| certkey |
<String> |
Read-write |
Name for the certificate and private-key pair. Must begin with an ASCII alphanumeric or underscore (_) character, and must contain only ASCII alphanumeric, underscore, hash (#), period (.), space, colon (:), at (@), equals (=), and hyphen (-) characters. Cannot be changed after the certificate-key pair is created. The following requirement applies only to the Citrix ADC CLI: If the name includes one or more spaces, enclose the name in double or single quotation marks (for example, "my cert" or 'my cert'). Minimum length = 1 |
| cert |
<String> |
Read-write |
Name of and, optionally, path to the X509 certificate file that is used to form the certificate-key pair. The certificate file should be present on the appliance's hard-disk drive or solid-state drive. Storing a certificate in any location other than the default might cause inconsistency in a high availability setup. /nsconfig/ssl/ is the default path. Minimum length = 1 |
| key |
<String> |
Read-write |
Name of and, optionally, path to the private-key file that is used to form the certificate-key pair. The certificate file should be present on the appliance's hard-disk drive or solid-state drive. Storing a certificate in any location other than the default might cause inconsistency in a high availability setup. /nsconfig/ssl/ is the default path. Minimum length = 1 |
| password |
<Boolean> |
Read-write |
Passphrase that was used to encrypt the private-key. Use this option to load encrypted private-keys in PEM format. |
| fipskey |
<String> |
Read-write |
Name of the FIPS key that was created inside the Hardware Security Module (HSM) of a FIPS appliance, or a key that was imported into the HSM. Minimum length = 1 |
| hsmkey |
<String> |
Read-write |
Name of the HSM key that was created in the External Hardware Security Module (HSM) of a FIPS appliance. Minimum length = 1 |
| inform |
<String> |
Read-write |
Input format of the certificate and the private-key files. The three formats supported by the appliance are: PEM - Privacy Enhanced Mail DER - Distinguished Encoding Rule PFX - Personal Information Exchange. Default value: PEM Possible values = DER, PEM, PFX |
| passplain |
<String> |
Read-write |
Pass phrase used to encrypt the private-key. Required when adding an encrypted private-key in PEM format. Minimum length = 1 |
| expirymonitor |
<String> |
Read-write |
Issue an alert when the certificate is about to expire. Possible values = ENABLED, DISABLED |
| notificationperiod |
<Integer> |
Read-write |
Time, in number of days, before certificate expiration, at which to generate an alert that the certificate is about to expire. Minimum value = 10 Maximum value = 100 |
| bundle |
<String> |
Read-write |
Parse the certificate chain as a single file after linking the server certificate to its issuer's certificate within the file. Default value: NO Possible values = YES, NO |
| deletecertkeyfilesonremoval |
<String> |
Read-write |
This option is used to automatically delete certificate/key files from physical device when the added certkey is removed. When deleteCertKeyFilesOnRemoval option is used at rm certkey command, it overwrites the deleteCertKeyFilesOnRemoval setting used at add/set certkey command. Default value: CERTKEYFILE_DELETE_NO Possible values = NO, ALWAYS, IF_EXPIRED |
| deletefromdevice |
<Boolean> |
Read-write |
Delete cert/key file from file system. |
| linkcertkeyname |
<String> |
Read-write |
Name of the Certificate Authority certificate-key pair to which to link a certificate-key pair. Minimum length = 1 |
| nodomaincheck |
<Boolean> |
Read-write |
Override the check for matching domain names during a certificate update operation. |
| ocspstaplingcache |
<Boolean> |
Read-write |
Clear cached ocspStapling response in certkey. |
| signaturealg |
<String> |
Read-only |
Signature algorithm. |
| certificatetype |
<String[]> |
Read-only |
Specifies whether the certificate is of type root-CA, intermediate-CA, server, client, or client and server. Possible values = ROOT_CERT, INTM_CERT, CLNT_CERT, SRVR_CERT, UNKNOWN_CERT |
| serial |
<String> |
Read-only |
Serial number. |
| issuer |
<String> |
Read-only |
Issuer name. |
| clientcertnotbefore |
<String> |
Read-only |
Not-Before date. |
| clientcertnotafter |
<String> |
Read-only |
Not-After date. |
| daystoexpiration |
<Integer> |
Read-only |
Days remaining for the certificate to expire. |
| subject |
<String> |
Read-only |
Subject name. |
| publickey |
<String> |
Read-only |
Public key algorithm. |
| publickeysize |
<Integer> |
Read-only |
Size of the public key. |
| version |
<Integer> |
Read-only |
Version. |
| priority |
<Integer> |
Read-only |
ocsp priority. |
| status |
<String> |
Read-only |
Status of the certificate. Possible values = Valid, Not yet valid, Expired |
| passcrypt |
<String> |
Read-only |
Passcrypt. Minimum length = 1 |
| data |
<Integer> |
Read-only |
Vserver Id. |
| servicename |
<String> |
Read-only |
Service name to which the certificate key pair is bound. |
| sandns |
<String> |
Read-only |
Subject Alternative Name (SAN) is an extension to X.509 that allows various values to be associated with a security certificate using a subjectAltName field. These values are called "Subject Alternative Names" (SAN). This field is for DNS names. |
| sanipadd |
<String> |
Read-only |
Subject Alternative Name (SAN) is an extension to X.509 that allows various values to be associated with a security certificate using a subjectAltName field. These values are called "Subject Alternative Names" (SAN). This field is for IP address. |
| ocspresponsestatus |
<String> |
Read-only |
Ocsp response status of the certificate. Possible values = NONE, EXPIRED, VALID |
| builtin |
<String[]> |
Read-only |
Flag to determine if Cert key is built-in or not. Possible values = MODIFIABLE, DELETABLE, IMMUTABLE, PARTITION_ALL |
| feature |
<String> |
Read-only |
The feature to be checked while applying this config. |
| certkeydigest |
<String> |
Read-only |
Stores the added md5sum of certificate and key files. |
| certificatesource |
<String> |
Read-only |
Location of the certificate. Default value: LOCAL Possible values = LOCAL, REMOTE |
| certkeystatus |
<String> |
Read-only |
Status of the certkey in PE. Possible values = ACTIVE, INACTIVE(Default state), INACTIVE(No Private Key), INACTIVE(Duplicate SAN-Multiple clashing certs), INACTIVE(Duplicate SAN-All SAN entires not covered), INACTIVE(Duplicate SAN-Earlier expiry), INACTIVE(Crossed MAX SAN limit), INACTIVE(No common name), INACTIVE(Common name/SAN too long), INACTIVE(No memory), INACTIVE(MAX cert req len reached), INACTIVE(X509 Name failure) |
| _nextgenapiresource |
<String> |
Read-only |
. |
| __count |
<Double> |
Read-only |
count parameter |