openapi: 3.2.0 info: title: Certificate Manager - SaaS Certificate Installations API version: '1.0' servers: - description: US Region url: https://api.venafi.cloud - description: EU Region url: https://api.eu.venafi.cloud - description: AU Region url: https://api.au.venafi.cloud - description: UK Region url: https://api.uk.venafi.cloud - description: SG Region url: https://api.sg.venafi.cloud - description: CA Region url: https://api.ca.venafi.cloud tags: - name: Certificate Installations paths: /outagedetection/v1/certificateinstances: get: description: 'Use this endpoint allows you to retrieve certificate instances according to specified criteria. Total certificate instances are the sum of the number of certificate installations, plus the total number of certificates that have no installations. Trusted CA certificates are not counted. For more information, see certificate instances. Use query parameters to limit your search based on certificate criteria.' operationId: certificateinstances_getAll parameters: - in: query name: source schema: enum: - UNKNOWN - USER_PROVIDED - USER_IMPORTED - USER_SCAN - TRUSTNET_SCAN - ON_PREM_CA_IMPORT - EXTERNAL_CA_IMPORT - FILE_IMPORT - EXTERNAL_SCAN - DOMAIN_SCAN - SMART_SCAN_INTERNAL - SMART_SCAN_EXTERNAL - SMART_VALIDATION_INTERNAL - SMART_VALIDATION_EXTERNAL - MACHINE_DISCOVERY - KUBERNETES_DISCOVERY - AWS_DISCOVERY - AZURE_DISCOVERY - GCP_DISCOVERY type: string - in: query name: ipAddress schema: type: string - in: query name: hostname schema: type: string - in: query name: limit schema: format: int32 type: integer responses: '200': content: application/json: examples: Certificate instances details response: description: Certificate instances details response summary: Certificate instance details value: count: 2 instances: - certificate: authorityKeyIdentifierHash: 3CD6AEAA77686C3B677FF6CBBE8BD051CC0AEB8A certificateName: www.venafi.com certificateStatus: ACTIVE companyId: 062a5e50-a8d6-11ed-afc9-45c12cf499bf encryptionType: RSA extendedKeyUsage: - 1.3.6.1.5.5.7.3.1 - 1.3.6.1.5.5.7.3.2 fingerprint: 99D89424CAF4AF24147898276FAF2AD1C360B540 id: d2516ca0-a8d7-12ed-9c90-87a729edc082 issuerC: US issuerCN: - HydrantID Server CA O1 issuerCertificateIds: - d24ed490-a8d7-11ed-9t90-87a729edc082 - d5636090-297e-11ea-bc4c-8b24e5a66fb6 issuerDN: cn=HydrantID Server CA O1,ou=HydrantID Trusted Certificate Service,o=IdenTrust,c=US issuerOU: - HydrantID Trusted Certificate Service keyStrength: 2048 keyUsage: - digitalSignature - keyEncipherment managedCertificateId: d3fgafd0-a8d7-11ed-96b6-1778d4537ec7 modificationDate: '2023-02-10T00:14:07.509+00:00' ocspNoCheck: false selfSigned: false serialNumber: 440185A2A93E676BEA5BBC65619B333D signatureAlgorithm: SHA256_WITH_RSA_ENCRYPTION signatureHashAlgorithm: SHA256 subjectAlternativeNameDns: - venafi.com - www.venafi.com subjectAlternativeNamesByType: dNSName: - venafi.com - www.venafi.com subjectC: US subjectCN: - www.venafi.com subjectDN: cn=www.venafi.com,o=Venafi Inc,c=US,st=Utah,l=Salt Lake City subjectKeyIdentifierHash: 75FFED443D57C47D3C0ED43EFC4CF82217AB729A subjectL: Salt Lake City subjectO: Venafi Inc subjectST: Utah validityEnd: '2024-01-06T21:06:58.000+00:00' validityStart: '2023-01-11T21:07:58.000+00:00' versionType: CURRENT certificateId: d2516ca0-8dd7-11ed-9c90-87a729edc082 certificateInstanceId: d2522ff0-dsd7-11ed-9c90-87a729edc082 certificateSource: USER_SCAN deploymentStatus: IN_USE hostname: venafi.com instanceChainValidationStatus: - OK ipAddress: 76.76.21.22 lastScanDate: '2023-02-10T00:14:05.854+00:00' lastValidatedAttempt: '2023-02-10T00:14:05.922+00:00' modificationDate: '2023-02-10T00:14:07.509+00:00' port: 443 serviceIds: - be7447c0-a8e3-11ed-bdca-d5b837a24ba9 sslProtocols: - TLSv1.3 - TLSv1.2 sslValidationErrorArguments: [] sslValidationStatus: OK - certificate: authorityKeyIdentifierHash: DD3C9ABA215BCA96FB8C1CDA555B7D1BFC26DF3D certificateName: venafi.cloud certificateStatus: ACTIVE companyId: 06285e50-a8d6-11ed-afc9-45c12cf499bf encryptionType: RSA extendedKeyUsage: - 1.3.6.1.5.5.7.3.1 - 1.3.6.1.5.5.7.3.2 fingerprint: 8BB7A7669BD689F98FFE90B0992D90C006A005A6 id: d21f8730-a8d7-11ed-9c90-87a729edc082 issuerC: US issuerCN: - Amazon issuerCertificateIds: - d21a7e20-a8d3-11ed-9c90-87a729edc082 - d58eb650-2972-11eb-bc4c-8b24e5a66fb6 issuerDN: cn=Amazon,ou=Server CA 1B,o=Amazon,c=US issuerOU: - Server CA 1B keyStrength: 2048 keyUsage: - digitalSignature - keyEncipherment managedCertificateId: d2cRfc30-a8d7-11ed-96b6-1778d4537ec7 modificationDate: '2023-02-10T00:14:06.011+00:00' ocspNoCheck: false selfSigned: false serialNumber: 047LL5D239595A32F91E83D94C8FFF7B signatureAlgorithm: SHA256_WITH_RSA_ENCRYPTION signatureHashAlgorithm: SHA256 subjectAlternativeNameDns: - venafi.cloud - www.venafi.cloud - ui.venafi.cloud - us1.venafi.cloud - ui.us1.venafi.cloud subjectAlternativeNamesByType: dNSName: - venafi.cloud - www.venafi.cloud - ui.venafi.cloud - us1.venafi.cloud - ui.us1.venafi.cloud subjectCN: - venafi.cloud subjectDN: cn=venafi.cloud subjectKeyIdentifierHash: BBCDA66901E1F7EE4723DD347643E7F2079DC14D validityEnd: '2024-01-30T23:59:59.000+00:00' validityStart: '2023-01-01T00:00:00.000+00:00' versionType: CURRENT certificateId: d21f8790-a8d7-11ed-9c90-87a729edc082 certificateInstanceId: d233e820-a8d7-11ed-9c90-87a729edc082 certificateSource: USER_SCAN deploymentStatus: IN_USE hostname: venafi.cloud instanceChainValidationStatus: - OK ipAddress: 11.35.125.124 lastScanDate: '2023-02-10T00:14:03.302+00:00' lastValidatedAttempt: '2023-02-10T00:14:04.014+00:00' modificationDate: '2023-02-10T00:14:06.011+00:00' port: 443 serviceIds: - be7447c0-a8d8-11ed-bdca-d5b837a24ba9 sslProtocols: - TLSv1.3 - TLSv1.2 sslValidationErrorArguments: [] sslValidationStatus: OK schema: $ref: '#/components/schemas/ExtendedCertificateInstanceResponse' text/csv: examples: Certificate instances details response: description: Certificate instances details response summary: Certificate instance details value: count: 2 instances: - certificate: authorityKeyIdentifierHash: 3CD6AEAA77686C3B677FF6CBBE8BD051CC0AEB8A certificateName: www.venafi.com certificateStatus: ACTIVE companyId: 062a5e50-a8d6-11ed-afc9-45c12cf499bf encryptionType: RSA extendedKeyUsage: - 1.3.6.1.5.5.7.3.1 - 1.3.6.1.5.5.7.3.2 fingerprint: 99D89424CAF4AF24147898276FAF2AD1C360B540 id: d2516ca0-a8d7-12ed-9c90-87a729edc082 issuerC: US issuerCN: - HydrantID Server CA O1 issuerCertificateIds: - d24ed490-a8d7-11ed-9t90-87a729edc082 - d5636090-297e-11ea-bc4c-8b24e5a66fb6 issuerDN: cn=HydrantID Server CA O1,ou=HydrantID Trusted Certificate Service,o=IdenTrust,c=US issuerOU: - HydrantID Trusted Certificate Service keyStrength: 2048 keyUsage: - digitalSignature - keyEncipherment managedCertificateId: d3fgafd0-a8d7-11ed-96b6-1778d4537ec7 modificationDate: '2023-02-10T00:14:07.509+00:00' ocspNoCheck: false selfSigned: false serialNumber: 440185A2A93E676BEA5BBC65619B333D signatureAlgorithm: SHA256_WITH_RSA_ENCRYPTION signatureHashAlgorithm: SHA256 subjectAlternativeNameDns: - venafi.com - www.venafi.com subjectAlternativeNamesByType: dNSName: - venafi.com - www.venafi.com subjectC: US subjectCN: - www.venafi.com subjectDN: cn=www.venafi.com,o=Venafi Inc,c=US,st=Utah,l=Salt Lake City subjectKeyIdentifierHash: 75FFED443D57C47D3C0ED43EFC4CF82217AB729A subjectL: Salt Lake City subjectO: Venafi Inc subjectST: Utah validityEnd: '2024-01-06T21:06:58.000+00:00' validityStart: '2023-01-11T21:07:58.000+00:00' versionType: CURRENT certificateId: d2516ca0-8dd7-11ed-9c90-87a729edc082 certificateInstanceId: d2522ff0-dsd7-11ed-9c90-87a729edc082 certificateSource: USER_SCAN deploymentStatus: IN_USE hostname: venafi.com instanceChainValidationStatus: - OK ipAddress: 76.76.21.22 lastScanDate: '2023-02-10T00:14:05.854+00:00' lastValidatedAttempt: '2023-02-10T00:14:05.922+00:00' modificationDate: '2023-02-10T00:14:07.509+00:00' port: 443 serviceIds: - be7447c0-a8e3-11ed-bdca-d5b837a24ba9 sslProtocols: - TLSv1.3 - TLSv1.2 sslValidationErrorArguments: [] sslValidationStatus: OK - certificate: authorityKeyIdentifierHash: DD3C9ABA215BCA96FB8C1CDA555B7D1BFC26DF3D certificateName: venafi.cloud certificateStatus: ACTIVE companyId: 06285e50-a8d6-11ed-afc9-45c12cf499bf encryptionType: RSA extendedKeyUsage: - 1.3.6.1.5.5.7.3.1 - 1.3.6.1.5.5.7.3.2 fingerprint: 8BB7A7669BD689F98FFE90B0992D90C006A005A6 id: d21f8730-a8d7-11ed-9c90-87a729edc082 issuerC: US issuerCN: - Amazon issuerCertificateIds: - d21a7e20-a8d3-11ed-9c90-87a729edc082 - d58eb650-2972-11eb-bc4c-8b24e5a66fb6 issuerDN: cn=Amazon,ou=Server CA 1B,o=Amazon,c=US issuerOU: - Server CA 1B keyStrength: 2048 keyUsage: - digitalSignature - keyEncipherment managedCertificateId: d2cRfc30-a8d7-11ed-96b6-1778d4537ec7 modificationDate: '2023-02-10T00:14:06.011+00:00' ocspNoCheck: false selfSigned: false serialNumber: 047LL5D239595A32F91E83D94C8FFF7B signatureAlgorithm: SHA256_WITH_RSA_ENCRYPTION signatureHashAlgorithm: SHA256 subjectAlternativeNameDns: - venafi.cloud - www.venafi.cloud - ui.venafi.cloud - us1.venafi.cloud - ui.us1.venafi.cloud subjectAlternativeNamesByType: dNSName: - venafi.cloud - www.venafi.cloud - ui.venafi.cloud - us1.venafi.cloud - ui.us1.venafi.cloud subjectCN: - venafi.cloud subjectDN: cn=venafi.cloud subjectKeyIdentifierHash: BBCDA66901E1F7EE4723DD347643E7F2079DC14D validityEnd: '2024-01-30T23:59:59.000+00:00' validityStart: '2023-01-01T00:00:00.000+00:00' versionType: CURRENT certificateId: d21f8790-a8d7-11ed-9c90-87a729edc082 certificateInstanceId: d233e820-a8d7-11ed-9c90-87a729edc082 certificateSource: USER_SCAN deploymentStatus: IN_USE hostname: venafi.cloud instanceChainValidationStatus: - OK ipAddress: 11.35.125.124 lastScanDate: '2023-02-10T00:14:03.302+00:00' lastValidatedAttempt: '2023-02-10T00:14:04.014+00:00' modificationDate: '2023-02-10T00:14:06.011+00:00' port: 443 serviceIds: - be7447c0-a8d8-11ed-bdca-d5b837a24ba9 sslProtocols: - TLSv1.3 - TLSv1.2 sslValidationErrorArguments: [] sslValidationStatus: OK schema: $ref: '#/components/schemas/ExtendedCertificateInstanceResponse' description: Certificate response. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' text/csv: schema: $ref: '#/components/schemas/ErrorResponse4' description: Request conditions failed. