PUT Enrollment Patterns Settings

The PUT /EnrollmentPatterns/Settings operation creates or updates the system-wide enrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). pattern policy settings in Keyfactor Command. On success, the operation returns HTTP 200 OK with  details about the enrollment pattern policy settings.

Tip:  Enrollment pattern policies may also be set for an individual enrollment pattern to apply only to that enrollment pattern (see POST Enrollment Patterns). Enrollment pattern policies set at the individual enrollment pattern level take precedence over policies set at the global level.
Tip:  The following permissions (see Security Roles and Claims) are required to use this feature:

/enrollment_pattern/modify/

Important:  This operation replaces the entire record. Any fields not included in the request are cleared or set to their default values.

To avoid unintended data loss, first perform a GET to retrieve the existing record, update only the required fields, and then submit the full set of values in the PUT request.

Table 531: PUT Enrollment Patterns Settings Input Parameters

Name In

Description

Defaults Body

An array of objects containing the system-wide enrollment pattern default settings. These apply to all enrollments that are not otherwise overridden by individual enrollment pattern settings, including those that do not use an enrollment pattern (for example, from a standalone CA). ClosedShow enrollment pattern default details.

For example:

Copy
"Defaults": [
   {
      "SubjectPart": "L",
      "Value": "Denver"
   },
   {
      "SubjectPart": "ST",
      "Value": "Colorado"
   }
]
Note:  See also the Subject Format application setting, which takes precedence over enrollment defaults at both the system-wide and enrollment pattern level (see Application Settings: Enrollment Tab) but does not apply to enrollment requests done through the Keyfactor API.
Policies Body

An object containing the system-wide enrollment pattern policy settings. These apply to all enrollments that are not otherwise overridden by individual enrollment pattern settings, including those that do not use an enrollment pattern (for example, from a standalone CA). ClosedShow enrollment pattern policy details.

For example:

Copy
"Policies": {
    "AllowKeyReuse": true,
    "AllowWildcards": true,
    "RFCEnforcement": false,
    "CertificateOwnerRole": 0,
    "DefaultCertificateOwnerRoleId": 3,
    "DefaultCertificateOwnerRoleName": "Power Users",
    "DefaultCertificateOwnerOverride": false,
    "KeyInfo": {
      "ECDSA": {
        "name": "ECDSA",
        "bit_lengths": [
          256,
          384,
          521
        ],
        "curves": [
          "1.2.840.10045.3.1.7",
          "1.3.132.0.34",
          "1.3.132.0.35"
        ]
      },
      "RSA": {
        "name": "RSA",
        "bit_lengths": [
          2048,
          4096
        ],
        "curves": []
      },
      "Ed448": {
        "name": "Ed448",
        "bit_lengths": [
          448
        ],
        "curves": []
      },
      "Ed25519": {
        "name": "Ed25519",
        "bit_lengths": [
          255
        ],
        "curves": []
      },
      "MLDSA44": {
        "name": "ML-DSA-44",
        "bit_lengths": [
          0
        ],
        "curves": []
      },
      "MLDSA65": {
        "name": "ML-DSA-65",
        "bit_lengths": [
          0
        ],
        "curves": []
      },
      "MLDSA87": {
        "name": "ML-DSA-87",
        "bit_lengths": [
          0
        ],
        "curves": []
      }
    },
    "PrimaryKeyAlgorithms": [
      {
        "name": "RSA",
        "bit_lengths": [
          2048,
          4096
        ],
        "curves": []
      },
      {
        "name": "ECDSA",
        "bit_lengths": [
          256,
          384,
          521
        ],
        "curves": [
          "1.2.840.10045.3.1.7",
          "1.3.132.0.34",
          "1.3.132.0.35"
        ]
      },
      {
        "name": "Ed448",
        "bit_lengths": [
          448
        ],
        "curves": []
      },
      {
        "name": "Ed25519",
        "bit_lengths": [
          255
        ],
        "curves": []
      },
      {
        "name": "ML-DSA-44",
        "bit_lengths": [
          0
        ],
        "curves": []
      },
      {
        "name": "ML-DSA-65",
        "bit_lengths": [
          0
        ],
        "curves": []
      },
      {
        "name": "ML-DSA-87",
        "bit_lengths": [
          0
        ],
        "curves": []
      }
    ],
    "AlternativeKeyAlgorithms": [
      {
        "name": "RSA",
        "bit_lengths": [],
        "curves": []
      },
      {
        "name": "ECDSA",
        "bit_lengths": [],
        "curves": []
      },
      {
        "name": "Ed448",
        "bit_lengths": [],
        "curves": []
      },
      {
        "name": "Ed25519",
        "bit_lengths": [],
        "curves": []
      },
      {
        "name": "ML-DSA-44",
        "bit_lengths": [],
        "curves": []
      },
      {
        "name": "ML-DSA-65",
        "bit_lengths": [],
        "curves": []
      },
      {
        "name": "ML-DSA-87",
        "bit_lengths": [],
        "curves": []
      }
    ],
   "CSRSANControl": 0
  },
Regexes Body

