ICS-Specific Configurations Using REST APIs
config management archiving local backup retrieves the list of local backups for system configurations and user accounts request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/maintenance/archiving/localbackup?config type=system/user/ivs' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "result" \[ { "identifier" 1692987215, "time" "2023/08/25 18 13 35" }, { "identifier" 1692987216, "time" "2023/08/25 18 13 36" } ] } save/restore/delete local backup for system configurations or user accounts request save curl x 'post' \\ 'https //\<ics ip>/api/v1/system/maintenance/archiving/localbackup' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "config type" "system", "operation" "save" }' request restore curl x 'post' \\ 'https //10 10 10 10/api/v1/system/maintenance/archiving/localbackup' \\ h 'accept application/json' \\ h 'content type application/json' \\ d '{ "config type" "system", "operation" "restore", "identifier" 1637076447, "restorecertificate" 1, "restoreipaddressandnetworksettings" 1, "restorenetworksettings" 1 }' request delete curl x 'post' \\ 'https //10 10 10 10/api/v1/system/maintenance/archiving/localbackup' \\ h 'accept application/json' \\ h 'content type application/json' \\ d '{ "config type" "user", "operation" "delete", "identifier" \[ 1639043345, 1639043307 ] }' response { "identifier" 1637076447, "time" "2021/11/16 15 27 27", "overwritten" true } snapshots operations to fetch, save, delete all or generate snapshots generate snapshots request curl location 'https //\<ics ip>/api/v1/system/maintenance/snapshots' \\ \ header 'content type application/json' \\ \ header 'authorization ••••••' \\ \ data '{ "action" "generate" }' response { "result" { "info" \[ { "message" "successfully generated system snapshot pulsesecure state admin localhost2 7 20250618 162753 encrypted " } ] } } save snapshot request curl location 'https //\<ics ip>/api/v1/system/maintenance/snapshots' \\ \ header 'content type application/json' \\ \ header 'authorization ••••••' \\ \ data '{ "action" "save", "file" "\<filename>" }' response output contains encrypt file, user can save it and use fetch snapshots request curl location 'https //\<ics ip>/api/v1/system/maintenance/snapshots' \\ \ header 'content type application/json' \\ \ header 'authorization ••••••' \\ \ data '{ "action" "fetch details" }' response { "result" { "snapshots" \[ { "date" "2025 06 18 16 28 32", "file" "pulsesecure state admin localhost2 7 20250618 162753 encrypted", "size" 4381057, "snapshot" "admin generated snapshot (with debuglog, config)" }, { "date" "2025 06 18 16 27 43", "file" "pulsesecure state admin localhost2 7 20250618 162704 encrypted", "size" 4380704, "snapshot" "admin generated snapshot (with debuglog, config)" } ] } } delete all snapshot request curl location 'https //\<ics ip>/api/v1/system/maintenance/snapshots' \\ \ header 'content type application/json' \\ \ header 'authorization ••••••' \\ \ data '{ "action" "delete", "file list" \["file name1", "filename2"] response { "result" { "info" \[ { "message" "successfully deleted 2 selected snapshots " } ] } } delete all request curl location 'https //\<ics ip>/api/v1/system/maintenance/snapshots' \\ \ header 'content type application/json' \\ \ header 'authorization ••••••' \\ \ data '{ "action" "delete all" }' response { "result" { "info" \[ { "message" "successfully deleted all snapshots " } ] } } trigger user record synchronization to trigger update to user record synchronization clients and server status request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/user record synchronization?operation=triggerstatusupdate' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' h 'accept application/json' \\ h 'content type application/json' \\ d '{}' response { "result" { "info" \[ { "message" "successfully triggered an update to urs clients and servers status " } ] } } export and import user record synchronization to export user details from urs database or cache request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/user record synchronization/database/export' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "datasource" "database", "usepassword" "on", "exportpassword" "password", "confirmexportpassword" "password", "exportlas" "systemlocallogical" }' response { "result" { "info" \[ { "message" "7acaadnri2ve+wmaaqaaaeu5rwdlncecbyzmygvhgk/gmeyiqc6yqiszvxxjlytlw07f0qqsa2ev93i30padypzziekg/enbeqftrsj82qzqmhdzsyduafyumwjylmawttnv2021p5py9yxtlpkxoasz+g5fwd8zclkilpj0hfwmyfnnjvjygv/xxjfvqehiguewcm9gmlumlbsdujoevphvmwljnathpluizwjvffdyzvdrzam/fvfr0mjmlw/sr/pzjmolv6nca0cry8o296q9gozy+nggvt16bsajt8ttucx6riftneme1u024wbuplbceni27fqp6ddi1a1mulatt60iuswytopqsvmfmnv5/uybzvscvg8zenz29+32cvyxpmaf4+6hev7xgvw2m+hmbuz0aabeveleb+b2bi5xsg5nio19ubqayjzpj/qg3oqpyojqbejztarzwsveow64d5nhfejv/7ykslr1m9++90axwwcw6oibvulnfyzgvye4d9vk9d72bkfnpqjfgtas7xry5jnubpvmbub/afpgbrrroiyfxcl8yl21t2tc8fkvhfsojv+gwxv5ktk+eyco5pzhxlfz7kd+p34bc3qlctrjyjczrhmir9jxy2d1vzgw/irloxxzjqptmhfntnmjzim/g7kelxv6t2rysxeinvjbl7p+t5hqj48ns6i6hy+feqqbnam4zvp5izhqs9yzbyhrmfsauruhoxltlalistdbn5k686j3kuaoo8pqcrw6vkstaeolosl4jk5lq11vaulhwn5kvksxsguk4mri9oyecehff1gljltxaklmwjo22ekysk7rwxniqoam9nhr9mk8fs/atiytk1ghs7cteurnsseeynj8ktbuysknsncr6bhwwrj4cd8r/1pjbrunbkumkszm0ezrxruqug4piwkgwvawxhakpf1vvkbslaqcbaehtovlwx8ykrimfsp3uhl5hxwmin7rm2wez0zd7w2pmkksezyrih07+q2sovivuadkaxekpk3zfknvdm7k9fpc64zzpz71qw08qanw+edg9xlhh4p5/73ye/kqjht9+qxyvywtydklhk4wk2rycz9ylahjo9yk4vrkfo/aezcz9o+zmz7kr87dmtvtcghlvpbfsk4pypqbeqzlm3youkalwbgcxleysphbh9gltrka0yw0kaptoy4d1b7uuxse8ipvnimtcmx4v53o3tz6oike7ka9zgcbj0slcxsgfuy5sifr7tl0trvgx8a3wfivulpdwecphgfjcdxmfhraulxhl8vxeybcmx1lkef0b4h9wqd83bg+outaxawafbico6zuapyovptsetrrbdbhgyeopt4ocrg1hc+epyhmzkh165qo8yqatmcxfllymsktlcgonsxzkzhqj69jln0jmklquu6zuqb0qoc4km6hr6lqpwlsbgaindhdt17f2wvmwh7avwbfpdbxeq89y+rdnwoswzprvzxhzkfufxy2nfipg7xqfhakfijnyxealakh6keltilj2vjffwa63eutlsdmhfwi6rkyqsuk/tmdy9fvljuknbhfnfzqknsgkwn+5wf6jk3aeoge+laj8fpyc2bdo9dji+on28aes51jjtw916/oimfmr35phclp47yluwqnyxsjgsjb1buxeadtzqyg2ugmk+tsh0kglup6315qusg+hyky4lnctkpil1dkk0se/hcyg6mtnewt1shoyrpzdursgn0w5dhb74efi8uloejdxc7jcjf4nknsthcwdst5rl7wm20keozoy1sdt2n2l27+3ucto7kig8pwm1eck1zwzzqbijritir9dszyhf15u3zzhm18dfj9fkuezztgmm09skuqrpauuyukmldnn2xixvbmldrojhjptzhqsk1wsbd7dmnwvwjvijo45mpwwxb1eh0uu9sykmxzrpiz8cvbnccuvxmpolyzgoudyatvcvx6adgjkdn40ywavkl/f9djh9oxcsrermyrx+wxbtszetgejq7clqy1kvtcpxhlmm1aegih+ge/muii9aohhjiqqigyfj8f/gugohjyil+ckoqlatwazddftmnfchcqpmiebuyruze/hwki9t8ual428a1sd/ygwcjgm4nhz3plix35kmbsdzji/xpgqxo3uwdytux1qtx7obsamoifhknewwhyf7pxcaqexi26trwafnobpenzmbqkbxqpd2ytluno9hmnvspmnjxuntj/bppcmdve1vyqvhvwxuintld+/lwgd1s8xr+fbbh4sddbnywofyggdnawyzuocd0gxezh925w78gfifsiep1+g602ak+x5j3fylbxuqq9ayfdt+shftwlnpkri9twdhomgpfncnrjrxws+qh/v3nexjtytgt/78lbucp8ckzffwmc72gxvtfuegklczljvhojlx1ivgyrlb4n6bsy9wfpwmgo16d1z0uaermw163j8bdqlbqeyqju0mgobtvaziuaz6xmheeyhgbgvbkqtbovldk9calavfsuqmvd219jorrejiu9q8ntymzdcstyagj6vn7mqdintwxicu1o2lvv2huytfnsm2gu7znmzkgguks8p/ez6mjr5xelaa9u0um3tolnmg2rn1i3fmkljrupcsm0o81pcljc3kjdmlzbrhtsmjos2cvgmxkmvw==" } ] } } to import user details from a file or cache request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/user record synchronization/database/import' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "datasource" "file", "filedata" "7acaaaxvi2wt0gqaaqaaaleicuw4cvc3ytcl4azmkppeiy5ygjhcqbkknjk+s7didkbdq2hlyagvkss/bu/8vwjnqxlif17ql75s9ik754xoycpxbnl+dls888pcmpgxsx++fcpjbr2vcdtwnpgljuqchjkndgmrrp/adir95md3n6slkjk3hkuv7lqmmq5ft5carjp7zud/jcp/uesayth/dyy5rcg8aaefbwynrk4zxk1kzsk1b8ggyi8ojqumpwkl0dry7zlvxtmjjaddl1m8yhra7i6jvjvk8tuoub0thkkrr2vuh2x3wxptzlb+yksvhyswwlpav6y4yilyblyutaydppantgq9asgv3fg1vsvofu2ut6wvc/ei6m383mll/shheehgng5krtdug5g3ra4muu83n9v8tluge1pzsyox+rovlltxechtihgpuwy9otnsxutkthtp8jxm/dfvpxllakruyem/vnzolajxb3s9/hibpgeb6mv5y5vt+vi28s71quob3gqfdezpcfi/ibmusi+ys+ap4rqsnnwrundlnxuvd46jejdw34tq/qyjunsl2sujnf6anpaufgkxk2no8zm+tq0i2c5msypzmngwkvhu7g5wcewarolep2hthfrcf5/za5kejnomocxsojzgewbecy8s04bphqdnxl5n4kjzw5so+e5cgdwvegngkhuhnxfqnwbm+vpuzj2jeg7wubfk6pn/tif79efv6sj/v/xjlcg7mm9mxhynkow33uk6f/uo8lgzqhq0kq+u6gbjsoat0wgashfobrevofbcwcfxyesy1npx6bsuvkst+vjedim6kghmnrhwl/ufzmr7ds7yo++m5or0gj6macxsgodzjfhhegav1raq8cakf9gywjcy5llnyhyo1wdgjbzfd86knp+zzlbqab0n87hnzwawt76qzpshqzg8uod9rgx5vk16fchrx1tefi8dok0cv+vfon40suo+a32wsxsg5bn991sdvttcvztlfuy6ie5ry0lstj8jakhweq9i/tnewrcfr0lulbhtz2sis3ttygcamrsy3ytj3fa5ovo51envv5ybdfkn0dakhqdyyndkqhxrrddw1v/hcbatbnra23lanjtjwpv/0r/5cbnnrjrvdl8elfazwrmr79awiopmjpyu1kodn/gz3g2ckuzohspipd1dx1hfqeggee2rf1t4pv0u/zrx9qjlhj/1cg9rsf0ljqjono6ajrdepnzax6ioi/+pqokcyvzmgxl/gg4znmhkx5rf/xnu26ftuipw90iu3kvk0ornkxzghgowuwt1drhted2to25keghlkekdzyd9s7ouxll8f534xxox9ovzvwk/eq1aaotzwulirvpmmzd0vn9dsxkzfgt7xxowxvth7l7+uwllp/lq6sl1zrom20a3thkqckpzwtlyncjl3l27mpwi4m9rygzni3utazc586pphzlsjomzcv9gwy/dofi6iwy3upxgeyg3hqj99ukbm7ehaezv10kucrt1wqqqtxzpzxptpdubqp0mb2n69ifmb6ch8vb5wjw3h5pvwzyxgcjjnna7crohfu24we3lliiocsgjiznftpcajqvhzhrlivynex1scypbahmkegcopsof7vucfkmouj93hzetlcdgi84smdwuhns1kwrhlkolfv18lwjtjbjnv3fzkeih8qxikdmn0hsxfxoueu7vmtzsvkijti9smml/qkhu0owdw6wpimk+ffatqsqw/nwzztfmsyvbrehmfpvymf7tbiceqrxyuwtzpiesdi89gqc3soahnhyh/dmeqo5jcd9fsdoea3zx/oljaxtaqqyyvqygd3a04bnlccl8zrk9ny8drykoe0r7pkk2x7gsyq7m8flhvjuiux+dvz8eo2ixdgn4kzvfvnalphod+mqsmcovdr9ptbdd5oxca/hgtllk1vm7izjkhxpzoodldnaryiimt8a+1cg9ud6ixqljxkjk+1norhhxkzrplkksreotdcnkm3slzmg2nnh/4mjgo6fededphxcgrvcqgtphwt0fvbqh/hgprxruzqhxvfntea2sfeaetjyrwpy7gqvgvvvemjpwh4qcgxeejmsgthfllhpgdx9uokjziv4f2ttgwuiyqv+e5v1ntk7atbnno+jobmcq6qbj1feufkcmy87rvxvivuoejn1hxwhcbs1afa2iqjxa7fnenlqmmnpv864pu5wn9l7ioehii3olsf329owrskj/6aqucr7edbkmjzpvhadkhjyqvh0k0dofnegalk+i6tdjoid5+hgwl0ownft25+ipypzrz+tdwfbbt6+nta67tpczj3ulutlhmk6wnmrpprexaukoj7p0c17mluojrmyzkcji5ticfmu8yz+bpxzuspj0hb/d+iq9slad9g08uusoo4idg5+t6jtgvvue6rbvqqru28cmpmykaurbl/c176qdxetsv1h2egwv++wkvgoogqrff3bamnamr0smenrdronl0zlw1w7fbwwjkqwcwsimqfc4/w0aql2l1lheuzejqz+pmqfj3/jgmwfltyxza7mj2eoc1jgv31aqspb0wptomyvedy9usdksdd7mxuhytbbz+xrbs1m9wz/w8vqe4sucj0cmxjhbleitym4igwrvnba8rextyp90qassjg==", "importlas" "systemlocallogical", "importpassword" "password", "usenspaceoverride" "on" }' response { "result" { "info" \[ { "message" "imported 5 record(s) from the uploaded file" } ] } } delete details in user record synchronization delete user details from urs database request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/user record synchronization/database/delete' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "deleteoperation" "specific", "deleteloginname" "user1", "deletelas" "systemlocallogical" }' response { "result" { "info" \[ { "message" "successfully deleted 5 user record(s)" } ] } } fetch count of user record retrieve count of user records in urs database request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/user record synchronization/database/retrieve stats' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' h 'accept application/json' \\ d '' response { "records count" 2 } generate html file to generate html file for the specified java applet request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/resource profiles/web profile/test' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "sub type" "windows terminal service", "vdi type" "vdi type 0", "use default html" "use default html 1" }' response { "result" "\<html>\<head>\<title>premier java rdp applet\</title>\</head>\</html>" } device management upgrading system software ensure that there is a minimum diskspace of 2 gb available in /tmp directory rebooting the gateway clears the /tmp directory incase if there is not enough space to upgrade system software request curl location 'https //x x x x/api/v1/system/maintenance/upgrade' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' \\ \ form 'file=@"/users/user1/downloads/package 354 1 pkg"' response { "result" { "info" \[ { "message" "successfully triggered upgrade of system software to 22 x (build xxxx) system will now reboot " } ] } } upload package request curl location 'https //x x x x/api/v1/system/maintenance/upgrade?operation=stage package' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' \\ \ form 'file=@"/users/user1/downloads/ics package pkg" response { "result" { "info" \[ { "message" "successfully staged service package 22 x (build xxxx)" } ] } } staged package version request curl location 'https //x x x x/api/v1/system/maintenance/staged package info' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' response { "staged package version" " 22 x (build xxx) } delete stage package request curl location request post 'https //x x x x/api/v1/system/maintenance/upgrade?operation=delete staged package' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' response { "result" { "info" \[ { "message" "successfully deleted staged service package 22 x (buid xxxx)" } ] } } upgrade from stage package request curl location request post 'https //x x x x/api/v1/system/maintenance/upgrade?operation=upgrade from staged package' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' response { "result" { "info" \[ { "message" "successfully triggered upgrade of system software to 22 x (build xxxx)using staged service package system will now reboot " } ] } } downgrade downgrade using clean=true this allows admin to stage or upgrade to a lower version package form the present one usage of clean=true https //x x x x/api/v1/system/maintenance/upgrade?clean=true https //x x x x/api/v1/system/maintenance/upgrade?operation=stage package\&clean=true https //x x x x/api/v1/system/maintenance/upgrade?operation=upgrade from staged package\&clean=true request curl location 'https //x x x x/api/v1/system/maintenance/upgrade?clean=true ' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' \\ \ form 'file=@"/users/user1/downloads/ics package