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' text/csv: schema: $ref: '#/components/schemas/ErrorResponse4' description: Request conditions failed. security: - tppl-api-key: [] summary: Retrieve Certificate Instances tags: - Certificate Installations /outagedetection/v1/certificateinstances/{id}: get: description: Retrieves the details of the certificate installation that has the specified `id`. operationId: certificateinstances_getById parameters: - description: UUID of a certificate installation. in: path name: id required: true schema: format: uuid type: string responses: '200': content: application/json: examples: Certificate instance details response: description: Certificate instance details response summary: Certificate instance details value: count: 1 instances: - certificate: authorityKeyIdentifierHash: 654C87C811C70BD19AB7E0F2D910570198160EE1 certificateName: www.venafi.com certificateStatus: ACTIVE companyId: 85595df0-8e14-wq12-87e3-755db050f29d encryptionType: RSA extendedKeyUsage: - 1.3.6.1.5.5.7.3.2 - 1.3.6.1.5.5.7.3.1 fingerprint: 4027AEDB24237BB634DA4FB733345F6445959105 id: 7ec12010-9051-34ew-8e50-b994b27d2ece issuerC: US issuerCN: - HydrantID SSL CA G3 issuerCertificateIds: - 7ebed620-9051-11ed-32ew-b994b27d2ece - d50a4410-297e-11eb-32sa-8b24e5a66fb6 issuerDN: cn=HydrantID SSL CA G3,o=HydrantID (Avalanche Cloud Corporation),c=US keyStrength: 2048 keyUsage: - digitalSignature - keyEncipherment managedCertificateId: 7f0aac30-7420-11ed-8ab8-19e0a618d9cd modificationDate: '2023-01-10T19:12:25.948+00:00' ocspNoCheck: false selfSigned: false serialNumber: 289B5FBB3DA7A3E7E58C2BD3894C70ACBC1C66F9 signatureAlgorithm: SHA256_WITH_RSA_ENCRYPTION signatureHashAlgorithm: SHA256 subjectAlternativeNameDns: - www.venafi.com - venafi.com subjectAlternativeNamesByType: dNSName: - www.venafi.com - venafi.com subjectC: US subjectCN: - www.venafi.com subjectDN: cn=www.venafi.com,o=Venafi, Inc.,c=US,st=Utah,l=Salt Lake City subjectKeyIdentifierHash: 44EC9FAC232FA74EBFFD7E63FE8F92233CAA965B subjectL: Salt Lake City subjectO: Venafi, Inc. subjectST: Utah validityEnd: '2023-03-14T19:39:00.000+00:00' validityStart: '2022-03-14T19:29:38.000+00:00' versionType: CURRENT certificateId: 7ec12010-4151-11ed-8e50-b994b27d2ece certificateInstanceId: 7ec1bc43-9051-11ed-8e50-b994b27d2ece certificateSource: USER_SCAN deploymentStatus: IN_USE hostname: venafi.com instanceChainValidationStatus: - OK ipAddress: 23.185.0.2 lastScanDate: '2023-01-10T19:12:05.015+00:00' lastValidatedAttempt: '2023-01-10T19:12:10.225+00:00' modificationDate: '2023-01-10T19:12:25.948+00:00' port: 443 serviceIds: - 1d61e9e0-9046-11ed-bf54-53a1b041cf25 sslProtocols: - TLSv1.3 - TLSv1.2 sslValidationStatus: OK schema: $ref: '#/components/schemas/ExtendedCertificateInstanceInformation' description: Certificate installation was found; details in response body. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Incomplete or malformed request. '404': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Certificate installation not found. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Incomplete or malformed request. security: - tppl-api-key: [] summary: Get a certificate installation's details tags: - Certificate Installations /outagedetection/v1/certificateinstances/validation: post: description: Submits one or more certificate installation for TLS validation. operationId: certificateinstances_validation requestBody: content: application/json: examples: Certificate instance validation request: description: Certificate instance validation request summary: Certificate instance validation value: instanceIds: - 7ec1bc50-9051-11ed-8e50-b994b27d2ece schema: $ref: '#/components/schemas/CertificateInstanceValidationRequest' required: true responses: '202': content: application/json: schema: $ref: '#/components/schemas/Response' description: Certificate installations were submitted for validation. '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Incomplete or malformed request. '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' description: Incomplete or malformed request. security: - tppl-api-key: [] summary: Request validation for a set of certificate installations tags: - Certificate Installations /outagedetection/v1/certificateinstancesearch: post: description: Use this endpoint to retrieve certificate instance data according to specified search criteria based on commonly used field search parameters. Some examples are `signatureHashAlgorithm`, `validityEnd`, and `issuerCN`. For more information, see common search parameters operationId: certificateinstances_search_getByExpression requestBody: content: application/json: examples: Certificate instance search request by expression: description: Certificate instance search request by expression summary: Certificate instance search by expression value: expression: operands: - field: ipAddress operator: EQ value: 127.0.0.1 - field: hostname operator: EQ value: venafi.com operator: OR ordering: orders: - direction: ASC field: certificatInstanceModificationDate paging: pageNumber: 0 pageSize: 10 schema: $ref: '#/components/schemas/Filter2' responses: '200': content: application/json: examples: Certificate instance details response: description: Certificate instance details response summary: Certificate instance details value: count: 1 instances: - certificate: authorityKeyIdentifierHash: 294C87C811C70BD19AB7E0F2D910570198160EE1 certificateName: www.venafi.com certificateStatus: ACTIVE companyId: 85595df0-8e14-11ed-87e3-755db050f29d encryptionType: RSA extendedKeyUsage: - 1.3.6.1.5.5.7.3.2 - 1.3.6.1.5.5.7.3.1 fingerprint: 4027AEDB24237BB632DA4FB733345F6445959105 id: 7ec12010-9051-11ed-8e50-b994b27d2ece issuerC: US issuerCN: - HydrantID SSL CA G3 issuerCertificateIds: - 7ebed620-9051-11ed-8e50-b994b27d2ece - d50a4410-297e-11eb-bc4c-8b24e5a66fb6 issuerDN: cn=HydrantID SSL CA G3,o=HydrantID (Avalanche Cloud Corporation),c=US keyStrength: 2048 keyUsage: - digitalSignature - keyEncipherment managedCertificateId: 7f0aac30-9051-11ed-8ab8-19e0a618d9cd modificationDate: '2023-01-10T21:38:03.140+00:00' ocspNoCheck: false selfSigned: false serialNumber: 278B5FBB3DA7A3E7E58C2BD3894C70ACBC1C66F9 signatureAlgorithm: SHA256_WITH_RSA_ENCRYPTION signatureHashAlgorithm: SHA256 subjectAlternativeNameDns: - www.venafi.com - venafi.com subjectAlternativeNamesByType: dNSName: - www.venafi.com - venafi.com otherName: [] rfc822Name: [] subjectC: US subjectCN: - www.venafi.com subjectDN: cn=www.venafi.com,o=Venafi, Inc.,c=US,st=Utah,l=Salt Lake City subjectKeyIdentifierHash: 32EC9FAC232FA74EBFFD7E63FE8F92233CAA965B subjectL: Salt Lake City subjectO: Venafi, Inc. subjectST: Utah validityEnd: '2023-03-14T19:39:00.000+00:00' validityStart: '2022-03-14T19:29:38.000+00:00' versionType: CURRENT certificateId: 7ec12010-9051-11ed-8e50-b994b27d2ece certificateInstanceId: 7ec1bc50-9051-11ed-8e50-b994b27d2ece certificateSource: USER_SCAN deploymentStatus: IN_USE hostname: venafi.com instanceChainValidationStatus: - OK ipAddress: 23.185.0.2 lastScanDate: '2023-01-10T21:38:02.886+00:00' lastValidatedAttempt: '2023-01-10T21:38:03.090+00:00' modificationDate: '2023-01-10T21:38:03.140+00:00' port: 443 serviceIds: - 1d61e9e0-9046-11ed-bf12-53a1b041cf25 sslProtocols: - TLSv1.3 - TLSv1.2 sslValidationStatus: OK schema: $ref: '#/components/schemas/ExtendedCertificateInstanceResponse' text/csv: examples: Certificate instance details response: description: Certificate instance details response summary: Certificate instance details value: count: 1 instances: - certificate: authorityKeyIdentifierHash: 294C87C811C70BD19AB7E0F2D910570198160EE1 certificateName: www.venafi.com certificateStatus: ACTIVE companyId: 85595df0-8e14-11ed-87e3-755db050f29d encryptionType: RSA extendedKeyUsage: - 1.3.6.1.5.5.7.3.2 - 1.3.6.1.5.5.7.3.1 fingerprint: 4027AEDB24237BB632DA4FB733345F6445959105 id: 7ec12010-9051-11ed-8e50-b994b27d2ece issuerC: US issuerCN: - HydrantID SSL CA G3 issuerCertificateIds: - 7ebed620-9051-11ed-8e50-b994b27d2ece - d50a4410-297e-11eb-bc4c-8b24e5a66fb6 issuerDN: cn=HydrantID SSL CA G3,o=HydrantID (Avalanche Cloud Corporation),c=US keyStrength: 2048 keyUsage: - digitalSignature - keyEncipherment managedCertificateId: 7f0aac30-9051-11ed-8ab8-19e0a618d9cd modificationDate: '2023-01-10T21:38:03.140+00:00' ocspNoCheck: false selfSigned: false serialNumber: 278B5FBB3DA7A3E7E58C2BD3894C70ACBC1C66F9 signatureAlgorithm: SHA256_WITH_RSA_ENCRYPTION signatureHashAlgorithm: SHA256 subjectAlternativeNameDns: - www.venafi.com - venafi.com subjectAlternativeNamesByType: dNSName: - www.venafi.com - venafi.com otherName: [] rfc822Name: [] subjectC: US subjectCN: - www.venafi.com subjectDN: cn=www.venafi.com,o=Venafi, Inc.,c=US,st=Utah,l=Salt Lake City subjectKeyIdentifierHash: 32EC9FAC232FA74EBFFD7E63FE8F92233CAA965B subjectL: Salt Lake City subjectO: Venafi, Inc. subjectST: Utah validityEnd: '2023-03-14T19:39:00.000+00:00' validityStart: '2022-03-14T19:29:38.000+00:00' versionType: CURRENT certificateId: 7ec12010-9051-11ed-8e50-b994b27d2ece certificateInstanceId: 7ec1bc50-9051-11ed-8e50-b994b27d2ece certificateSource: USER_SCAN deploymentStatus: IN_USE hostname: venafi.com instanceChainValidationStatus: - OK ipAddress: 23.185.0.2 lastScanDate: '2023-01-10T21:38:02.886+00:00' lastValidatedAttempt: '2023-01-10T21:38:03.090+00:00' modificationDate: '2023-01-10T21:38:03.140+00:00' port: 443 serviceIds: - 1d61e9e0-9046-11ed-bf12-53a1b041cf25 sslProtocols: - TLSv1.3 - TLSv1.2 sslValidationStatus: OK schema: $ref: '#/components/schemas/ExtendedCertificateInstanceResponse' description: Certificate Instances Response '400': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' text/csv: schema: $ref: '#/components/schemas/ErrorResponse4' description: Request Conditions Failed '412': content: application/json: schema: $ref: '#/components/schemas/ErrorResponse4' text/csv: schema: $ref: '#/components/schemas/ErrorResponse4' description: Request Conditions Failed security: - tppl-api-key: [] summary: Retrieve certificate instance data matching search criteria tags: - Certificate Installations components: schemas: Response: properties: allowedMethods: items: type: string type: array uniqueItems: true closed: type: boolean