> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Activate a prepared Certificate Authority

> This API activates a prepared Certificate Authority for the service, and it should be called when the current CA rotation phase of the service is in "prepared". This activates a new CA by updating the prepared Service CA state to "active" and the old active Service CA state to "deactivated". Then it mints new certificates with the newly activated CA, and propagates the new certs and trust bundle to all Aviatrix nodes. The rotation phase is changed from "prepared" to "activated".



## OpenAPI

````yaml /openapi/9.0/aviatrix-api.json patch /v2.5/api/pkis/{service}/certificate-authorities/{uid}
openapi: 3.1.0
info:
  title: Aviatrix Controller API
  version: '9.0'
  description: >-
    Aviatrix Controller API — version 9.0. Selected operations with Mintlify
    metadata.
servers: []
security: []
tags:
  - name: policies
    x-group: Policies
  - name: authentication
    x-group: Authentication
  - name: account-management
    x-group: Account Management
  - name: rbac
    x-group: RBAC & Permissions
  - name: gateways
    x-group: Gateways
  - name: transit
    x-group: Transit
  - name: nat
    x-group: NAT
  - name: app-domains
    x-group: SmartGroups
  - name: certificates
    x-group: Certificates
  - name: mitm
    x-group: MITM
  - name: monitoring
    x-group: Monitoring & Diagnostics
  - name: fqdn
    x-group: FQDN
  - name: logging
    x-group: Logging
  - name: vpn
    x-group: UserVPN
  - name: site-to-cloud
    x-group: Site-to-Cloud
  - name: controller
    x-group: Controller
  - name: bgp
    x-group: BGP
  - name: general
    x-group: General
  - name: firenet
    x-group: FireNet
  - name: networking
    x-group: Networking
  - name: tgw
    x-group: AWS TGW
  - name: ips
    x-group: IPS
  - name: saml
    x-group: SAML
paths:
  /v2.5/api/pkis/{service}/certificate-authorities/{uid}:
    patch:
      tags:
        - certificates
      summary: Activate a prepared Certificate Authority
      description: >
        This API activates a prepared Certificate Authority for the service, and
        it should be

        called when the current CA rotation phase of the service is in
        "prepared". This activates

        a new CA by updating the prepared Service CA state to "active" and the
        old active Service

        CA state to "deactivated". Then it mints new certificates with the newly
        activated CA, and

        propagates the new certs and trust bundle to all Aviatrix nodes.

        The rotation phase is changed from "prepared" to "activated".
      operationId: activateServiceCA
      parameters:
        - description: The service to activate the prepared CA for.
          in: path
          name: service
          required: true
          schema:
            $ref: '#/components/schemas/ServiceCAServiceParam'
        - description: >
            The ID of a ServiceCA from protostore
            `service_certificate_authority` to activate.
          in: path
          name: uid
          required: true
          schema:
            type: string
        - name: Authorization
          in: header
          required: true
          description: 'Controller ID in the format: cid <CID>.'
          schema:
            type: string
            example: cid <CID>
            default: cid <CID>
          example: cid <CID>
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ServiceCAActivateData'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  failed_nodes:
                    description: >-
                      List of nodes that failed to be updated with the latest
                      PKI data
                    items:
                      type: string
                    type: array
                  rotation_phase:
                    $ref: '#/components/schemas/ServiceCARotationPhase'
                  service_ca:
                    $ref: '#/components/schemas/ServiceCARedactedEnrichedServiceCA'
                    description: The Service CA that is newly activated for the service
                required:
                  - rotation_phase
                  - service_ca
                  - failed_nodes
                type: object
          description: Successfully activated Certificate Authority
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceCAError'
          description: Bad Request - Invalid input or CA rotation error
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceCAError'
          description: Internal Server Error
        default:
          $ref: '#/components/responses/general_response_v25'
      x-codeSamples:
        - lang: curl
          label: cURL
          source: >-
            curl -sk -X PATCH
            "https://<controller>/v2.5/api/pkis/{service}/certificate-authorities/{uid}"
            \
              -H "Authorization: cid <CID>"
        - lang: python
          label: Python
          source: >-
            import requests


            url =
            "https://<controller>/v2.5/api/pkis/{service}/certificate-authorities/{uid}"

            headers = {"Authorization": "cid <CID>"}


            response = requests.patch(url, headers=headers)

            print(response.text)
        - lang: go
          label: Go
          source: |-
            package main

            import (
              "fmt"
              "net/http"
            )

            func main() {
              req, _ := http.NewRequest("PATCH", "https://<controller>/v2.5/api/pkis/{service}/certificate-authorities/{uid}", nil)
              req.Header.Set("Authorization", "cid <CID>")

              client := &http.Client{}
              resp, err := client.Do(req)
              if err != nil {
                panic(err)
              }
              defer resp.Body.Close()

              fmt.Println(resp.Status)
            }
components:
  schemas:
    ServiceCAServiceParam:
      enum:
        - internal
        - uservpn
      type: string
    ServiceCAActivateData:
      additionalProperties: false
      properties:
        check_interval:
          default: 5
          description: Wait time (secs) for checking the activation status
          maximum: 10
          minimum: 2
          type: integer
        state:
          description: >-
            Set the ServiceCA state to "active" (currently only "active" is
            supported).
          enum:
            - active
          type: string
        timeout_in_secs:
          default: 300
          description: Timeout (secs) for activation
          maximum: 600
          minimum: 120
          type: integer
      required:
        - state
      type: object
    ServiceCARotationPhase:
      description: CA rotation phase of a service
      enum:
        - done
        - prepared
        - activated
      type: string
    ServiceCARedactedEnrichedServiceCA:
      properties:
        certificate_authority_id:
          description: ID of the associated certificate authority
          type: string
        created_time:
          description: Creation time as a UNIX timestamp
          type: integer
        display_name:
          description: Display name for the certificate authority
          type: string
        id:
          description: >-
            The ID of the Service CA from protostore
            `service_certificate_authority`
          type: string
        origin:
          description: Origin of the certificate authority
          enum:
            - Unspecified
            - Aviatrix
            - Custom
          type: string
        service:
          $ref: '#/components/schemas/ServiceCAServiceParam'
          description: Service using this certificate authority
        signing_certificate:
          description: Signing certificate in PEM format
          type: string
        state:
          description: Current state of the certificate authority
          enum:
            - active
            - deactivated
            - prepared
          type: string
      type: object
    ServiceCAError:
      properties:
        message:
          description: Error message
          type: string
      required:
        - message
      type: object
    general_response_v25:
      description: A generic API response container for v2.5 style APIs.
      properties:
        message:
          description: A human-readable message.
          type: string
      title: General Response v2.5
      type: object
  responses:
    general_response_v25:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/general_response_v25'
      description: General v2.5 API response schema.

````