Membuat Sertifikat Otoritas Sertifikat (CA) subordinat di bawah CA root yang sudah ada.
Deskripsi operasi
This operation issues an intermediate CA certificate from an existing root CA certificate. You can use the intermediate CA certificate to issue client and server certificates.
Before calling this operation, you must call the CreateRootCACertificate operation to create a root CA certificate.
QPS limit
The queries per second (QPS) limit for this operation is 10 calls per user. Calls that exceed this limit are throttled. This may affect your business. Plan your calls accordingly.
Coba sekarang
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-cert:CreateSubCACertificate |
create |
*全部资源
|
None | None |
Parameter permintaan
|
Parameter |
Type |
Required |
Description |
Example |
| ParentIdentifier |
string |
No |
Pengidentifikasi unik Sertifikat CA root. Catatan
Panggil operasi DescribeCACertificateList untuk mendapatkan pengidentifikasi unik semua Sertifikat CA. |
1a83bcbb89e562885e40aa0108f5**** |
| CommonName |
string |
Yes |
Nama umum organisasi Anda. Nama dapat berisi karakter Cina dan huruf Inggris. |
Aliyun |
| OrganizationUnit |
string |
Yes |
Nama departemen dalam organisasi Anda. Nama dapat berisi karakter Cina dan huruf Inggris. |
Security |
| Organization |
string |
Yes |
Nama organisasi Anda, seperti nama perusahaan. Nama dapat berisi karakter Cina dan huruf Inggris. |
Alibaba |
| Locality |
string |
Yes |
Nama kota tempat organisasi Anda berada. Nama dapat berisi karakter Cina dan huruf Inggris. |
Hangzhou |
| State |
string |
Yes |
Nama provinsi atau negara bagian tempat organisasi berada. Karakter Cina dan huruf Inggris didukung.. |
Zhejiang |
| CountryCode |
string |
No |
Kode negara atau wilayah dua atau tiga huruf dalam format huruf kapital. Misalnya, CN menunjukkan Cina dan US menunjukkan Amerika Serikat. Untuk informasi lebih lanjut, lihat bagian Kode negara di Kelola informasi perusahaan. |
CN |
| Algorithm |
string |
Yes |
Algoritma kunci untuk Sertifikat CA perantara. Algoritma dalam format
Algoritma enkripsi Sertifikat CA perantara harus sama dengan Sertifikat CA root, tetapi panjang kunci dapat berbeda. Misalnya, jika Sertifikat CA root menggunakan algoritma RSA_2048, Sertifikat CA perantara harus menggunakan RSA_1024, RSA_2048, atau RSA_4096. Catatan
Panggil operasi DescribeCACertificate untuk mendapatkan algoritma kunci Sertifikat CA root. |
RSA_2048 |
| Years |
integer |
Yes |
Periode validitas Sertifikat CA perantara, dalam tahun. Nilai valid: 5 hingga 10. Atur parameter ini ke nilai dari 5 hingga 10. Catatan
Periode validitas Sertifikat CA perantara tidak boleh melebihi periode validitas Sertifikat CA root. Panggil operasi DescribeCACertificate untuk mendapatkan periode validitas Sertifikat CA root. |
5 |
| PathLenConstraint |
integer |
No |
Batasan panjang jalur sertifikat. Nilai default adalah 0. |
0 |
| ExtendedKeyUsages |
array |
No |
Penggunaan kunci yang diperluas. |
|
|
string |
No |
The extended key usage. Valid values:
Valid values:
|
serverAuth |
|
| EnableCrl |
boolean |
No |
Apakah akan mengaktifkan fitur daftar pencabutan sertifikat (CRL).
Valid values:
|
true |
| CrlDay |
integer |
No |
Periode validitas CRL, dalam hari. Nilai valid: 1 hingga 365. |
30 |
| Tags |
array<object> |
No |
Daftar tag. |
|
|
object |
No |
A list of tags. |
||
| Key |
string |
No |
The tag key. |
testKey |
| Value |
string |
No |
The tag value. |
test |
| ResourceGroupId |
string |
No |
ID kelompok sumber daya. |
rg-ae****vty |
| ClientToken |
string |
No |
Token yang dihasilkan klien yang digunakan untuk memastikan idempotensi permintaan. Token harus unik untuk setiap permintaan. Token dapat berisi hingga 64 karakter ASCII. |
XXX |
| CertMaxTime |
integer |
No |
签发证书的最长时间由 CA 的 certMaxTime 指定。 |
30 |
Elemen respons
|
Element |
Type |
Description |
Example |
|
object |
The response object. |
||
| RequestId |
string |
The ID of the request. |
15C66C7B-671A-4297-9187-2C4477247A74 |
| Identifier |
string |
The unique identifier of the intermediate CA certificate. |
160ae6bb538d538c70c01f81dcf2**** |
| Certificate |
string |
The certificate returned by this call, in PEM format. |
-----BEGIN CERTIFICATE-----\n......\n-----END CERTIFICATE----- |
| CertificateChain |
string |
The CA certificate chain of the certificate that is returned by the call. |
-----BEGIN CERTIFICATE-----\n......\n-----END CERTIFICATE-----\n-----BEGIN CERTIFICATE-----\n......\n-----END CERTIFICATE-----\n |
-
serverAuth: Autentikasi server
-
clientAuth: Autentikasi klien
-
codeSigning: Penandatanganan kode
-
emailProtection: Perlindungan email
-
timeStamping: Penandaan waktu
-
OCSPSigning: Penandatanganan OCSP
-
OID penggunaan kunci yang diperluas lainnya.
Contoh
Respons sukses
JSONformat
{
"RequestId": "15C66C7B-671A-4297-9187-2C4477247A74",
"Identifier": "160ae6bb538d538c70c01f81dcf2****",
"Certificate": "-----BEGIN CERTIFICATE-----\\n......\\n-----END CERTIFICATE-----",
"CertificateChain": "-----BEGIN CERTIFICATE-----\\n......\\n-----END CERTIFICATE-----\\n-----BEGIN CERTIFICATE-----\\n......\\n-----END CERTIFICATE-----\\n"
}
Kode kesalahan
Lihat Error Codes untuk daftar lengkap.
Catatan rilis
Lihat Release Notes untuk daftar lengkap.