ResourceDefinition
uris
/redfish/v1/Managers/manager_id/SecurityService/HttpsCert
properties
| 名称 | 类型 | 是否只读 | 取值范围/枚举值 | 说明 |
|---|---|---|---|---|
| @odata.context | string | true | - | SSL证书资源模型的OData描述信息 |
| @odata.id | string | true | - | SSL证书资源节点的访问路径 |
| @odata.type | string | true | - | SSL证书资源类型 |
| Id | string | true | - | SSL证书资源的ID |
| Name | string | true | - | SSL证书资源的名称 |
| X509CertificateInformation { | object | true | - | X.509证书信息 |
| X509CertificateInformation.ServerCert { | object | true | - | SSL证书链中的末端生效证书信息,为此CA证书的主要信息,展示内容和外层信息一致 |
| X509CertificateInformation.ServerCert.Issuer | string | true | - | 中间证书签发者 |
| X509CertificateInformation.ServerCert.KeyUsage | string | true | - | 中间证书密钥用法 |
| X509CertificateInformation.ServerCert.PublicKeyLengthBits | number | true | - | 中间证书公钥长度 |
| X509CertificateInformation.ServerCert.SerialNumber | string | true | - | 中间证书序列号 |
| X509CertificateInformation.ServerCert.SignatureAlgorithm | string | true | - | 中间证书签名算法 |
| X509CertificateInformation.ServerCert.Subject | string | true | - | 中间证书使用者 |
| X509CertificateInformation.ServerCert.ValidNotAfter | string | true | - | 中间证书生效结束日期 |
| X509CertificateInformation.ServerCert.ValidNotBefore | string | true | - | 中间证书生效起始日期 |
| X509CertificateInformation.ServerCert.IsDefaultSSLCert | boolean | true | - | 标志当前服务器证书是否是初始证书说明BMC300 5.01.00.01及以上版本支持,布尔类型 |
| } | ||||
| X509CertificateInformation.IntermediateCert [ { | array | true | - | 中间证书列表 |
| X509CertificateInformation.IntermediateCert[].Subject | string | true | - | 中间证书使用者 |
| X509CertificateInformation.IntermediateCert[].Issuer | string | true | - | 中间证书签发者 |
| X509CertificateInformation.IntermediateCert[].ValidNotBefore | string | true | - | 中间证书生效起始日期 |
| X509CertificateInformation.IntermediateCert[].ValidNotAfter | string | true | - | 中间证书生效结束日期 |
| X509CertificateInformation.IntermediateCert[].SerialNumber | string | true | - | 中间证书序列号 |
| X509CertificateInformation.IntermediateCert[].SignatureAlgorithm | string | true | - | 中间证书签名算法 |
| X509CertificateInformation.IntermediateCert[].KeyUsage | string | true | - | 中间证书密钥用法 |
| X509CertificateInformation.IntermediateCert[].PublicKeyLengthBits | number | true | - | 中间证书公钥长度 |
| } ] | ||||
| X509CertificateInformation.RootCert { | object | true | - | 根证书 |
| X509CertificateInformation.RootCert.Subject | string | true | - | 根证书使用者 |
| X509CertificateInformation.RootCert.Issuer | string | true | - | 根证书签发者 |
| X509CertificateInformation.RootCert.ValidNotBefore | string | true | - | 根证书生效起始日期 |
| X509CertificateInformation.RootCert.ValidNotAfter | string | true | - | 根证书生效结束日期 |
| X509CertificateInformation.RootCert.SerialNumber | string | true | - | 根证书序列号 |
| X509CertificateInformation.RootCert.SignatureAlgorithm | string | true | - | 根证书签名算法 |
| X509CertificateInformation.RootCert.KeyUsage | string | true | - | 根证书密钥用法 |
| X509CertificateInformation.RootCert.PublicKeyLengthBits | number | true | - | 根证书公钥长度 |
| } | ||||
| } | ||||
| AlternativeInitialCertificate { | object | true | - | 备用初始证书信息 |
| AlternativeInitialCertificate.ServerCert { | object | true | - | SSL证书链中的末端生效证书信息,为此CA证书的主要信息,展示内容和外层信息一致 |
| AlternativeInitialCertificate.ServerCert.Issuer | string | true | - | 中间证书签发者 |
