Create internal CA certificate¶
POST/
Email Management API · SMIME
Create an internal CA certificate with specified organization details. This CA certificate is used to sign certificates created for internal users. If no S/MIME configuration exists, a disabled configuration is created automatically. Creating the CA does not enable S/MIME.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
Request body¶
Content type: application/json
Request body fields
organizationNamestringrequiredOrganization name (O) to be included in Distinguished Name (DN) structure of the certificate subject.
Must be 3–128 characters long.
Must be 3–128 characters long.
organizationUnitstringOrganization Unit (OU) to be included in Distinguished Name (DN) structure of the certificate subject.
Must be 3–64 characters long.
Must be 3–64 characters long.
localitystringrequiredLocality (L) to be included in Distinguished Name (DN) structure of the certificate subject.
Must be 1–64 characters long.
Must be 1–64 characters long.
countrystringrequiredTwo-letter ISO 3166-1 country code (C) to be included in Distinguished Name (DN) structure of the certificate subject.
Must match the pattern
Must match the pattern
^[A-Z]{2}$. Must be exactly 2 characters long.emailstring (email)requiredEmail address of the user.
Must be 3–255 characters long.
Must be 3–255 characters long.
certExpiryDatestring (date)Certificate expiry date in YYYY-MM-DD (ISO 8601) format. Default: 20 years from the current date. Earliest allowed date - Tomorrow. Latest allowed date - 20 years from today. Provide either certExpiryDate or certValidityPeriod. If both are provided, the API will use whichever results in the shorter validity period.
Must match the pattern
Must match the pattern
^\d{4}-\d{2}-\d{2}$. Must be at most 10 characters long.certValidityPeriodintegerThe certificate validity duration in years, starting from the current date. Default: 20 years, minimum: 1 year, maximum: 20 years.
Must be ≥ 1 and ≤ 20.
Must be ≥ 1 and ≤ 20.
Request samples¶
curl -X POST "https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
\"organizationName\": \"Sophos Limited\",
\"organizationUnit\": \"Engineering\",
\"locality\": \"Abingdon\",
\"country\": \"GB\",
\"email\": \"john.doe@sophos.com\",
\"certExpiryDate\": \"2028-12-31\",
\"certValidityPeriod\": 3
}"
import requests
response = requests.post(
"https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
json={ 'organizationName': 'Sophos Limited',
'organizationUnit': 'Engineering',
'locality': 'Abingdon',
'country': 'GB',
'email': 'john.doe@sophos.com',
'certExpiryDate': '2028-12-31',
'certValidityPeriod': 3},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
"Content-Type" = "application/json"
}
$body = '{
"organizationName": "Sophos Limited",
"organizationUnit": "Engineering",
"locality": "Abingdon",
"country": "GB",
"email": "john.doe@sophos.com",
"certExpiryDate": "2028-12-31",
"certValidityPeriod": 3
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal" -Headers $headers -Body $body -ContentType "application/json"
package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal", strings.NewReader(`{
"organizationName": "Sophos Limited",
"organizationUnit": "Engineering",
"locality": "Abingdon",
"country": "GB",
"email": "john.doe@sophos.com",
"certExpiryDate": "2028-12-31",
"certValidityPeriod": 3
}`))
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
req.Header.Set("Content-Type", "application/json")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal", {
method: "POST",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
body: JSON.stringify({
"organizationName": "Sophos Limited",
"organizationUnit": "Engineering",
"locality": "Abingdon",
"country": "GB",
"email": "john.doe@sophos.com",
"certExpiryDate": "2028-12-31",
"certValidityPeriod": 3
}),
});
const data = await response.json();
console.log(data);
Responses¶
201 — Internal CA certificate created successfully.¶
Response fields
fingerprintstringrequiredSHA-256 fingerprint of the certificate.
Must match the pattern
Must match the pattern
^[a-fA-F0-9]{64}$. Must be exactly 64 characters long.certificateDetailsobjectrequiredDetailed information about a CA certificate.
Show child attributesHide child attributes
subjectstringCertificate subject distinguished name.
Must be at most 255 characters long.
Must be at most 255 characters long.
commonNamestringCertificate common name (CN).
Must be at most 255 characters long.
Must be at most 255 characters long.
issuerstringrequiredCertificate issuer distinguished name.
Must be at most 255 characters long.
Must be at most 255 characters long.
validFromstring (date-time)requiredCertificate validity start date.
expiresAtstring (date-time)requiredCertificate validity end date.
originstringrequiredIndicates how the certificate was obtained.
Must be one of:
Must be one of:
created, uploaded, extracted, unknown.Errors¶
| Status | Meaning |
|---|---|
400 | Invalid request. |
401 | Authentication required. |
403 | Authorization required. |
409 | Conflict. An internal CA certificate already exists. |
500 | Internal server error. |
503 | Server Unavailable. |
All error responses share the same shape — see the error response object.
Response examples¶
201¶
{
"fingerprint": "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2",
"certificateDetails": {
"subject": "C=UK,O=Sophos Limited,CN=Sophos Intermediate CA - A",
"commonName": "Sophos Intermediate CA - A",
"issuer": "C=UK,O=Sophos Limited,CN=Sophos Root CA",
"validFrom": "2024-12-31T14:25:09Z",
"expiresAt": "2029-12-31T18:30:12Z",
"origin": "created"
}
}
See the guide for a narrative walkthrough of this API.