GET Certificates ID Roots

The GET /Certificates/{id}/Roots operation retrieves one or more CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. root certificates found in a trust bundle to which the specified certificate chains. On success, the operation returns HTTP 200 OK with  details of the root CA certificate or certificates—if found in a trust bundle.

Note:  Results are cached per evaluated certificate for a short period. Changes to trust bundles may not be reflected immediately until the cache expires.
Tip:  The following permissions (see Security Roles and Claims) are required to use this feature:
/certificates/collections/read/
OR
/certificates/collections/read/#/
OR
/certificate_stores/read/
OR
/certificate_stores/read/#/

Permissions for certificates can be set at the system-wide or resource-specific level. The appropriate level depends on how the certificates are accessed. See Certificate CollectionClosed The certificate search function allows you to query the Keyfactor Command database for certificates from any available source based on any criteria of the certificates and save the results as a collection that will be available in other places in the Management Portal (for example expiration alerts and certain reports). Permissions and Application Permissions for more information.

In permission strings, # represents a specific resource identifier. In /certificates/collections/ permission strings it refers to a certificate collection ID (for example, CollectionId) and in /certificate_stores/ permission strings it refers to a certificate store application ID (for example, containerId).

Table 284: GET Certificates ID Roots Input Parameters

Name In Description
Id Path

An integer indicating the Keyfactor Command reference ID of the certificate to check for applicable trust bundle root certificates.

Use the GET Certificates operation to retrieve a list of all the certificates or view the certificate in the Management Portal to determine the ID.

CollectionId Query

An optional integer that specifies the certificate collection (CollectionId) to validate whether the user has sufficient permissions to perform the action. If a CollectionId is not provided, the user must have appropriate permissions granted system-wide or via certificate store applications.

Providing a CollectionId allows the system to check the user's permissions at the certificate collection level. Permissions are evaluated in the following order:

  1. System-wide certificate permissions
  2. Granular certificate permissions

Use either ContainerId or CollectionId, not both. If both are specified, CollectionId takes precedence, and the ContainerId is ignored (defaults to 0).

See Certificate Collection Permissions for more information.

ContainerId Query

An optional integer that specifies the certificate store application (ContainerId) to validate whether the user has sufficient permissions to perform the action. If a ContainerId is not provided, the user must have appropriate permissions granted system-wide or via certificate collections.

Providing a ContainerId allows the system to check the user's permissions at the application level. Permissions are evaluated in the following order:

  1. System-wide certificate permissions
  2. System-wide certificate store application permissions
  3. Granular certificate store application permissions

Use either ContainerId or CollectionId, not both.

See Application Permissions for more information.

Table 285: GET Certificates ID Roots Response Data

Name Description
CertificateId

An integer indicating the Keyfactor Command reference ID of the root CA certificate.

Tip:  Certificate Id and Keyfactor Id both refer to the same value—the Keyfactor Command–assigned reference ID for a certificate. You may see either name in different parts of the Management Portal or Keyfactor API because Certificate Id was the original term, and Keyfactor Id is its newer replacement. The updated name helps avoid confusion with a different value—the certificate’s identifier on the issuing CA—which is now called the CA Record ID.
IssuedDN A string indicating the distinguished name of the root CA certificate.
Thumbprint A string indicating the thumbprint of the root CA certificate.