> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a new DCF TLS profile

> Create a new DCF TLS profile.



## OpenAPI

````yaml /openapi/10.1/aviatrix-api.json post /v2.5/api/dcf/tls-profile
openapi: 3.1.0
info:
  title: Aviatrix Controller API
  version: '10.1'
  description: >-
    Aviatrix Controller API — version 10.1. Selected operations with Mintlify
    metadata.
servers: []
security: []
tags:
  - name: policies
    x-group: Policies
  - name: authentication
    x-group: Authentication
  - name: account-management
    x-group: Account Management
  - name: rbac
    x-group: RBAC & Permissions
  - name: gateways
    x-group: Gateways
  - name: transit
    x-group: Transit
  - name: nat
    x-group: NAT
  - name: app-domains
    x-group: SmartGroups
  - name: certificates
    x-group: Certificates
  - name: mitm
    x-group: MITM
  - name: monitoring
    x-group: Monitoring & Diagnostics
  - name: fqdn
    x-group: FQDN
  - name: logging
    x-group: Logging
  - name: vpn
    x-group: UserVPN
  - name: site-to-cloud
    x-group: Site-to-Cloud
  - name: controller
    x-group: Controller
  - name: bgp
    x-group: BGP
  - name: general
    x-group: General
  - name: firenet
    x-group: FireNet
  - name: networking
    x-group: Networking
  - name: tgw
    x-group: AWS TGW
  - name: ips
    x-group: IPS
  - name: saml
    x-group: SAML
paths:
  /v2.5/api/dcf/tls-profile:
    post:
      tags:
        - mitm
      summary: Create a new DCF TLS profile
      operationId: post_dcf_tls_profile
      parameters:
        - name: Authorization
          in: header
          required: true
          description: 'Controller ID in the format: cid <CID>.'
          schema:
            type: string
            example: cid <CID>
            default: cid <CID>
          example: cid <CID>
      requestBody:
        content:
          application/json:
            example:
              ca_bundle_id: f47ac10b-58cc-4372-a567-0e02b2c3d479
              certificate_validation: CERTIFICATE_VALIDATION_ENFORCE
              display_name: Production TLS Profile
              verify_sni: true
            schema:
              $ref: '#/components/schemas/TLSProfile'
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TLSProfileResponse'
          description: TLS profile created successfully
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TLSProfileErrorResponse'
          description: Invalid input
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TLSProfileErrorResponse'
          description: Server error
        default:
          $ref: '#/components/responses/general_response_v25'
      x-codeSamples:
        - lang: curl
          label: cURL
          source: |-
            curl -sk -X POST "https://<controller>/v2.5/api/dcf/tls-profile" \
              -H "Authorization: cid <CID>"
        - lang: python
          label: Python
          source: |-
            import requests

            url = "https://<controller>/v2.5/api/dcf/tls-profile"
            headers = {"Authorization": "cid <CID>"}

            response = requests.post(url, headers=headers)
            print(response.text)
        - lang: go
          label: Go
          source: |-
            package main

            import (
              "fmt"
              "net/http"
            )

            func main() {
              req, _ := http.NewRequest("POST", "https://<controller>/v2.5/api/dcf/tls-profile", nil)
              req.Header.Set("Authorization", "cid <CID>")

              client := &http.Client{}
              resp, err := client.Do(req)
              if err != nil {
                panic(err)
              }
              defer resp.Body.Close()

              fmt.Println(resp.Status)
            }
components:
  schemas:
    TLSProfile:
      properties:
        CA_bundle_id:
          description: >-
            UUID of the CA bundle that should be used for origin certificate
            validation. If not populated the default bundle would be used.
          type: string
        certificate_validation:
          description: Certificate validation mode
          enum:
            - CERTIFICATE_VALIDATION_NONE
            - CERTIFICATE_VALIDATION_LOG_ONLY
            - CERTIFICATE_VALIDATION_ENFORCE
          type: string
        display_name:
          description: Display name for the TLS profile
          type: string
        origin_cert_expiration:
          description: Controls behavior when an origin certificate has expired
          enum:
            - ORIGIN_CERT_EXPIRATION_UNSPECIFIED
            - ORIGIN_CERT_EXPIRATION_LOG_ONLY
            - ORIGIN_CERT_EXPIRATION_ENFORCE
          type: string
        verify_sni:
          description: Toggle to enable advanced SNI verification of client
          type: boolean
      required:
        - verify_sni
        - certificate_validation
        - display_name
      type: object
    TLSProfileResponse:
      properties:
        uuid:
          description: The unique identifier for the created TLS profile
          type: string
      required:
        - uuid
      type: object
    TLSProfileErrorResponse:
      example:
        message: Invalid TLS profile configuration
      properties:
        message:
          description: Error message describing what went wrong
          type: string
      required:
        - message
      type: object
    general_response_v25:
      description: A generic API response container for v2.5 style APIs.
      properties:
        message:
          description: A human-readable message.
          type: string
      title: General Response v2.5
      type: object
  responses:
    general_response_v25:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/general_response_v25'
      description: General v2.5 API response schema.

````