GET Certificates ID History

The GET /Certificates/{id}/History operation returns details for the history of transactions for a certificate with the specified ID. Query parameters support control over pagination by specifying the page number and return limit and customization of sorting based on specified fields and order. On success, the operation returns HTTP 200 OK with  certificate history details in the message body.

History records are stored for a certificate for a variety of activities including initial import or enrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA)., revocation, key recovery, additions or removals from certificate stores, renewals, and certificate discoveries in various certificate stores. For more information about certificate history records, see Certificate Details.

Tip:  The following permissions (see Security Roles and Claims) are required to use this feature:
/certificates/collections/read/
OR
/certificates/collections/read/#/
OR
/certificate_stores/read/
OR
/certificate_stores/read/#/

Permissions for certificates can be set at the system-wide or resource-specific level. The appropriate level depends on how the certificates are accessed. See Certificate CollectionClosed The certificate search function allows you to query the Keyfactor Command database for certificates from any available source based on any criteria of the certificates and save the results as a collection that will be available in other places in the Management Portal (for example expiration alerts and certain reports). Permissions and Application Permissions for more information.

In permission strings, # represents a specific resource identifier. In /certificates/collections/ permission strings it refers to a certificate collection ID (for example, CollectionId) and in /certificate_stores/ permission strings it refers to a certificate store application ID (for example, containerId).

Table 282: GET Certificates {id} History Input Parameters

Name In Description
id Path Required. An integer containing the Keyfactor Command reference ID of the certificate.
CollectionId Query

An optional integer that specifies the certificate collection (CollectionId) to validate whether the user has sufficient permissions to perform the action. If a CollectionId is not provided, the user must have appropriate permissions granted system-wide or via certificate store applications.

Providing a CollectionId allows the system to check the user's permissions at the certificate collection level. Permissions are evaluated in the following order:

  1. System-wide certificate permissions
  2. Granular certificate permissions

Use either ContainerId or CollectionId, not both. If both are specified, CollectionId takes precedence, and the ContainerId is ignored (defaults to 0).

See Certificate Collection Permissions for more information.

ContainerId Query

An optional integer that specifies the certificate store application (ContainerId) to validate whether the user has sufficient permissions to perform the action. If a ContainerId is not provided, the user must have appropriate permissions granted system-wide or via certificate collections.

Providing a ContainerId allows the system to check the user's permissions at the application level. Permissions are evaluated in the following order:

  1. System-wide certificate store application permissions
  2. Granular certificate store application permissions

Use either ContainerId or CollectionId, not both. If both are specified, CollectionId takes precedence, and the ContainerId is ignored (defaults to 0).

See Application Permissions for more information.

PageReturned Query An integer that specifies how many multiples of the returnLimit to skip and offset by before returning results, to enable paging. The default is 1.
ReturnLimit Query An integer that specifies how many results to return per page. The default is 50. Very large values can result in long processing time.
SortField Query

A string containing the property by which the results should be sorted. Fields available for sorting through the API include:

  • Comment

  • Id

  • OperationEnd

  • OperationStart

  • Username

The default sort field is OperationStart.

SortAscending Query An integer that sets the sort order on the returned results. A value of 0 sorts results in ascending order while a value of 1 sorts results in descending order. The default is ascending.

Table 283: GET Certificates {id} History Response Data

Name Description
Id An integer containing the Keyfactor Command reference ID of the certificate.
OperationStart The date, in UTC, on which the operation begin.
OperationEnd The date, in UTC, on which the operation completed.
Username The name of the user who initiated the transaction that created the history record (for example, enrolled for the certificate, revoked the certificate), in DOMAIN\\username format for Active Directory users.
Comment A string containing a comment that provides more information about the history record. For example (for a metadata field):
"AppOwnerEmailAddress has been updated from 'john.smith@keyexample.com' to 'martha.jones@keyexample.com'"
Action A string naming the action that was taken. For example:
Metadata Updated