pkg"' response { "result" { "info" \[ { "message" "successfully triggered upgrade of system software to 22 x (build xxxx) system will now reboot " } ] } } restarting system services to restart system services request post /api/v1/system/maintenance http/1 1 host \<ip address> authorization basic ywrtaw4xomrhbmexmjm= content type application/json { "operation" "restart" } response http/1 1 200 ok content type application/json { "name" "{ "result" { "info" \[ { "message" "successfully triggered restart of system services" } ] } }" } rebooting system to reboot the system ensure that there is a minimum diskspace of 2 gb available in /tmp directory rebooting the gateway clears the /tmp directory incase if there is no enough space request post /api/v1/system/maintenance http/1 1 host \<ip address> authorization basic ywrtaw4xomrhbmexmjm= content type application/json { "operation" "reboot" } response http/1 1 200 ok content type application/json { "name" "{ "result" { "info" \[ { "message" "successfully triggered reboot" } ] } }" } rolling back system software to roll back system software request post /api/v1/system/maintenance http/1 1 host \<ip address> authorization basic ywrtaw4xomrhbmexmjm= content type application/json { "operation" "rollback" } response http/1 1 200 ok content type application/json { "name" "{ "result" { "info" \[ { "message" "successfully triggered rollback" } ] } }" } enabling console password protection to enable console password protection request post /api/v1/system/maintenance/password protection http/1 1 host \<ip address> authorization basic ywrtaw4xomrhbmexmjm= content type application/json { "operation" "enable" } response http/1 1 200 ok content type application/json { "name" "{ "result" { "info" \[ { "message" "successfully enabled console password protection" } ] } }" } disabling console password protection to disable console password protection request post /api/v1/system/maintenance/password protection http/1 1 host \<ip address> authorization basic ywrtaw4xomrhbmexmjm= content type application/json { "operation" "disable" } response http/1 1 200 ok content type application/json { "name" "{ "result" { "info" \[ { "message" "successfully disabled console password protection" } ] } }" } enable terminal console to enable virtual terminal console request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/maintenance/options' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "enable virtual terminal console" true, "clear all configuration data" true }' response { "result" { "info" \[ { "message" "successfully updated the virtual terminal console" } ] } } to get virtual terminal console status request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/maintenance/options' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "current persistent user records" 14, "enable virtual terminal console" true } generate password key id creates a new password key id corresponding to an admin provided password request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/content encryption keys' \\ h 'accept application/json' \\ h 'content type application/json' \\ d '{ "password" "test123" } response { "key id" "66773" } fetch content encryption key fetches if a content encryption key exists and return its validity period request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/content encryption keys/66773' \\ h 'accept application/json' response { "valid till" "2024 10 30 19 47 09" } certificate management acme server to retrieve list of all configured acme servers request get https {ics ip}/api/v1/configuration/system/configuration/certificates/acme/acme servers response { "acme server" \[ { "href" "/api/v1/configuration/system/configuration/certificates/acme/acme servers/acme server/pebble%20acme%20server", "issuer name" "pebble acme server" } ] } to retrieve details of a specific acme server request get https //{ics ip}/api/v1/configuration/system/configuration/certificates/acme/acme servers/acme server/{issuer name} response { "external account" { "key encrypted" "\<encrypted key>", "kid" "ivanti" }, "issuer name" "pebble acme server", "preferred chain" "pebble test root ca x2", "prof mode" "required", "profile" "three days", "uri" "https //acme engdevroot com/dir" } to configure a new acme server via rest api response post https //{ics ip}/api/v1/configuration/system/configuration/certificates/acme/acme servers/acme server request { "external account" { "key cleartext" "", "kid" "" }, "issuer name" "pebble acme server 2", "preferred chain" "", "profile" "shortlived", "prof mode" "required", "uri" "https //acme engdevroot com/dir" } to modify an existing acme server response put https //{ics ip}/api/v1/configuration/system/configuration/certificates/acme/acme servers/acme server/{issuer name} request { "external account" { "key cleartext" "frqps9zisanuo 8 aacxgdrzingn1tponoh2sllt0mg", "kid" "ivanti" }, "issuer name" "pebble acme server", "preferred chain" "pebble test root ca x1", "profile" "shortlived", "prof mode" "required", "uri" "https //acme engdevroot com/dir" } to delete an acme server request delete https //{ics ip}/api/v1/configuration/system/configuration/certificates/acme/acme servers/acme server/{issuer name} example delete /acme server/pebble%20acme%20server%2d2 to map acme server to device certificate and schedule renewal date the acme renewal date field uses the iso 8601 date and time format the format is yyyy mm ddthh🇲🇲ss where yyyy mm dd represents the date t separates the date and time components hh🇲🇲ss represents the time in 24 hour format although iso 8601 also supports optional milliseconds ( sss) and time zone indicators (z, +hh\ mm, hh\ mm), these are not required for the acme renewal date field the date and time are interpreted using the time zone configured on the ivanti connect secure (ics) system therefore, milliseconds and an explicit time zone designator should not be included in the api request request put https //{ics ip}/api/v1/configuration/system/configuration/certificates/device certificates/device certificate/{cert thumbprint} { "acme key" "ecdsa 256", "acme renewal date" "2026 04 27t09 36 25", "acme sans" \["www example com", "info example com"], "acme server" "pebble acme server", "thumb print" "87\ c7 2a\ ae 2b 40 23\ d0 60\ e1 85 9c\ fe\ d6\ b9 2e 59\ bc 4d\ dc 40 46 84\ c5\ d8 16 96 0a\ ab 71 21\ d8" } respone { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } to trigger acme certificate renewal request post https //{ics ip}/api/v1/system/certificates/device certificate?operation=renew { "thumb print" "f2\ b7 2a\ ba 1b 7e\ b6 46\ c1 71 4a\ d5 40 1d\ ac 87\ b7 73 00 86 5a 20 9c\ f0 9f 27 75\ e6\ b8 31 2d\ a5" } response { "result" { "info" \[ { "message" "certificate renewal triggered successfully " } ] } } to update acme server, acme sans, and acme key on an existing device certificate request put https //{ics ip}/api/v1/configuration/system/configuration/certificates/device certificates/device certificate/{cert thumbprint} { "acme key" "rsa 2048", "acme sans" \[ "vpn example com", "gw\ example com" ], "acme server" "pebble acme server 2", "thumb print" "cc 8b 51\ eb 39 94\ f9 05\ fd 9d\ f0 0a 14 55\ e5 02 03\ ff 39\ f8\ e2\ ba 91 4f 02 22\ e4\ a6 65\ b5\ c7 7e" } response { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } device intermediate certificates to add intermediate certificate serial number was used as an identifier in the certificate apis before ics 22 7r2 6 request curl location 'https //\<ics ip>/api/v1/configuration/system/configuration/certificates/device intermediate certificates/device intermediate certificate/' \\ \ header 'content type application/json' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' \\ \ data '{ "cert pem" "ls0tls1crudjtibdrvjusuzjq0furs0tls0tck1jsud6akndqkxhz0f3sujbz0lrzuztzwdtshpgwwxjvk9myzjxsnbfrefoqmdrcwhrauc5dzbcqvfzrkfeqxaktvnjd0prwurwuvferxg1vvjstwdur0zpy3lcrfpysjbhv1pwwtjgmfptqkjkwfjvyjnkcgria3diagnotwpjeapnrev3tvrjee5qttvxagnotxpjee1erxdnvgn5tmpnnfdqqxbnu2n3slfzrfzruurfedvvumxnz1rhrmljeujeclpysjbhv1pwwtjgmfptqkjkwfjvyjnkcgria3dnz0lptuewr0ntcudtswizrfffqkfrvufbneldrhdbd2dnsuskqw9jq0frrgpxce1mru9lt0jpn2y3rjrnofptuhd3d3y2amd4utnzvkzgzxjvyktluc8rytjcznbkl2szwmy3nqpsugp2ulvlchvtdjb4emdxy0j1lzdav2vpz2xpyte0n1kybknht2petxo5qvv2t3z6vfbhewllumt0shu1r0hicnm3ogevvza2ajzyukwwa3luwwy1suxbahznak8zqlhbbwjsrhyrzhzuqte4nuqwwhz0z1dtyjl6t1vfvc8vunukbux3yvhjy2lrogwzz0d4ww5eotjxbvlsd0g4ytn1azdxust0ogphqvbrqtdgs3lbvhi3es92uxz4rytzogrioap0ss9rdehhuzd1ww5aczi2uurquejocgfjl2owlzh5v2nia2fvyll0vndfrg56mexhqmtiuhu5bkp5aurgz1mycnvhqtrvby95ale5shzsbtvltytkzmlxd2vjbexyl01hcuz1rnq4ngn5y25jl2o5djd3njvyoge3bjf1skgzejckbdhvnlk5sxpdvevwy2fmzkpkd2xzu0z2vjjpbjnodxptnzk4qnromjzeows0owlun0rmnhc3d1vwm3jrb2lqrqp0vtzcduzfa2i1avpet3zytxjoytnzehhuk1nmbw9imupyyjzqr3y4vvm1k0rtn1cybxrpturayjdosxprzni5cisytnrtrmtlb2txrstvqwoyrzjawhpsqnu5a2r3c0rwmkjpag41wujsrgnsuwvsrhvyc0t6ekkvdhpyttu0cgsknunmqllyrzftejvvamhltuvnenzhvythnu1zd3bkvjngcfvybdb6k2fvqzvjdmpxu0k4rjg5tkdjqlovemheagposeqvbvewthvoym9pzmnjk2jvd2uynnzurznitgivoth2wu9betvkwwkxcddkullpuuleqvfbqm80sui4rendckfld3ddd1levliwuejbuurbz0dhtue4r0exvwrfd0vcl3drrk1btujbzjh3sffzrfzsme9cqllfrkdxthbzstmknuvtnfjvovdzz1b6lzn3wdbksg9nqkfhq1nzr0fruujnamnwqvfrrefnrufnsulcbvfzrfzsmgdcsulca0rdqwpbwxd3qmdzrvzsmgdbrendqvlbr0ndb0rcsxn2utfrrk1jsujjakndqvr3r0ndc0dbuvvgqndjq01jsujmadzdckftb0fwqujvqudvqulbqlvbrvlbvxdbz0ffd0fzuujpquhnqulbqkrbr1vby2dcmefha0faz0jwqudnqvlrqjakqudrqwj3qnvbq0fbuvfcmufiuufhquj2quhjqwfrqjbbsgtbsufccefitufjqujoquc0qulbqnbbrzrbzefcbapbselbymdcaefhd0fjquj5qudvqwn3qnzbsfvby2dcakfhvufmz0fnquvnqvprqnlbsffbyvfcbufha0fzd0jockfiuufauuj6qunbqwrbqm9br0vbzefbz0fhrufjz0jsqunbqwfrqnpbse1bzffcbefhuufjqujpquhrqulbqjakqudnqwfrqnpbq0fbuxdcbefisufkqujwqudzqwfrqmpbr0vbzefcbefdqufruuixquhrqwfbqnzbselbyvfcmapbsgtbsufcaefisufauufnqudzqwj3qnlbq0fbyvfcdufiuufauuj5quc0qvlrqnnbq0fbzffcekfhrufad0jsckfdqufid0j1qud3qwvrqxvnrefhq0nzr0frvuzcd0lcrmlsb2riundpath2y0d0cexttnzjbkf1zedaemjhrmkky3k1amiymhzzm0j6tg1omgjxd3deuvlks29aswh2y05buuvmqlfbrgdnsujbqm56nevqum5ua2hlqwtgyunyugpll1nud3awsfl4v2u3axh5vmltrldzcllwuhu5mnl6dy80wjfyt3phn0fgqudyelv5tlf4tetib1jpag9bzee3cknndznjcwn2ymlsdu0vou5lnuhnbexnk041y2x4vlfpexfjtvrtmw5mrhu0qi9pexdmb3lob0wysm8yztg0neoksgy5ennhsdjbmu9woey4c1r3elr2r3nbvvnsagpabddnzesxb3mzlzvzbxrxtmlrt2c5detvoeyxsetuakzsaappz3azdkljc1l3exbsbdiruejyng1iclfmelbcsfgzdmfxv1vrctl0mhhzm0pcr3fryxbicedloddxa3hrsxfkcmpisnhfvxfrbmr1rfbzvkn0c05kqnvru1r3zg9ysjrbdfc4rhd2yza4rdjnsfc1ccs0d1hnelkwc212m3bmbtukmmhxbtjwblnjr2remgzrrhj0dc9erepus0hzd3cxwnhqulhjdhi5b3i1qjhkvdhymefpbnjrsehsrlriew5rugo5ste2rmdrc1e0bc9pz25idhp1evu5mdm3c1bzs29htmzls3lgwwhozzm2wdb0derhq1p4kytby3f3mjbod2vkclzjd2dzbjnla0rsvfbwr3p0zu40n3brnhl0u0liqju1dmzwqmjbvwleaupjwxl5bfq2s0pjdwdndxftrky0s20kvfpwq1y1d3dswgm1avpcynhqdfe1ykc3b1joswrnymy0cxjznfjqvnh4qunntflkmwf1v3dmamreagzkqwowrqpwsvryckntc1hrvk93rwzstjnkaji1szdvr3g4ndnsswp1ovplu0tuuy93twjioxrutne3bmvozumwdxzgyvh1clnpdeq5vwduy1vhwld1sui0eeezdkxrmgotls0tluvorcbdrvjusuzjq0furs0tls0tcg==", "serial number" "78 54 9e 82 61\ f3 15 89 48 54\ e2\ dc\ d9 62 69 10" }' response { "result" { "warnings" \[ { "message" "the configuration has been implicitly changed" } ] } } beginning with ics 22 7r2 6 onwards, thumbprint must be used as identifier instead of the serial number in the certificate apis request get \<ics ip>/api/v1/configuration/system/configuration/certificates/device certificates response { "device certificate" \[ { "href" "/api/v1/configuration/system/configuration/certificates/device certificates/device certificate/da%3a51%3afd%3afc%3a73%3aa1%3a8f%3ad6%3ae5%3ac1%3a49%3a2e%3a98%3adc%3ace%3a5d%3aac%3ac8%3ab4%3a71%3af9%3aa4%3a73%3aab%3aaf%3a2d%3a61%3ae9%3a73%3a56%3af3%3ae8", "thumb print" "da 51\ fd\ fc 73\ a1 8f\ d6\ e5\ c1 49 2e 98\ dc\ ce 5d\ ac\ c8\ b4 71\ f9\ a4 73\ ab\ af 2d 61\ e9 73 56\ f3\ e8" }, { "href" "/api/v1/configuration/system/configuration/certificates/device certificates/device certificate/3a%3a55%3ab2%3a5a%3a66%3aa4%3aa6%3aa5%3a4d%3a38%3aa2%3a7e%3afb%3a6b%3a6c%3ad2%3af3%3a48%3a7c%3ae5%3af3%3a86%3adf%3afe%3a35%3a22%3a3d%3ae9%3a36%3a8b%3aa6%3ad1", "thumb print" "3a 55\ b2 5a 66\ a4\ a6\ a5 4d 38\ a2 7e\ fb 6b 6c\ d2\ f3 48 7c\ e5\ f3 86\ df\ fe 35 22 3d\ e9 36 8b\ a6\ d1" } ] } to delete the intermediate certificates curl location request delete 'https //\<ics ip>/api/v1/configuration/system/configuration/certificates/device intermediate certificates/device intermediate certificate/78 54 9e 82 61\ f3 15 89 48 54\ e2\ dc\ d9 62 69 10' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' fetch device csr to fetch details of a particular csr based on the csr id provided request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/certificates/device certificate csrs/csr 396' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "csr" { "country" "us", "creation time" "11/07/2023 05 22 14", "csr id" "csr 396", "email address" "email\@provider com", "key size" 2048, "locality" "locality", "organization name" "ivanti", "organization unit name" "org unit name", "pem" " begin certificate request \nmiidgdccagacaqawgzyxczajbgnvbaytalvtmq4wdaydvqqidavtdgf0zterma8g\na1uebwwitg9jywxpdhkxdzanbgnvbaombkl2yw50atewmbqga1uecwwnt3jnifvu\naxqgtmftztehmb8gcsqgsib3dqejaryszw1hawxachjvdmlkzxiuy29tmrgwfgyd\nvqqdda9wdwxzzxnly3vyzs5uzxqwggeima0gcsqgsib3dqebaquaa4ibdwawggek\naoibaqc4lwdijmpeljyczjnx7h7k5p2kh5nutaqgelmcdijlp+mbch0xg+xtwnc/\nr1jvcgd7reslej5vzjqupz77awo6ibr8mlwe9esb5pcb2ajso04jnrmsppkckvic\n19xmxukxkvf1cke6ehpyuc8dwtt7k+qrvxsqwyhdxnef97py+xefohiiejyysimz\nt73purrdfthi6nessqwmgzubpyker64g7fernygqsdh0nkqsgvzehwjtfuds+iyy\n7jo2bhe5cgmcnqh629dfkv7ao8il1euct7wtr6efizzkcmf908kfouhvq+jitrdz\nt7ue1f/iwfsegs+n3xqvz7lgydzpagmbaaggpda6bgkqhkig9w0bcq4xltarmakg\na1udewqcmaawcwydvr0pbaqdagxgmbegcwcgsagg+eibaqqeawif4danbgkqhkig\n9w0baqsfaaocaqealho9uzlujxsvjayx6z8a1soqzgfbd1yjujnkx4ykjo9gjnr0\nbmebv/kju1+zl1b/lf4acln3c+xmvguxrb4pgcmmlhdkwjqhjngjn/1joiqx5bjm\n3g5q5p9sptpj763pqp3cva/7wgz2atmkbykzrs2rktzve2/p5dis7lgusksd/vpi\nlplkszia6n4+17eluwkfqdytkjxnjjsfkrlopa9gjkdyvvtjl4zgjftn7ldfi78n\nfssaykj3j5hu12c4tcptpoir1mhju+96zq78q0evp4kjeyzluxm7s/csa6mbakfb\nrrpefqtodxhjwrfnlygjiihi8phg2mrnsptriq==\n