Before you can use mTLS APIs, you must complete the following: 

  • Enable mTLS on the Cryptographic Security Platform Vault for Secrets.

  • Create and download the client certificate and the CA certificate. For more information, see Creating a client certificate.

    When you download the client certificate from the webGUI, the downloaded zip bundle contains both the client certificate and the CA certificate. For more information, see Downloading a client certificate.

    Note: If you want to use API commands, use the CreateClientCert API to create the certificate and the GetClientCertificateBundleInText API to download both the client certificate and the CA certificate.

Important: All APIs in the Cryptographic Security Platform Vault for Secrets can be used with mTLS except for login APIs. These include logging in or logging out with local authentication, AD, or OIDC, or renewing the authentication token.