| AlternativeInitialCertificate.ServerCert.KeyUsage | string | true | - | 中间证书密钥用法 |
| AlternativeInitialCertificate.ServerCert.PublicKeyLengthBits | number | true | - | 中间证书公钥长度 |
| AlternativeInitialCertificate.ServerCert.SerialNumber | string | true | - | 中间证书序列号 |
| AlternativeInitialCertificate.ServerCert.SignatureAlgorithm | string | true | - | 中间证书签名算法 |
| AlternativeInitialCertificate.ServerCert.Subject | string | true | - | 中间证书使用者 |
| AlternativeInitialCertificate.ServerCert.ValidNotAfter | string | true | - | 中间证书生效结束日期 |
| AlternativeInitialCertificate.ServerCert.ValidNotBefore | string | true | - | 中间证书生效起始日期 |
| } | ||||
| } | ||||
| CertificateSigningRequest | null | true | - | CSR信息说明导入服务器证书后,之前生成的CSR信息清除,此处显示为“null”。 |
| Actions { | object | true | - | SSL证书组密钥导入操作 |
| Actions.#HttpsCert.GenerateCSR { | object | true | - | 生成CSR文件的资源路径 |
| Actions.#HttpsCert.GenerateCSR.@Redfish.ActionInfo | string | true | - | 操作信息查询路径 |
| Actions.#HttpsCert.GenerateCSR.target | string | true | - | 操作路径 |
| } | ||||
| Actions.#HttpsCert.ImportServerCertificate { | object | true | - | 导入服务器证书的资源路径 |
| Actions.#HttpsCert.ImportServerCertificate.@Redfish.ActionInfo | string | true | - | 操作信息查询路径 |
| Actions.#HttpsCert.ImportServerCertificate.target | string | true | - | 操作路径 |
| } | ||||
| Actions.#HttpsCert.ImportCustomCertificate { | object | true | - | 导入自定义证书的资源路径 |
| Actions.#HttpsCert.ImportCustomCertificate.@Redfish.ActionInfo | string | true | - | 操作信息查询路径 |
| Actions.#HttpsCert.ImportCustomCertificate.target | string | true | - | 操作路径 |
| } | ||||
| Actions.#HttpsCert.ExportCSR { | object | true | - | 导出CSR文件 |
| Actions.#HttpsCert.ExportCSR.@Redfish.ActionInfo | string | true | - | 操作信息查询路径 |
| Actions.#HttpsCert.ExportCSR.target | string | true | - | 操作路径 |
| } | ||||
| } |
supported_methods
- GET
- POST
HTTP methods
GET
命令功能
查询 SSL 证书资源信息
命令格式
URL: https://device_ip/redfish/v1/Managers/manager_id/SecurityService/HttpsCert
请求头:
X-Auth-Token: auth_value请求消息体: 无
参数说明
| 参数 | 参数说明 | 取值 |
|---|---|---|
| device_ip | 登录设备的IP地址 | IPv4或IPv6地址 |
| auth_value | 请求消息的鉴权参数 | 可通过/redfish/v1/SessionService/Sessions创建会话时获得 |
使用指南
无
使用实例
请求样例: GET https://device_ip/redfish/v1/Managers/manager_id/SecurityService/HttpsCert
X-Auth-Token: auth_value 请求消息体:无
响应样例:
{
"@odata.context": "/redfish/v1/$metadata#HttpsCert.HttpsCert",
"@odata.id": "/redfish/v1/Managers/1/SecurityService/HttpsCert",
"@odata.type": "#HttpsCert.v1_0_0.HttpsCert",
"Id": "HttpsCert",
"Name": "Https cert info",
"X509CertificateInformation": {
"ServerCert": {
"Subject": "CN=Server, OU=IT, O=xxx, L=ShenZhen, S=GuangDong, C=CN",
"Issuer": "CN=Server, OU=IT, O=xxx, L=ShenZhen, S=GuangDong, C=CN",
"ValidNotBefore": "Jul 25 2014 GMT",
"ValidNotAfter": "Jul 22 2024 GMT",
"SerialNumber": "07 ",
"SignatureAlgorithm": "sha256WithRSAEncryption",
"KeyUsage": "Certificate Signing, CRL Sign",
"PublicKeyLengthBits": 2048,
"IsDefaultSSLCert": true
},
"IntermediateCert": [
{
"Subject": "CN=Intermediate, OU=IT, O=xxx, L=ShenZhen, S=GuangDong, C=CN",
"Issuer": "CN=Root, OU=IT, O=xxx, L=ShenZhen, S=GuangDong, C=CN",
"ValidNotBefore": "Jan 01 2020 GMT",
"ValidNotAfter": "Jan 01 2030 GMT",
"SerialNumber": "01 ",
"SignatureAlgorithm": "sha256WithRSAEncryption",
