n * `DOMAIN_CONTROL_EMAIL` - Domain verified using HTML file or DNS zone file text value\n * `DOMAIN_ZONE_CONTROL` - DNS zone file containing a pre-generated text value used for domain verification\n * `MANUAL_DOMAIN_ACCESS_EMAIL` - DAE sent to an email address manually entered by a rep\n * `PREVIOUS_DOMAIN_ACCESS_EMAIL` - Customers domain access email for a prior certificate request was used for domain verification\n * `REGISTRATION_AUTHORITY_DOMAIN_ACCESS_LETTER` - Representative reviewed a customer provided domain access letter and verified domain\n * `REGISTRATION_AUTHORITY_DOMAIN_ZONE_CONTROL` - Representative verified domain using a manual domain zone control check\n * `REGISTRATION_AUTHORITY_OVERRIDE` - Representative verified domain using alternative methods\n * `REGISTRATION_AUTHORITY_WEBSITE_CONTROL` - Representative verified domain using a manual website control check\n * `CUSTOMER_OWNED` - Validated customer account information used for domain control verification\n * `WEBSITE_CONTROL` - HTML file in root website directory containing pre-generated value used for domain control verification\n" enum: - DOMAIN_CONTROL_EMAIL - AUTO_GENERATED_DOMAIN_ACCESS_EMAIL_ADMIN - AUTO_GENERATED_DOMAIN_ACCESS_EMAIL_ADMINSTRATOR - AUTO_GENERATED_DOMAIN_ACCESS_EMAIL_HOST_MASTER - AUTO_GENERATED_DOMAIN_ACCESS_EMAIL_POST_MASTER - AUTO_GENERATED_DOMAIN_ACCESS_EMAIL_WEB_MASTER - DOMAIN_ACCESS_EMAIL - DOMAIN_ACCESS_LETTER - DOMAIN_ZONE_CONTROL - MANUAL_DOMAIN_ACCESS_EMAIL - PREVIOUS_DOMAIN_ACCESS_EMAIL - REGISTRATION_AUTHORITY_DOMAIN_ACCESS_LETTER - REGISTRATION_AUTHORITY_DOMAIN_ZONE_CONTROL - REGISTRATION_AUTHORITY_OVERRIDE - REGISTRATION_AUTHORITY_WEBSITE_CONTROL - CUSTOMER_OWNED - WEBSITE_CONTROL type: string usage: description: Type of domain name used for domain verification enum: - COMMON_NAME - SUBJECT_ALTERNATIVE_NAME type: string required: - domain - domainEntityId - status - createdAt - modifiedAt - type - usage CertificateAddress: properties: address1: description: Address line 1 of organization address type: string address2: description: Address line 2 of organization address type: string city: description: City/Locality of organization address type: string country: description: Two character country code of organization enum: - AC - AD - AE - AF - AG - AI - AL - AM - AN - AO - AQ - AR - AS - AT - AU - AW - AZ - BA - BB - BD - BE - BF - BG - BH - BI - BJ - BM - BN - BO - BR - BS - BT - BV - BW - BY - BZ - CA - CC - CD - CF - CG - CH - CI - CK - CL - CM - CN - CO - CR - CV - CX - CY - CZ - DE - DJ - DK - DM - DO - DZ - EC - EE - EG - EH - ER - ES - ET - FI - FJ - FK - FM - FO - FR - GA - GB - GD - GE - GF - GG - GH - GI - GL - GM - GN - GP - GQ - GR - GS - GT - GU - GW - GY - HK - HM - HN - HR - HT - HU - ID - IE - IL - IM - IN - IO - IQ - IS - IT - JE - JM - JO - JP - KE - KG - KH - KI - KM - KN - KR - KW - KY - KZ - LA - LB - LC - LI - LK - LR - LS - LT - LU - LV - LY - MA - MC - MD - ME - MG - MH - ML - MM - MN - MO - MP - MQ - MR - MS - MT - MU - MV - MW - MX - MY - MZ - NA - NC - NE - NF - NG - NI - NL - 'NO' - NP - NR - NU - NZ - OM - PA - PE - PF - PG - PH - PK - PL - PM - PN - PR - PS - PT - PW - PY - QA - RE - RO - RS - RU - RW - SA - SB - SC - SE - SG - SH - SI - SJ - SK - SL - SM - SN - SO - SR - ST - SV - SZ - TC - TD - TF - TG - TH - TJ - TK - TL - TM - TN - TO - TP - TR - TT - TV - TW - TZ - UA - UG - UM - US - UY - UZ - VA - VC - VE - VG - VI - VN - VU - WF - WS - YE - YT - YU - ZA - ZM - ZW format: iso-country-code type: string postalCode: description: Postal code of organization address type: string state: description: Full name of State/Province/Territory of organization address type: string required: - address1 - country CertificateSummariesV2: properties: certificates: type: array items: $ref: '#/components/schemas/CertificateSummaryV2' description: List of certificates for a specified customer. pagination: $ref: '#/components/schemas/Pagination' required: - certificates - pagination DomainVerificationDetail: allOf: - $ref: '#/components/schemas/DomainVerificationSummary' - type: object properties: certificateAuthorityAuthorization: description: 'Contains information about the last Certificate Authority Authorization (CAA) Lookup details for the specified domain. In order for a domain to be eligible to be included in the certificate, the entire domain hierarchy must be scanned for DNS CAA records, as outlined by RFC 6844. The absence of any CAA records found in the domain hierarchy indicates that the domain may be included in the certificate. Alternatively, if CAA records are found when scanning the domain hierarchy, the domain may be included in the certificate as long as `godaddy.com` or `starfieldtech.com` is found in the DNS record value. However, if CAA records are found, yet `godaddy.com` or `starfieldtech.com` is not found in any CAA record''s value, then we must drop the domain from the certificate request. In the case where there are repeated DNS errors when scanning the domain hierarchy for CAA records, thus ending in an unsuccessful scan, then the domain can still be included in the certificate provided the primary domain is not setup with DNSSEC. Conversely, if DNSSEC is found to be setup on the primary domain when scanning