openapi: 3.2.0 info: contact: email: support@paloaltonetworks.com name: Palo Alto Networks Technical Support url: https://support.paloaltonetworks.com description: These APIs are used to define how Advanced DNS Security Resolver configurations are implemented. license: name: MIT url: https://opensource.org/license/mit termsOfService: https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/legal/palo-alto-networks-end-user-license-agreement-eula.pdf title: Advanced DNS Security Resolver Configuration EDL CA Certificates API version: 1.0.0 servers: - description: Prod url: https://api.strata.paloaltonetworks.com security: - scmToken: [] tags: - name: EDL CA Certificates paths: /adns-resolver/v1/ca-certs: get: description: Retrieve all EDL CA certificates. Returns certificate metadata including download paths. operationId: ListCACerts responses: '200': content: application/json: schema: $ref: '#/components/schemas/ca-certs' description: OK '400': content: application/json: schema: $ref: '#/components/schemas/error' description: Bad Request '401': content: application/json: schema: $ref: '#/components/schemas/error' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/error' description: Forbidden '404': content: application/json: schema: $ref: '#/components/schemas/error' description: Not Found '405': content: application/json: schema: $ref: '#/components/schemas/error' description: Method Not Allowed '409': content: application/json: schema: $ref: '#/components/schemas/error' description: Conflict '412': content: application/json: schema: $ref: '#/components/schemas/error' description: Precondition Failed '422': content: application/json: schema: $ref: '#/components/schemas/error' description: Unprocessable Entity '500': content: application/json: schema: $ref: '#/components/schemas/error' description: Internal Server Error '503': content: application/json: schema: $ref: '#/components/schemas/error' description: Service Unavailable default: content: application/json: schema: $ref: '#/components/schemas/error' description: Error summary: List EDL CA certificates tags: - EDL CA Certificates /adns-resolver/v1/ca-certs/{ca-cert-id}: delete: description: Delete a specific EDL CA certificate by ID. operationId: DeleteCACertByID parameters: - description: CA Certificate ID in: path name: ca-cert-id required: true schema: description: CA Certificate ID type: string responses: '204': description: No Content '400': content: application/json: schema: $ref: '#/components/schemas/error' description: Bad Request '401': content: application/json: schema: $ref: '#/components/schemas/error' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/error' description: Forbidden '404': content: application/json: schema: $ref: '#/components/schemas/error' description: Not Found '405': content: application/json: schema: $ref: '#/components/schemas/error' description: Method Not Allowed '409': content: application/json: schema: $ref: '#/components/schemas/error' description: Conflict '412': content: application/json: schema: $ref: '#/components/schemas/error' description: Precondition Failed '422': content: application/json: schema: $ref: '#/components/schemas/error' description: Unprocessable Entity '500': content: application/json: schema: $ref: '#/components/schemas/error' description: Internal Server Error '503': content: application/json: schema: $ref: '#/components/schemas/error' description: Service Unavailable default: content: application/json: schema: $ref: '#/components/schemas/error' description: Error summary: Delete an EDL CA certificate tags: - EDL CA Certificates get: description: Returns CA certificate metadata. Use the download_path to retrieve the certificate file. operationId: GetCACertByID parameters: - description: CA Certificate ID in: path name: ca-cert-id required: true schema: description: CA Certificate ID type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/ca-cert-item' description: OK '400': content: application/json: schema: $ref: '#/components/schemas/error' description: Bad Request '401': content: application/json: schema: $ref: '#/components/schemas/error' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/error' description: Forbidden '404': content: application/json: schema: $ref: '#/components/schemas/error' description: Not Found '405': content: application/json: schema: $ref: '#/components/schemas/error' description: Method Not Allowed '409': content: application/json: schema: $ref: '#/components/schemas/error' description: Conflict '412': content: application/json: schema: $ref: '#/components/schemas/error' description: Precondition Failed '422': content: application/json: schema: $ref: '#/components/schemas/error' description: Unprocessable Entity '500': content: application/json: schema: $ref: '#/components/schemas/error' description: Internal Server Error '503': content: application/json: schema: $ref: '#/components/schemas/error' description: Service Unavailable default: content: application/json: schema: $ref: '#/components/schemas/error' description: Error summary: Get an EDL CA certificate tags: - EDL CA Certificates /adns-resolver/v1/ca-certs/{ca-cert-id}/download: get: description: Download an EDL CA certificate file. Returns the PEM-encoded certificate. operationId: DownloadCACertAsFile parameters: - description: CA Certificate ID in: path name: ca-cert-id required: true schema: description: CA Certificate ID type: string responses: '200': content: application/x-pem-file: {} description: Certificate file successfully downloaded headers: Content-Disposition: schema: type: string Content-Type: schema: type: string '400': content: application/json: schema: $ref: '#/components/schemas/error' description: Bad Request '401': content: application/json: schema: $ref: '#/components/schemas/error' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/error' description: Forbidden '404': content: application/json: schema: $ref: '#/components/schemas/error' description: Not Found '405': content: application/json: schema: $ref: '#/components/schemas/error' description: Method Not Allowed '409': content: application/json: schema: $ref: '#/components/schemas/error' description: Conflict '412': content: application/json: schema: $ref: '#/components/schemas/error' description: Precondition Failed '422': content: application/json: schema: $ref: '#/components/schemas/error' description: Unprocessable Entity '500': content: application/json: schema: $ref: '#/components/schemas/error' description: Internal Server Error '503': content: application/json: schema: $ref: '#/components/schemas/error' description: Service Unavailable default: content: application/json: schema: $ref: '#/components/schemas/error' description: Error summary: Download an EDL CA certificate as PEM file tags: - EDL CA Certificates /adns-resolver/v1/ca-certs:upload: post: description: Upload an EDL CA certificate file. Accepts a PEM-encoded certificate via multipart/form-data. operationId: UploadCACertFromFile requestBody: content: multipart/form-data: encoding: cert: contentType: application/x-pem-file,application/x-x509-ca-cert name: contentType: text/plain schema: properties: cert: contentEncoding: binary contentMediaType: application/octet-stream description: PEM-encoded CA certificate file (.pem, .crt, or .cer) format: binary type: string name: description: Name of the CA certificate examples: - My CA Cert maxLength: 128 type: string required: - name - cert type: object responses: '201': content: application/json: schema: $ref: '#/components/schemas/ca-cert-item' description: Created headers: Location: schema: description: URI of the created CA certificate resource type: string '400': content: application/json: schema: $ref: '#/components/schemas/error' description: Bad Request '401': content: application/json: schema: $ref: '#/components/schemas/error' description: Unauthorized '403': content: application/json: schema: $ref: '#/components/schemas/error' description: Forbidden '404': content: application/json: schema: $ref: '#/components/schemas/error' description: Not Found '405': content: application/json: schema: $ref: '#/components/schemas/error' description: Method Not Allowed '409': content: application/json: schema: $ref: '#/components/schemas/error' description: Conflict '412': content: application/json: schema: $ref: '#/components/schemas/error' description: Precondition Failed '422': content: application/json: schema: $ref: '#/components/schemas/error' description: Unprocessable Entity '500': content: application/json: schema: $ref: '#/components/schemas/error' description: Internal Server Error '503': content: application/json: schema: $ref: '#/components/schemas/error' description: Service Unavailable default: content: application/json: schema: $ref: '#/components/schemas/error' description: Error summary: Upload an EDL CA certificate from file tags: - EDL CA Certificates components: schemas: error-code: oneOf: - enum: - 1001 title: 1001 - Forbidden type: integer - enum: - 1002 title: 1002 - Invalid Input type: integer - enum: - 1004 title: 1004 - Invalid Output type: integer - enum: - 1005 title: 1005 - Internal Server Error type: integer - enum: - 1006 title: 1006 - Precondition Failed type: integer - enum: - 1007 title: 1007 - Method Not Allowed type: integer - enum: - 1008 title: 1008 - Not Found type: integer - enum: - 1009 title: 1009 - Service Unavailable type: integer - enum: - 1010 title: 1010 - Duplicate Not Allowed type: integer - enum: - 1011 title: 1011 - Expired License type: integer - enum: - 1012 title: 1012 - Dependency Error type: integer - enum: - 1013 title: 1013 - Subnet Already Verified type: integer - enum: - 1014 title: 1014 - In Grace type: integer - enum: - 1015 title: 1015 - Limit Exceeded type: integer - enum: - 1016 title: 1016 - Duplicate Subnet Not Allowed type: integer - enum: - 1017 title: 1017 - IP Limit Exceeded type: integer - enum: - 1018 title: 1018 - FQDN Limit Exceeded type: integer - enum: - 1019 title: 1019 - Private Subnet type: integer - enum: - 1020 title: 1020 - Mapped IPv4 type: integer - enum: - 1021 title: 1021 - Invalid Subnet type: integer - enum: - 1022 title: 1022 - Invalid Sinkhole type: integer - enum: - 1023 title: 1023 - Allowed Subnet Required type: integer - enum: - 1024 title: 1024 - Cross Tenant Subnet Conflict type: integer title: error-code type: integer error-detail: additionalProperties: false properties: code: $ref: '#/components/schemas/error-code' description: Error code identifier details: description: Additional error details items: type: string type: - array - 'null' help: description: URL to error documentation type: string message: description: Human-readable error message type: string required: - code - message type: object ca-cert-item: additionalProperties: false properties: item: $ref: '#/components/schemas/ca-cert' required: - item type: object error: additionalProperties: false properties: _errors: description: Array of error objects items: $ref: '#/components/schemas/error-detail' type: - array - 'null' _request_id: description: Request identifier for tracking type: string required: - _errors type: object ca-cert: additionalProperties: false properties: download_path: description: API path to download the certificate file examples: - /adns-resolver/v1/ca-certs/ca-cert-123/download readOnly: true type: string id: description: Unique identifier for the CA certificate examples: - ca-cert-123 readOnly: true type: string name: description: Name of the CA certificate examples: - My CA Cert maxLength: 128 type: string required: - id - name type: object ca-certs: additionalProperties: false properties: data: items: $ref: '#/components/schemas/ca-cert' type: - array - 'null' required: - data type: object securitySchemes: scmToken: bearerFormat: JWT description: "Advanced DNS Security Resolver APIs authenticate client requests using the \nOAuth 2.0 Client Credentials flow. Please use the `client_id`, \n`client_secret` values associated with an IAM service account along \nwith a scope value of `tsg_id:XXXXXXXXXX`, where `XXXXXXXXXX` is the \nTenant Service Group (TSG) ID. The resulting JWT access token should \nbe attached to all API calls as a `Bearer` token in the `Authorization` \nheader (ex. `Authorization: Bearer tokenstring`).\n" scheme: bearer type: http