end certificate request \n", "state" "state", "subject common name" "subject common name" } } delete device csr to delete a particular csr based on the csr id provided response curl x 'delete' \\ 'https //\<ics ip>/api/v1/system/certificates/device certificate csrs/csr 396' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' request { "result" { "info" \[ { "message" "csr id 'csr 396' deleted successfully" } ] } } create device csr to create a new csr request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/certificates/device certificate csrs' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "subject common name" "subject common name", "organization name" "ivanti", "organization unit" "organization unit", "locality name" "locality", "state" "state", "country" "us", "email" "email\@provider com", "key type" "rsa", "key length" 1024, "random data" "randomcharacters" }' response { "result" { "info" \[ { "message" "created csr 'csr 408' successfully" }, { "message" "use post /api/v1/system/certificates/device certificate csrs/csr 408/certificate to upload the signed certificate" } ] } } import device csr import the signed certificate based on a particular csr request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/certificates/client auth certificate csrs/csr 396/certificate' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "certificate" "string" }' response { "result" { "info" \[ { "message" "imported certificate for csr 'csr 396' successfully" } ] } } import or delete signing certificate imports and delete sun and java certificates request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/certificates/code signing certificates?operation=\<import or delete>' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "type" "ms", "certfile" "miigzqyjkozihvcnaqccoiigvjccblicaqexadalbgkqhkig9w0bbwggggy6miignjccbr6gawibagikwdocoaaaaaab1danbgkqhkig9w0baqufadbcmrmweqykczimizpylgqbgrydy29tmrgwfgykczimizpylgqbgryiyxnxywnlcnqxetapbgnvbamtcg1zcm9vdgnhmb4xdtewmdmynta2ndmyn1oxdti2mdmynta2ntmyn1owgaqxczajbgnvbaytaklomriweaydvqqiewllyxjuyxrha2exejaqbgnvbactcujhbmdhbg9yztedmbsga1uechmusnvuaxblcibozxr3b3jrcybjbmmxdtalbgnvbastbefbqluxhtabbgnvbamtfep1bmlwzxigtmv0d29ya3mgsw5jmsawhgyjkozihvcnaqkbfhfszwvtyubqdw5pcgvylm5lddccasiwdqyjkozihvcnaqebbqadggepadccaqocggebaojuaa1+11ubsbmd9kmadktfnzwv11hjkgvvewogbqqtpc1/grjkx8w8l/7jzgdbdtu20ljv8fe02kcatdnaal/igvxyuy9de4s7uuvbwczth+643aagsx7bkjuauzybr54anaynqfvyj58qp9iwx4csfzvjvkwvabdmxlqz2j5aixk4zohsjhlcimrdqowmlmtytgigw99sdfdjqtwqjyxcjo7cg8do6ok+btorrll1b2mak6bom/truiwfw5cvqegctwmjceuknuxoc7k0bf2syte7+lebbbmpsesyetuufos7aegd1m3wkjy3qoxd4on72k0xvbaamoz00paq3u8caweaaaocaskwgglfma4ga1uddweb/wqeawie8dbebgkqhkig9w0bcq8enza1ma4gccqgsib3dqmcagiagdaobggqhkig9w0dbaicaiawbwyfkw4dagcwcgyikozihvcnawcwhqydvr0obbyefgvb7pnz2hozqmpl+q0aijjk6jczmbmga1udjqqmmaogccsgaqufbwmdmb8ga1udiwqymbaafl3qkufimtnb+i/qr11owjynsuxemih+bgnvhr8egfywgfmwgfcgge2ggeqgngh0dha6ly9tc3jvb3rjys5hc3fhy2vydc5jb20vq2vydevucm9sbc9tc3jvb3rjys5jcmyggbfszgfwoi8vl0nopw1zcm9vdgnhlenopw1zcm9vdgnhlenopuneucxdtj1qdwjsawmlmjblzxklmjbtzxj2awnlcyxdtj1tzxj2awnlcyxdtj1db25mawd1cmf0aw9ulerdpwfzcwfjzxj0lerdpwnvbt9jzxj0awzpy2f0zvjldm9jyxrpb25maxn0p2jhc2u/b2jqzwn0q2xhc3m9y1jmrglzdhjpynv0aw9uug9pbnqwggevbggrbgefbqcbaqscaqcwggedmigobggrbgefbqcwaoabm2xkyxa6ly8vq049bxnyb290y2esq049qulblenopvb1ymxpyyuymetlesuymfnlcnzpy2vzlenopvnlcnzpy2vzlenopunvbmzpz3vyyxrpb24srem9yxnxywnlcnqsrem9y29tp2nbq2vydglmawnhdgu/ymfzzt9vymply3rdbgfzcz1jzxj0awzpy2f0aw9uqxv0ag9yaxr5mfygccsgaqufbzachkpodhrwoi8vbxnyb290y2euyxnxywnlcnquy29tl0nlcnrfbnjvbgwvbxnyb290y2euyxnxywnlcnquy29tx21zcm9vdgnhlmnyddanbgkqhkig9w0baqufaaocaqeaorckx8rgmrpiuanedud1v/h4oxyg9bbrs6li09eesnkyly546zxtddxpcs9tszzn+b1+ij6gxz3trlmwdiggdsp3ck19i7rik51ibvj52t/b/trzn65pulwlb5qwejuz120djtwjozyafssmwlay62blqy2gbgfbcpommnv3ykv7ebkt1/mmhdgetdf918aqvlcd6bldgslk1jyhwfxgyaomvinsbyxwkz8a2cvgktgciqum3xc4joiij+ullfmjbnsfl6edtqeuqp/qlhzmtfwfkzbvliobmqg6x5y8t3yo3cpjixxwtffe4l4dwibh3iuj7baxmnlvzzujbx31/zea", "keyfile" "hvg1saaaaaacaaaaaqaaabaaaacubaaaa512tmrlpt+m8vbukkmmkwccaaaajaaa1duedpqkbrr/yiiejdcswozc8vlv0l9vcbygwamhijyhiom+zjxnwuiwtaootc9grt7bszp05ouyebjmuw0pjeglujx4mryftoculpwvudw/fryxu4ls14y+qepnyuehbhhvfw1lo01vunooxfi1cmfjiaalpxq9iira+zczlpzbvynsn49kyalnunc/v6/uf5xobwus8l7qyhjszlty/vwggrwcicyygn3uwkuvxpjzc8/podpbwt52ulzynixlae3d3hv55mu0er9lysjbzd0r4kkq/ttta8y6wbk/rixh3giose/lz309f+fwat/kvfawxp4bcgempz/tqhlk3m1gjjqakegirjuljsvr92l7ayzpntqzzmcrfuopaz80174z9mctcjtudsje2irygddltzzizxkpk75gwma4cfxerntinit+wj/orsid+vzrnkd1s6qxtweqdkkqikemleauts1ufg+tvktkzblp6b9r8gigycf1xf0dbvx7qnqxy5yir2atsvn3tpzsietvvj8krs74hhjle6oxx6g8i8dl83r37dkc5la0upmo2f6ozjv3spiu56b1nvyucehcx78gvcexhc+eia9rana4r5sr73ofze8f3i72ih7sfser4ly6qu/apl5acabj9y1jrkk72m6qmr0iueq92km9uyqpk4lq/6zkwhpgiq+siewiwki6yp8z3tyui0dpmx0iypvotxrug/dht1u/ib0wmlgvejqe3yo2qsmezj2zw3txditoschyahi9jacepdv7t5ybh15b2cdkgoxglerkor60hjbmwsrwwcdeen9dgmuioim+t8f3dmp0o6ca+stjm9ls0sbv6mbzgjbsq/tcv+ppzb20yzu9ymohsmtfofznudqcm+cvailnihg4ovtc/eiwgoccjja7jy8akwqlo/c4j/d+zitwbskpysbh5atiscj20qjk2rouv4y6jw0kidfu04gnl0tuuzvii6gi13mh4i64addwxylfbfq9lvhow2qni+zqo+kushcugs0akuo62l+t7uycmxuhgwus8havpxl2q35bllvdtpuilpr5eim1wean6lmnqgexpcsrkrbijegkgqvha+9fu3bsvrrgbt5/q0ui4and8upizyfflpb/qn4+2njaa4f9k9+btp6dpgpjeumes/lwxo5klubirhpofkjkiy7c2egwxdlco1qpozyzmayfvg23dtqwank1nngnpot3gy9yuon52us116nue97grjulrmtgeynfgqiatdtpavzu/lwyxxdpgscxotaxcmcidbqgfsuar2ix0juzgvzjmneulmbknnkh/a7jqhgupe+yzg0mx1jgkml0avlngjh3mbw25zls4skxf5xrewo+6gg6bsbcokhkk+x7mrm8sltbvuts7d8yi0taesztcog/cqznxis3i4gvnawqpneukshcdogtvt6qh00ew4bopt04fdnsnzbu+jz9wz6ivs33mnyyylicmmhnik8bctu3cd609lqz17m+uoha+1n+hnm5cksj", "password" "neoteris" } responses { "result" { "info" \[ { "message" "import of ms certificates is successful" } ] } } updating client certificate to trigger update now for crl in client certificate request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/certificates/crl?operation=updatenow' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "clientca" "ca common name" }' response { "result" { "info" \[ { "message" "successfully initiated crl download ca common name" } ] } } import, renew and reset certificates to import, renew or reset the specified certificate request curl x 'post' \\ 'https //10 10 10 10/api/v1/system/certificates/device certificate?operation=\<import/renew/reset' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' \\ h 'accept application/json' \\ h 'content type application/json' \\ d '{ "certificate" "miibhgibazccgtogcsqgsib3dqehaaccgsseghrhmiiawzccbgwgcsqgsib3dqehaaccbf0eggx5miif9tccbfegcyqgsib3dqemcgecoiie/jccbpowhaykkozihvcnaqwbazaobainu2gcy3sl9wicb9aeggtygztg+efl+xyqtakan2amovwxhvlws6zpzykeuisf5qvifsbcpvoufqwkroqfqoejpph9liren1nega+4usjfeqwjqok8evsxxclvz2sso7ijrvhob4abkyvp2tewwcgvewjfclxvsgehhde+/wnqfuucqdjyjtvojcopcmn85kalf5jfrhbdfzz5hvs6dbqq0zuharhokksbbn82kaizjdtg1jqjwgkubihxvlggvyvzeseiluzmp9gzjmqlxh2f7ghi78kb2gam3jqjbbrd3816bonq6vbhyahbzfhxug3wpxp4bq1xgrgajvw3lstsqjhiplwax3otfpn5pds+th2/g62nqr2hss/pohlbhjsvzyz1x0sy4hw9bkhjpwj1pe+vbvejk9zz0/zjhiiu9nvj+ivqo11erb7eyprna50n0yc+mcmxq8bmaenafoccolpm9bdktepdazmbnitbcu9gywhvbqfsbbqxpaejpjwmbzthihtcymg1itvkjceyagfxdii7kg6au2hnsuuwxtdfsudqic654hp2yhc+fruaurdmlg3oejhkaqtivr+zva0q47oaubje2nw/0qybggddtrthr0/a4tnurormapsefow7cvwd9eufw9diotf/idkenv+lq1krnhieob/bslgfs8lyg171twlf647ky6b1xqdo7i+hgecdlmwis9w3+nt3oguiq0otgfqthbqenobuosru7aaygdacajtlxeoeu9nogqk3sxvuewscozhuwo65ayb4vounrvldeibgenpswbnt9y3zdtqhpompyzzfqfvmvqwxbuc3iqazh8pxfkxxjt54rjw09ackvfqtulxwsfiobj25wt+hluzmoerlukt+w0ue3rk9d2yxqbhqhx8ybw9oynpmxzaegts711/wp37s/tcmqx+xoyrcpy+ip6eq/xuoaq2xptb8lo7ao7bhqqww7vfglg8rspwwq4b+mc7gl4ubgo9qi+vf2gqdmtk7is8feknskt3hqpsczzwlv1efp/sxlhrkp5eyjbrbin/gsbpyy8pcfohssjf0k29/4m15iwej1tq7o89m7e0hpk8i1iz4bpgfe8f+jvnlfrgdxkfx10+ej01kwxmi7mvo1wnweo0ljkvnmaw9tc1qvcrvtjust+8nmzldleae76oqbaujbq9ptdgklatoedsegjrwxfgco2+djhnljl1coxdczpx5q5ixhngi7li8mauaittpxtvjduaovu4ktdq9axbanhyreb4iisq0upkrnpyj1vdapuqihwduq0y4q9wbpbtzqp6bfdjnljrxfbwm2gbdsdzknvx4fpj3ahoqxz8rypzwayspowu5in7ezxemmmgtrkbqg7bwivjunngkdlcuo7lnq1oamy/amp+8txjuodztahmqqtl9afn1+c1bgqwjc3wtqaknnntumke4i6euqtwsagwwxi0yrtmthb0h0ocrln3e5rdasejnwe8akyqjtiuygkldevd8tlnoqq7fczxa/mqaoaujmfocuf9atmgh4kclsbeec6wxscwtj8/vg6q6phbar1wmtl2gsyrcoshncpvayvjimni5etbkwemmieshwwly8xjakqbt/4c0vzj0hlyhlcsgyoiip6yd0zgb3zatbgkqhkig9w0bcruxbgqeaqaaadbbbgkqhkig9w0bcrqxth5mahsanga1aeyamgawaeuamqayac0amga0aeeanwatadqaqqayadmalqbbaduamqawac0anaa0aeeanwazadyangbdaduamwa2adqaftbrbgkrbgeeayi3eqexxh5cae0aaqbjahiabwbzag8azgb0acaarqbuaggayqbuagmazqbkacaaqwbyahkacab0ag8azwbyageacaboagkaywagafaacgbvahyaaqbkaguacgagahyamqauadawghsvbgkqhkig9w0bbwagghsgmiiunaibadccfjugcsqgsib3dqehatacbgoqhkig9w0bdaegma4ecfoa6covleb1agih0iccfgi6t89ihdronyjmdh2xuohp3hc65ciuzvncd65cbfq3qqjssannbdfdrrfvg9vliaxmcpdkel9c5z6ykgdi+rnl447lfdbfhczkyxrmkfov+zdgz5bxkecsnaguewdxqkexfwsu8gusaiqec0pdq5fdj0ljvlbbm898fpy5xfjuly6t8jkkg9jgk5a4v1hzr719in2cd1qpptutb3ulrg6rve+yxnedkw2lnex+9xvsiky703zq9qkqira/7eqfumvcpalo4cfioc6h8gvoebn0kp/xd1l1oyhcpx38fv/c+fs3i8y2bjfghwlz1t8wtfycg+ibf3fmagxdpnq9fohgdc1tx/x/7epukhgi1y0x29qcxsl7qu35t0ezufcze8/yjlsc82sefxyiz11yqa2cfdu9cqplacrooultt4vubuqx7gwdmfnerxbf6ypwsmg+ps1sz5n/wtxm1xdjwxmtbr4xpmjmf7+dq8ogyaxtnqefrfkc8p3aeaqiamsjhftp0rm6eo/+e+9hltoyrjovoegaz081i7uuozoccaqsv/cuzx9qfdmh8g4o/v+9a3w3ums9ohw1y8tbsin4xwmxcgujali1ssjfctgtqokwfmbxrenjpv1ats9+9h5mtp5robo2d8if6i/is9p2bsml8he9qrouhk/uktlz1vbet5esj3i0kh2qybx3ft2huklatoz3f5ayl8ueszwtwxkodlgprih9pp9ewtyfflab3uos7rcnknmepnq+0gbgoaau/6blcjitd6lpa6rhx3ein6dz4eyu1sbq87p1blf7rnsq34od99z/ezqrxbmf6uxa3twe9mfgb3xcxwdnaphjq4rbslcba9gyx5mdpsw4rs2lq7idq0cwjjgw89j2guc87iegybjs+snnfs5s3nph2cp1dqgahhk/u9g00tu7ozb2onoczh12/0qzahqtzqc2phv+/5yxojzr/khglzsmurpwgyle2kmcx7hd3d1r6chdk85xcfkjzvzr+i61r2s2e28+nfcecncmulkwscj1swgndseig22bn1/hijm8hcaqhli77ihqk+flt+7nfzwunhocot5d+lpkw4nfm2vm+icyolswglhyyg0to3/sggpuv+ip9k4zlvyehjqctmn141nox8xqjs0adui5j6gqs6mxakdxmejmjefgsous/qam9e/diy2zve3ayzbmetrrb0ogszlwa+u55vmar8r+ei22+atlm5nmhy4dkoccwn5ztviohenvl+eeqyjhkibodxyqttivhhh7aufwg2eini+ierimxqammxlzcdecdeayko7aobdzoxdj+usvw0gw1gd9k++6d+csczlx/l8lzw9l7jdb19bxijmclt07ol0phfr1z0sfpgcsudw+qbel9yzabazntx0sr8ktqvvdq2uz4hxtm6a2ndr7j5ivu9a/pcvx5cmrf5fndvv0/f4wu5oqi5v2ugqgsdjl4g4txdshywttexo0n8qyp7+vkd8mhtc4u6vb1mh5kfsfjkwnv9kmtnsrhjd0kz2gocepwmapht7xwvz9if2s8yybebnhmu/sinos94or2ivjw/bltosgtabfxngysja7oxakmar+ugok0iny3zjbbc4nfshwsymgcqnpsypitbohdmeau/qnk7vdj2tymxdatd6ths7bvixigvyphceaqygntpn34gqhre2t7yrut1ndzv0xcleu6hqa3dam84qd/jbd4htqkiwzjtve0poza6qzgffggvbydviui0o0ofjtlv9slenbxp19ozwezhvbm5vj7o/szzbbjh8jrg0xxq1ybho7johtg5vzpuwilvipsxzlamkccdwzwm530zylzeddobs9zqz1xc74pqqbjo/i+ibw/l9+edeoahjep9ofmsfgowe6hqxwkyh/nmy5x7gv3g4x7hynuf4rui+6uyvswhagfzgs+byturc9tqmgz7vc5copevf1smm2mknnzg8vj+o+wkzbitwhjuedfovda4a7izag7sq49ywrfsswj1o3u2j+9gjzeoo00hmzk1rbgvqzubns94bkzchyjvwhukodx9i9c4+ticcj8y/s8e71hg/y0n7tato7qufa6vfxx7usvhzfoi/46abjjgsuzbxhw4lmm5fgfotl95gezsckwi3ssxugifokkkp7gkv8rizv4ixsdhz9ufb2mbrw3d9bvwevmqyynqq9nmkpg2vdg/pishs6vxscltt5unzft3zhlrsfwgscvsrm64gyjiyoxlcfxegrorfzuiudu+qvxcbpfy9xsmmmhvxxl64e3yvlwrze0b2nwc1+knmxupzhvm3qc4hmfz72hmpgpp+5ums+vyw+xkz4d9uzkice5wx2tllvur9jhqdm87r79nlijavn7i+ujeq8cu8uggpjm74vsuib4rx4fyiouy3t4/ycrfhaqfynz1mduaycou1rauw4vpeiuy7ycselnxprpktowv60ici/uorph627b4i9ae95izv7h8rdtrbvrwyxxv1a+czfeuuz/tt/zn+1wcbmdtrxbpgvab13di2ge0u9o2rfqmbnhlcacqjpg1t+uc6rf35qadovizxgyd28njyqp/cfqffwo0trnhagkhkdyrjrszij5zu7b7t+q/end4gkigmrwsc2osjf/odcimruyyfui6sstqbodty45kljl6ehojo61kgmsx+vob8qhy2d0ifvevdy7hur1xs8ytjfjvtllnwnfwaarwzlg87keqmdicnvblof+gpj5naonxpz7aeidynfm+d8it7pgzlorovk6ub3i93bglyjmpip5znxgdycuvhtntbjfnuaw4wr54tgvik7qtle+/keomz00s0ll9qurwa4k5mjo9avw9m1imnx1qnvammue6gk4xhvzth2kho+htouhlqoqawsbgyf363jgu1xz8phbuql+my/reszozcudmg9rem1con1vebpdu6k2tnow5uxd9xdih+melsydkxf8mkddijjalpqzzpsr1rj9k8u8fgv5odtl9dthlbygmeu+/rqnfa8y0/fg/3xf3f0lhg+mm6yhbp2crwglmmpgsjojiwwtfjp8crtxton5oa4yma/ev8h8mz6vnjxn+cqhu7qlbn7svesau4/b9hqwn0jx8jlv/l4m6qu/0yq+twfnviorouyvirpuiaqxeusjls/f7yxcbctxedldmnbfol8iwk5sylihwtfasaydmhzthwpnaf16r76ttkiyjaihpdabucvyya2mnzpxyddfwreeazsxe2fgd/tt1wrexipj53g6pzbyyogsp+9hxwhr69quysiyurpmdvu2llmehw/ssyetzh+cecs7lqhp7h/g8ihkzn7u93wachuju26xk/dkpr6deuywzzybpd+azocvjq85wm8e7xm8b3paodfbfoamynkhnsx8upiihfseol1o0r9rn4eczzaqp1xerrv7zv2eb9zbcq9xyue+ieszlxcqfrkkgowzqzpwgub7yny9e1b0gghdljaqzcbclryjgvxpp4uw9vzdzqvgxg6zle+l1823z23645xzojw9ketbey7g3un/sntiokznzazc7x86lxmazgjunvrksxgpfykvyd8ahnpl6qnqxen7mhphxiysyqr3j2yrvrnz2cysa0r+keh8cxvzperc4/gqfgmzetw/c+fpfzxrulrn9g8dofwmigw34etzereb4zix0xjwhgo2l8ohxwltpzeuqbt6nipm54bte6gkmvynon9y7blfcfp97dtrclxojp7gptogivawq6xsubxls15z5amhigvnwb363fs/wfqtrqqg9lnjhendab3qas39tjeyl0a4qnm+6+nu1rf906nam+qfopgd0hfodezwdyzjofow0srzde4asjm5ycfogxlbbgfvomoz+fynebeec6hornku830th7rck/lfud0+xe4c2wbrhnqe3rpdvxtjhanz3qpghawz/pcfypcmtlcxasakgoxmuc1fwnxixvbwbca1hs4ckyg1p/tseqevmetgoeim59y5ehajcvfnch8wssqxa3fpvsohqujhvesblx9mdlqaniae7rconj2qgkgkj1pkxadienvahdubemjwa+txraywq4u2mo0u+xks5gkow6/zvfmmssvwzjy1dnckxxn13ukh2fpze7kewlwxkreu9lgn1ycnegdyqj39fjkivyzzxzma03pnv99fw7d7qvvzu7okapub239j2sbql60pmx1nq7yj3juetbfpfebzqgpvzav3co2z/x9cfiir2b/br4bduw7lxy0ve63gieajxamv4+38au8m9pnn+zmso0+o8mbvkrqgy4dwd0dlktqaygcodtztce8qch2m+m7nv1lgj9pv4rafdanoaavbvbgxqgftdw55qvlf/tberoomgnldnbmspkib7c1klgmo2vimwvkohny9gps2r+r2dkgfl9wzz8ezv5jje1wqvmfxxzjofnrekc6imbbpbjrnsh54bzxfizoul3qaytvaojtddnbh8hutnxmxp5gprg4kw3uph0kgfdhpjpw2bqf5xcmlrj0qlxyl+y7ycskjkoffckzhve8tlwql9f1qdrbipbshxpqvcuv7hqz3+xqn+oh8l2urc1lypgoaz7kvghrecr8bibz33vlqfehu2gjahhb/n8pdd6a0ka9fqoyz6oetfa7