> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Prune all deactivated Certificate Authorities of the service

> This API (idempotently) prunes all deactivated CAs of the service and it should be called when the current CA rotation phase of the service is in "activated". It removes all entries whose state is "deactivated" from protostore `service_certificate_authority` to unlink the CA from the service. This will also change the rotation phase from "activated" to "done".



## OpenAPI

````yaml /openapi/9.0/aviatrix-api.json post /v2.5/api/pkis/{service}/certificate-authorities:prune
openapi: 3.1.0
info:
  title: Aviatrix Controller API
  version: '9.0'
  description: >-
    Aviatrix Controller API — version 9.0. Selected operations with Mintlify
    metadata.
servers: []
security: []
tags:
  - name: policies
    x-group: Policies
  - name: authentication
    x-group: Authentication
  - name: account-management
    x-group: Account Management
  - name: rbac
    x-group: RBAC & Permissions
  - name: gateways
    x-group: Gateways
  - name: transit
    x-group: Transit
  - name: nat
    x-group: NAT
  - name: app-domains
    x-group: SmartGroups
  - name: certificates
    x-group: Certificates
  - name: mitm
    x-group: MITM
  - name: monitoring
    x-group: Monitoring & Diagnostics
  - name: fqdn
    x-group: FQDN
  - name: logging
    x-group: Logging
  - name: vpn
    x-group: UserVPN
  - name: site-to-cloud
    x-group: Site-to-Cloud
  - name: controller
    x-group: Controller
  - name: bgp
    x-group: BGP
  - name: general
    x-group: General
  - name: firenet
    x-group: FireNet
  - name: networking
    x-group: Networking
  - name: tgw
    x-group: AWS TGW
  - name: ips
    x-group: IPS
  - name: saml
    x-group: SAML
paths:
  /v2.5/api/pkis/{service}/certificate-authorities:prune:
    post:
      tags:
        - certificates
      summary: Prune all deactivated Certificate Authorities of the service
      description: >
        This API (idempotently) prunes all deactivated CAs of the service and it
        should be called

        when the current CA rotation phase of the service is in "activated". It
        removes all entries

        whose state is "deactivated" from protostore
        `service_certificate_authority` to unlink the

        CA from the service. This will also change the rotation phase from
        "activated" to "done".
      operationId: pruneServiceCAs
      parameters:
        - description: The service to prune deactivated CAs for.
          in: path
          name: service
          required: true
          schema:
            $ref: '#/components/schemas/ServiceCAServiceParam'
        - name: Authorization
          in: header
          required: true
          description: 'Controller ID in the format: cid <CID>.'
          schema:
            type: string
            example: cid <CID>
            default: cid <CID>
          example: cid <CID>
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  failed_nodes:
                    description: >-
                      List of nodes that failed to be updated with the latest
                      PKI data
                    items:
                      type: string
                    type: array
                  rotation_phase:
                    $ref: '#/components/schemas/ServiceCARotationPhase'
                  service_ca_list:
                    description: List of pruned Service CAs for the service
                    items:
                      $ref: '#/components/schemas/ServiceCARedactedEnrichedServiceCA'
                    type: array
                required:
                  - rotation_phase
                  - service_ca_list
                  - failed_nodes
                type: object
          description: Successfully pruned Certificate Authorities
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceCAError'
          description: Bad Request - Invalid input or CA rotation error
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ServiceCAError'
          description: Internal Server Error
        default:
          $ref: '#/components/responses/general_response_v25'
      x-codeSamples:
        - lang: curl
          label: cURL
          source: >-
            curl -sk -X POST
            "https://<controller>/v2.5/api/pkis/{service}/certificate-authorities:prune"
            \
              -H "Authorization: cid <CID>"
        - lang: python
          label: Python
          source: >-
            import requests


            url =
            "https://<controller>/v2.5/api/pkis/{service}/certificate-authorities:prune"

            headers = {"Authorization": "cid <CID>"}


            response = requests.post(url, headers=headers)

            print(response.text)
        - lang: go
          label: Go
          source: |-
            package main

            import (
              "fmt"
              "net/http"
            )

            func main() {
              req, _ := http.NewRequest("POST", "https://<controller>/v2.5/api/pkis/{service}/certificate-authorities:prune", nil)
              req.Header.Set("Authorization", "cid <CID>")

              client := &http.Client{}
              resp, err := client.Do(req)
              if err != nil {
                panic(err)
              }
              defer resp.Body.Close()

              fmt.Println(resp.Status)
            }
components:
  schemas:
    ServiceCAServiceParam:
      enum:
        - internal
        - uservpn
      type: string
    ServiceCARotationPhase:
      description: CA rotation phase of a service
      enum:
        - done
        - prepared
        - activated
      type: string
    ServiceCARedactedEnrichedServiceCA:
      properties:
        certificate_authority_id:
          description: ID of the associated certificate authority
          type: string
        created_time:
          description: Creation time as a UNIX timestamp
          type: integer
        display_name:
          description: Display name for the certificate authority
          type: string
        id:
          description: >-
            The ID of the Service CA from protostore
            `service_certificate_authority`
          type: string
        origin:
          description: Origin of the certificate authority
          enum:
            - Unspecified
            - Aviatrix
            - Custom
          type: string
        service:
          $ref: '#/components/schemas/ServiceCAServiceParam'
          description: Service using this certificate authority
        signing_certificate:
          description: Signing certificate in PEM format
          type: string
        state:
          description: Current state of the certificate authority
          enum:
            - active
            - deactivated
            - prepared
          type: string
      type: object
    ServiceCAError:
      properties:
        message:
          description: Error message
          type: string
      required:
        - message
      type: object
    general_response_v25:
      description: A generic API response container for v2.5 style APIs.
      properties:
        message:
          description: A human-readable message.
          type: string
      title: General Response v2.5
      type: object
  responses:
    general_response_v25:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/general_response_v25'
      description: General v2.5 API response schema.

````