PUT Certificates Metadata All

The PUT /Certificates/MetadataClosed Metadata provides information about a piece of data. It is used to summarize basic information about data, which can make working with the data easier. In Keyfactor Command, the certificate metadata feature allows you to create custom metadata fields that allow you to tag certificates with tracking information about certificates./All operation updates one or more metadata values for a specified set of certificates. On success, the operation returns 204 with no content.

Tip:  The following permissions (see Security Roles and Claims) are required to use this feature:

/certificates/collections/metadata/modify/
OR
/certificates/collections/metadata/modify/#/

Permissions for certificates can be set at the system-wide or resource-specific level. The appropriate level depends on how the certificates are accessed. See Certificate Collection Permissions for more information.

In permission strings, # represents a specific resource identifier. In /certificates/collections/ permission strings it refers to a certificate collection ID (for example, CollectionId) and in /certificate_stores/ permission strings it refers to a certificate store application ID (for example, containerId).

Table 327: PUT Certificates Metadata All Input Parameters

Name

In

Description

Query Body

Required in some cases. A string containing a query to limit the certificates to update (for example, field1 -eq value1 AND field2 -gt value2). Fields available for querying through the API for the most part match those that appear in the Keyfactor Command Management Portal search dropdowns. For querying guidelines, refer to: Searching Certificates.

A value for one of CertificateIds, Query, or CollectionId is required.

Tip:  To exclude revoked certificates from the update, include a query of:
CertState -ne \"2\"

To exclude expired certificates from the update, include a query of:

ExpirationDate -ge \"%TODAY%\"

CertificateIds

Body

Required in some cases. An array of integers indicating the Keyfactor Command certificate IDs to update. A value for one of CertificateIds, Query, or CollectionId is required.

Metadata

Body

Required. An array of objects containing information about the metadata fields to update. ClosedShow metadata details.

For example:

Copy
"Metadata": [
   {
      "MetadataName": "AppOwnerEmailAddress", // This is a String field.
      "Value": "john.smith@keyexample.com",
      "OverwriteExisting": true
   },
   {
      "MetadataName": "SiteCode", // This is an Integer field.
      "Value": 5,
      "OverwriteExisting": true
   },
   {
      "MetadataName": "BusinessCritical", // This is a Boolean field.
      "Value": true,
      "OverwriteExisting": true
   },
   {
      "MetadataName": "Notes", // This is a BigText field.
      "Value": "Here are some notes about this certificate.",
      "OverwriteExisting": true
   },
   {
      "MetadataName": "BusinessUnit", // This is a Multiple Choice field.
      "Value": "E-Business", // This is a value pre-defined for the field.
      "OverwriteExisting": true
   },
   {
      "MetadataName": "TicketResolutionDate", // This is a Date field in yyyy-mm-dd format.
      "Value": "2021-07-23",
      "OverwriteExisting": true
   }
]
CollectionId Query

Required in some cases. Red /One = Hide for POST /Enrollment/RenewAn optional integer that specifies the certificate collection (CollectionId) to validate whether the user has sufficient permissions to perform the action. If a CollectionId is not provided, the user must have appropriate permissions granted system-wide or via certificate store applications.Providing a CollectionId allows the system to check the user's permissions at the certificate collection level. Permissions are evaluated in the following order:System-wide certificate permissionsGranular certificate permissionsUse either ContainerId or CollectionId, not both. If both are specified, CollectionId takes precedence, and the ContainerId is ignored (defaults to 0).See Certificate Collection Permissions for more information.

This field can also be used to specify the certificate collection containing certificates that should be updated. A value for one of CertificateIds, Query, or CollectionId is required.