"KeyUsage": "Certificate Signing, CRL Sign",
"PublicKeyLengthBits": 2048
}
],
"RootCert": {
"Subject": "CN=Root, OU=IT, O=xxx, L=ShenZhen, S=GuangDong, C=CN",
"Issuer": "CN=Root, OU=IT, O=xxx, L=ShenZhen, S=GuangDong, C=CN",
"ValidNotBefore": "Jan 01 2010 GMT",
"ValidNotAfter": "Jan 01 2040 GMT",
"SerialNumber": "00 ",
"SignatureAlgorithm": "sha256WithRSAEncryption",
"KeyUsage": "Certificate Signing, CRL Sign",
"PublicKeyLengthBits": 2048
}
},
"AlternativeInitialCertificate": {
"ServerCert": {
"Subject": "CN=Alternative Server, OU=IT, O=xxx, L=ShenZhen, S=GuangDong, C=CN",
"Issuer": "CN=Alternative Server, OU=IT, O=xxx, L=ShenZhen, S=GuangDong, C=CN",
"ValidNotBefore": "Jul 25 2024 GMT",
"ValidNotAfter": "Jul 22 2034 GMT",
"SerialNumber": "08 ",
"SignatureAlgorithm": "sha256WithRSAEncryption",
"KeyUsage": "Certificate Signing, CRL Sign",
"PublicKeyLengthBits": 2048
}
},
"CertificateSigningRequest": null,
"Actions": {
"#HttpsCert.GenerateCSR": {
"target": "/redfish/v1/Managers/Blade8/SecurityService/HttpsCert/Actions/HttpsCert.GenerateCSR",
"@Redfish.ActionInfo": "/redfish/v1/Managers/Blade8/SecurityService/HttpsCert/GenerateCSRActionInfo"
},
"#HttpsCert.ImportServerCertificate": {
"target": "/redfish/v1/Managers/Blade8/SecurityService/HttpsCert/Actions/HttpsCert.ImportServerCertificate",
"@Redfish.ActionInfo": "/redfish/v1/Managers/Blade8/SecurityService/HttpsCert/ImportServerCertificateActionInfo"
},
"#HttpsCert.ImportCustomCertificate": {
"target": "/redfish/v1/Managers/Blade8/SecurityService/HttpsCert/Actions/HttpsCert.ImportCustomCertificate",
"@Redfish.ActionInfo": "/redfish/v1/Managers/Blade8/SecurityService/HttpsCert/ImportCustomCertificateActionInfo"
},
"#HttpsCert.ExportCSR": {
"target": "/redfish/v1/Managers/Blade8/SecurityService/HttpsCert/Actions/HttpsCert.ExportCSR",
"@Redfish.ActionInfo": "/redfish/v1/Managers/Blade8/SecurityService/HttpsCert/ExportCSRActionInfo"
}
}
}响应码:200
POST (ACTION)
GenerateCSR
命令功能
生成 CSR
命令格式
URL: https://device_ip/redfish/v1/Managers/manager_id/SecurityService/HttpsCert/Actions/HttpsCert.GenerateCSR
请求头:
X-Auth-Token: auth_value
Content-Type: header_type请求消息体:
{
"Country": country,
"CommonName": commonname,
"City": city,
"State": state,
"OrgName": orgname,
"OrgUnit": orgunit
}请求头参数说明
参见 请求头参数说明
请求体参数说明
| 参数 | 参数说明 | 取值 |
|---|---|---|
| country | 使用者所在的国家,为必配参数。 | 支持字母,长度为2个字符。 |
| commonname | 使用者的名称为必配参数。 | 支持字母、数字、连字符、下划线、句点和空格,最大长度64个字符。 |
| city | 使用者所在的城市,非必配参数。 | 支持字母、数字、连字符、下划线、句点和空格,最大长度128个字符。 |
| state | 使用者所在的省份,非必配参数。 | 支持字母、数字、连字符、下划线、句点和空格,最大长度128个字符。 |
| orgname | 使用者所在的公司,非必配参数。 | 支持字母、数字、连字符、下划线、句点和空格,最大长度64个字符。 |
| orgunit | 使用者所在的部门,非必配参数。 | 支持字母、数字、连字符、下划线、句点和空格,最大长度64个字符。 |
使用指南
无
使用实例
请求样例: POST https://device_ip/redfish/v1/Managers/manager_id/SecurityService/HttpsCert/Actions/HttpsCert.GenerateCSR
X-Auth-Token: auth_value Content-Type: header_type 请求消息体:
{
"Country": country,
"CommonName": commonname,
"City": city,
"State": state,
"OrgName": orgname,
"OrgUnit": orgunit
}响应样例:
{
"@odata.context": "/redfish/v1/$metadata#TaskService/Tasks/Members/$entity",
"@odata.type": "#Task.v1_0_2.Task",
"@odata.id": "/redfish/v1/TaskService/Tasks/1",
"Id": "1",
"Name": "csr generation task",
"Description": "",
"TaskState": "Running",
"TaskStatus": "OK",