cookies: additionalProperties: $ref: '#/components/schemas/NewCookie' type: object date: format: date-time type: string entity: $ref: '#/components/schemas/AnyValue3' entityTag: $ref: '#/components/schemas/EntityTag' headers: additionalProperties: items: $ref: '#/components/schemas/AnyValue3' type: array properties: empty: type: boolean type: object language: properties: country: type: string displayCountry: type: string displayLanguage: type: string displayName: type: string displayScript: type: string displayVariant: type: string extensionKeys: items: type: string type: array uniqueItems: true iso3Country: type: string iso3Language: type: string language: type: string script: type: string unicodeLocaleAttributes: items: type: string type: array uniqueItems: true unicodeLocaleKeys: items: type: string type: array uniqueItems: true variant: type: string type: object lastModified: format: date-time type: string length: format: int32 type: integer links: items: $ref: '#/components/schemas/Link' type: array uniqueItems: true location: format: uri type: string mediaType: $ref: '#/components/schemas/MediaType' metadata: additionalProperties: items: $ref: '#/components/schemas/AnyValue3' type: array properties: empty: type: boolean type: object status: format: int32 type: integer statusInfo: $ref: '#/components/schemas/StatusType' stringHeaders: additionalProperties: items: type: string type: array properties: empty: type: boolean type: object type: object FilterOperands: properties: operands: description: A list of conditions that will be used for filtering example: - field: certificateStatus operator: EQ value: ACTIVE - field: certificateName operator: EQ value: venafi.com items: $ref: '#/components/schemas/BaseFilter' type: array operator: description: An operator for filtering enum: - AND - OR example: OR type: string type: object ExtendedApplicationOwnership: properties: id: format: uuid type: string owningTeams: items: format: uuid type: string type: array uniqueItems: true owningUsers: items: format: uuid type: string type: array uniqueItems: true type: type: string type: object CertificateInstanceValidationRequest: properties: instanceIds: description: Unique certificate instance id(s) containing numbers, letters and dashes. example: - 7860eedb-c140-4354-b0ad-991cc7a7b4d1 - 0b0f6424-30bc-4ed8-ae83-cdeca3eaf60e items: format: uuid type: string type: array required: - instanceIds type: object Condition: description: A Condition for filtering properties: field: description: Represents a field for filtering example: certificateName type: string operator: description: An operator for filtering enum: - EQ - LT - LTE - GT - GTE - MATCH - FIND - IN example: EQ type: string value: description: represents a field's value example: venafi.com type: string values: description: represents a field's values example: - venafi.com - www.venafi.com items: type: string type: array type: object CertificateOwnership: properties: owningContainers: items: $ref: '#/components/schemas/ExtendedApplicationOwnership' type: array uniqueItems: true type: object CertificateInstanceInformation: properties: applicationIds: description: A collection of application IDs example: - d3cce873-6957-4071-a65e-7676c0ae1123 - 322bcd99-286a-47ea-8dcd-8291ec5bff14 items: format: uuid type: string type: array certificateId: description: UUID of a certificate example: 2eb29780-9046-11ed-8e50-b994b27d2ece format: uuid type: string certificateInstanceId: description: UUID of a certificate instance example: f68daf30-4690-45bc-85b3-bb327024735e format: uuid type: string certificateSource: description: Certificate source enum: - UNKNOWN - USER_PROVIDED - USER_IMPORTED - USER_SCAN - TRUSTNET_SCAN - ON_PREM_CA_IMPORT - EXTERNAL_CA_IMPORT - FILE_IMPORT - EXTERNAL_SCAN - DOMAIN_SCAN - SMART_SCAN_INTERNAL - SMART_SCAN_EXTERNAL - SMART_VALIDATION_INTERNAL - SMART_VALIDATION_EXTERNAL - MACHINE_DISCOVERY - KUBERNETES_DISCOVERY - AWS_DISCOVERY - AZURE_DISCOVERY - GCP_DISCOVERY example: USER_SCAN type: string deploymentStatus: description: The deployment status enum: - UNKNOWN - IN_USE - SUPERSEDED example: IN_USE type: string hostname: description: A hostname example: venafi.com type: string instanceChainValidationStatus: description: A collection of the instance chain validation status example: - OK items: enum: - OK - CHAIN_BUILDING_FAILED - INCOMPLETE_CHAIN - CHAIN_EXPIRE_BEFORE_EE - DISTRUSTED - UNKNOWN_ERROR - SELF_SIGNED type: string type: array ipAddress: description: An ip address example: 14.183.1.32 type: string lastScanDate: description: The last scan date example: '2023-01-10T09:12:28Z' format: date-time type: string lastValidatedAttempt: description: The last validation attempt date example: '2023-01-11T09:12:28Z' format: date-time type: string modificationDate: description: The last modification date example: '2023-01-10T09:12:28Z' format: date-time type: string port: description: A port number example: 443 format: int32 type: integer serviceIds: description: A collection of service IDs example: - 1d61e9e0-9046-11ed-bf12-53a1b041cf2 items: format: uuid type: string type: array