# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Palo Alto Networks Certificates API version: 1.0.0 extends: openapi/palo-alto-networks-certificates-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-09-26' generator: build-phrasing.py label: Generated by API Evangelist operations: 18 - target: $.paths['/sse/config/v1/certificates'].get update: x-apievangelist-phrasing: intent: List certificates in a Prisma Access SSE folder effect: read questions: - Which certificates are configured in a given Prisma Access folder on the SSE config API? - Can I look up an SSE-managed certificate by name within one folder? instructions: - text: List the SSE config certificates in folder {folder}. slots: folder: query.folder - text: Find the SSE certificate named {name} in folder {folder}. slots: name: query.name folder: query.folder method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/certificates'].post update: x-apievangelist-phrasing: intent: Generate a certificate in a Prisma Access SSE folder effect: write questions: - How do I generate a new certificate inside a Prisma Access folder with the SSE config API? - Can the SSE config API mint a certificate authority certificate for a folder? instructions: - text: Generate SSE certificate {certificate_name} for common name {common_name} in folder {folder} using {algorithm} and digest {digest}. slots: certificate_name: requestBody.certificate_name common_name: requestBody.common_name folder: query.folder algorithm: requestBody.algorithm digest: requestBody.digest - text: In SSE folder {folder}, create certificate {certificate_name} for {common_name} valid for {day_till_expiration} days. slots: folder: query.folder certificate_name: requestBody.certificate_name common_name: requestBody.common_name day_till_expiration: requestBody.day_till_expiration method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/certificates/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a certificate from Prisma Access SSE config effect: destructive questions: - How do I remove a certificate from the Prisma Access SSE configuration? - Is deleting an SSE config certificate done by its ID? instructions: - text: Delete SSE config certificate {id}. slots: id: path.id - text: Remove certificate {id} from the Prisma Access SSE configuration. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/sse/config/v1/certificates:import'].post update: x-apievangelist-phrasing: intent: Import a certificate into a Prisma Access SSE folder effect: write questions: - Can I upload an existing certificate file into a Prisma Access SSE folder? - What formats does the SSE config certificate import take, and can I include a private key? instructions: - text: Import certificate file {certificate_file} as {name} in {format} format into SSE folder {folder}. slots: certificate_file: requestBody.certificate_file name: requestBody.name format: requestBody.format folder: query.folder - text: Import {name} into SSE folder {folder} with key file {key_file} and passphrase {passphrase}, format {format}, from {certificate_file}. slots: name: requestBody.name folder: query.folder key_file: requestBody.key_file passphrase: requestBody.passphrase format: requestBody.format certificate_file: requestBody.certificate_file method: generated generated: '2026-09-26' - target: $.paths['/certificates'].get update: x-apievangelist-phrasing: intent: List Strata Cloud Manager certificates effect: read questions: - Which certificates are attached to a particular snippet or device in Strata Cloud Manager? - Can I page through all managed firewall certificates with limit and offset? instructions: - text: List the certificates configured on device {device}. slots: device: query.device - text: Show certificates defined in snippet {snippet}. slots: snippet: query.snippet method: generated generated: '2026-09-26' - target: $.paths['/certificates'].post update: x-apievangelist-phrasing: intent: Generate a signed certificate in Strata Cloud Manager effect: write questions: - How do I generate a certificate signed by an existing CA in Strata Cloud Manager configuration? - Can I add subject alternative names like a hostname or IP when generating a managed certificate? instructions: - text: Generate certificate {certificate_name} for {common_name} signed by {signed_by}, using {algorithm} with digest {digest}. slots: certificate_name: requestBody.certificate_name common_name: requestBody.common_name signed_by: requestBody.signed_by algorithm: requestBody.algorithm digest: requestBody.digest - text: Create a CA-signed certificate {certificate_name} for hostname {hostname}, signer {signed_by}. slots: certificate_name: requestBody.certificate_name hostname: requestBody.hostname signed_by: requestBody.signed_by method: generated generated: '2026-09-26' - target: $.paths['/certificates:import'].post update: x-apievangelist-phrasing: intent: Import a certificate into Strata Cloud Manager effect: write questions: - How do I bring my own certificate file into Strata Cloud Manager configuration without choosing a folder? - Does the Strata Cloud Manager certificate import accept an encrypted private key with a passphrase? instructions: - text: Import {certificate_file} as managed certificate {name} in {format} format. slots: certificate_file: requestBody.certificate_file name: requestBody.name format: requestBody.format - text: Upload managed certificate {name} from {certificate_file} with private key {key_file}, format {format}. slots: name: requestBody.name certificate_file: requestBody.certificate_file key_file: requestBody.key_file format: requestBody.format method: generated generated: '2026-09-26' - target: $.paths['/certificates/{id}'].get update: x-apievangelist-phrasing: intent: Get a Strata Cloud Manager certificate effect: read questions: - How can I view the settings of one managed certificate by its ID? - What details does Strata Cloud Manager return for a single configured certificate? instructions: - text: Get managed certificate {id}. slots: id: path.id - text: Show me the configuration of certificate {id} in Strata Cloud Manager. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/certificates/{id}'].delete update: x-apievangelist-phrasing: intent: Delete a Strata Cloud Manager certificate effect: destructive questions: - How do I delete a certificate object from Strata Cloud Manager configuration? - Can a managed certificate be removed by ID outside a Prisma Access SSE folder? instructions: - text: Delete managed certificate {id}. slots: id: path.id - text: Remove certificate {id} from Strata Cloud Manager. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/certificates/{id}:export'].post update: x-apievangelist-phrasing: intent: Export a managed certificate effect: write questions: - How do I export a certificate from Strata Cloud Manager in a specific format? - Can I protect an exported certificate with a passphrase? instructions: - text: Export certificate {id} in {format} format. slots: id: path.id format: requestBody.format - text: Export certificate {id} as {format}, protected with passphrase {passphrase}. slots: id: path.id format: requestBody.format passphrase: requestBody.passphrase method: generated generated: '2026-09-26' - target: $.paths['/outagedetection/v1/certificates'].get update: x-apievangelist-phrasing: intent: List certificates in the outage detection inventory effect: read questions: - What certificates are in my outage detection inventory, filtered by subject? - Can I leave superseded certificate versions out of the inventory listing? instructions: - text: List inventory certificates whose subject matches {subject}. slots: subject: query.subject - text: 'Pull the certificate inventory, excluding superseded instances: {excludeSupersededInstances}.' slots: excludeSupersededInstances: query.excludeSupersededInstances method: generated generated: '2026-09-26' - target: $.paths['/outagedetection/v1/certificates/{id}'].get update: x-apievangelist-phrasing: intent: Get an inventory certificate's details effect: read questions: - How do I see the details of one certificate in the outage detection inventory? - Can I include the ownership tree when looking up a single inventory certificate? instructions: - text: Get details for inventory certificate {id}. slots: id: path.id - text: Show inventory certificate {id} with its ownership tree. slots: id: path.id method: generated generated: '2026-09-26' - target: $.paths['/outagedetection/v1/certificates/{id}/contents'].get update: x-apievangelist-phrasing: intent: Download a certificate in PEM or DER effect: read questions: - How do I download a certificate from the inventory as a PEM file? - Can the downloaded PEM include the CA chain with the root certificate first? instructions: - text: Download certificate {id} in {format} format. slots: id: path.id format: query.format - text: Download certificate {id} as PEM with chain order {chainOrder}. slots: id: path.id chainOrder: query.chainOrder method: generated generated: '2026-09-26' - target: $.paths['/outagedetection/v1/certificates/validation'].post update: x-apievangelist-phrasing: intent: Request TLS validation of certificates effect: write questions: - How do I trigger a TLS validation check for specific certificates in my inventory? - Can I submit several certificates for validation in one request? instructions: - text: Submit certificates {certificateIds} for TLS validation. slots: certificateIds: requestBody.certificateIds - text: Revalidate the TLS status of certificate IDs {certificateIds}. slots: certificateIds: requestBody.certificateIds method: generated generated: '2026-09-26' - target: $.paths['/outagedetection/v1/certificates/retirement'].post update: x-apievangelist-phrasing: intent: Retire certificates from active use effect: destructive questions: - How do I retire certificates I no longer use in the outage detection inventory? - Can retired certificates also be added to a blocklist? instructions: - text: Retire certificates {certificateIds}. slots: certificateIds: requestBody.certificateIds - text: 'Retire certificates {certificateIds} and add them to the blocklist: {addToBlocklist}.' slots: certificateIds: requestBody.certificateIds addToBlocklist: requestBody.addToBlocklist method: generated generated: '2026-09-26' - target: $.paths['/outagedetection/v1/certificates/recovery'].post update: x-apievangelist-phrasing: intent: Recover retired certificates effect: write questions: - Is it possible to bring back certificates I retired by mistake? - Does recovering a retired certificate also restore its previous versions? instructions: - text: Recover retired certificates {certificateIds}. slots: certificateIds: requestBody.certificateIds - text: Restore retired certificates {certificateIds} and associate them with applications {applicationIds}. slots: certificateIds: requestBody.certificateIds applicationIds: requestBody.applicationIds method: generated generated: '2026-09-26' - target: $.paths['/outagedetection/v1/certificates/deletion'].post update: x-apievangelist-phrasing: intent: Permanently delete retired certificates effect: destructive questions: - How do I permanently purge retired certificates from the inventory? - Can I delete a certificate for good once it has been retired? instructions: - text: Permanently delete retired certificates {certificateIds}. slots: certificateIds: requestBody.certificateIds - text: Purge the retired certificates {certificateIds} from inventory. slots: certificateIds: requestBody.certificateIds method: generated generated: '2026-09-26' - target: $.paths['/outagedetection/v1/certificatesearch'].post update: x-apievangelist-phrasing: intent: Search certificates by field criteria effect: read questions: - Which of my certificates expire soon or use a weak signature hash algorithm? - Can I search certificates by issuer common name and sort the results? instructions: - text: Search certificates matching expression {expression}. slots: expression: requestBody.expression - text: Search certificates with {expression}, ordered by {ordering}. slots: expression: requestBody.expression ordering: requestBody.ordering method: generated generated: '2026-09-26'