"StartTime": "2016-07-10T11:31:02+00:00",
"Messages": [],
"PercentComplete": null,
"Oem": {
"Public": {
"TaskPercentage": null
}
}
}响应码:202
POST (ACTION)
ExportCSR
命令功能
导出 CSR
命令格式
URL: https://device_ip/redfish/v1/Managers/manager_id/SecurityService/HttpsCert/Actions/HttpsCert.ExportCSR
请求头:
X-Auth-Token: auth_value
Content-Type: header_type请求消息体:
{
"Type": type_value,
"Content": Content
}请求头参数说明
参见 请求头参数说明
请求体参数说明
| 参数 | 参数说明 | 取值 |
|---|---|---|
| type_value | 导出类型 | ● URI |
| Content | 导出文件路径 | 支持导出到本地路径和远程路径(本地路径必须在tmp目录下) |
使用指南
无
使用实例
请求样例: POST https://device_ip/redfish/v1/Managers/manager_id/SecurityService/HttpsCert/Actions/HttpsCert.ExportCSR
X-Auth-Token: auth_value Content-Type: header_type 请求消息体:
{
"Type": type_value,
"Content": Content
}响应样例:
{
"error": {
"code": "Base.1.0.GeneralError",
"message": "A general error has occurred. See ExtendedInfo for more information.",
"@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_0_0.Message",
"MessageId": "Base.1.0.Success",
"RelatedProperties": [],
"Message": "Successfully Completed Request",
"MessageArgs": [],
"Severity": "OK",
"Resolution": "None"
}
]
}
}响应码:200
POST (ACTION)
ImportServerCertificate
命令功能
导入服务器证书
命令格式
URL: https://device_ip/redfish/v1/Managers/manager_id/SecurityService/HttpsCert/Actions/HttpsCert.ImportServerCertificate
请求头:
X-Auth-Token: auth_value
Content-Type: header_type请求消息体:
{
"Certificate": text_value
}请求头参数说明
参见 请求头参数说明
请求体参数说明
| 参数 | 参数说明 | 取值 |
|---|---|---|
| text_value | 服务器证书文件或证书链文件 | BASE64编码的证书文件的内容 |
使用指南
无
使用实例
请求样例: POST https://device_ip/redfish/v1/Managers/manager_id/SecurityService/HttpsCert/Actions/HttpsCert.ImportServerCertificate
X-Auth-Token: auth_value Content-Type: header_type 请求消息体:
{
"Certificate": text_value
}响应样例:
{
"error": {
"code": "Base.1.0.GeneralError",
"message": "A general error has occurred. See ExtendedInfo for more information.",
"@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_0_0.Message",
"MessageId": "iBMC.1.0.CertImportOK",
"RelatedProperties": [],
"Message": "The certificate has been imported successfully.",
"MessageArgs": [],
"Severity": "OK",
"Resolution": "Restart the iBMC for the certificate to take effect."
}
]
}
}响应码:200
POST (ACTION)
ImportCustomCertificate
命令功能
导入自定义证书
命令格式
URL: https://device_ip/redfish/v1/Managers/manager_id/SecurityService/HttpsCert/Actions/HttpsCert.ImportCustomCertificate
请求头:
X-Auth-Token: auth_value
Content-Type: header_type请求消息体:
{
"Certificate": text_value
}请求头参数说明
参见 请求头参数说明
请求体参数说明
| 参数 | 参数说明 | 取值 |
|---|---|---|
| text_value | 自定义证书文件或自定义证书链文件 | BASE64编码的证书文件内容 |
使用指南
无
使用实例
请求样例: POST https://device_ip/redfish/v1/Managers/manager_id/SecurityService/HttpsCert/Actions/HttpsCert.ImportCustomCertificate
X-Auth-Token: auth_value Content-Type: header_type 请求消息体:
{
"Certificate": text_value
}响应样例:
{
"error": {
"code": "Base.1.0.GeneralError",
"message": "A general error has occurred. See ExtendedInfo for more information.",
"@Message.ExtendedInfo": [
{
"@odata.type": "#Message.v1_0_0.Message",
"MessageId": "iBMC.1.0.CertImportOK",
"RelatedProperties": [],
"Message": "The certificate has been imported successfully.",
"MessageArgs": [],
"Severity": "OK",
"Resolution": "Restart the iBMC for the certificate to take effect."
}
]
}
}响应码:200