Consume a challenge

Consume a one-time WebRA challenge and enroll the certificate it authorizes.

This endpoint requires no authentication: presenting a valid challenge is the authorization. The challenge is single-use and time-limited, and is bound to the profile it was issued on. A challenge that is expired, already consumed, or submitted on another profile is rejected.

The enrollment is always synchronous.

Body required
application/json

The challenge to consume

profile
string required

The WebRA profile name the challenge was issued on

challenge
string required

The one-time challenge that authorizes this enrollment

template
object (WebRA Challenge Submit Request Template) required

The user-data that will be used to generate the certificate

Responses
  • 201 Challenge consumed and certificate enrolled
    certificate
    string required

    The certificate that was enrolled (PEM)

    pkcs12
    string

    The generated PKCS#12, only returned in centralized mode. It is encrypted with the submitted challenge as its password, in DER Base64 format.

  • 400 Invalid request
  • 403 Forbidden action
  • 500 Internal server error