All Products
Search
Document Center

ApsaraMQ for MQTT:RegisterCaCertificate

Last Updated:May 29, 2026

RegisterCaCertificate

Operation description

  • Only ApsaraMQ for MQTT Enterprise Platinum Edition instances support this operation.

  • You can call this operation up to 500 times per second per Alibaba Cloud account. If you want to increase the limit, join the DingTalk group (ID: 35228338) to contact ApsaraMQ for MQTT technical support.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

mq:RegisterCa

create

*Instance

acs:mq:{#regionId}:{#accountId}:{#InstanceId}

None
  • mq:MqttInstanceAccess

Request parameters

Parameter

Type

Required

Description

Example

MqttInstanceId

string

Yes

The ID of the ApsaraMQ for MQTT instance to which you want to bind the CA certificate.

post-cn-7mz2d******

CaName

string

Yes

The name of the CA certificate that you want to register with an ApsaraMQ for MQTT broker.

mqtt_ca

CaContent

string

Yes

The content of the CA certificate that you want to register with an ApsaraMQ for MQTT broker.

Note

In the example, \n indicates a line feed.

-----BEGIN CERTIFICATE-----\nMIIDuzCCAqdGVzdC5jbi1xaW5n******\n-----END CERTIFICATE-----

VerificationContent

string

Yes

The content of the validation certificate issued by the CA certificate that you want to register with an ApsaraMQ for MQTT broker. The validation certificate must be used together with the registration code of the CA certificate to verify the private key of the CA certificate.

Note

In the example, \n indicates a line feed.

-----BEGIN CERTIFICATE-----\nMIID/DCCAu+Y5sRMpp9tnd+4s******\n-----END CERTIFICATE-----

Response elements

Element

Type

Description

Example

object

Schema of Response

RequestId

string

The request ID.

020F6A43-19E6-4B6E-B846-44EB31DF****

Sn

string

The serial number of the registered CA certificate. The serial number is the unique identifier of a CA certificate.

007269004887******

Examples

Success response

JSON format

{
  "RequestId": "020F6A43-19E6-4B6E-B846-44EB31DF****",
  "Sn": "007269004887******"
}

Error codes

HTTP status code

Error code

Error message

Description

400 InstancePermissionCheckFailed An error occurred while validating the permissions of the instance. Please verify the account that created the instance and its permissions settings.
400 MqttOwnerCheckError Failed to validate the instance permission
400 RegisterCodeError Register code error in verification certificate.
400 ParameterFieldCheckFailed Failed to validate the parameters. The parameters may be missing or invalid.
400 MqttApplyCluster4InstanceFailed the instance can not find cluster. The instance failed to obtain cluster information.
400 SystemError system error. System error, please try again
400 MqttInstanceNotFound Specified instance is not found
401 RegisterCodeUsed Register code has been used.
401 GetCaNumError Failed to get ca num. Try again later.
401 CaNumExceed CA certificate num exceed
401 CertificateContentError Certificate content error, please check ca/verification certificate content. BasicConstraints extension should be set to true in CA certificate
401 SnNotUnique Sn is not unique in gloabal
403 PermissionCheckFailed Failed to verify API permissions. ram permission check failed

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.