Upload internal CA PKCS#12¶
POST/
Email Management API · SMIME
Upload a Base64-encoded PKCS#12 certificate-key bundle for the internal CA. This key is used to sign internal user certificates. If no S/MIME configuration exists, a disabled configuration is created automatically. Uploading the CA does not enable S/MIME. There can be only one internal CA certificate.
Parameters¶
| Name | In | Type | Required | Description |
|---|---|---|---|---|
X-Tenant-ID | header | string (uuid) | Yes | Tenant ID. |
Request body¶
Content type: application/json
Request body fields
passwordstring (password)requiredPassword to decrypt the certificate-key bundle file in PKCS12 format.
Must be 3–50 characters long.
Must be 3–50 characters long.
pkcs12stringrequiredPKCS#12 format certificate-key bundle file content after Base64 encoding.
Must be 1200–24000 characters long.
Must be 1200–24000 characters long.
Request samples¶
curl -X POST "https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal/certificate" -H "Authorization: Bearer <access-token>" -H "X-Tenant-ID: <tenant-id>" -H "Content-Type: application/json" -d "{
\"password\": \"SecurePassword123\",
\"pkcs12\": \"string\"
}"
import requests
response = requests.post(
"https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal/certificate",
headers={
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
json={'password': 'SecurePassword123', 'pkcs12': 'string'},
)
print(response.json())
$headers = @{
"Authorization" = "Bearer <access-token>"
"X-Tenant-ID" = "<tenant-id>"
"Content-Type" = "application/json"
}
$body = '{
"password": "SecurePassword123",
"pkcs12": "string"
}'
Invoke-RestMethod -Method POST -Uri "https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal/certificate" -Headers $headers -Body $body -ContentType "application/json"
package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
req, err := http.NewRequest("POST", "https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal/certificate", strings.NewReader(`{
"password": "SecurePassword123",
"pkcs12": "string"
}`))
if err != nil {
panic(err)
}
req.Header.Set("Authorization", "Bearer <access-token>")
req.Header.Set("X-Tenant-ID", "<tenant-id>")
req.Header.Set("Content-Type", "application/json")
resp, err := http.DefaultClient.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
body, _ := io.ReadAll(resp.Body)
fmt.Println(string(body))
}
const response = await fetch("https://api-<data-region>.central.sophos.com/email/v1/smime/ca/internal/certificate", {
method: "POST",
headers: {
"Authorization": "Bearer <access-token>",
"X-Tenant-ID": "<tenant-id>",
"Content-Type": "application/json",
},
body: JSON.stringify({
"password": "SecurePassword123",
"pkcs12": "string"
}),
});
const data = await response.json();
console.log(data);
Responses¶
201 — Internal CA certificate uploaded successfully.¶
Response fields
fingerprintstringrequiredSHA-256 fingerprint of the certificate.
Must match the pattern
Must match the pattern
^[a-fA-F0-9]{64}$. Must be exactly 64 characters long.certificateDetailsobjectrequiredDetailed information about a CA certificate.
Show child attributesHide child attributes
subjectstringCertificate subject distinguished name.
Must be at most 255 characters long.
Must be at most 255 characters long.
commonNamestringCertificate common name (CN).
Must be at most 255 characters long.
Must be at most 255 characters long.
issuerstringrequiredCertificate issuer distinguished name.
Must be at most 255 characters long.
Must be at most 255 characters long.
validFromstring (date-time)requiredCertificate validity start date.
expiresAtstring (date-time)requiredCertificate validity end date.
originstringrequiredIndicates how the certificate was obtained.
Must be one of:
Must be one of:
created, uploaded, extracted, unknown.Errors¶
| Status | Meaning |
|---|---|
400 | Invalid request. |
401 | Authentication required. |
403 | Authorization required. |
409 | One internal CA certificate is already present. |
500 | Internal server error. |
503 | Server Unavailable. |
All error responses share the same shape — see the error response object.
Response examples¶
201¶
{
"fingerprint": "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2",
"certificateDetails": {
"subject": "C=UK,O=Sophos Limited,CN=Sophos Intermediate CA - A",
"commonName": "Sophos Intermediate CA - A",
"issuer": "C=UK,O=Sophos Limited,CN=Sophos Root CA",
"validFrom": "2024-12-31T14:25:09Z",
"expiresAt": "2029-12-31T18:30:12Z",
"origin": "created"
}
}
See the guide for a narrative walkthrough of this API.