following repeated CAA failures, the domain must be dropped from the certificate request. Finally, if DNS errors persist to the point where a successful DNSSEC query could not be obtained, then the domain must be dropped from the certificate request. ' type: object properties: status: description: 'Returns the status of the CAA Lookup for the specified domain: * `PENDING` - The CAA lookup has not yet been attempted for the specified domain. * `REMOVED_DNS_ERROR` - Repeated errors occurred while scanning for CAA records, thereby resulting in a DNSSEC scan. DNS errors then prevented the system from determining if DNSSEC was enabled for the specified domain, and it had to be removed from the certificate request. * `REMOVED_DNSSEC_ENABLED` - Repeated errors occurred while scanning for CAA records, thereby resulting in a DNSSEC scan. DNSSEC was determined to be enabled for the specified domain, and it had to be removed from the certificate request. * `REMOVED_NOT_FOUND_CA` - CAA records were found during the CAA lookup for the speicified domain, but `godaddy.com` or `starfieldtech.com` was not listed as a value, thereby not allowing us to issue a certificate with this domain. The specified domain was removed from the certificate request. * `REMOVED_UNKNOWN_CRITICAL_TAG` - A CAA record was found during the CAA lookup with its Critical bit set, as outlined by RFC 6844, yet the Tag of the CAA record was not understood (as outlined by RFC 6844). The specified domain was removed from the certificate request. * `SUCCESS_CAA` - The CAA lookup was successful for the specified domain, and the domain can remain in the certificate request. * `SUCCESS_DNSSEC` - Repeated errors occurred while scanning for CAA records, thereby resulting in a DNSSEC scan. The system detemined that DNSSEC was not enabled for the specified domain, so the domain is allowed to remain in the certificate request. ' enum: - PENDING - REMOVED_DNS_ERROR - REMOVED_DNSSEC_ENABLED - REMOVED_NOT_FOUND_CA - REMOVED_UNKNOWN_CRITICAL_TAG - SUCCESS_CAA - SUCCESS_DNSSEC type: string queryPaths: description: Details all the individual DNS paths that were scanned for CAA records for this domain, as detailed by RFC 6844. This element not only contains the parts determined from parsing the domain, but also any CNAME or DNAME targets specified by any of those individual parts. type: array items: type: string recommendations: description: Returns a list of fix recommendations if the query was unsuccessful, or if the domain was dropped from the certificate request, so that a subsequent certificate request with the specified domain will successfully pass its CAA scan. type: array items: description: '* `ADD_CA_TO_CAA` - The system found a CAA record in the domain hierarchy, but it did not find our CA in the record''s values. Add `godaddy.com` or `starfieldtech.com` to the CAA record''s values. * `CREATE_TARGET_DOMAIN_CAA` - Create a CAA record on the specified domain with `godaddy.com` or `starfieldtech.com` as the value. If the system finds a CAA record in the specified domain, it will stop scanning the domain hierarchy, thereby preventing potentially problematic parent domain paths from being scanned. * `DISABLE_DNSSEC` - Disable DNSSEC on the domain if CAA lookups fail and a DNSSEC scan is being used as the method for determining if the specified domain can remain in the certificate request. * `FIX_CRITICAL_TAG` - When setting the critical flag in a CAA record, you must ensure you''re using a well-known tag, per RFC 6844. * `VALIDATE_SOA` - Make sure all queryPaths for the specified domain have an SOA record pointing to a valid publicly-accessible nameserver and respond in a timely fashion. ' enum: - ADD_CA_TO_CAA - CREATE_TARGET_DOMAIN_CAA - DISABLE_DNSSEC - FIX_CRITICAL_TAG - VALIDATE_SOA type: string completedAt: description: The date the certificate request completed processing. format: iso-datetime type: string Pagination: type: object properties: first: type: string description: URI to access the first page previous: type: string description: URI to access the previous page next: type: string description: URI to access the next page last: type: string description: URI to access the last page total: type: integer description: Number of records available JurisdictionOfIncorporation: properties: city: type: string country: format: iso-country-code type: string county: type: string state: type: string required: - country Error: properties: code: description: Short identifier for the error, suitable for indicating the specific error within client code format: constant type: string fields: description: List of the specific fields, and the errors found with their contents items: $ref: '#/components/schemas/ErrorField' type: array message: description: Description of the error type: string required: - code ErrorField: properties: code: description: Short identifier for the error, suitable for indicating the specific error within client code format: constant type: string message: description: Description of the problem with the contents of the field type: string path: description: JSONPath referring to the field within the submitted data containing an error format: json-path type: string required: - path - code