An array of objects containing the system-wide enrollment pattern regular expression settings. These apply to all enrollments that are not otherwise overridden by enrollment pattern settings, including those that do not use an enrollment pattern (for example, from a standalone CA). ClosedShow regular expression settings.

Name Description
Subject Part A string indicating the portion of the subject the regular expression applies to (for example, CN).
RegEx

A string specifying the regular expression against which data entered in the indicated subject part field (for example, CN) in the enrollment pages of the Keyfactor Command Management Portal or using an API enrollment operation will be validated.

Use the GET Enrollment Patterns Subject Parts operation to retrieve a list of all the supported subject parts.

ClosedShow regular expression examples.

Error

A string specifying the error message displayed to the user when the subject part referenced in the CSR or entered for a PFX enrollment does not match the given regular expression.

Note:  The error message already includes a leading string with the subject part (for example, Common Name: or Invalid CN provided: depending on the interface used). Your custom message follows this.
CaseSensitive A Boolean that sets the validation for the field to be case-sensitive (True or False). If the subject part does not match the expected case, the value specified by the Error parameter will display. If the CaseSensitive option is set to False, even if the regular expression contains requirements to enforce case, the case requirement will not be enforced.

For example:

Copy
"Regexes": [
   {
      "SubjectPart": "O",
      "Regex": "^(?:Key Example Company|Key Example\, Inc\.)$",
      "Error": "Organization must be Key Example, Inc or Key Example Company.",
      "CaseSensitive": true
   }
]

Table 532: PUT Enrollment Patterns Settings Response Data

Name

Description

Defaults

An array of objects containing the system-wide enrollment pattern default settings. These apply to all enrollments that are not otherwise overridden by individual enrollment pattern settings, including those that do not use an enrollment pattern (for example, from a standalone CA). ClosedShow enrollment pattern default details.

Note:  See also the Subject Format application setting, which takes precedence over enrollment defaults at both the system-wide and enrollment pattern level (see Application Settings: Enrollment Tab) but does not apply to enrollment requests done through the Keyfactor API.
Policies

An object containing the system-wide enrollment pattern policy settings. These apply to all enrollments that are not otherwise overridden by individual enrollment pattern settings, including those that do not use an enrollment pattern (for example, from a standalone CA). ClosedShow enrollment pattern policy details.

Regexes

An array of objects containing the system-wide enrollment pattern regular expression settings. These apply to all enrollments that are not otherwise overridden by enrollment pattern settings, including those that do not use an enrollment pattern (for example, from a standalone CA). ClosedShow regular expression settings.

Name Description
Subject Part A string indicating the portion of the subject the regular expression applies to (for example, CN).
RegEx

A string specifying the regular expression against which data entered in the indicated subject part field (for example, CN) in the enrollment pages of the Keyfactor Command Management Portal or using an API enrollment operation will be validated.

Use the GET Enrollment Patterns Subject Parts operation to retrieve a list of all the supported subject parts.

ClosedShow regular expression examples.

Error

A string specifying the error message displayed to the user when the subject part referenced in the CSR or entered for a PFX enrollment does not match the given regular expression.

Note:  The error message already includes a leading string with the subject part (for example, Common Name: or Invalid CN provided: depending on the interface used). Your custom message follows this.
CaseSensitive A Boolean that sets the validation for the field to be case-sensitive (True or False). If the subject part does not match the expected case, the value specified by the Error parameter will display. If the CaseSensitive option is set to False, even if the regular expression contains requirements to enforce case, the case requirement will not be enforced.