By default, all APIs in the Cryptographic Security Platform Vault for Cryptographic APIs use the following API endpoint.
https://<VAULT_IP_or_FQDN>/token/1.0/key/API_COMMANDWhen you enable mTLS, you will need to change your API endpoint to
https://<VAULT_IP_or_FQDN>/mtls/crypto/1.0/key/API_COMMAND If you disable mTLS, switch the endpoint back to:
https://<VAULT_IP_or_FQDN>/token/1.0/key/API_COMMANDBefore you can use the mTLS APIs:
mTLS must be enabled for the CSP Vault for Cryptographic APIs.
You must have a CA certificate. This can be downloaded from the CSP Vault Management appliance, or it can be downloaded using the Get Client Certificate along with CA certificate API
You must have a Client certificate. You can create this using the Create Client Cert API and download it using the Get Client Certificate along with CA certificate API.
See below for examples.
Sample curl command
See below for a sample curl command to use mTLS APIs.
[root@user1-10.1.10.10 mtls]# curl -s --cert ./client_cert.pem --key ./client_key.pem --cacert ./ca_cert.pem -X POST -H "Content-Type: application/json" -d '{"name": "rsa-2048", "cipher": "RSA-2048"}' https://10.1.10.10/mtls/crypto/1.0/key/Sample Python script
See below for a sample Python script to use mTLS APIs.
import requestsimport json# Define the URL of the API endpointurl = "https://10.1.228.140/mtls/crypto/1.0/key/"payload = {"name": "aes-128", "cipher": "AES-128"}# Path to the client certificate and key filesclient_cert = ( "./client_cert.pem", "./client_key.pem",) # Client key is present in the client_cert.pem if external CSR is not used. If external CSR is used then it has to specified additionally.# Path to the CA certificate fileca_cert = "./ca_cert.pem"# Make the API request with mTLSresponse = requests.post( url, cert=(client_cert), data=json.dumps(payload), verify=ca_cert)# Print the responseprint(response.status_code)print(response.text.encode("utf-8").decode("unicode_escape"))mTLS API Examples
See below for creating an AES key
https://<VAULT_IP_or_FQDN>/mtls/crypto/1.0/CreateKey{ "cipher": "AES-256", "description": "Signing key", "keyset_guid": "b4e6b2a8-a693-40ab-9cb3-5f34cbf2227e", "name": "key1"}See below to create a tokenization policy using the GUID of an AES key that you created.
Post: https://<VAULT_IP_or_FQDN>/mtls/crypto/1.0/CreateTokenPolicy/{ "charset": "Alphanumeric", "charsetOption": [ 1, 4, 8 ], "description": "Tokenization Policy for SSN", "isNew": true, "keyGuid": "52bbf639-babf-47a6-a54b-bb92ad6954ad", "name": "Tokenization-Policy-1", "preservedPrefixLength": 2, "preservedSuffixLength": 2}See below to encrypt an AES key.
https://<VAULT_IP_or_FQDN>/mtls/crypto/1.0/encrypt{ "aad": "VEVTVA==", "data": "TWFyeSBoYWQgYSBsaXR0bGUgbGFtYg==", "iv": "MDEyMzQ1Njc4OTAxMjM0NQ==", "keyGuid": "9f726ba4-3b88-48d7-8a02-df2e8472d4dc", "mode": "AES_ECB"}