Origin certificates
A zone's origin certificate has an endpoint of its own, like its signing key, so listing zones never returns it: one call reads it, one creates or reissues it and is the only answer that carries its private key, and one revokes it. The zone object says only whether there is one, as ORIGIN_CERTIFICATE (1 or 0). What an origin certificate is and how to install one: Origin certificates.
Read the certificate#
https://api.cachegenie.com/v1/cdn/{ZONE_ID}/origin-certificatecurl https://api.cachegenie.com/v1/cdn/AB12CD34E/origin-certificate \
-H "Authorization: Bearer YOUR_API_KEY"{
"CODE": 200,
"MESSAGE": "Origin Certificate Returned.",
"DATA": {
"CERTIFICATE":
"-----BEGIN CERTIFICATE-----\nMIIDDzCCAfegAwIBAgIIQnB5...",
"FINGERPRINT":
"ad95d920ed8534d333cfefd23fb6368fa5bb2c3745ac191dbc2b06804dc3c88b",
"CREATED": 1790395200,
"EXPIRES": 253402262400
}
}CERTIFICATEStringthe certificate, PEM. The private key is never returned here.FINGERPRINTStringthe SHA-256 of the whole certificate, 64 lower-case hexadecimal characters, which is what our servers compare.CREATEDIntegerwhen it was made, Unix seconds.EXPIRESIntegerwhen it stops being valid, Unix seconds: 31 December 9999, the date the certificate standard sets aside for one that does not expire.
A zone with none answers 404 This zone has no origin certificate. Create one with POST.
Create or reissue#
https://api.cachegenie.com/v1/cdn/{ZONE_ID}/origin-certificateMakes a new certificate and key and returns both, with MESSAGE Origin Certificate Created., or Origin Certificate Reissued. when the zone had one, which our servers then stop trusting within a few seconds. DATA is the object above with PRIVATE_KEY (String, PEM) beside the certificate. This is the only answer that carries the key, and it is not kept anywhere, so save it from this answer.
- 400
An origin certificate needs an https:// ORIGIN_URL, and a private S3 bucket origin does not use one. - 409
The zone's origin certificate changed while this request was made, so nothing was created. Retry. - 500
Unable to create an origin certificate - Internal Server Error, please try again., or a message saying the certificate could not be saved: read it with GET, and reissue it if one is there, because its key was not returned.
Revoke#
https://api.cachegenie.com/v1/cdn/{ZONE_ID}/origin-certificateOur servers stop trusting the certificate within a few seconds, and it is removed from the zone. The answer is Origin Certificate Revoked. with an empty DATA. A zone with none answers 404 This zone has no origin certificate.; one whose certificate changed during the call answers 409.
The zone's origin#
A zone with an origin certificate keeps an https:// ORIGIN_URL. Setting an http:// one through Zones answers 400 ORIGIN_URL has to be https:// while the zone has an origin certificate. Revoke it first with DELETE /v1/cdn/{ZONE_ID}/origin-certificate.