zbewiyznvy39adyq3p0201inmcqunmqi99xna+xknfarrv/oamdacjrjv1/cnxq54igkhuhwch8+pnzrbtxhsmgsuz4srgbtbtpg4o8fxags6dcoqjuq6aiwuysrbuts2zxwhadhb3pktlh1yredlhqqkrsos/5zkkssrmz5+fby3iubntcillqibvigc4lll32pdbaupzdpqvmaad/p48qm7sih7kz0ysvjnhejzhautdes4c6kxo9itcn0jlmjedijwbezksgqtefvtny3ylr0wy2fhmadoz7bizsqlxzwzn4f1srmkaj13sx+4ljtiyur31d+jzabc580xab1b3djudbduuk7xigyhmslaavc5blyl2aagfyajrpzmqlsucnm8nsfguviinl/a4hvpsxql4grzydpkuyxwpi7hpudpsvt20+fr6pgx/xobpwilhse0aqsl4ifuc1nfpkupm51moymm4gz0t67hc3482epwpzoqcfotzhz8bhr/5pejj6/0j+sxnk2cl0exajvlscditlsuozcqmk67slreaeo0fxvnpho01kqdwrbco+rkdb7jag46fxunq3a8l8y0yz6/3whfbjudhsrx19hr4o4bl0tdrgk0eaofvclgnuivcnfbezohd4nvpx//ngc3qcwnjsorbadtecq/q2fqwkiu0xqwmkje/umotgjqovbve11sbwpfdkkwdhbfhhjzqm07qexz7mzc83niu/qpan9jhhezhrntcxs6aqskedn9j1bqzmlrocczp/0mxmuo4c9djqoxz60pf+ljagjo787i4pkvy5ihlmvcek28qr8wqvtltm99cpe4xqgztqubmwxkdzhrp7jufink7yufrcy82dfevmjmbqjuelbdytt+vdtia5jlcjrcajqhmaeuxxm37q4qlnm3tnzcactqoxdwia8c/plfnwql8ljitym9ufbhgg4yx0mjfjntkoiny2uivooivpgqzewnngcznwh5mcropkjkrjhrfuq7q+fgjl5q945ppzwuina0pyolguqfcn5oucvkiwgk6vqfnnmj+p1ygvj9bz2ux+epbrlup9kgxexyhjkt2dz8chqrtjm7y/kvzqkur6vswskk0umwlfjbc75qwjyuoyjxedodr+kk3/mexsdhoamseq20bovrfoexrfpxabetx4sqaur3lstxnhatx37dd1zepnvb8k7dkdetaqzy5jziwc8gvmatlnqchzsh6z6qbcvi1biuoj9yucggf2qd8tj1+0tnkjriyllcm79ajn3isqdjevozv3gqpc89wahtna9av7jeluns8c4n+wcd5s8wrz8ulnvavngu08ugs8ugddp7zz+ymzv1qmacpwn29534y1iw/iajgyc+eq1u3r6cjgmv9tfwexfeh/qgvyeccnprnwpdrktiu1qw5ln5o+rihqmb0bqh5o9me/32si4ashxgdljqo+isijcfe2bvtiimieu/0xwe7qzxsbmwgojvr4xnjglctqx1d+2kwyafo0dxohhmk6aybvdejebmpbe1vesakd4lrrm/muy+mq6udrk4xw0vkhd16hgoqylbj8iedofpvkc8kbql+ivpwuilxamjoomhy7jwjp3bbfom3eq8hn73ypx292p4hfm48pusczpi+bgebflyjh3puywqx+uizruyom30gmrcxna7d5dt8ecvk8ctjm+b1luyjmqscoksauxf9o5cqgoxw/qqxxab5bgxm+njkl745y10uaq5+z/us1wxest3oilzea4yvayzbbdgsc3msi995v2imj9nccprbhfrnyhfghpjjrrinx/gxxbavvac2ywxduuksy03yareshklsjyluttrcozn6l+yjnidqtyj06kr8mwermazh7nbyid0nfukgpva5/pf3suv902ssl5s6zbjeconbxxkp/ifv1b9lispm3dlyvfrtiskh4uiecjulqhha2bxsosr6kylfadju17pdcw5mp63zpymvjf6h9fax0zibckvjfp4oj/igiemusc3y2k3dos3xbfn5wdwvxxgvfzvzqfrfu/mk7hmoircbb8/wnrsjy3cpdwrdjfsyfobusgusaau7svj1xkchvmce9chvyvdtckfplv5vwcnvtv1aqedtcei+8egvbdip4cfouspgbyekzvkunmvbrp+ayhhqz9qf59w6mkdcik6xgfmdswhzahbgurdgmcggquqgx8sjj8lp0o36tk3odzr7zxh1qefploagogbh/w4/w4uin3r7jur7g6agih0a==", "password" "password" }' response { "result" { "info" \[ { "message" "import certificates is successful" } ] } } delete s/mime certificate to delete s/mime certificate query parameter 'certificate type' must be 'smime certificate' request curl x 'delete' \\ 'https //10 10 10 10/api/v1/system/certificates/device certificate?operation=import' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' \\ h 'accept application/json' response { "result" { "info" \[ { "message" "import certificates is successful" } ] } } fetch expiry dates for certificates to fetch expiry dates for certificates of given types request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/certificates/expiring certificates' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "cert types" \[ "device cert", "trusted client ca", "trusted server ca", "code signing cert", "client auth cert" ], "expiry duration" 100 }' response { "result" \[ { "certificate" "trustis fps root ca", "certificate type" "trusted server ca", "expiry date" "sun 2024 01 21 11 36 54 gmt" }, { "certificate" "vrk gov root ca", "certificate type" "trusted server ca", "expiry date" "mon 2023 12 18 13 51 08 gmt" } ] } mapping thumbprint to interfaces to map thumbprints to interfaces beginning with ics 22 7r2 6 onwards, thumbprint must be used as identifier instead of the serial number in the certificate apis request get /api/v1/configuration/system/configuration/certificates/device certificates/device certificate/{thumb print} host \<ip address> authorization basic ywrtaw5kyjpkyw5hmtiz content type application/json response http/1 1 200 ok content type application/json { "device certificate" \[ { "href" "/api/v1/configuration/system/configuration/certificates/device certificates/device certificate/0a%3a90%3a0d%3ad0%3ae6%3aaf%3ac8%3a7e", "thumb print" "da 51\ fd\ fc 73\ a1 8f\ d6\ e5\ c1 49 2e 98\ dc\ ce 5d\ ac\ c8\ b4 71\ f9\ a4 73\ ab\ af 2d 61\ e9 73 56\ f3\ e8" } ] } request put /api/v1/configuration/system/configuration/certificates/device certificates/device certificate/da%3a51%3afd%3afc%3a73%3aa1%3a8f%3ad6%3ae5%3ac1%3a49%3a2e%3a98%3adc%3ace%3a5d%3aac%3ac8%3ab4%3a71%3af9%3aa4%3a73%3aab%3aaf%3a2d%3a61%3ae9%3a73%3a56%3af3%3ae8 "{ "internal ports" { "internal port" \["\<internal port>"] }, "thumb print" "da 51\ fd\ fc 73\ a1 8f\ d6\ e5\ c1 49 2e 98\ dc\ ce 5d\ ac\ c8\ b4 71\ f9\ a4 73\ ab\ af 2d 61\ e9 73 56\ f3\ e8" }" response { "content type" "application/json", "content length" "128" } "{ "result" { "warnings" \[ { "message" "operation succeeded without warning or error!" } ] } }" network management creating a vlan to create a vlan on a cluster node request post /api/v1/configuration/system/network/vlans/node88/vlan/ http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json { "arp cache" { "arp entry" \[] }, "name" "vlan int 1", "routes" { "route" \[] }, "settings" { "default gateway" "\<ip address>", "default vlan interface" "false", "enable ipv6" "enabled", "ip address" "\<ip address>", "ipv6 address" "\<ipv6 address>", "ipv6 default gateway" "\<ipv6 address>", "ipv6 prefix length" "64", "is enabled" "enabled", "netmask" "\<ip address>", "vlan id" "2", "vlan parent" "0" }, "virtual ports" { "virtual port" \[] } } response http/1 1 201 created content length 128 content type application/json { "result" { "warnings" \[ { "message" "the configuration has been implicitly changed" } ] } } deleting a vlan to delete a vlan from cluster node request delete /api/v1/configuration/system/network/vlans/node88/vlan/vlan int 1 http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json response http/1 1 204 no content content length 0 content type application/json collect arp cache trigger update to collect arp cache entries for specific port request curl x 'post' \\ 'https //10 10 10 10/api/v1/network/arp cache?port=20' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' \\ d '' response { "result" { "info" \[ { "message" "successfully triggered an update to collect all the internal port arp entries" } ] } } collect ndp cache trigger update to collect ndp cache entries request curl x 'post' \\ 'https //\<ics ip>/api/v1/network/ndp cache?operation=triggerupdate' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' \\ d '' response { "result" { "info" \[ { "message" "successfully triggered an update to collect all the ndp entries" } ] } } delete all arp cache to delete all arp cache entries for a specific port request curl x 'delete' \\ 'https //\<ics ip>/api/v1/network/arp cache/ports/test' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "result" { "info" \[ { "message" "successfully deleted arp cache from 'internal' port" } ] } } delete all ndp cache delete all ndp cache entries for a specific port request curl x 'delete' \\ 'https //\<ics ip>/api/v1/network/ndp cache/ports/test' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "result" { "info" \[ { "message" "successfully deleted ndp cache from 'internal' port" } ] } } delete ndp cache of specific port flush ndp cache entries for a specific port request curl x 'delete' \\ 'https //\<ics ip>/api/v1/network/ndp cache/ports/test/flush ndp entries' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "result" { "info" \[ { "message" "successfully flushed ndp entries from 'internal' port" } ] } } fetch port status to get status of all ports request curl x 'get' \\ 'https //\<ics ip>/api/v1/network/ports/status' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "external" { "connected" "yes", "duplex" "full", "name" "external", "rxdrop" "48449", "rxerror" "0", "rxmulticast" "158218", "rxpacket" "130181285", "speed" "10000mb/s", "txdrop" "0", "txerror" "0", "txmulticast" "0", "txpacket" "435254" }, "internal" { "connected" "yes", "duplex" "full", "name" "internal", "rxdrop" "48504", "rxerror" "0", "rxmulticast" "158218", "rxpacket" "141565698", "speed" "10000mb/s", "txdrop" "0", "txerror" "0", "txmulticast" "0", "txpacket" "9842276" }, "management" { "connected" "yes", "duplex" "full", "name" "management", "rxdrop" "48450", "rxerror" "0", "rxmulticast" "158218", "rxpacket" "130183315", "speed" "10000mb/s", "txdrop" "0", "txerror" "0", "txmulticast" "0", "txpacket" "439559" }, "vlan port int 1" { "connected" "yes", "duplex" "full", "name" "vlan port int 1", "rxdrop" "0", "rxerror" "0", "rxmulticast" "0", "rxpacket" "0", "speed" "10000mb/s", "txdrop" "0", "txerror" "0", "txmulticast" "0", "txpacket" "3" } } to get status of a specific port request curl x 'get' \\ 'https //\<ics ip>/api/v1/network/ports/test/status' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "connected" "yes", "duplex" "full", "name" "internal", "rxdrop" "48541", "rxerror" "0", "rxmulticast" "158440", "rxpacket" "141770609", "speed" "10000mb/s", "txdrop" "0", "txerror" "0", "txmulticast" "0", "txpacket" "9855017" } fetch source ip of interfaces fetch the source ipv4 and ipv6 addresses of vlan request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/user roles/vlansourceip' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "internal port ip" "interface ip (10 204 62 218|fd70 1889 79fb 63 acc 3eda)", "vlan0 int0" "interface ip (10 204 62 118)" } uploading ueba\ esap package request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/maintenance/upload/\<ueba or esap>' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type multipart/form data' \\ f 'filename=' \\ f 'activate=' response { "result" { "info" \[ { "message" "successfully installed and activated ueba/esap package " } ] } } system information and operations fetch system information to get system hardware and software details request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/system information' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "rollback partition information" { "build" "948", "os name" "ive sa", "os version" "22 7r2" }, "software inventory" { "software" { "build" "1056", "name" "ive os", "type" "operating system", "version" "22 7r2" } }, "system information" { "cpu cores" { "active" 12, "licensed" 4 }, "hardware model" "isa4000 v", "host name" "localhost2", "hypervisor" "vmware", "machine id" "vasph327i49so7wcs", "os name" "ive sa", "os version" "22 7r2", "serial number" "vasph327i49so7wcs" } } fetch host id and secure id to fetch host id and secure id file creation time for all nodes request curl x 'get' \\ 'https //\<ics ip>/api/v1/configuration/auth/ace server/log table' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "node 1" { "host" "this node", "time" "2023 11 01 14 16 42 utc" } } fetch system overview status and ntp status to fetch the system overview page details request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/status/overview' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "active sync connections" 0, "cluster member status" \[ { "enabled" false, "name" "localhost2", "notes" "disabled", "status code" "0x8001" } ], "concurrent connections for authorization only access" 1, "last config update" { "device" "sat dec 23 05 06 21 2023" }, "logging disk" "0% full", "max licensed users" 2, "signed in users" { "default network" 1, "device" 1 }, "system date and time" "fri dec 22 15 15 41 2023", "uptime" { "days" 9, "hours" 14, "minutes" 47, "seconds" 4 } } to fetch the ntp status request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/status/ntp' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "ntp server status" { "216 239 35 0" { "delay" "93 425", "jitter" "2188 68", "offset" " 9852 2", "pool" "8", "reach" "377", "refid" " goog ", "remote ntp server" "216 239 35 0", "stratum" "1", "type" "u", "when" "5" } } } fetch the current time to fetch the current time (epoch time), iso date time (yyyy mm ddthh🇲🇲ss) and time zone request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/date time' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "current time" 1698873402, "iso date time" "2023 11 01t14 16 42", "time zone" "(gmt 08 00) pacific time (us & canada); tijuana" } set system date and time to set the system date and time request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/date time' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "iso date time" "2000 01 15t12 57 00" }' response { "result" { "info" \[ { "message" "updated time successfully" } ] } } disk usage monitoring fetch the current disk utilization information request curl x 'get' \\ 'https //10 10 10 10/api/v1/system/maintenance/disk usage' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "output" \[ { "avail" "6 1g", "filesystem" "/dev/mapper/runtime", "mounted on" "/data", "size" "8 6g", "use%" "26%%", "used" "2 1g" }, { "avail" "3 7g", "filesystem" "/dev/mapper/swap", "mounted on" "/tmp", "size" "4g", "use%" "1%", "used" "10 1k" } ] } disk cleanup cleanup the disk space by deleting temporary/log files request curl x 'put' \\ 'https //10 10 10 10/api/v1/system/maintenance/disk cleanup' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "deleted" \[ "admin access, user access and events logs", "snapshots", "tcp dump", "core files", "postgresql log files", "temporary archive files", "all debug logs", "staged/leftover packages", "html5 cache" ], "info esap" "2 esap packages are installed remove unused packages to free additional disk space ", "status" "disk cleanup completed successfully " } session management fetching active number of html5 sessions request curl k u \<api key> https //\<ics ip>/api/v1/stats \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' example curl k u