Adds a fingerprint to an OpenID Connect (OIDC) identity provider (IdP).
Operation description
This topic provides an example on how to add the fingerprint 902ef2deeb3c5b13ea4c3d5193629309e231**** to the OIDC IdP named TestOIDCProvider.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
ram:AddFingerprintToOIDCProvider |
create |
*OIDCProvider
|
|
None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| OIDCProviderName |
string |
No |
The name of the OIDC IdP. |
TestOIDCProvider |
| Fingerprint |
string |
No |
The fingerprint of the HTTPS CA certificate. The fingerprint can contain letters and digits. The fingerprint can be up to 128 characters in length. |
902ef2deeb3c5b13ea4c3d5193629309e231**** |
For more information about common request parameters, see API Reference.
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID. |
4B809BBC-0E78-544A-A91A-648926412E3E |
| OIDCProvider |
object |
The name of the OIDC IdP. |
|
| UpdateDate |
string |
The time when the OIDC IdP was modified. The time is displayed in UTC. |
2021-11-12T08:38:29Z |
| Description |
string |
The description of the OIDC IdP. |
This is a new OIDC Provider. |
| OIDCProviderName |
string |
The name of the OIDC IdP. |
TestOIDCProvider |
| CreateDate |
string |
The time when the OIDC IdP was created. The time is displayed in UTC. |
2021-11-11T06:56:03Z |
| Arn |
string |
The Alibaba Cloud Resource Name (ARN) of the OIDC IdP. |
acs:ram::177242285274****:oidc-provider/OIDCProvider |
| IssuerUrl |
string |
The URL of the issuer. |
https://xxxxxx.example.com |
| Fingerprints |
string |
The fingerprint of the HTTPS certificate. If multiple fingerprints are returned, the fingerprints are separated by commas (,). |
502ef2deeb3c5b13ea4c3d5193629309e231****,902ef2deeb3c5b13ea4c3d5193629309e231**** |
| ClientIds |
string |
The ID of the client. If multiple client IDs are returned, the client IDs are separated by commas (,). |
498469743454717**** |
| GmtCreate |
string |
The timestamp when the OIDC IdP was created. |
1636613763000 |
| GmtModified |
string |
The timestamp when the OIDC IdP was modified. |
1636706309000 |
| IssuanceLimitTime |
integer |
The earliest time when an external IdP can issue an ID token. If the value of the iat field in the ID token is later than the current time, the request is rejected. Unit: hours. Valid values: 1 to 168. |
12 |
Examples
Success response
JSON format
{
"RequestId": "4B809BBC-0E78-544A-A91A-648926412E3E",
"OIDCProvider": {
"UpdateDate": "2021-11-12T08:38:29Z",
"Description": "This is a new OIDC Provider.",
"OIDCProviderName": "TestOIDCProvider",
"CreateDate": "2021-11-11T06:56:03Z",
"Arn": "acs:ram::177242285274****:oidc-provider/OIDCProvider",
"IssuerUrl": "https://xxxxxx.example.com",
"Fingerprints": "502ef2deeb3c5b13ea4c3d5193629309e231****,902ef2deeb3c5b13ea4c3d5193629309e231****",
"ClientIds": "498469743454717****",
"GmtCreate": "1636613763000",
"GmtModified": "1636706309000",
"IssuanceLimitTime": 12
}
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.