Versions Compared


  • This line was added.
  • This line was removed.
  • Formatting was changed.


MethodEndpointParameterReturned values

NameIs required?Transfer methodDescriptionNameAlways returned?Transfer methodDescription


CA nameYesPath parameterName of Certificate Authority which should sign sent CSR. Must match CertService's CMPv2 servers configuration.Error messageNo, only if error occurred on server sideBody (JSON)Verbose information what wrong happened on server side.
Base64 encoded CSR (Certificate Signing Request) in PEM formatYesHeaderCertificate Signing Request for given componentCertificate chainNo, only in success case.Body (JSON)Base64 encoded (question) signed certificate with whole certificate chain (intermediate CA certificates) in PEM format. Signed certificate should be returned first and then all intermediate certificates in following order: singer of previous certificate till certificate which is signed by root CA. All certificates are in PEM format.
Base64 encoded private key in PEM formatYesHeaderPrivate key. Needed to create proof of possession (PoP)Trusted certificatesNo, only in success case.Body (JSON)Base64 encoded (question) list of trusted certificates in PEM format. In other words list of root CAs which should be treated as trust anchors. Must contain root CA which was used to sign certificate and may contain other root CAs. Order doesn't matter. All certificates are in PEM format. 


HTTP codeDescription
200 (OK)Everything is ok. Certificate chain and trusted certificates returned
400 (Bad Request)Incorrect/missing CSR and/or private key
401 (Unauthorized)Missing client certificate or presented certificate is not trusted
404 (Not found)Invalid CA name in REST API call or wrong endpoint called
500 (Internal Server Error)In case of exception on server side.


View file
Swagger will be added here (warning)

CMPv2 server properties

CertService contains configuration of CMPv2 servers. To enroll certificate at least one CMPv2 server has to be configured. CMPv2 servers configuration is read during CertService startup and to take runtime changes into account CertService's refresh configuration endpoint has to be called.


Relevant values in Initialization Request (IR) message sent to CMPv2 server:



Information Included

PKIHeaderContains information common to many PKI messages.



ProtectionAlgorithm (used for PkiProtection below)

PKIBodyContains message-specific information ie. initialization request message

CertificateRequestMessage, which includes:




PKIProtectionContains bits that protect PKImessage (Specifically the iak/rv)

Return values from CMPv2 client

Following table represents return values from CMPv2 client.

Output valueOutput typeDescription
certificateChainList <>Enrolled certificate with full certificate chain (all certificates of intermediate CAs), without root CA
trustedCertsList <>All trusted certificates returned from CMPv2 server, including root CA

Test code for running cmpv2 client against EJBCA server through unit test