tv6yqpetdvoxeo0lckcofweq5qeet2wsto8gbililta= https //\<ip address>/api/v1/stats response content type application/json { "active advanced html5 sessions" { "active advanced html5 sessions rdp" 0, "active advanced html5 sessions ssh" 0, "active advanced html5 sessions telnet" 0, "active advanced html5 sessions total" 2, "active advanced html5 sessions vnc" 0 }, "cpu load" { "average cpu load" "0 33", "dsagentd load" "0 00", "is cpu overloaded" "false", "is dsagentd overloaded" "false" } } fetching active number of advanced html5 sessions request curl k u \<api key> https //\<ics ip>/api/v1/stats/active advanced html5 sessions \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' example curl k u tv6yqpetdvoxeo0lckcofweq5qeet2wsto8gbililta= https //\<ip address>/api/v1/stats/ active advanced html5 sessions response content type application/json { "active advanced html5 sessions rdp" 0, "active advanced html5 sessions ssh" 0, "active advanced html5 sessions telnet" 0, "active advanced html5 sessions total" 2, "active advanced html5 sessions vnc" 0 } delete all active user to delete all active user sessions request curl x 'delete' \\ 'https //10 10 10 10/api/v1/system/active users?all=all' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept / ' response { "result" { "errors" \[ { "message" "unsupported api " } ] } } delete active user sessions to delete a list of user sessions based on their sid or session unique id request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/active users/delete sessions' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "sessions" \[ "sid26a79db9e2beca93d70025cc37abaa7c42b1e810085ffcbd", "sessionuniqueid28d11ff39a" ] }' resoponse { "result" { "errors" \[ { "message" "missing required param 'sessions', an array of session ids corresponding to the sessions to be deleted " } ] } } fetch active users to get details of active user sessions on the device refresh dynamic policy evaluation for single or all auth realms, or retrieve filtered active user sessions the field is last recordcan be used in script to get the list of all the active users in a loop is last record set to false, if there are more users it sets to true, when the gateway returned the last list of users request curl x 'post' \\ 'https //10 10 10 10/api/v1/system/active users' \\ h 'accept application/json' \\ h 'content type application/json' \\ d '{ "start" 1, "number" 50, "realm" "users", "role" "fullaccess", "primary auth server name" "system local", "hc status" "fully compliant" }' response { "active users" { "active user records" { "active user record" \[{ "active secondary user name" null, "active user name" "user1", "agent type" "mozilla/5 0 ", "authentication realm" "users", "browser id" "c02a789746114cb426183cae3ade8513", "device id" null, "endpoint security status" "fully compliant\npassed policies hc policy\nfailed policies \neliminated roles ", "events" 0, "hc failed reasons" null, "login node" "localhost2", "mac address" null, "network connect ip" null, "network connect ipv6" null, "network connect transport mode" null, "ngp session id" "173a229e9a", "primary auth server name" "system local", "primary auth server type" "local authentication", "pulse client version" null, "secondary auth server name" null, "secondary auth server type" null, "session id" "sid8d40db34996df948e870fb097b2b07c20555e8dc00000000", "sign in time micro" "1699327095 643966", "source ip" "10 96 224 53", "user roles" "fullaccess", "user sign in time" "2023/11/07 08 48 15" }] }, "total matched record number" 1, "total returned record number" 1, "is last record" true, "user login permission" true } clustering and high availability test connectivity of a cluster node tests connectivity for configured auth servers, node ip and dns request curl x 'post' \\ 'https //10 10 10 10/api/v1/system/platform?operation=testconnectivity' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' \\ h 'content type application/json' \\ d '{ "node" "test1" }' response { "result" \[ "destination host 10 204 63 254 used as gateway address is responding", "destination host 10 64 0 10 used as dns server is responding", "destination host 10 20 20 20 used as radius server is not responding", "destination host 10 30 30 30 used as nis server is not responding", "destination host 10 40 40 40 used as ldap server is not responding", "destination host a com used as mdm server is not responding" ] } rebooting cluster node to reboot cluster node request post /api/v1/system/maintenance http/1 1 host \<ip address> authorization basic ywrtaw4xomrhbmexmjm= content type application/json { "operation" "reboot node" } response http/1 1 200 ok content type application/json { "name" "{ "result" { "info" \[ { "message" "successfully triggered reboot of cluster node" } ] } }" } rebooting entire cluster to reboot entire cluster request post /api/v1/system/maintenance http/1 1 host \<ip address> authorization basic ywrtaw4xomrhbmexmjm= content type application/json { "operation" "reboot cluster" } response http/1 1 200 ok content type application/json { "name" "{ "result" { "info" \[ { "message" "successfully triggered reboot of entire cluster" } ] } }" } user realm creating a user realm to create a user realm request post /api/v1/configuration/users/user realms/realm/ http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json { "accounting server" "none", "authentication group" "", "authentication policy" { "browser" { "customized" "any user agent", "user agent patterns" { "user agent pattern" \[] } }, "certificate" { "cert key value pairs" { "cert key value pair" \[] }, "customized" "allow all users" }, "host checker" { "enforce all policies" "false", "enforce policy list" null, "evaluate all policies" "false", "evaluate logic" "all policies must succeed", "evaluate policy list" null }, "limits" { "guaranteed minimum" null, "limit concurrent users" "false", "max sessions per user" "1", "maximum" null }, "password" { "primary password expiration warning days" "14", "primary password management" "true", "primary password minimum length" "4", "primary password restricted" "allow passwords of minimum length", "secondary password expiration warning days" "14", "secondary password management" "false", "secondary password minimum length" "4", "secondary password restricted" "allow passwords of minimum length" }, "source ip" { "apply ip rules" "true", "apply location rules" "true", "customized" "selected ip locations", "ips" { "ip" \[ { "access" "allow", "address" "1 1 1 1", "netmask" "255 255 255 0" } ] }, "locations" { "location" \[ { "access" "allow", "address" "afghanistan" } ] } } }, "authentication server" "ad server", "description" "", "device server" "none", "directory server" "ad server", "dynamic policy" { "dynamic policy evaluation" "false", "refresh interval" "60", "refresh policies" "false", "refresh roles" "false" }, "editing description" "false", "migration sharing type" "enable session migration", "name" "rest user realm", "role mapping rules" { "rule" \[ { "name" "rest admin rule", "roles" \[ "test1" ], "stop rules processing" "false", "user name" { "test" "is", "user names" \[ "user1" ] } } ], "user selects role" "false", "user selects roleset" "false" }, "secondary authentication settings" { "authentication must succeed" "true", "name" " ", "password input" "user", "predefined password" "", "predefined user name" "", "user name input" "user" }, "session migration" "false" } response http/1 1 201 created content length 122 content type application/json { "result" { "info" \[ { "message" "operation succeed without warning or error!" } ] } } deleting a user realm to delete a user realm request delete /api/v1/configuration/users/user realms/realm/rest user realm http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json response http/1 1 204 no content content length 0 content type application/json user roles creating a user role to create a user role request post /api/v1/configuration/users/user roles/user role/ http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json { "name" "rest userrole 4", "web" { "web bookmarks" { "bookmark" \[ { "auto allow" "disable", "description" "", "name" "web bm 1", "new window" "false", "no address bar" "false", "no tool bar" "false", "parent" " none ", "standard" { "url" "http //www msn com" } } ] }, "web options" { "browsing untrusted sslsites" "true", "flash content" "false", "hpxproxy connection timeout" "1800", "http connection timeout" "240", "java applets" "true", "mask hostname" "false", "persistent cookies" "false", "rewrite file urls" "false", "rewrite links pdf" "false", "unrewritten page newwindow" "false", "user add bookmarks" "false", "user enter url" "false", "users bypass warnings" "false", "warn certificate issues" "true", "websocket connection timeout" "900" } } } response http/1 1 201 created content length 122 content type application/json { "result" { "info" \[ { "message" "operation succeed without warning or error!" } ] } } fetching the user login statistics to fetch the user login statistics request get /api/v1/system/user stats http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json response http/1 1 200 ok content length 169 content type application/json { "user stats" { "allocated user count" "25", "current user count" "0", "max active user count 24hrs" "1", "min active user count 24hrs" "0" } } updating the user role settings to update the user role settings request put /api/v1/configuration/users/user roles/user role/rest userrole 4 http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json { "name" "rest userrole 4", "web" { "web bookmarks" { "bookmark" \[ { "auto allow" "disable", "description" "", "name" "web bm 1", "new window" "false", "no address bar" "false", "no tool bar" "false", "parent" " none ", "standard" { "url" "http //www yahoo com" } } ] }, "web options" { "browsing untrusted sslsites" "true", "flash content" "false", "hpxproxy connection timeout" "1800", "http connection timeout" "240", "java applets" "true", "mask hostname" "false", "persistent cookies" "false", "rewrite file urls" "false", "rewrite links pdf" "false", "unrewritten page newwindow" "false", "user add bookmarks" "false", "user enter url" "false", "users bypass warnings" "false", "warn certificate issues" "true", "websocket connection timeout" "900" } } } response http/1 1 200 ok content length 122 content type application/json { "result" { "info" \[ { "message" "operation succeed without warning or error!" } ] } } deleting a user role to delete a user role request delete /api/v1/configuration/users/user roles/user role/rest userrole 4 http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json response http/1 1 204 no content content length 0 content type application/json delete user records delete user records using rest api request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/delete records' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' \\ h 'content type application/json' \\ d '{ "cleanup limit" 2, "max limit" 2 }' response { "result" { "info" \[ { "message" "successfully deleted user records " } ] } } saml fetch saml service provider fetch settings for ics acting as saml service provider request curl x 'get' \\ 'https //\<ics ip>/api/v1/saml config/sp?name=test\&peersp=test' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' \\ h 'accept application/json' response { "download url" "/dana admin/auth/servers cgi?sdpauthname=saml1", "idp entity id" "https //www domain com", "idp issuer" "https //www domain com", "idp signing certificate" " begin certificate miifijcca3iccqcmxmkkhadnetanbgkqhkig9w0baqsfadcbhjelmakga1uebhmc\nwfgxejaqbgnvbagmcvn0yxrltmftzterma8ga1uebwwiq2l0eu5hbwuxfdasbgnv\nbaomc0nvbxbhbnloyw1lmrswgqydvqqldbjdb21wyw55u2vjdglvbk5hbwuxhtab\nbgnvbammfenvbw1vbk5hbwvpckhvc3ruyw1lmb4xdtizmtewmjawmde1nloxdtmz\nmtazmdawmde1nlowgyyxczajbgnvbaytalhymriweaydvqqidaltdgf0zu5hbwux\netapbgnvbacmcenpdhloyw1lmrqwegydvqqkdatdb21wyw55tmftztebmbkga1ue\ncwwsq29tcgfuevnly3rpb25oyw1lmr0wgwydvqqddbrdb21tb25oyw1lt3jib3n0\nbmftztccaiiwdqyjkozihvcnaqebbqadggipadccagocggibanffus4btynelgkz\nl4tnqelfusa+uet2xh1q7m219roq3pxib4jm2qd3uphlk6hkdwgimv19xl2b1oy3\n7xyvueegpkkbximnqqsygtt1ucazhbgstn3rps5bqkf6joogxf4w9lrvsk5w6nck\ngna4ibsodnizumjb0pgory1b7ae64g3ipmfnxripugvzom4vyeaycbhptsuzcnjm\n/vvm5damhcf1gvmutqsnn289xkdn/lpd+rxlh6zqf1iuqwpkg9mq6dviiuikcxub\nwi6nhnckw9ioebjedonhuh3nndgmpmtszb2azdnxi8xhyhic+ks7f73fotnd05rc\nipwgtydibo+e0vdybp1zdfgus7ex8goqljrzcxqnizob7de3w8xwte8cd4/u/rym\nejegsjiwxjebfo1xajao/ui+nscfnytjxfmcp8bkgkevkl2mpc6jjgoj/en2cqte\nffe5adh1qvjahrzrff7rz1y3kk9eebl2jeilwesabun2utx+2wrado++y2a9+y9/\nvj4byp1aigijlxzxaa70dez6tfchm/kzhtkszsm0jbfdv/xwrr2i5zqojsaipkur\nrgngdzwaex2rr5rv6qgw+2w0nixq0dzbhemnetbhhtmf3kayaxjvj2qv11xty56p\njkqiftjz2j8fp3tsc47gxqdxufq5agmbaaewdqyjkozihvcnaqelbqadggibaiyh\ncyicgkzfzuonml4tcc3p1ru9louglav5a9semp6vrjpjuf2z8hitt5mojr79e8sc\nf5xe0gxj5gqbmpmt4uxyjngtbd/vg7awk5/kxzaadzddinaszcmlemt0npqk6bwc\neqfgjrsvnjnf3os4wcsa712aijt7jfymycdeu5avetrmv8xekk3s3wajj0vfdiyx\nlaksgdcmg055w8hwgzydqe6voelwvqi35tqkxnkkfyf6+6fprqoj7h8mlaloflpo\nsea5oobpzxnd83lbbltm7v57hkwoolbfv4vi7ffus2qauganp+uw84tmmnzhyqqf\nxixqtqws8ns6tgoia+aspstexpa/ixmqpn0gqlrkitxenewprgw+lvxdgyf5ou3m\np5c7c7cpcakf7lacaa0tofcahmlb/axqyesijhno3eycvqztql+wadke+7eemklh\nnnyu5wem6qmapqb4bqzg8pxrdgamjlpgufiypg4aabhns81m8wo8nsigwzfudzpx\njfha4lm53joos44bwzbvcjonyuwpveavlvxhwidmwr7pl2suupgn9co44niqpbrk\niyt9yp2/leiljlwmkqieiwpmx5qmo9w+e00eanbm/+/cq7moc7lbdsuvipguzjhm\n5qojleit3tg6ndazpkrptru4tfub2wgj1ezkpz5q\n end certificate , "idp slo service" "https //www domain com/slo", "idp transfer url" "https //www domain com/transfer", "status" "success", "zta auth sp acs url" "https //sso pulsesecureaccess net/dana na/auth/saml consumer cgi", "zta auth