Azion CLI digital-certificate
Azion CLI commands that upload, request, list, describe, update, and delete TLS certificates, with every flag, its type, and its default.
The Azion CLI digital-certificate commands create, list, describe, update, and delete the certificates that Certificate Manager stores for TLS. A certificate is a server certificate you upload with its private key or request from Let’s Encrypt, or a Trusted CA certificate that verifies client certificates. These commands store the certificate and do not bind it to a workload. The options every command accepts, such as --format, --out, and -y, are on Global options.
Create
azion create digital-certificate uploads a certificate from PEM files, or requests one from a certificate authority when you pass --authority:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--alternative-names | — | string | — | Comma-separated list of Subject Alternative Names (SANs) for the requested certificate. |
--authority | — | string | — | Certificate authority that issues the certificate, such as lets_encrypt. With it, the command requests the certificate instead of uploading one. |
--certificate | — | string | — | Path to the certificate file, in PEM format. A path that does not exist fails with Error: Failed to read the certificate file: <path>. |
--certificate-type | — | string | — | Type of the certificate: edge_certificate for a server certificate or trusted_ca_certificate for a Trusted CA certificate. Without it, the certificate is created as edge_certificate. |
--challenge | — | string | — | Method that solves the ACME challenge of a requested certificate: dns or http. |
--common-name | — | string | — | Common Name (CN) of the requested certificate. |
--file | — | string | — | Path to a JSON file with the attributes of the certificate. Use - to read the JSON from standard input. |
--key-algorithm | — | string | — | Key algorithm of the certificate: rsa_2048, rsa_4096, or ecc_384. Without it, a requested certificate uses ecc_384. |
--name | — | string | — | Name of the certificate. |
--private-key | — | string | — | Path to the private key file, in PEM format. Without it, an uploaded certificate is created in status pending. |
This command uploads a server certificate named my-certificate from a certificate file and its private key:
The command prints the ID of the certificate:
This command requests a Let’s Encrypt certificate for example.com, validated through the DNS challenge:
The command prints Requested instead of Created:
For what each challenge needs before Let’s Encrypt issues the certificate, refer to Issuance and renewal.
List
azion list digital-certificate lists the certificates of your account, 50 to a page:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--details | — | — | — | Adds the ISSUER, VALIDITY, TYPE, MANAGED, LAST EDITOR, and LAST MODIFIED columns to the ID, NAME, and STATUS columns. |
--filter | — | string | — | Name to filter the list by. |
--order-by | — | string | — | Field to sort the list by. |
--page | — | int | 1 | Number of the page to return. |
--page-size | — | int | 50 | Number of certificates on each page. |
This command lists the certificates of the account:
The command prints one row per certificate. The certificate uploaded without its private key reads pending:
Describe
azion describe digital-certificate prints the settings and the status of one certificate:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--digital-certificate-id | — | int | — | ID of the certificate to describe. |
This command describes the certificate with ID 123477:
The command prints the attributes of the certificate:
With --format json, the command prints the full object: active, authority, certificate, challenge, created_at, csr, id, issuer, key_algorithm, last_editor, last_modified, managed, name, product_version, renewed_at, status, status_detail, subject_name, type, and validity. The certificate field holds the PEM text of the certificate, and the object carries no private key. A requested certificate has managed set to true. For what each status means, refer to Certificates.
Update
azion update digital-certificate changes the name, the PEM files, or the request settings of a certificate:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--active | — | string | — | Takes true or false. Sets whether the certificate is active. |
--authority | — | string | — | Certificate authority that issues the managed certificate, such as lets_encrypt. |
--certificate | — | string | — | Path to the certificate file, in PEM format. |
--certificate-type | — | string | — | Type of the certificate: edge_certificate or trusted_ca_certificate. |
--challenge | — | string | — | Method that solves the ACME challenge of a requested certificate: dns or http. |
--digital-certificate-id | — | int | — | ID of the certificate to update. |
--file | — | string | — | Path to a JSON file with the attributes to change. Use - to read the JSON from standard input. |
--key-algorithm | — | string | — | Key algorithm of the certificate: rsa_2048, rsa_4096, or ecc_384. |
--name | — | string | — | New name of the certificate. |
--private-key | — | string | — | Path to the private key file, in PEM format. |
This command renames the certificate with ID 123477 to my-certificate-renamed:
The command prints the ID of the updated certificate:
A certificate created without its private key stays pending. This command sends the certificate and its private key, and completes the certificate with ID 123480:
The command prints the ID of the updated certificate, and the certificate then reads inactive:
An active certificate cannot be deactivated. With --active false, the command fails with this error:
Delete
azion delete digital-certificate deletes a certificate:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--digital-certificate-id | — | int | — | ID of the certificate to delete. |
This command deletes the certificate with ID 123478:
The command confirms the deletion:
An ID that does not exist fails with this error:
Use a JSON file
azion create digital-certificate and azion update digital-certificate read the attributes of the certificate from a JSON file with --file.
This file creates a Trusted CA certificate named my-ca-certificate. The command reads name, type, and certificate from it. The certificate value is the PEM text of the certificate as one JSON string, with each line break written as \n:
Pass the file to the create command:
The command prints the ID of the certificate:
On update, the file can carry only the keys to change. This file renames the certificate, and its type stays trusted_ca_certificate:
Pass the file and the ID of the certificate to the update command:
The command prints the ID of the updated certificate: