# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for TLS Protect Cloud API for Strata Cloud Manager Certificate… version: 1.0.0 extends: openapi/palo-alto-networks-certificate-policy-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 6 - target: $.paths['/v1/certificateissuingtemplates'].get update: x-apievangelist-phrasing: intent: List certificate issuing templates effect: read questions: - Which issuing templates control how certificates get requested? - Can I list the issuing templates tied to one CA account? instructions: - text: List all certificate issuing templates. - text: List issuing templates for CA account {certificateAuthorityAccountId}. slots: certificateAuthorityAccountId: query.certificateAuthorityAccountId method: generated generated: '2026-09-26' - target: $.paths['/v1/certificateissuingtemplates'].post update: x-apievangelist-phrasing: intent: Create a certificate issuing template effect: write questions: - How do I set up an issuing template with allowed key types and a CA product? - Can I restrict common names and SANs with regexes in a new issuing template? instructions: - text: Create issuing template {name} using CA {certificateAuthority} and product option {certificateAuthorityProductOptionId}. slots: name: requestBody.name certificateAuthority: requestBody.certificateAuthority certificateAuthorityProductOptionId: requestBody.certificateAuthorityProductOptionId - text: Add issuing template {name} allowing key types {keyTypes} with key reuse {keyReuse}. slots: name: requestBody.name keyTypes: requestBody.keyTypes keyReuse: requestBody.keyReuse method: generated generated: '2026-09-26' - target: $.paths['/v1/certificateissuingtemplates/{id}'].get update: x-apievangelist-phrasing: intent: Get an issuing template effect: read questions: - What settings does one issuing template enforce? - Can I fetch a single issuing template by id? instructions: - text: Get issuing template {id}. slots: id: path.id - text: Show the details of issuing template {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/v1/certificateissuingtemplates/{id}'].put update: x-apievangelist-phrasing: intent: Overwrite an issuing template effect: write questions: - Does updating an issuing template replace all of its settings? - How do I change the allowed key types on an existing issuing template? instructions: - text: Overwrite issuing template {id} with name {name} and key types {keyTypes}. slots: id: path.id name: requestBody.name keyTypes: requestBody.keyTypes - text: Replace issuing template {id} settings to use CA {certificateAuthority}. slots: id: path.id certificateAuthority: requestBody.certificateAuthority method: generated generated: '2026-09-26' - target: $.paths['/v1/certificateissuingtemplates/{id}'].delete update: x-apievangelist-phrasing: intent: Delete an issuing template effect: destructive questions: - How do I remove an issuing template nobody uses? - Is deleting an issuing template permanent? instructions: - text: Delete issuing template {id}. slots: id: path.id - text: Remove the issuing template with id {id}. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/v1/certificateissuingtemplates/domainssynchronization'].post update: x-apievangelist-phrasing: intent: Sync issuing template domains from a CA effect: write questions: - Can I pull the domain list from my CA into my issuing templates? - What keeps issuing template domains in sync with the certificate authority? instructions: - text: Synchronize domains from CA account {certificateAuthorityAccountId} into templates {issuingTemplatesIds} with action {action}. slots: certificateAuthorityAccountId: requestBody.certificateAuthorityAccountId issuingTemplatesIds: requestBody.issuingTemplatesIds action: requestBody.action - text: Load the CA domain list for account {certificateAuthorityAccountId} into templates {issuingTemplatesIds} using {action}. slots: certificateAuthorityAccountId: requestBody.certificateAuthorityAccountId issuingTemplatesIds: requestBody.issuingTemplatesIds action: requestBody.action method: generated generated: '2026-09-26'