By default, all APIs in the Cryptographic Security Platform Vault for Cryptographic APIs use the following API endpoint. 

https://<VAULT_IP_or_FQDN>/token/1.0/key/API_COMMAND

When you enable mTLS, you will need to change your API endpoint to

https://<VAULT_IP_or_FQDN>/mtls/crypto/1.0/key/API_COMMAND

If you disable mTLS, switch the endpoint back to:

https://<VAULT_IP_or_FQDN>/token/1.0/key/API_COMMAND

Before you can use the mTLS APIs: 

  • mTLS must be enabled for the CSP Vault for Cryptographic APIs.

  • You must have a CA certificate. This can be downloaded from the CSP Vault Management appliance, or it can be downloaded using the Get Client Certificate along with CA certificate API

  • You must have a Client certificate. You can create this using the Create Client Cert API and download it using the Get Client Certificate along with CA certificate API.

See below for examples.

Sample curl command

See below for a sample curl command to use mTLS APIs.

[root@user1-10.1.10.10 mtls]# curl -s --cert ./client_cert.pem --key ./client_key.pem --cacert ./ca_cert.pem -X POST -H "Content-Type: application/json" -d '{"name": "rsa-2048", "cipher": "RSA-2048"}' https://10.1.10.10/mtls/crypto/1.0/key/

Sample Python script

See below for a sample Python script to use mTLS APIs. 

import requests
 
import json
 
# Define the URL of the API endpoint
url = "https://10.1.228.140/mtls/crypto/1.0/key/"
payload = {"name": "aes-128", "cipher": "AES-128"}
 
# Path to the client certificate and key files
client_cert = (
"./client_cert.pem",
"./client_key.pem",
) # Client key is present in the client_cert.pem if external CSR is not used. If external CSR is used then it has to specified additionally.
 
# Path to the CA certificate file
ca_cert = "./ca_cert.pem"
 
# Make the API request with mTLS
response = requests.post(
url, cert=(client_cert), data=json.dumps(payload), verify=ca_cert
)
 
# Print the response
print(response.status_code)
print(response.text.encode("utf-8").decode("unicode_escape"))

mTLS API Examples 

See below for creating an AES key

Post
https://<VAULT_IP_or_FQDN>/mtls/crypto/1.0/CreateKey
Request payload
{
"cipher": "AES-256",
"description": "Signing key",
"keyset_guid": "b4e6b2a8-a693-40ab-9cb3-5f34cbf2227e",
"name": "key1"
}

See below to create a tokenization policy using the GUID of an AES key that you created.

Post
Post: https://<VAULT_IP_or_FQDN>/mtls/crypto/1.0/CreateTokenPolicy/
Request payload
{
"charset": "Alphanumeric",
"charsetOption": [
1,
4,
8
],
"description": "Tokenization Policy for SSN",
"isNew": true,
"keyGuid": "52bbf639-babf-47a6-a54b-bb92ad6954ad",
"name": "Tokenization-Policy-1",
"preservedPrefixLength": 2,
"preservedSuffixLength": 2
}

See below to encrypt an AES key.

https://<VAULT_IP_or_FQDN>/mtls/crypto/1.0/encrypt
Request payload
{
  "aad": "VEVTVA==",
  "data": "TWFyeSBoYWQgYSBsaXR0bGUgbGFtYg==",
  "iv": "MDEyMzQ1Njc4OTAxMjM0NQ==",
  "keyGuid": "9f726ba4-3b88-48d7-8a02-df2e8472d4dc",
  "mode": "AES_ECB"
}