PUT Certificates ID Owner
The PUT /Certificates/{id}/Owner method is used to update the certificate owner for a specified certificate. The optional certificate owner is a security role defined in Keyfactor Command (see Security Roles and Claims). This endpoint An endpoint is a URL that enables the API to gain access to resources on a server. returns 204 with no content upon success. The certificate history will be updated on the certificate details for actions on this endpoint.
In addition, the method checks the following to determine whether the user has permissions to change owner on
For Change Owner permission:
- The security role(s) assigned to the requesting user
- The current certificate owner assigned to the certificate, if any
For Expanded Change Owner permission:
- The permission set(s) associated with the user's role(s)
- The permission set(s) associated with the certificate owner role, if defined
The change owner action succeeds only if all applicable permission checks pass.
See Change Owner and Certificates for more information about change owner permissions.
Permissions for certificates can be configured at multiple levels. You can apply them system-wide—for all certificates The certificate search function allows you to query the Keyfactor Command database for certificates from any available source based on any criteria of the certificates and save the results as a collection that will be availble in other places in the Management Portal (e.g. expiration alerts and certain reports).
Table 345: PUT Certificates {id} Owner Input Parameters
Name |
In |
Description |
---|---|---|
Id | Path | Required. An integer specifying the Keyfactor Command reference ID for the certificate to update. |
CollectionId | Query |
An optional integer that specifies the certificate collection (CollectionId) to validate whether the user has sufficient permissions to perform the action. If a CollectionId is not provided, the user must have appropriate permissions granted system-wide or via certificate store containers. Providing a CollectionId allows the system to check the user's permissions at the certificate collection level. Permissions are evaluated in the following order:
Use either ContainerId or CollectionId, not both. If both are specified, CollectionId takes precedence, and the ContainerId is ignored (defaults to 0). See Certificate Collection Permissions for more information. |
ContainerId | Query |
An optional integer that specifies the certificate store container (ContainerId) to validate whether the user has sufficient permissions to perform the action. If a ContainerId is not provided, the user must have appropriate permissions granted system-wide or via certificate collections. Providing a ContainerId allows the system to check the user's permissions at the container level. Permissions are evaluated in the following order:
Use either ContainerId or CollectionId, not both. If both are specified, CollectionId takes precedence, and the ContainerId is ignored (defaults to 0). See Container Permissions for more information. |
NewRoleId | Body |
An integer indicating the Keyfactor Command reference ID of the security role to assign as the certificate owner. Set this value to null to clear an existing certificate owner. The value cannot be unset if the enrollment pattern or system-wide settings Certificate Owner Role policy has been configured as Required. Note: To assign a certificate owner, one of NewRoleId or NewRoleName is required, not both.
|
NewRoleName | Body |
A string containing the name of the security role to assign as the certificate owner. This name must match the existing name of the security role. Set this value to null or blank to clear an existing certificate owner. The value cannot be unset if the enrollment pattern or system-wide settings Certificate Owner Role policy has been configured as Required. Note: To assign a certificate owner, one of NewRoleId or NewRoleName is required, not both.
|



Was this page helpful? Provide Feedback