# Azion CLI digital-certificate

The Azion CLI `digital-certificate` commands create, list, describe, update, and delete the [certificates](/en/documentation/platform/workloads/certificate-manager/certificates/) that Certificate Manager stores for TLS. A certificate is a server certificate you upload with its private key or request from Let's Encrypt, or a Trusted CA certificate that verifies client certificates. These commands store the certificate and do not bind it to a workload. The options every command accepts, such as `--format`, `--out`, and `-y`, are on [Global options](/en/documentation/devtools/cli/globals/).

---

## Create

`azion create digital-certificate` uploads a certificate from PEM files, or requests one from a certificate authority when you pass `--authority`:

```bash
azion create digital-certificate [flags]
```

| Flag                  | Short | Type   | Default | Description                                                                                                                                                                                  |
| --------------------- | ----- | ------ | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--alternative-names` | —     | string | —       | Comma-separated list of Subject Alternative Names (SANs) for the requested certificate.                                                                                                      |
| `--authority`         | —     | string | —       | Certificate authority that issues the certificate, such as `lets_encrypt`. With it, the command requests the certificate instead of uploading one.                                           |
| `--certificate`       | —     | string | —       | Path to the certificate file, in PEM format. A path that does not exist fails with `Error: Failed to read the certificate file: <path>`.                                                     |
| `--certificate-type`  | —     | string | —       | Type of the certificate: `edge_certificate` for a server certificate or `trusted_ca_certificate` for a Trusted CA certificate. Without it, the certificate is created as `edge_certificate`. |
| `--challenge`         | —     | string | —       | Method that solves the ACME challenge of a requested certificate: `dns` or `http`.                                                                                                           |
| `--common-name`       | —     | string | —       | Common Name (CN) of the requested certificate.                                                                                                                                               |
| `--file`              | —     | string | —       | Path to a JSON file with the attributes of the certificate. Use `-` to read the JSON from standard input.                                                                                    |
| `--key-algorithm`     | —     | string | —       | Key algorithm of the certificate: `rsa_2048`, `rsa_4096`, or `ecc_384`. Without it, a requested certificate uses `ecc_384`.                                                                  |
| `--name`              | —     | string | —       | Name of the certificate.                                                                                                                                                                     |
| `--private-key`       | —     | string | —       | Path to the private key file, in PEM format. Without it, an uploaded certificate is created in status `pending`.                                                                             |

This command uploads a server certificate named `my-certificate` from a certificate file and its private key:

```bash
azion create digital-certificate --name my-certificate --certificate ./certs/cert.pem --private-key ./certs/key.pem
```

The command prints the ID of the certificate:

```text
Created Digital Certificate with ID 123477
```

This command requests a Let's Encrypt certificate for `example.com`, validated through the DNS challenge:

```bash
azion create digital-certificate --name my-lets-encrypt-certificate --authority lets_encrypt --challenge dns --common-name example.com
```

The command prints `Requested` instead of `Created`:

```text
Requested Digital Certificate with ID 123479
```

For what each challenge needs before Let's Encrypt issues the certificate, refer to [Issuance and renewal](/en/documentation/platform/workloads/certificate-manager/issuance-and-renewal/).

---

## List

`azion list digital-certificate` lists the certificates of your account, 50 to a page:

```bash
azion list digital-certificate [flags]
```

| Flag          | Short | Type   | Default | Description                                                                                                                             |
| ------------- | ----- | ------ | ------- | --------------------------------------------------------------------------------------------------------------------------------------- |
| `--details`   | —     | —      | —       | Adds the `ISSUER`, `VALIDITY`, `TYPE`, `MANAGED`, `LAST EDITOR`, and `LAST MODIFIED` columns to the `ID`, `NAME`, and `STATUS` columns. |
| `--filter`    | —     | string | —       | Name to filter the list by.                                                                                                             |
| `--order-by`  | —     | string | —       | Field to sort the list by.                                                                                                              |
| `--page`      | —     | int    | `1`     | Number of the page to return.                                                                                                           |
| `--page-size` | —     | int    | `50`    | Number of certificates on each page.                                                                                                    |

This command lists the certificates of the account:

```bash
azion list digital-certificate
```

The command prints one row per certificate. The certificate uploaded without its private key reads `pending`:

```text
ID      NAME                         STATUS
123477  my-certificate               inactive
123478  my-ca-certificate            inactive
123479  my-lets-encrypt-certificate  inactive
123480  my-pending-certificate       pending
```

---

## Describe

`azion describe digital-certificate` prints the settings and the status of one certificate:

```bash
azion describe digital-certificate [flags]
```

| Flag                       | Short | Type | Default | Description                        |
| -------------------------- | ----- | ---- | ------- | ---------------------------------- |
| `--digital-certificate-id` | —     | int  | —       | ID of the certificate to describe. |

This command describes the certificate with ID `123477`:

```bash
azion describe digital-certificate --digital-certificate-id 123477
```

The command prints the attributes of the certificate:

```text
ID:              123477
Name:            my-certificate
Issuer:          ""
Subject Names:   []
Validity:        "2026-01-31 12:00:00+00:00"
Type:            edge_certificate
Managed:         false
Status:          inactive
Status Detail:
Challenge:
Authority:
Key Algorithm:   rsa_2048
Active:          true
Last Editor:     you@example.com
Created At:      "2026-01-01T12:00:14.812268Z"
Last Modified:   "2026-01-01T12:00:14.812268Z"
Renewed At:      null
```

With `--format json`, the command prints the full object: `active`, `authority`, `certificate`, `challenge`, `created_at`, `csr`, `id`, `issuer`, `key_algorithm`, `last_editor`, `last_modified`, `managed`, `name`, `product_version`, `renewed_at`, `status`, `status_detail`, `subject_name`, `type`, and `validity`. The `certificate` field holds the PEM text of the certificate, and the object carries no private key. A requested certificate has `managed` set to `true`. For what each status means, refer to [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates/#statuses).

