Skip to content

Create internal CA certificate

POST/smime/ca/internal

Email Management API · SMIME

Create an internal CA certificate with specified organization details. This CA certificate is used to sign certificates created for internal users. If no S/MIME configuration exists, a disabled configuration is created automatically. Creating the CA does not enable S/MIME.

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.

Request body

Content type: application/json

Request body fields

organizationNamestringrequired
Organization name (O) to be included in Distinguished Name (DN) structure of the certificate subject.
Must be 3–128 characters long.
organizationUnitstring
Organization Unit (OU) to be included in Distinguished Name (DN) structure of the certificate subject.
Must be 3–64 characters long.
localitystringrequired
Locality (L) to be included in Distinguished Name (DN) structure of the certificate subject.
Must be 1–64 characters long.
countrystringrequired
Two-letter ISO 3166-1 country code (C) to be included in Distinguished Name (DN) structure of the certificate subject.
Must match the pattern ^[A-Z]{2}$. Must be exactly 2 characters long.
emailstring (email)required
Email address of the user.
Must be 3–255 characters long.
certExpiryDatestring (date)
Certificate expiry date in YYYY-MM-DD (ISO 8601) format. Default: 20 years from the current date. Earliest allowed date - Tomorrow. Latest allowed date - 20 years from today. Provide either certExpiryDate or certValidityPeriod. If both are provided, the API will use whichever results in the shorter validity period.
Must match the pattern ^\d{4}-\d{2}-\d{2}$. Must be at most 10 characters long.
certValidityPeriodinteger
The certificate validity duration in years, starting from the current date. Default: 20 years, minimum: 1 year, maximum: 20 years.
Must be ≥ 1 and ≤ 20.

Request samples

curl -X POST "https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"organizationName\": \"Sophos Limited\",
  \"organizationUnit\": \"Engineering\",
  \"locality\": \"Abingdon\",
  \"country\": \"GB\",
  \"email\": \"john.doe@sophos.com\",
  \"certExpiryDate\": \"2028-12-31\",
  \"certValidityPeriod\": 3
}"

import requests

response = requests.post(
    "https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'organizationName': 'Sophos Limited',
    'organizationUnit': 'Engineering',
    'locality': 'Abingdon',
    'country': 'GB',
    'email': 'john.doe@sophos.com',
    'certExpiryDate': '2028-12-31',
    'certValidityPeriod': 3},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "organizationName": "Sophos Limited",
  "organizationUnit": "Engineering",
  "locality": "Abingdon",
  "country": "GB",
  "email": "john.doe@sophos.com",
  "certExpiryDate": "2028-12-31",
  "certValidityPeriod": 3
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal", strings.NewReader(`{
  "organizationName": "Sophos Limited",
  "organizationUnit": "Engineering",
  "locality": "Abingdon",
  "country": "GB",
  "email": "john.doe@sophos.com",
  "certExpiryDate": "2028-12-31",
  "certValidityPeriod": 3
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal", {
  method: "POST",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "organizationName": "Sophos Limited",
  "organizationUnit": "Engineering",
  "locality": "Abingdon",
  "country": "GB",
  "email": "john.doe@sophos.com",
  "certExpiryDate": "2028-12-31",
  "certValidityPeriod": 3
}),
});
const data = await response.json();
console.log(data);

Responses

201 — Internal CA certificate created successfully.

Response fields

fingerprintstringrequired
SHA-256 fingerprint of the certificate.
Must match the pattern ^[a-fA-F0-9]{64}$. Must be exactly 64 characters long.
certificateDetailsobjectrequired
Detailed information about a CA certificate.
Show child attributesHide child attributes
subjectstring
Certificate subject distinguished name.
Must be at most 255 characters long.
commonNamestring
Certificate common name (CN).
Must be at most 255 characters long.
issuerstringrequired
Certificate issuer distinguished name.
Must be at most 255 characters long.
validFromstring (date-time)required
Certificate validity start date.
expiresAtstring (date-time)required
Certificate validity end date.
originstringrequired
Indicates how the certificate was obtained.
Must be one of: created, uploaded, extracted, unknown.

Errors

Status Meaning
400 Invalid request.
401 Authentication required.
403 Authorization required.
409 Conflict. An internal CA certificate already exists.
500 Internal server error.
503 Server Unavailable.

All error responses share the same shape — see the error response object.

Response examples

201

{
  "fingerprint": "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2",
  "certificateDetails": {
    "subject": "C=UK,O=Sophos Limited,CN=Sophos Intermediate CA - A",
    "commonName": "Sophos Intermediate CA - A",
    "issuer": "C=UK,O=Sophos Limited,CN=Sophos Root CA",
    "validFrom": "2024-12-31T14:25:09Z",
    "expiresAt": "2029-12-31T18:30:12Z",
    "origin": "created"
  }
}

See the guide for a narrative walkthrough of this API.