Skip to main content
GET
TypeScript

Query Parameters

keyAlgorithm
enum<string>
default:RSA

Algorithm of the private key the CSR is generated for. ECDSA keys are smaller and quicker to issue, but the certificate authority signing the request has to accept an EC subject key, which some do not by default.

Available options:
RSA,
ECDSA
Example:

"RSA"

Response

The mTLS CSR PEM

mTLS Certificate Signing Request response

csr
string
required

The Fireblocks PEM-encoded Certificate Signing Request (CSR).

Example:

"-----BEGIN CERTIFICATE REQUEST-----\n...\n-----END CERTIFICATE REQUEST-----"

keyAlgorithm
enum<string>
required

Algorithm of the Fireblocks-held mTLS private key. A workspace may hold one key of each type, so a CSR is always returned for the type requested, and the type is echoed back on the response. ECDSA keys are smaller and quicker to issue, but the certificate authority signing the request has to accept an EC subject key, which some do not by default.

Available options:
RSA,
ECDSA
Example:

"RSA"