---

## Update

`azion update digital-certificate` changes the name, the PEM files, or the request settings of a certificate:

```bash
azion update digital-certificate [flags]
```

| Flag                       | Short | Type   | Default | Description                                                                                      |
| -------------------------- | ----- | ------ | ------- | ------------------------------------------------------------------------------------------------ |
| `--active`                 | —     | string | —       | Takes `true` or `false`. Sets whether the certificate is active.                                 |
| `--authority`              | —     | string | —       | Certificate authority that issues the managed certificate, such as `lets_encrypt`.               |
| `--certificate`            | —     | string | —       | Path to the certificate file, in PEM format.                                                     |
| `--certificate-type`       | —     | string | —       | Type of the certificate: `edge_certificate` or `trusted_ca_certificate`.                         |
| `--challenge`              | —     | string | —       | Method that solves the ACME challenge of a requested certificate: `dns` or `http`.               |
| `--digital-certificate-id` | —     | int    | —       | ID of the certificate to update.                                                                 |
| `--file`                   | —     | string | —       | Path to a JSON file with the attributes to change. Use `-` to read the JSON from standard input. |
| `--key-algorithm`          | —     | string | —       | Key algorithm of the certificate: `rsa_2048`, `rsa_4096`, or `ecc_384`.                          |
| `--name`                   | —     | string | —       | New name of the certificate.                                                                     |
| `--private-key`            | —     | string | —       | Path to the private key file, in PEM format.                                                     |

This command renames the certificate with ID `123477` to `my-certificate-renamed`:

```bash
azion update digital-certificate --digital-certificate-id 123477 --name my-certificate-renamed
```

The command prints the ID of the updated certificate:

```text
Updated Digital Certificate with ID 123477
```

A certificate created without its private key stays `pending`. This command sends the certificate and its private key, and completes the certificate with ID `123480`:

```bash
azion update digital-certificate --digital-certificate-id 123480 --certificate ./certs/cert.pem --private-key ./certs/key.pem
```

The command prints the ID of the updated certificate, and the certificate then reads `inactive`:

```text
Updated Digital Certificate with ID 123480
```

An active certificate cannot be deactivated. With `--active false`, the command fails with this error:

```text
Error: Failed to update the Digital Certificate: ["The active certificates cannot be deactivated, as doing so may lead to complications for active domains."]. Check your settings and try again. If the error persists, contact Azion support
```

---

## Delete

`azion delete digital-certificate` deletes a certificate:

```bash
azion delete digital-certificate [flags]
```

| Flag                       | Short | Type | Default | Description                      |
| -------------------------- | ----- | ---- | ------- | -------------------------------- |
| `--digital-certificate-id` | —     | int  | —       | ID of the certificate to delete. |

This command deletes the certificate with ID `123478`:

```bash
azion delete digital-certificate --digital-certificate-id 123478 -y
```

The command confirms the deletion:

```text
Digital Certificate 123478 was successfully deleted
```

An ID that does not exist fails with this error:

```text
Error: Failed to delete the Digital Certificate: The given ID or API's endpoint doesn't exist or isn't available. Check that the identifying information is correct. Check your settings and try again. If the error persists, contact Azion support
```

---

## Use a JSON file

`azion create digital-certificate` and `azion update digital-certificate` read the attributes of the certificate from a JSON file with `--file`.

This file creates a Trusted CA certificate named `my-ca-certificate`. The command reads `name`, `type`, and `certificate` from it. The `certificate` value is the PEM text of the certificate as one JSON string, with each line break written as `\n`:

```json
{
  "name": "my-ca-certificate",
  "type": "trusted_ca_certificate",
  "certificate": "<pem-certificate>"
}
```

Pass the file to the create command:

```bash
azion create digital-certificate --file dc-create.json
```

The command prints the ID of the certificate:

```text
Created Digital Certificate with ID 123478
```

On update, the file can carry only the keys to change. This file renames the certificate, and its `type` stays `trusted_ca_certificate`:

```json
{
  "name": "my-ca-certificate-updated"
}
```

Pass the file and the ID of the certificate to the update command:

```bash
azion update digital-certificate --digital-certificate-id 123478 --file dc-update.json
```

The command prints the ID of the updated certificate:

```text
Updated Digital Certificate with ID 123478
```

---

## Related resources

- [Global options](/en/documentation/devtools/cli/globals.md): The options every command accepts, such as `--format`, `--out`, and `-y`.
- [Certificates](/en/documentation/platform/workloads/certificate-manager/certificates.md): Every field, status, and key algorithm of a stored certificate.
- [Azion CLI csr](/en/documentation/devtools/cli/resources/csr.md): The commands that create a certificate signing request, which shares the ID space of certificates.
- [Azion CLI workload](/en/documentation/devtools/cli/resources/workload.md): The commands that manage the workload that serves a certificate over TLS.