sp entity id" "https //sso pulsesecureaccess net/dana na/auth/saml endpoint cgi?p=sp1" } fetch metadata for a saml to fetch metadata for specified saml auth server request curl x 'post' \\ 'https //\<ics ip>/api/v1/saml config/test/download metadata' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' \\ h 'accept application/json' \\ d '' response { "result" "\<md\ entitydescriptor xmlns\ md=\\"urn\ oasis\ names\ tc\ saml 2 0\ metadata\\" cacheduration=\\"p9999dt0h0m0s\\" entityid=\\"https //sso pulsesecureaccess net/dana na/auth/saml endpoint cgi?p=sp1\\">\<md\ spssodescriptor protocolsupportenumeration=\\"urn\ oasis\ names\ tc\ saml 2 0\ protocol\\">\<md\ singlelogoutservice binding=\\"urn\ oasis\ names\ tc\ saml 2 0\ bindings\ http redirect\\" location=\\"https //sso pulsesecureaccess net/dana na/auth/saml logout cgi?spid=sp1\\"/>\<md\ nameidformat>urn\ oasis\ names\ tc\ saml 1 1\ nameid format\ unspecified\</md\ nameidformat>\<md\ nameidformat>urn\ oasis\ names\ tc\ saml 1 1\ nameid format\ emailaddress\</md\ nameidformat>\<md\ nameidformat>urn\ oasis\ names\ tc\ saml 1 1\ nameid format\ x509subjectname\</md\ nameidformat>\<md\ nameidformat>urn\ oasis\ names\ tc\ saml 1 1\ nameid format\ windowsdomainqualifiedname\</md\ nameidformat>\<md\ nameidformat>urn\ oasis\ names\ tc\ saml 2 0\ nameid format\ kerberos\</md\ nameidformat>\<md\ nameidformat>urn\ oasis\ names\ tc\ saml 2 0\ nameid format\ entity\</md\ nameidformat>\<md\ nameidformat>urn\ oasis\ names\ tc\ saml 2 0\ nameid format\ transient\</md\ nameidformat>\<md\ assertionconsumerservice binding=\\"urn\ oasis\ names\ tc\ saml 2 0\ bindings\ http post\\" location=\\"https //sso pulsesecureaccess net/dana na/auth/saml consumer cgi\\" index=\\"1\\" isdefault=\\"1\\"/>\</md\ spssodescriptor>\</md\ entitydescriptor>" } fetch status of saml idp configuration to fetch status of saml idp configuration and the url to download idp metadata request curl x 'get' \\ 'https //\<ics ip>/api/v1/saml config/idp' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' \\ h 'accept application/json' response { "download url" "/dana admin/auth/signinsamlmdp cgi?download=true", "idp entity id" "https //sso pulsesecureaccess net/dana na/auth/saml endpoint cgi", "saas apps sp entities" \[], "status" "success" } fetch idp signin metadata request curl x 'post' \\ 'https //\<ics ip>/api/v1/saml config/idp/download signin metadata' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' \\ h 'accept application/json' \\ d '' response { "result" "\<md\ entitydescriptor xmlns\ md=\\"urn\ oasis\ names\ tc\ saml 2 0\ metadata\\" cacheduration=\\"p365dt0h0m0s\\" entityid=\\"https //sso pulsesecureaccess net/dana na/auth/saml endpoint cgi\\">\<md\ idpssodescriptor wantauthnrequestssigned=\\"1\\" protocolsupportenumeration=\\"urn\ oasis\ names\ tc\ saml 2 0\ protocol\\">\<md\ keydescriptor use=\\"signing\\">\<ds\ keyinfo xmlns\ ds=\\"http //www w3 org/2000/09/xmldsig#\\">\<ds\ x509data>\<ds\ x509certificate>\nmiienzcca4egawibagiidyhjrddysduwdqyjkozihvcnaqelbqawcjelmakga1ue\nbhmcpz8xczajbgnvbagmaj8/mqswcqydvqqhdai/pzepma0ga1uecgwgsxzhbnrp\nmqswcqydvqqldai/pzeymbyga1ueawwpchvsc2vzzwn1cmuubmv0mrewdwyjkozi\nhvcnaqkbfgi/pzaefw0ymzewmzaymti3mdjafw0yota0mjeymti3mdjamhixczaj\nbgnvbaytaj8/mqswcqydvqqidai/pzelmakga1uebwwcpz8xdzanbgnvbaombkl2\nyw50atelmakga1uecwwcpz8xgdawbgnvbammd3b1bhnlc2vjdxjllm5ldderma8g\ncsqgsib3dqejarycpz8wggeima0gcsqgsib3dqebaquaa4ibdwawggekaoibaqdi\nqhys1pubhp18rupw0dzrgd2ul/fwapuytorae6q92j575007aqlmjhetxof7bq7c\nlitlr19xuw/ocxoajbltol9a1sbidkzmi0nymks7a9zunm2nkrx77ij8fee0cnqw\ncv1pome6qf3xbgiv35ou6in8sgbk8oo7vwfg/bw7b7vwryxylejvqpc2wgar/vwl\nqhdic/fbak7zibfmxwavs5fxogxo/zigh9pbdzualicoqgtnsnuotlsbm1o/17yd\nm1cti1byiqzldkb4vcjsdivt+s6yeb+foj5e1qnse/ewo2nbstlij6lvahffj3vc\n4qrhja5y3lrgwjjdm07vagmbaagjgge3miibmzajbgnvhrmeajaambegcwcgsagg\n+eibaqqeawigqdazbglghkgbhvhcaq0ejhykt3blblnttcbhzw5lcmf0zwqgu2vy\ndmvyienlcnrpzmljyxrlmb0ga1uddgqwbbqsnreiyq0w4r91wlueacoeuhvcazcb\nmqydvr0jbigrmigooxakddbymqswcqydvqqgewi/pzelmakga1uecawcpz8xczaj\nbgnvbacmaj8/mq8wdqydvqqkdazjdmfudgkxczajbgnvbasmaj8/mrgwfgydvqqd\nda9wdwxzzxnly3vyzs5uzxqxetapbgkqhkig9w0bcqewaj8/ghqttluisnvfsnsk\n4dmoe9oau1eqntaobgnvhq8baf8ebamcbaawewydvr0lbawwcgyikwybbquhawew\ndqyjkozihvcnaqelbqadggebadojxbvjip1qspgfqtvjtdt5lxe+l4vqee6bbiak\njtjt0drj6svlptxvyuxhc74efcwgpdd4f+qobno6k6wgxsvbnff7egccqhpbio2p\ngu3n27dj6mqpd+satdw0xmfedsnxwv0nvvrjyx+b8yrzgnxoly0xi2lxu9uqcwwl\nkuhdpqwehnug/8bzun5b/xzwjnqtbsjvkhv8sima7vst2olqyod6jvbsjjswgqca\nmyr949uz8ndhoeoxtpn8lsiwe1e73ojxpov57au991fp1txmqikz6ju209dmv1mq\nhfchwcyde6rmicmjbdbp9csbttpug9qqclg0fg/blojrk/4=\n\</ds\ x509certificate>\</ds\ x509data>\</ds\ keyinfo>\</md\ keydescriptor>\<md\ artifactresolutionservice binding=\\"urn\ oasis\ names\ tc\ saml 2 0\ bindings\ soap\\" location=\\"https //sso pulsesecureaccess net/dana ws/saml20 ws\\" index=\\"1\\" isdefault=\\"1\\"/>\<md\ singlelogoutservice binding=\\"urn\ oasis\ names\ tc\ saml 2 0\ bindings\ http redirect\\" location=\\"https //sso pulsesecureaccess net/dana na/auth/saml logout cgi\\"/>\<md\ nameidformat>urn\ oasis\ names\ tc\ saml 1 1\ nameid format\ unspecified\</md\ nameidformat>\<md\ nameidformat>urn\ oasis\ names\ tc\ saml 1 1\ nameid format\ emailaddress\</md\ nameidformat>\<md\ nameidformat>urn\ oasis\ names\ tc\ saml 1 1\ nameid format\ x509subjectname\</md\ nameidformat>\<md\ nameidformat>urn\ oasis\ names\ tc\ saml 1 1\ nameid format\ windowsdomainqualifiedname\</md\ nameidformat>\<md\ singlesignonservice binding=\\"urn\ oasis\ names\ tc\ saml 2 0\ bindings\ http redirect\\" location=\\"https //sso pulsesecureaccess net/dana na/auth/saml sso cgi\\"/>\<md\ singlesignonservice binding=\\"urn\ oasis\ names\ tc\ saml 2 0\ bindings\ http post\\" location=\\"https //sso pulsesecureaccess net/dana na/auth/saml sso cgi\\"/>\</md\ idpssodescriptor>\</md\ entitydescriptor>" } fetch metadata for a metadata provider fetch metadata for specified metadata provider request curl x 'post' \\ 'https //\<ics ip>/api/v1/saml config/test?operation=download saml metadata' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' \\ h 'accept application/json' \\ d '' response { "result" "\<md\ entitydescriptor xmlns\ md=\\"urn\ oasis\ names\ tc\ saml 2 0\ metadata\\" entityid=\\"https //sso pulsesecureaccess net/dana na/auth/saml endpoint cgi?p=sp1\\">\<md\ spssodescriptor wantassertionssigned=\\"0\\" protocolsupportenumeration=\\"urn\ oasis\ names\ tc\ saml 2 0\ protocol\\">\<md\ assertionconsumerservice binding=\\"urn\ oasis\ names\ tc\ saml 2 0\ bindings\ http redirect\\" location=\\"https //sso pulsesecureaccess net/dana na/auth/saml logout cgi?spid=sp1\\" index=\\" 1\\" isdefault=\\"0\\"/>\<md\ assertionconsumerservice binding=\\"urn\ oasis\ names\ tc\ saml 2 0\ bindings\ http post\\" location=\\"https //sso pulsesecureaccess net/dana na/auth/saml consumer cgi\\" index=\\"1\\" isdefault=\\"1\\"/>\</md\ spssodescriptor>\</md\ entitydescriptor>" } update entity ids request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/saml/metadata server configuration?operation=updateentityids' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' \\ h 'accept application/json' \\ d '' response { "result" { "info" \[ { "message" "update entity ids succeeded " } ] } } saml metadata providers to configure saml metadata providers request put /api/v1/configuration/system/configuration/saml configuration/metadata providers/metadata provider response { "accept unsigned metadata" false, "cert subjectcn" "", "enable signing cert validation" false, "entity ids" {}, "filename" "saml metadata xml", "local location" { "saml entity ids" null } "name" "saml", "select idp" true, "select sp" false, "validity" "0" "xml text" "pg1kokvudgl0eurlc2nyaxb0b3igeg1sbnm6bwq9invybjpvyxnpczpuyw1lczp0yzptqu1mojiumdptzxrhzgf0ysigy2fjagvedxjhdglvbj0iudmzm0rumegwttbtiiblbnrpdhljrd0iahr0chm6ly9zc28uchvsc2vzzwn1cmvhy2nlc3mubmv0l2rhbmetbmevyxv0ac9zyw1slwvuzhbvaw50lmnnat9wpxnwmsi+pg1kolnqu1nprgvzy3jpchrvcibwcm90b2nvbfn1chbvcnrfbnvtzxjhdglvbj0idxjuom9hc2lzom5hbwvzonrjolnbtuw6mi4wonbyb3rvy29sij48bwq6u2luz2xltg9nb3v0u2vydmljzsbcaw5kaw5npsj1cm46b2fzaxm6bmftzxm6dgm6u0fntdoylja6ymluzgluz3m6sfruuc1szwrpcmvjdcigtg9jyxrpb249imh0dhbzoi8vc3nvlnb1bhnlc2vjdxjlywnjzxnzlm5ldc9kyw5hlw5hl2f1dggvc2ftbc1sb2dvdxquy2dpp1nwswq9c3axii8+pg1kok5hbwvjrezvcm1hdd51cm46b2fzaxm6bmftzxm6dgm6u0fntdoxlje6bmftzwlklwzvcm1hddp1bnnwzwnpzmllzdwvbwq6tmftzulerm9ybwf0pjxtzdpoyw1lsurgb3jtyxq+dxjuom9hc2lzom5hbwvzonrjolnbtuw6ms4xom5hbwvpzc1mb3jtyxq6zw1hawxbzgryzxnzpc9tzdpoyw1lsurgb3jtyxq+pg1kok5hbwvjrezvcm1hdd51cm46b2fzaxm6bmftzxm6dgm6u0fntdoxlje6bmftzwlklwzvcm1hddpynta5u3viamvjde5hbwu8l21kok5hbwvjrezvcm1hdd48bwq6tmftzulerm9ybwf0pnvybjpvyxnpczpuyw1lczp0yzptqu1mojeumtpuyw1lawqtzm9ybwf0oldpbmrvd3neb21haw5rdwfsawzpzwroyw1lpc9tzdpoyw1lsurgb3jtyxq+pg1kok5hbwvjrezvcm1hdd51cm46b2fzaxm6bmftzxm6dgm6u0fntdoylja6bmftzwlklwzvcm1hddprzxjizxjvczwvbwq6tmftzulerm9ybwf0pjxtzdpoyw1lsurgb3jtyxq+dxjuom9hc2lzom5hbwvzonrjolnbtuw6mi4wom5hbwvpzc1mb3jtyxq6zw50axr5pc9tzdpoyw1lsurgb3jtyxq+pg1kok5hbwvjrezvcm1hdd51cm46b2fzaxm6bmftzxm6dgm6u0fntdoylja6bmftzwlklwzvcm1hddp0cmfuc2llbnq8l21kok5hbwvjrezvcm1hdd48bwq6qxnzzxj0aw9uq29uc3vtzxjtzxj2awnliejpbmrpbmc9invybjpvyxnpczpuyw1lczp0yzptqu1mojiumdpiaw5kaw5nczpivfrqlvbpu1qiiexvy2f0aw9upsjodhrwczovl3nzby5wdwxzzxnly3vyzwfjy2vzcy5uzxqvzgfuys1uys9hdxrol3nhbwwty29uc3vtzxiuy2dpiibpbmrled0imsigaxnezwzhdwx0psixii8+pc9tzdptufntt0rlc2nyaxb0b3i+pc9tzdpfbnrpdhlezxnjcmlwdg9ypg==" } resource profile creating a resource profile to create a web resource profile request post /api/v1/configuration/users/resource profiles/web profiles/web profile/ http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json { "custom" { "bookmarks" { "bookmark" \[ { "apply" "all", "description" "", "name" "web resourceprofile", "new window" "false", "no address bar" "false", "no tool bar" "false", "roles" null, "url" "http //www google com" } ] }, "client authentication" \[], "java acl" \[], "rewriting options" { "ptp" \[], "selective rewriting" "false", "use jsam" \[], "use wsam" \[] }, "sso basic ntlm kerberos" \[], "sso header" \[], "sso post" \[], "url" "http //www google com", "web compression" \[], "webacl" \[ { "rules" { "rule" \[ { "action" "allow", "name" "allow http //www google com 80/ ", "resource" "http //www google com 80/ " } ] } } ], "webcaching" \[] }, "description" "", "name" "web resourceprofile", "roles" \[ "rest userrole 3" ] } response http/1 1 201 created content length 128 content type application/json { "result" { "warnings" \[ { "message" "the configuration has been implicitly changed" } ] } } deleting a resource profile to delete a web resource profile request delete /api/v1/configuration/users/resource profiles/web profiles/web profile/web resourceprofile http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json response http/1 1 204 no content content length 0 content type application/json creating a resource policy to create a web resource policy request post /api/v1/configuration/users/resource policies/web policies/web acls/web acl/ http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json { "action" "allow", "apply" "selected", "description" "", "name" "web acl policy", "parent type" "none", "resources" \[ "\<ip address> 80,443/ " ], "roles" \[ "rest userrole 1" ], "rules" { "rule" \[] } } response http/1 1 201 created content length 122 content type application/json { "result" { "info" \[ { "message" "operation succeed without warning or error!" } ] } } fetching a resource policy to fetch a web resource policy request get /api/v1/configuration/users/resource policies/web policies/web acls/web acl/name=web acl policy,parent type=none http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json response http/1 1 200 ok content length 245 content type application/json { "action" "allow", "apply" "selected", "description" "", "name" "web acl policy", "parent type" "none", "resources" \[ "\<ip address> 80,443/ " ], "roles" \[ "rest userrole 1" ], "rules" { "rule" \[] } } deleting a resource policy to delete a web resource policy request delete /api/v1/configuration/users/resource policies/web policies/web acls/web acl/name=web acl policy,parent type=none http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json response http/1 1 204 no content content length 0 content type application/json vpn acl creation request put /api/v1/configuration/users/resource policies/network connect policies/network connect acls host \<ip address> authorization basic skuyv1bavjrjcgxleelrmnnizxpyaje2devium9oa05wwddrwhh3mmpjzz06 content type text/html; charset=utf 8 { "network connect acl" \[ { "action" "allow", "apply" "all", "description" "vpnacl", "name" "vpnacl", "resource" \[ " " ], "resources fqdn" null, "resources v6" null, "roles" null, "rules" { "rule" \[] } } ] } response http/1 1 200 ok content length 124 content type application/json { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } request get /api/v1/configuration/users/resource policies/network connect policies/network connect acls host \<ip address> authorization basic skuyv1bavjrjcgxleelrmnnizxpyaje2devium9oa05wwddrwhh3mmpjzz06 content type application/json response http/1 1 200 ok content length 205 content type application/json { "network connect acl" \[ { "href" "/api/v1/configuration/users/resource policies/network connect policies/network connect acls/network connect acl/vpnacl", "name" "vpnacl" } ] } create multiple acls this api allows for the creation, deletion an update of multiple configuration elements in a single api call, allowing for the bulk processing of configuration changes performance and batch size guidelines up to 90 acls can be processed in a single request, depending on the acl type and payload size using this batching approach, the creation