Get mTLS CSR
Returns the Certificate Signing Request (CSR) PEM that customers use to generate their signed client certificate.
The private key the CSR is built from is held by Fireblocks and is specific to this workspace. It is created on the first request for a given key type, and the same CSR is returned on subsequent requests for that type.
Pass keyAlgorithm to choose RSA or ECDSA. A workspace may hold one key of each: the CSR returned is always the one for the type requested, so a certificate signed against it matches the key used at delivery time.
Query Parameters
Algorithm of the private key the CSR is generated for. ECDSA keys are smaller and quicker to issue, but the certificate authority signing the request has to accept an EC subject key, which some do not by default.
RSA, ECDSA "RSA"
Response
The mTLS CSR PEM
mTLS Certificate Signing Request response
The Fireblocks PEM-encoded Certificate Signing Request (CSR).
"-----BEGIN CERTIFICATE REQUEST-----\n...\n-----END CERTIFICATE REQUEST-----"
Algorithm of the Fireblocks-held mTLS private key. A workspace may hold one key of each type, so a CSR is always returned for the type requested, and the type is echoed back on the response. ECDSA keys are smaller and quicker to issue, but the certificate authority signing the request has to accept an EC subject key, which some do not by default.
RSA, ECDSA "RSA"