Skip to content

Update S/MIME config

PATCH/smime/config

Email Management API · SMIME

Update S/MIME configuration. Setting smimeEnabled to true requires an internal CA certificate to already exist for the tenant.

Parameters

Name In Type Required Description
X-Tenant-ID header string (uuid) Yes Tenant ID.

Request body

Content type: application/json

Request body fields

smimeEnabledboolean
Whether S/MIME is enabled for the tenant.
extractCertificateboolean
Whether to extract certificates from incoming messages.
certExpiryNotificationEmailAddressesarray of string (email)
Target email addresses to which certificate expiry notification emails are sent. Set to null or an empty array to clear all notification addresses. Email addresses are deduplicated.
Must contain at most 5 items. Each item must be 3–255 characters long.

Request samples

curl -X PATCH "https://api-<data-region>.central.sophos.com/email/v1/smime/config" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
  \"smimeEnabled\": true,
  \"extractCertificate\": true,
  \"certExpiryNotificationEmailAddresses\": [
    \"john.doe@sophos.com\"
  ]
}"

import requests

response = requests.patch(
    "https://api-<data-region>.central.sophos.com/email/v1/smime/config",
    headers={
        "Authorization": "Bearer <access-token>",
        "X-Tenant-ID": "<tenant-id>",
        "Content-Type": "application/json",
    },
    json={   'smimeEnabled': True,
    'extractCertificate': True,
    'certExpiryNotificationEmailAddresses': ['john.doe@sophos.com']},
)
print(response.json())

$headers = @{
    "Authorization" = "Bearer <access-token>"
    "X-Tenant-ID" = "<tenant-id>"
    "Content-Type" = "application/json"
}
$body = '{
  "smimeEnabled": true,
  "extractCertificate": true,
  "certExpiryNotificationEmailAddresses": [
    "john.doe@sophos.com"
  ]
}'
Invoke-RestMethod -Method PATCH -Uri "https://api-<data-region>.central.sophos.com/email/v1/smime/config" -Headers $headers -Body $body -ContentType "application/json"

package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    req, err := http.NewRequest("PATCH", "https://api-<data-region>.central.sophos.com/email/v1/smime/config", strings.NewReader(`{
  "smimeEnabled": true,
  "extractCertificate": true,
  "certExpiryNotificationEmailAddresses": [
    "john.doe@sophos.com"
  ]
}`))
    if err != nil {
        panic(err)
    }
    req.Header.Set("Authorization", "Bearer <access-token>")
    req.Header.Set("X-Tenant-ID", "<tenant-id>")
    req.Header.Set("Content-Type", "application/json")

    resp, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer resp.Body.Close()

    body, _ := io.ReadAll(resp.Body)
    fmt.Println(string(body))
}

const response = await fetch("https://api-<data-region>.central.sophos.com/email/v1/smime/config", {
  method: "PATCH",
  headers: {
    "Authorization": "Bearer <access-token>",
    "X-Tenant-ID": "<tenant-id>",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
  "smimeEnabled": true,
  "extractCertificate": true,
  "certExpiryNotificationEmailAddresses": [
    "john.doe@sophos.com"
  ]
}),
});
const data = await response.json();
console.log(data);

Responses

200 — Updated S/MIME configuration details.

Response fields

smimeEnabledbooleanrequired
Whether S/MIME is enabled for the tenant.
extractCertificatebooleanrequired
Whether to extract certificates from incoming messages.
certExpiryNotificationEmailAddressesarray of string (email)required
Target email addresses to which certificate expiry notification emails are sent.
Must contain at most 5 items.
deleteTokenstringrequired
Token required for the DELETE request to remove the S/MIME configuration (use as the path parameter in DELETE /config/{deleteToken}).
Must be exactly 8 characters long.

Errors

Status Meaning
400 Invalid request.
401 Authentication required.
403 Authorization required.
404 Resource not found.
409 The requested state is invalid. This can happen if there's an attempt to enable S/MIME before an internal CA certificate is configured, or if concurrent update changed the tenant state.
500 Internal server error.
503 Server Unavailable.

All error responses share the same shape — see the error response object.

Response examples

200

{
  "smimeEnabled": true,
  "extractCertificate": true,
  "certExpiryNotificationEmailAddresses": [
    "user_bob@sophos.com"
  ],
  "deleteToken": "a1b2c3d4"
}

See the guide for a narrative walkthrough of this API.