of 10,000 acls typically completes in approximately 50–60 minutes, depending on the acl type and request payload size each batch should be limited to approximately 30 kb for sam acls, this corresponds to roughly 65 acl entries per batch the same size guideline applies to all supported acl types the effective batch size is constrained by the overall request payload size, which depends on list based parameters such as resources and rules as these lists grow, the payload size increases, making request size the primary limiting factor rather than a fixed limit on the number of acls per request the patch api requires a path parameter for each acl operation the exact path format depends on the acl type being modified to determine the correct path, use the url for a standard single acl of that type, e g /api/v1/configuration/users/resource policies/web policies/web acls/web acl/name=testprofile,parent type=web for using different acl types, see create resource policy docid\ tefgymbzjpphrdnf qdqz , here path field specifies the url for the acl type being configured and the value field contains the json body that would normally be sent to the acl endpoint supported patch operations "op" "add" represents create "op" "replace" represents update "op” ”remove” represents delete request curl x 'post' \\ 'https //\<ics ip>/api/v1/configuration/patch' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' \\ h 'accept application/json' \\ d '' \[{ "op" "replace", "path" "/users/resource policies/file policies/file win acls/file win acl", "value" { "action" "allow", "apply" "all", "description" "", "name" "acl15", "parent roles" "", "parent type" "none", "resources" \[ "\\\\\\\intranet\\\employees\\\forms\\\\% doc" ], "role" null, "rules" { "rule" \[] } }, "name" "new acl1" }, { "op" "add", "path" "/users/resource policies/file policies/file win acls/file win acl", "value" { "action" "deny", "apply" "all", "description" "", "name" "acl16", "parent roles" "", "parent type" "none", "resources" \[ "\\\\\\\intranet\\\employees\\\forms\\\\% doc" ], "role" null, "rules" { "rule" \[] } }, "name" "new acl1" } ] response { "result" { "info" \[ { "message" "operation succeed without warning or error!" } ] } } delete multiple acls this apis is used to delete acls this api does not support get/post request curl x 'delete' \\ 'https //\<ics ip>/api/v1/configuration/patch' \\ \ header 'authorization basic k3i0uzfsowk0dmxmzhyzu0tiwxvzstnsl1vxd1jlvgpgbgsxwwi3k243wt06' \\ h 'accept application/json' \\ d '' \[{ "op" "remove", "path" "/users/resource policies/file policies/file win acls/file win acl/name=acl16,parent type=none", "value" "null" }] response { "result" { "info" \[ { "message" "successfully deleted acls " } ] } } refresh dynamic policy to refresh dynamic policy evaluation for single or all auth realms request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/active users?number=200\&start=0' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' 'https //\<ics ip>/api/v1/system/active users?operation=refreshnow' \\ h 'accept application/json' \\ d '' response { "result" { "info" \[ { "message" "refresh roles for active users is successful" } ] } } auth servers creating an ad authentication server request post /api/v1/configuration/authentication/auth servers/auth server http/1 1 host \<ip address> \ header 'x encryption key id 78387' \\ \ header 'x encryption salt rerabxshqo/qbyevttuqjgdnlowro4olbqiam6me727iagukkq==' \\ authorization basic qmjyzlz6eer2tzhodjh4nzhlu28vu1nnz0theljjuhhsbc9pdjcrzlrxcz06 content type application/json { "ad" { "server catalog" { "custom variables" { "custom variable" \[] }, "expressions" { "custom expression" \[] }, "groups" { "ad group" \[] } }, "settings" { "additional options" { "allow trusted domains" "false", "change machine password after every" "0", "enable ntlm protocol" "true", "enable periodic password change of machine account" "false", "kerberos" "true", "max domain connections" "5", "ntlm protocol" "ntlmv2" }, "container name" "computers", "domain" "test", "kerberos realm" "test saqacertserv com", "nodenames" \[ { "computer name" "0332mwk0nrp111", "machine hardware id" "0332mogwk0nrp111s", "node" "localhost2" } ], "password encrypted" "3u+ur6n8agabaaaaycaupkhcg3j/y46bhb4wz6mnupqh0othotftexjxp2k=", "save credentials" "true", "username" "administrator" } }, "logical name" "", "name" "ad server", "user record sync" "false" } response http/1 1 201 created content length 128 content type application/json { "result" { "warnings" \[ { "message" "the configuration has been implicitly changed" } ] } } fetch an ad authentication server request curl location request get '\<ics ip>api/v1/configuration/authentication/auth servers/auth server/\<server name>'\\ \ header 'x encryption key id 78387'\\ \ header 'authorization basic tlrgallqzgpzvghqwlrjek1tstnnemmytm1fevlusmpnr1f6tjjjne9evt06' response http / 1 1 200 ok { content length 893 content type application / json \ header 'x encryption salt rerabxshqo/qbyevttuqjgdnlowro4olbqiam6me727iagukkq=='\\ } { "ad" { "aaa traffic server level" { "nodenames" \[] }, "server catalog" { "custom variables" { "custom variable" \[] }, "expressions" { "custom expression" \[] }, "groups" { "ad group" \[] } }, "settings" { "additional options" { "allow trusted domains" "false", "change machine password after every" "0", "enable ntlm protocol" "true", "enable periodic password change of machine account" "false", "kerberos" "true", "max domain connections" "5", "ntlm protocol" "ntlmv2" }, "container name" "secured devices", "domain" "reports", "kerberos realm" "reports net", "nodenames" \[{ "computer name" "vasph5fo3138km", "machine hardware id" "vasphl65fo3138kis", "node" "localhost2" }], "password encrypted" "qoxfxaaaaaabaaaamjg0vwnauyqsyomj6gdx+ymeu4e7ywtbaowgt1wfy6o=", "save credentials" "true", "username" "administrator" }, "users" { "user" \[] } }, "auth server type" "ad", "logical name" "", "name" "ad reports", "user record sync" "false" } deleting an ad authentication server request delete /api/v1/configuration/authentication/auth servers/auth server/ad server http/1 1 host \<ip address> authorization basic qmjyzlz6eer2tzhodjh4nzhlu28vu1nnz0theljjuhhsbc9pdjcrzlrxcz06 content type application/json response http/1 1 204 no content content length 0 content type application/json troubleshooting in ad authentication server request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/auth/auth server/test/troubleshoot?operation=test user pswd change' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "user name" "username", "old password" "oldpassword", "new password" "newpassword" }' response { "result" { "info" \[ { "message" "password change for user username" } ] } } fetch api key for auth server to fetch api key for a remote profiler auth server request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/auth/auth server/test/api key' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "primary api key" "primary api key\ qt675rt5rfff5jjikiu8", "secondary api key" "secondary api key\ qt675rt5rfff5jjikiu8" } to fetch api key for a remote profiler server without first creating a remote profiler auth server configuration request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/auth/auth server/api key without saving' \\ h 'accept application/json' \\ h 'content type application/json' \\ d '{ "hostname" "1 1 1 1", "username" "username", "password" "password", "validate cert" 1, "secondary profiler hostname" "1 1 1 2", "secondary profiler username" "sec username", "secondary profiler password" "sec password", "secondary profiler validatecert" 0 }' response { "primary api key" "primary api key\ qt675rt5rfff5jjikiu8", "secondary api key" "secondary api key\ qt675rt5rfff5jjikiu8" } test ldap connection to test ldap server connection without first creating an ldap auth server configuration request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/auth/auth server/ldap test connection' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "auth server name" "ldap server", "ldap server" "10 204 50 81", "ldap port" 636, "backup server1" "10 204 50 82", "backup port1" 989, "backup server2" "10 204 50 87", "backup port2" 636, "domain name" "psecure net", "domain port" 636, "domain enabled" 1, "ldap connection" "ldaps", "server type" "active directory", "cert validation" 1, "ldap cert verify" 1, "connection timeout" 15, "search timeout" 60 } response { "result" \[ { "info" "for server 1 1 1 1 at port 389 ldap server is reachable" } ] } creating an ldap authentication server request post / api / v1 / configuration / authentication / auth servers / auth server http / 1 1 host < ip address > \ header 'x encryption key id 78387'\\ \ header 'x encryption salt rerabxshqo/qbyevttuqjgdnlowro4olbqiam6me727iagukkq=='\\ authorization basic qmjyzlz6eer2tzhodjh4nzhlu28vu1nnz0theljjuhhsbc9pdjcrzlrxcz06 content type application / json { "ldap" { "server catalog" { "attributes" { "user attribute" \[{ "name" "cn" }, { "name" "department" }, { "name" "departmentnumber" }, { "name" "employeenumber" }, {}, { "name" "o" }, { "name" "ou" }, { "name" "samaccountname" }, { "name" "uid" }, { "name" "homedirectory" }, { "name" "homedrive" }, { "name" "wwwhomepage" } ] }, "custom variables" { "custom variable" \[] }, "expressions" { "custom expression" \[] }, "groups" { "user group" \[] } }, "settings" { "admin dn" "cn=administrator,cn=users,dc=test,dc=saqacertserv,dc=com", "admin password encrypted" } "3u+ur6n8agabaaaaqkyh+te/ebxl7gsn+w6iepov2yfsaaikh2svxkb8ltkzwhs1epflsnxbpuqp5swxfeoyfjmhqsrz5dp/z9uhq/l16ddne9/u7lw67hye/8q=", "attribute to update at server" "", "attribute type" "type integer", "attribute value to update at server" "\<logintimeldap>", "authentication required to search ldap" "true", "backup port 1" null, "backup port 2" null, "backup server 1" "", "backup server 2" "", "connection timeout" "15", "connection type" "plain", "enable attribute update at server" "false", "group base dn" "", "group filter" "", "ldap server type" "active directory", "meetings" { "email address" "mail", "full name" "displayname", "name attribute mapping" "", "user name" "samaccountname" }, "member attribute" "", "nested group level" "0", "port" "389", "query attribute" "", "reverse group search" "false", "search timeout" "60", "server" "10 209 124 88", "server catalog" "catalog", "test user dn" "", "user base dn" "dc=test,dc=saqacertserv,dc=com", "user filter" "samaccountname=\<user>", "validate referral cert" "verifyserverconfigured", "validate server cert" "false" } }, "logical name" "", "name" "ldap server", "user record sync" "false" } response http / 1 1 201 created content length 128 content type application / json { "result" { "warnings" \[{ "message" "the configuration has been implicitly changed" }] } } fetch an ldap authentication server request get / api / v1 / configuration / authentication / auth servers / auth server / < server name > http / 1 1 host < ip address > \ header 'x encryption key id 78387'\\ authorization basic qmjyzlz6eer2tzhodjh4nzhlu28vu1nnz0theljjuhhsbc9pdjcrzlrxcz06 response http / 1 1 200 ok { content length 893 content type application / json \ header 'x encryption salt rerabxshqo/qbyevttuqjgdnlowro4olbqiam6me727iagukkq=='\\ } { "ldap" { "server catalog" { "attributes" { "user attribute" \[{ "name" "cn" }, { "name" "department" }, { "name" "departmentnumber" }, { "name" "employeenumber" }, {}, { "name" "o" }, { "name" "ou" }, { "name" "samaccountname" }, { "name" "uid" }, { "name" "homedirectory" }, { "name" "homedrive" }, { "name" "wwwhomepage" } ] }, "custom variables" { "custom variable" \[] }, "expressions" { "custom expression" \[] }, "groups" { "user group" \[] } }, "settings" { "admin dn" "cn=administrator,cn=users,dc=test,dc=saqacertserv,dc=com", "admin password encrypted" } "3u+ur6n8agabaaaaqkyh+te/ebxl7gsn+w6iepov2yfsaaikh2svxkb8ltkzwhs1epflsnxbpuqp5swxfeoyfjmhqsrz5dp/z9uhq/l16ddne9/u7lw67hye/8q=", "attribute to update at server" "", "attribute type" "type integer", "attribute value to update at server" "\<logintimeldap>", "authentication required to search ldap" "true", "backup port 1" null, "backup port 2" null, "backup server 1" "", "backup server 2" "", "connection timeout" "15", "connection type" "plain", "enable attribute update at server" "false", "group base dn" "", "group filter" "", "ldap server type" "active directory", "meetings" { "email address" "mail", "full name" "displayname", "name attribute mapping" "", "user name" "samaccountname" }, "member attribute" "", "nested group level" "0", "port" "389", "query attribute" "", "reverse group search" "false", "search timeout" "60", "server" "10 209 124 88", "server catalog" "catalog", "test user dn" "", "user base dn" "dc=test,dc=saqacertserv,dc=com", "user filter" "samaccountname=\<user>", "validate referral cert" "verifyserverconfigured", "validate server cert" "false" } }, "logical name" "", "name" "ldap server", "user record sync" "false" } group ldap and ad auth servers group lookup for ldap and ad auth servers request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/auth/auth server/test/groups' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "groups" \[ { "dn" "group1", "type" "static" }, { "dn" "group2", "type" "dynamic" } ] } mdm auth server configuration to test the connection for a potential mdm auth server configuration or for an already configured one request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/auth server/mdm?operation=testconnection' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' \\ h 'content type application/json' \\ d '{ "mdm type" "microsoft intune", "tenant id" "25f4343b ced7 4135 af22 d3a8a04b0b57", "client id" "test4b32 0c13 47e7 aca1 3fcb3e5d1e7b", "client