Skip to main content

Validity

The validity allows you to define the certificate validity: as a range with minimal and maximum values or as an expiration date.

JSON structure example

Range validity

{
  "validity": {
    "min_duration": {
      "unit": "days",
      "value": 10
    },
    "max_duration": {
      "unit": "years",
      "value": 5
    },
    "default_duration": {
      "unit": "years",
      "value": 5
    }, 
    "start_date": { 
      "allow_start_date_in_past": true,
      "max_duration_in_past": {
        "unit": "minutes",
        "value": 10
      }
    }
  } 
}

Expiration date validity

"validity": {
  "expiration_date": {
    "value": "9999-12-31T23:59:59Z"
  }
}

Parameters

Tabelle 1. Parameters: Certificate policies

Name

Type

Required/optional

Possible values

min_duration

Object

Required (range validity only)

-

.. value

Integer

Required

Specifies the duration value. Must be a positive integer

.. unit

String

Required

Specifies the duration unit. Supported values include:

  • minutes

  • hours

  • days

  • years

max_duration

Object

Required (range validity only)

-

.. value

Integer

Integer

Specifies the duration value. Must be a positive integer.

.. unit

String

Required

Specifies the duration unit. Supported values include:

  • minutes

  • hours

  • days

  • months

  • years

default_duration

Object

Required (range validity only)

-

..value

Integer

Required

Specifies the duration value. Must be a positive integer

..unit

String

Required

Specifies the duration unit. Supported values include:

  • minutes

  • hours

  • days

  • months

  • years

expiration_date

Object

Required (maximum expiration date validity only)

Specifies the latest date and time at which issued certificates can expire

.. value

String

Required

Specifies the expiration date or date and time. Supported formats include:

  • YYYY-MM-DD: Example: 2025-03-24. Time is automatically set to 00:00:00 UTC

  • YYYY-MM-DDTHH:mm:ssZ: Example: 2025-03-24T14:00:00Z

start_date

Object

Optional

Configures whether certificates can be issued with a start date in the past

.. allow_start_date_in_past

Boolean

Optional

Specifies whether certificate issuance requests can use a start date in the past. Supported values include:

  • true: Allows a start date in the past

  • false: Does not allow a start date in the past

.. max_duration_in_past

Object

Required (when allow_start_date_in_past is true)

Specifies the maximum amount of time before the current date and time that a certificate start date can be set

.. .. value

Integer

Required

Specifies the duration value. Must be a positive integer

.. .. unit

String

Required

Specifies the duration unit. Supported values include:

  • minutes

  • hours

  • days

  • months

  • years