The "Get CA Capabilities" endpoint returns the following values for each certificate management capability.

CertificateAction

List the lifecycle management actions supported by the issued certificates.

Action

SM

ECS

MS ADCS

HoldAction

(tick)


(tick)

UnholdAction

(tick)


(tick)

RevokeAction

(tick)

(tick)

(tick)

DeactivateAction


(tick)


RenewAction


(tick)


ReissueAction


(tick)


RevokeAction

List the revocation reasons supported by the certificates.

Reason

SM

ECS

MS ADCS

unspecified

(tick)

(tick)

(tick)

keyCompromise

(tick)

(tick)

(tick)

cACompromise



(tick)

affiliationChanged

(tick)

(tick)

(tick)

superseded

(tick)

(tick)

(tick)

cessationOfOperation

(tick)

(tick)

(tick)

certificateHold

(tick)


(tick)

removeFromCRL

(Unholds a certificate previously revoked with the certificateHold reason)




privilegeWithdrawn




cACompromise




CertificateEvents

States if the CA supports the Certificates Events API.

CA

Returned value

Entrust Security Manager below 8.3.30

False

Entrust Security Manager 8.3.30 and above

True

ECS

True

Microsoft ADCS

True

Recover

States if the CA can recover certificates by DN.

CA

Returned value

Entrust Security Manager

Recover all certificates, recover the latest certificates.

ECS

True

Microsoft ADCS

Recover all certificates, recover the latest certificates.

SubjectDNAction

List the certificate actions by the subject's DN.

Actions

SM

ECS

MS ADCS

HoldAction

(tick)


(tick)

UnholdAction

(tick)


(tick)

RevokeAction

(tick)


(tick)

DeactivateAction

(tick)



ReactivateAction

(tick)