sslProtocols: description: A collection of ssl protocols example: - TLSv1.1 - TLSv1.2 items: type: string type: array sslValidationErrorArguments: description: A collection of ssl validation error arguments example: - B69950CC5F51EDDF55F36AD2BC898767BC43CC2A - 24E5796GA7298E78EDE47D6FAED0790E8F464G54 items: type: string type: array sslValidationStatus: description: SSL validation status enum: - HOSTNAME_NOT_RESOLVABLE - NO_CERTIFICATE_PRESENTED - INVALID_CERTIFICATE_FOUND - UNEXPECTED_CERTIFICATE_FOUND - OLD_VERSION_CERTIFICATE_FOUND - TARGET_UNREACHABLE - UNKNOWN_ERROR - OK example: OK type: string sslValidationStatusMessage: description: SSL validation status message example: Certificate installation is using older versions of certificate type: string type: object Order: properties: direction: description: An ordering direction enum: - ASC - DESC example: DESC type: string field: description: A field, that will be used for ordering example: modificationDate type: string type: object MediaType: properties: parameters: additionalProperties: type: string type: object subtype: type: string type: type: string wildcardSubtype: type: boolean wildcardType: type: boolean type: object EntityTag: properties: value: type: string weak: type: boolean type: object Link: properties: params: additionalProperties: type: string type: object rel: type: string rels: items: type: string type: array title: type: string type: type: string uri: format: uri type: string uriBuilder: $ref: '#/components/schemas/UriBuilder' type: object GeneralNamesData1: description: A certificate subject alternative name by type example: dNSName: - www.venafi.com - venafi.com properties: dNSName: items: type: string type: array directoryName: items: type: string type: array ediPartyName: items: type: string type: array iPAddress: items: type: string type: array otherName: items: type: string type: array registeredID: items: type: string type: array rfc822Name: items: type: string type: array uniformResourceIdentifier: items: type: string type: array x400Address: items: type: string type: array type: object Page2: description: Specify pagination on the search request properties: pageNumber: description: page number example: 0 format: int32 type: integer pageSize: description: page size example: 10 format: int32 type: integer type: object StatusType: properties: family: enum: - INFORMATIONAL - SUCCESSFUL - REDIRECTION - CLIENT_ERROR - SERVER_ERROR - OTHER type: string reasonPhrase: type: string statusCode: format: int32 type: integer type: object BaseOrdering: description: Specify the ordering of a search result properties: orders: items: $ref: '#/components/schemas/Order' type: array type: object ExtendedCertificateInstanceResponse: properties: count: format: int32 type: integer instances: items: $ref: '#/components/schemas/ExtendedCertificateInstanceInformation' type: array type: object AnyValue3: description: Can be any value - string, number, boolean, array or object. CertificateInformation: properties: applicationIds: description: A collection of application IDs example: - 561baf7c-98b7-49af-ab9c-7b3a9fea3028 - 4adeba6f-0c94-4595-a5b6-babea458249f items: format: uuid type: string type: array archivedDate: description: The date a certificate was archived example: '2022-05-24T09:12:28Z' format: date-time type: string authorityKeyIdentifierHash: description: An authority key identifier hash example: 40572B10F85DDAF18BFF987372178532AB875BCA type: string certificateAuthorityAccountId: description: UUID of a certificate authority account format: uuid type: string certificateName: description: A certificate name example: venafi.com type: string certificateRequestId: description: UUID of a certificate request example: 2e8964a0-9046-11ed-8e50-b994b27d2ece format: uuid type: string certificateStatus: description: Certificate's status enum: - ACTIVE - RETIRED - DELETED example: ACTIVE type: string companyId: description: UUID of a company example: 85595df0-8e14-11ed-87e3-755db050f29d format: uuid type: string dekHash: description: A certificate dek hash example: RaBDrLmQ69hACXOrPU6542RBT-M-yZOkw4XKsT-r55i= type: string encryptionType: description: A certificate encryption type enum: - RSA - DSA - EC - GOST3410 - ECGOST3410 - RESERVED3 - UNKNOWN example: EC type: string extendedKeyUsage: description: A collection of certificate extended key usages example: - 1.3.6.1.5.5.7.3.2 - 1.3.6.1.5.5.7.3.1 items: type: string type: array fingerprint: description: A certificate fingerprint example: 6D4C95512C117B004191F1A096ECAD13242FCD9F type: string id: description: UUID of a certificate example: 2eb29780-9046-11ed-8e50-b994b27d2ece format: uuid type: string inhibitAnyPolicy: description: Inhibit any policy example: 150 format: int32 type: integer inhibitPolicyMapping: description: Inhibit policy mapping example: 200 format: int32 type: integer instances: description: A collection of certificate instances information example: - certificateId: 7ec12010-9051-11ed-8e50-b994b27d2ece certificateInstanceId: 7ec1bc50-9051-11ed-8e50-b994b27d2ece certificateSource: USER_SCAN deploymentStatus: IN_USE hostname: venafi.com instanceChainValidationStatus: - OK ipAddress: 23.185.0.2 lastScanDate: '2023-01-09T19:12:05.314+00:00' lastValidatedAttempt: '2023-01-09T19:12:05.446+00:00' modificationDate: '2023-01-09T19:12:14.865+00:00' port: 443 serviceIds: - 1d61e9e0-9046-11ed-bf12-53a1b041cf25 sslProtocols: - TLSv1.3 - TLSv1.2 sslValidationErrorArguments: [] sslValidationStatus: OK items: $ref: '#/components/schemas/CertificateInstanceInformation' type: array issuerAlternativeNameDns: description: A collection of certificate issuer alternative names DNs example: - venafi.com - www.venafi.com items: type: string type: array issuerAlternativeNameNonDns: description: A collection of certificate issuer alternative name none DNs example: - venafi issuer doman items: type: string type: array issuerC: description: A certificate issues Country example: US type: string issuerCN: description: A collection of certificate issuer Common names example: - HydrantID SSL CA G3 items: type: string type: array issuerCertificateIds: description: A collection of issuer certificate IDs example: - 2e8964a0-9046-11ed-8e50-b994b27d2ece - d5b418a0-297e-11eb-bc4c-8b24e5a66fb6 items: format: uuid type: string type: array issuerDN: description: A certificate issue DN example: cn=HydrantID SSL CA G3,o=HydrantID (Avalanche Cloud Corporation),c=US type: string issuerL: description: A certificate issues Locality example: Salt Lake City type: string issuerOU: description: A collection of certificate issuer Organization units example: - Issuer CA items: type: string type: array issuerST: description: A certificate issuer State example: Utah type: string keyCurve: description: A certificate key curve enum: - P256 - P384 - P521 - ED25519 - UNKNOWN example: P256 type: string keyStrength: description: A certificate key strength example: 2048 format: int32 type: integer keyUsage: description: A collection of certificate key usages example: - digitalSignature - keyEncipherment items: type: string type: array lastNotification: format: int32 type: integer managedCertificateId: description: UUID of a managed certificate example: 2f0e7320-9046-11ed-8ab8-19e0a618d9cd format: uuid type: string modificationDate: description: The last date a certificate was modified example: '2022-03-24T09:12:28Z' format: date-time type: string ocspNoCheck: description: If a certificate no ocsp check example: false type: boolean ownership: $ref: '#/components/schemas/CertificateOwnership' pathLength: description: A certificate path length example: 3 format: int32 type: integer requireExplicitPolicy: description: Required explicit policy is required example: 1 format: int32 type: integer selfSigned: description: If the certificate is self singed example: true type: boolean serialNumber: description: A certificate serial number example: 0C51A562B02A19A222FFB4730C47A8E2 type: string signatureAlgorithm: description: A certificate signature algorithm enum: - MD2_WITH_RSA_ENCRYPTION - MD5_WITH_RSA_ENCRYPTION - SHA1_WITH_RSA_ENCRYPTION - SHA1_WITH_RSA_ENCRYPTION2 - SHA256_WITH_RSA_ENCRYPTION - SHA384_WITH_RSA_ENCRYPTION - SHA512_WITH_RSA_ENCRYPTION - ID_DSA_WITH_SHA1 - dsaWithSHA1 - EC_DSA_WITH_SHA1 - EC_DSA_WITH_SHA224 - EC_DSA_WITH_SHA256 - EC_DSA_WITH_SHA384 - EC_DSA_WITH_SHA512 - UNKNOWN - SHA1_WITH_RSAandMGF1 - GOST_R3411_94_WITH_GOST_R3410_2001 - GOST_R3411_94_WITH_GOST_R3410_94 example: SHA256_WITH_RSA_ENCRYPTION type: string signatureHashAlgorithm: description: A certificate signature hash algorithm enum: - MD5 - SHA1 - MD2 - SHA224 - SHA256 - SHA384 - SHA512 - UNKNOWN - GOSTR3411_94 example: SHA256 type: string statusModificationDate: description: The date a certificate's status was modified example: '2022-04-24T09:12:28Z' format: date-time type: string statusModificationUserId: description: UUID of the user that modified the certificate installation example: 3c9964a0-9046-11ed-8e50-b994b27d2ece format: uuid type: string subjectAlternativeNameDns: description: A collection of certificate subject alternative names DNs example: - venafi.com - www.venafi.com items: type: string type: array subjectAlternativeNameNonDns: description: A collection of certificate subject alternative name none DNs example: - venafi domain items: type: string type: array subjectAlternativeNamesByType: $ref: '#/components/schemas/GeneralNamesData1' subjectC: description: A certificate subject Country example: US type: string subjectCN: description: A collection of certificate subject CNs example: - venafi.com - cloud.venafi items: type: string type: array subjectDN: description: A certificate subject DN example: cn=www.venafi.com,o=Venafi, Inc.,c=US,st=Utah,l=Salt Lake City type: string subjectKeyIdentifierHash: description: A subject key identifier hash example: 4E0CE93D3240561F468C33A85F08FCD3B04CC9DC type: string subjectL: description: A certificate subject Locality example: Salt Lake City type: string subjectO: description: A certificate subject Organization example: Venafi, Inc. type: string subjectOU: description: A collection of certificate subject Organization units example: - devops - test items: type: string type: array subjectST: description: A certificate subject State example: Utah type: string tags: description: A collection of tags example: - owner:test.user - 90-day items: type: string type: array totalActiveInstanceCount: description: total active instances of a certificate example: 50 format: int32 type: integer totalInstanceCount: description: total instances of a certificate example: 100 format: int32 type: integer validityEnd: description: The date a certificate validity ends example: '2023-01-24T09:12:28Z' format: date-time type: string validityStart: description: The date a certificate validity starts example: '2022-01-24T09:12:28Z' format: date-time type: string versionType: description: A certificate version type enum: - OLD - CURRENT example: CURRENT type: string type: object FilterOperand: properties: operand: $ref: '#/components/schemas/Condition' operator: description: An operator for filtering enum: - NOT example: NOT type: string type: object ErrorInformation3: properties: args: items: $ref: '#/components/schemas/AnyValue3' type: array code: format: int32 type: integer message: type: string type: object ErrorResponse4: properties: errors: items: $ref: '#/components/schemas/ErrorInformation3' type: array type: object ExtendedCertificateInstanceInformation: properties: applicationIds: description: A collection of application IDs example: - d3cce873-6957-4071-a65e-7676c0ae1123 - 322bcd99-286a-47ea-8dcd-8291ec5bff14 items: format: uuid type: string type: array certificate: $ref: '#/components/schemas/CertificateInformation' certificateId: description: UUID of a certificate example: 2eb29780-9046-11ed-8e50-b994b27d2ece format: uuid type: string certificateInstanceId: description: UUID of a certificate instance example: f68daf30-4690-45bc-85b3-bb327024735e format: uuid type: string certificateSource: description: Certificate source enum: - UNKNOWN - USER_PROVIDED - USER_IMPORTED - USER_SCAN - TRUSTNET_SCAN - ON_PREM_CA_IMPORT - EXTERNAL_CA_IMPORT - FILE_IMPORT - EXTERNAL_SCAN - DOMAIN_SCAN - SMART_SCAN_INTERNAL - SMART_SCAN_EXTERNAL - SMART_VALIDATION_INTERNAL - SMART_VALIDATION_EXTERNAL - MACHINE_DISCOVERY - KUBERNETES_DISCOVERY - AWS_DISCOVERY - AZURE_DISCOVERY - GCP_DISCOVERY example: USER_SCAN type: string deploymentStatus: description: The deployment status enum: - UNKNOWN - IN_USE - SUPERSEDED example: IN_USE type: string hostname: description: A hostname example: venafi.com type: string instanceChainValidationStatus: description: A collection of the instance chain validation status example: - OK items: enum: - OK - CHAIN_BUILDING_FAILED - INCOMPLETE_CHAIN - CHAIN_EXPIRE_BEFORE_EE - DISTRUSTED - UNKNOWN_ERROR - SELF_SIGNED type: string type: array ipAddress: description: An ip address example: 14.183.1.32 type: string lastScanDate: description: The last scan date example: '2023-01-10T09:12:28Z' format: date-time type: string lastValidatedAttempt: description: The last validation attempt date example: '2023-01-11T09:12:28Z' format: date-time type: string modificationDate: description: The last modification date example: '2023-01-10T09:12:28Z' format: date-time type: string port: description: A port number example: 443 format: int32 type: integer serviceIds: description: A collection of service IDs example: - 1d61e9e0-9046-11ed-bf12-53a1b041cf2 items: format: uuid type: string type: array sslProtocols: description: A collection of ssl protocols example: - TLSv1.1 - TLSv1.2 items: type: string type: array sslValidationErrorArguments: description: A collection of ssl validation error arguments example: - B69950CC5F51EDDF55F36AD2BC898767BC43CC2A - 24E5796GA7298E78EDE47D6FAED0790E8F464G54 items: type: string type: array sslValidationStatus: description: SSL validation status enum: - HOSTNAME_NOT_RESOLVABLE - NO_CERTIFICATE_PRESENTED - INVALID_CERTIFICATE_FOUND - UNEXPECTED_CERTIFICATE_FOUND - OLD_VERSION_CERTIFICATE_FOUND - TARGET_UNREACHABLE - UNKNOWN_ERROR - OK example: OK type: string sslValidationStatusMessage: description: SSL validation status message example: Certificate installation is using older versions of certificate type: string type: object UriBuilder: type: object NewCookie: properties: comment: type: string domain: type: string expiry: format: date-time type: string httpOnly: type: boolean maxAge: format: int32 type: integer name: type: string path: type: string sameSite: enum: - NONE - LAX - STRICT type: string secure: type: boolean value: type: string version: format: int32 type: integer type: object BaseFilter: description: Root expression for filtering oneOf: - $ref: '#/components/schemas/FilterOperands' - $ref: '#/components/schemas/FilterOperand' - $ref: '#/components/schemas/Condition' type: object Filter2: properties: expression: $ref: '#/components/schemas/BaseFilter' ordering: $ref: '#/components/schemas/BaseOrdering' paging: $ref: '#/components/schemas/Page2' type: object securitySchemes: service-account: in: header name: service-account type: apiKey tppl-api-key: in: header name: tppl-api-key type: apiKey x-readme: samples-languages: - curl - go - java - javascript - node - python