secret" "test1234567789efgd feghf ffegdhf" }' response { "result" { "info" \[ { "message" "connection ok " } ] } } unlock users local auth server to unlock users under local auth server request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/auth/auth server/test/users?operation=unlock' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "users" { "users" \[ "user1", "user2" ] } }' response { "result" { "info" \[ { "message" "successfully unlocked users user1, user3 not found user user2" } ] } } oauth server operation to create oauth server request curl location 'https //{{ics ip}}/api/v1/configuration/authentication/auth servers/auth server' \\ \ header 'content type application/json' \\ \ header 'authorization ••••••' \\ \ data '{ "auth server type" "oauth", "logical name" "", "name" "google oauth", "oauth" { "settings" { "well known openid url" "https //accounts google com/ well known/openid configuration", "allowed clock skew" "0", "client id" "clientid 123456 apps googleusercontent com", "client secret cleartext" "clientsecret 123456", "config type" "dynamic", "enable pkce" "true", "force authentication" "false", "host fqdn for oauth" "sso oauthaccess net", "op conf file" "", "op config filename" "", "username template" "" } }, "user record sync" "false" }' response { "result" { "warnings" \[ { "message" "the configuration has been implicitly changed" } ] } } user operation in auth server perform selected operation on given auth server request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/auth/auth server/test?operation=testcredential' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "base dn" "dc=sales,dc=com", "filter" "cn=user1" }' response { "groups" \[ { "dn" "group1", "type" "static" }, { "dn" "group2", "type" "dynamic" } ] } simulating auth server variables to simulate custom variables and expressions response curl x 'post' \\ 'https //\<ics ip>/api/v1/system/user record synchronization/database/retrieve stats' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ d '' request { "records count" 1 } creating a radius server request post /api/v1/configuration/authentication/auth servers/auth server http/1 1 host \<ip address> \ header 'x encryption key id 78387' \\ \ header 'x encryption salt rerabxshqo/qbyevttuqjgdnlowro4olbqiam6me727iagukkq==' \\ authorization basic qmjyzlz6eer2tzhodjh4nzhlu28vu1nnz0theljjuhhsbc9pdjcrzlrxcz06 content type application/json { "logical name" "", "name" "radius server", "radius" { "server catalog" { "attributes" { "user attribute" \[] }, "custom variables" { "custom variable" \[] }, "expressions" { "custom expression" \[] } }, "settings" { "accounting port" "1813", "authenticate with tokens onetimepassword" "false", "authentication port" "1812", "backup accounting port" "1813", "backup authentication port" "1812", "backup server" "\<ip address>", "backup shared secret encrypted" "3u+ur6n8agabaaaa2th1suv9vxds9grdmt1ycb4ol6tacmtwhwstlifd7q4=", "custom radius rules" { "custom radius rule" \[] }, "interim update interval" null, "load balance auth" "false", "nasid" "", "nasipaddr" "\<ip address>", "process radius disconnect" "false", "retries" "0", "server" "\<ip address>", "shared secret encrypted" "3u+ur6n8agabaaaa2th1suv9vxds9grdmt1ycb4ol6tacmtwhwstlifd7q4=", "timeout" "30", "use nc assigned ip" "false", "use subsession interim update" "false", "user name" "\<user>(\<realm>)\[\<role sep=\\",\\">]" } }, "user record sync" "false" } response http/1 1 201 created content length 128 content type application/json { "result" { "warnings" \[ { "message" "the configuration has been implicitly changed" } ] } fetch a radius server request get / api / v1 / configuration / authentication / auth servers / auth server / < server name > http / 1 1 host < ip address > \ header 'x encryption key id 78387'\\ authorization basic qmjyzlz6eer2tzhodjh4nzhlu28vu1nnz0theljjuhhsbc9pdjcrzlrxcz06 response http / 1 1 200 ok { content length 893 content type application / json \ header 'x encryption salt rerabxshqo/qbyevttuqjgdnlowro4olbqiam6me727iagukkq=='\\ } { "logical name" "", "name" "radius server", "radius" { "server catalog" { "attributes" { "user attribute" \[] }, "custom variables" { "custom variable" \[] }, "expressions" { "custom expression" \[] } }, "settings" { "accounting port" "1813", "authenticate with tokens onetimepassword" "false", "authentication port" "1812", "backup accounting port" "1813", "backup authentication port" "1812", "backup server" "\<ip address>", "backup shared secret encrypted" "3u+ur6n8agabaaaa2th1suv9vxds9grdmt1ycb4ol6tacmtwhwstlifd7q4=", "custom radius rules" { "custom radius rule" \[] }, "interim update interval" null, "load balance auth" "false", "nasid" "", "nasipaddr" "\<ip address>", "process radius disconnect" "false", "retries" "0", "server" "\<ip address>", "shared secret encrypted" "3u+ur6n8agabaaaa2th1suv9vxds9grdmt1ycb4ol6tacmtwhwstlifd7q4=", "timeout" "30", "use nc assigned ip" "false", "use subsession interim update" "false", "user name" "\<user>(\<realm>)\[\<role sep=\\",\\">]" } }, "user record sync" "false" } modifying radius server details request put /api/v1/configuration/authentication/auth servers/auth server/radius server http/1 1 host \<ip address> authorization basic qmjyzlz6eer2tzhodjh4nzhlu28vu1nnz0theljjuhhsbc9pdjcrzlrxcz06 content type application/json { "name" "radius server", "radius" { "settings" { "backup accounting port" "1814", "backup authentication port" "1816", "backup server" "\<ip address>" } } } response http/1 1 200 ok content length 128 content type application/json { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } test totp connection to test connection for a potential totp auth server configuration, or for an already configured one response curl x 'post' \\ 'https //\<ics ip>/api/v1/system/auth server/totp?operation=testconnection\&name=test' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "remotetotphost" "1 1 1 1", "remotetotp" "test", "remoteadmin" "admin", "remotepasswd" "password", "remoterealm" "realm" }' request { "result" { "info" \[ { "message" "totp server 'test' is reachable " } ] } } fetch user totp auth server get details of users for provided local totp auth server request curl x 'get' \\ 'https //\<ics ip>/api/v1/totp/users list/totp' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "users list" \[ { "last attempted login time" "2023/12/27 03 53 52", "last login realm" "users", "last successful login time" "2023/12/27 03 53 52", "registration realm" "users", "user state" "active", "username" "user1" } ] } securely exporting totp users data from one device to another device to strengthen totp and ensure secure data export between devices, the data file is supplemented with password authentication this secure export is available from ics version 22 7r2 3 and onwards request curl k u \<api key> https //\<ics ip>/api/v1/totp/\<totp auth server name>/users //note this api can be executed only on totp server configured as local (and not remote) //example curl location 'https //\<ics ip>/api/v1/totp/totp server/users' \\ \ header 'content type application/json' \\ \ header 'authorization ••••••' \\ \ header 'cookie dsbrowserid=212d4475fb7e5f3e91cea3002321dfb5' \\ \ data '{ "type" "export", "password" "xxxxxxxx" }' response http/1 1 200 ok content length 191 content type application/json { "users" "21ubwxsvawabaaaalx9igwcqok9s+mv0zg/b+oer3z7kj0ixbvzj+qdmiguttwzaxnghgtgqechd7btmgjz1qybo00zbf+6dgp2y/9pj+8wf4sxtqbyiedomt4w2kl4oc1ezhfruwlwnll+58x2b0kxsurcb+p0it8k+msqfxbhoedy7l0w4+p+a8uzaz6in/gmq8qd766i7rn1oz+hzhumyjub72tziq+cia8ttv6awec6tgy9/a9c6vvbly0+zuggtffwzjxcozbebdwicfozyex5uwtufij0z4xapoz4htwzsxp5ywxcjpsnbozcqw/dtb6wpywyp6r+mun2yu/hzeu7z1qvhxlr8bk5lifh/u6j76sperl1eelh1byf17dwpfo6xspg7rffhs2k9vpvb1oq2kud+42hpo6vzamfcwaz9lkrrftigau2o3jbjfdnhrutou2+y6qmc0in6mfibnnrvr9d6hdwmidrnr7pxha4ujop+cauop3oamtox2sgmve7ynjc0slspgyffx0kfzcb2k3mrcq1uujujlhk7l3lne4f1qiwkoz8q8zluav+ersjhbez9pjo+lzbpywoxstduoc20fvy4+kchdasufdaocd/lga4mffe5itaui18obofrtxlvozuiugs8w019mbrandlva52suzuzbclqx+4luebcqyeunrdrhvg0azqubbael+wv8vrjrxvw8silarqy8n29pd66bozsgkoxbqxse/fzxedu9zqi4xfzsccsfqtiv0lam4p+czekhcjvrwtuimnjx+qj7a==" } exporting totp users from one device to another device to export the totp user data prior to ics version 22 7r2 3 request curl k u \<api key> https //ics ip>/api/v1/totp/\<totp auth server name>/users //note this api can be executed only on totp server configured as local (and not remote) example curl location 'https //ics ip>/api/v1/totp/totp server/users' \\ \ header 'authorization ••••••' \\ \ header 'cookie dsbrowserid=212d4475fb7e5f3e91cea3002321dfb5' response http/1 1 200 ok content length 191 content type application/json { "users" "21ubwxsvawabaaaalx9igwcqok9s+mv0zg/b+oer3z7kj0ixbvzj+qdmiguttwzaxnghgtgqechd7btmgjz1qybo00zbf+6dgp2y/9pj+8wf4sxtqbyiedomt4w2kl4oc1ezhfruwlwnll+58x2b0kxsurcb+p0it8k+msqfxbhoedy7l0w4+p+a8uzaz6in/gmq8qd766i7rn1oz+hzhumyjub72tziq+cia8ttv6awec6tgy9/a9c6vvbly0+zuggtffwzjxcozbebdwicfozyex5uwtufij0z4xapoz4htwzsxp5ywxcjpsnbozcqw/dtb6wpywyp6r+mun2yu/hzeu7z1qvhxlr8bk5lifh/u6j76sperl1eelh1byf17dwpfo6xspg7rffhs2k9vpvb1oq2kud+42hpo6vzamfcwaz9lkrrftigau2o3jbjfdnhrutou2+y6qmc0in6mfibnnrvr9d6hdwmidrnr7pxha4ujop+cauop3oamtox2sgmve7ynjc0slspgyffx0kfzcb2k3mrcq1uujujlhk7l3lne4f1qiwkoz8q8zluav+ersjhbez9pjo+lzbpywoxstduoc20fvy4+kchdasufdaocd/lga4mffe5itaui18obofrtxlvozuiugs8w019mbrandlva52suzuzbclqx+4luebcqyeunrdrhvg0azqubbael+wv8vrjrxvw8silarqy8n29pd66bozsgkoxbqxse/fzxedu9zqi4xfzsccsfqtiv0lam4p+czekhcjvrwtuimnjx+qj7a==" } importing totp users from one device to another device request curl k u \<api key> https //\<ics ip>/api/v1/totp/\<totp auth server name>/users h "content type application/json" d @totp users json x post //note this api can be executed only on totp server configured as local (and not remote) //example1\ to import totp user data file from ics version 22 7r2 3 curl k u k7z7xa54aknv1++kcviamcciurebgmsp+shkar4ecky= https //\<ip address>/api/v1/totp/totp server/users h "content type application/json" d @totp users json x post { "type" "import" "password" "xxxxxxxxxx" "users" "21ubwxsvawabaaaalx9igwcqok9s+mv0zg/b+oer3z7kj0ixbvzj+qdmiguttwzaxnghgtgqechd7btmgjz1qybo00zbf+6dgp2y/9pj+8wf4sxtqbyiedomt4w2kl4oc1ezhfruwlwnll+58x2b0kxsurcb+p0it8k+msqfxbhoedy7l0w4+p+a8uzaz6in/gmq8qd766i7rn1oz+hzhumyjub72tziq+cia8ttv6awec6tgy9/a9c6vvbly0+zuggtffwzjxcozbebdwicfozyex5uwtufij0z4xapoz4htwzsxp5ywxcjpsnbozcqw/dtb6wpywyp6r+mun2yu/hzeu7z1qvhxlr8bk5lifh/u6j76sperl1eelh1byf17dwpfo6xspg7rffhs2k9vpvb1oq2kud+42hpo6vzamfcwaz9lkrrftigau2o3jbjfdnhrutou2+y6qmc0in6mfibnnrvr9d6hdwmidrnr7pxha4ujop+cauop3oamtox2sgmve7ynjc0slspgyffx0kfzcb2k3mrcq1uujujlhk7l3lne4f1qiwkoz8q8zluav+ersjhbez9pjo+lzbpywoxstduoc20fvy4+kchdasufdaocd/lga4mffe5itaui18obofrtxlvozuiugs8w019mbrandlva52suzuzbclqx+4luebcqyeunrdrhvg0azqubbael+wv8vrjrxvw8silarqy8n29pd66bozsgkoxbqxse/fzxedu9zqi4xfzsccsfqtiv0lam4p+czekhcjvrwtuimnjx+qj7a==" } //example2 to import totp user data file prior to ics version 22 7r2 3 curl k u k7z7xa54aknv1++kcviamcciurebgmsp+shkar4ecky= https //\<ip address>/api/v1/totp/totp server/users h "content type application/json" d @totp users json x post { "type" "import" "users" "21ubwxsvawabaaaalx9igwcqok9s+mv0zg/b+oer3z7kj0ixbvzj+qdmiguttwzaxnghgtgqechd7btmgjz1qybo00zbf+6dgp2y/9pj+8wf4sxtqbyiedomt4w2kl4oc1ezhfruwlwnll+58x2b0kxsurcb+p0it8k+msqfxbhoedy7l0w4+p+a8uzaz6in/gmq8qd766i7rn1oz+hzhumyjub72tziq+cia8ttv6awec6tgy9/a9c6vvbly0+zuggtffwzjxcozbebdwicfozyex5uwtufij0z4xapoz4htwzsxp5ywxcjpsnbozcqw/dtb6wpywyp6r+mun2yu/hzeu7z1qvhxlr8bk5lifh/u6j76sperl1eelh1byf17dwpfo6xspg7rffhs2k9vpvb1oq2kud+42hpo6vzamfcwaz9lkrrftigau2o3jbjfdnhrutou2+y6qmc0in6mfibnnrvr9d6hdwmidrnr7pxha4ujop+cauop3oamtox2sgmve7ynjc0slspgyffx0kfzcb2k3mrcq1uujujlhk7l3lne4f1qiwkoz8q8zluav+ersjhbez9pjo+lzbpywoxstduoc20fvy4+kchdasufdaocd/lga4mffe5itaui18obofrtxlvozuiugs8w019mbrandlva52suzuzbclqx+4luebcqyeunrdrhvg0azqubbael+wv8vrjrxvw8silarqy8n29pd66bozsgkoxbqxse/fzxedu9zqi4xfzsccsfqtiv0lam4p+czekhcjvrwtuimnjx+qj7a==" } response http/1 1 200 ok content length →47 content type application/json { 'message' => 'successfully imported totp users' } resetting totp user request curl k u \<api key> https //\<ics ip>/api/v1/totp/\<totp auth server name>/users/\<totp user>?operation=reset x put example curl k u nnualllwajgujvf2yt4qyp4nyxy/nwxxbkp0chu2azq= https //\<ip address>/api/v1/totp/totp server/users/qauser1001?operation=reset x put response scenario totp user reset http/1 1 200 ok content type application/json { "result" { "info" \[ { "message" "totp user 'qauser1001' under authserver 'totp server' has been reset" } ] } } scenario totp user does not exist http/1 1 200 ok content type application/json { "result" { "errors" \[ { "message" "totp user 'qauser1001' is not present under authserver 'totp server'" } ] } } unlocking totp user request curl k u \<api key> https //\<ics ip>/api/v1/totp/\<totp auth server name>/users/\<totp user>?operation=unlock x put example curl k u nnualllwajgujvf2yt4qyp4nyxy/nwxxbkp0chu2azq= https //\<ip address>/api/v1/totp/totp server/users/qauser1001?operation=unlock x put response scenario totp user unlocked http/1 1 200 ok content type application/json { "result" { "info" \[ { "message" "totp user 'qauser1001' under authserver 'totp server' has been unlocked" } ] } } scenario totp user cannot be unlocked http/1 1 200 ok content type application/json { "result" { "errors" \[ { "message" "error only locked users can be unlocked" } ] } } fetch aaa ports to fetch the configuration of all the supported aaa ports request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/auth/aaa ports list' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "cluster" \[ { "name" "localhost2", "nics" \[ { "internal" { "device" "int0", "interface number" 0, "interface type" "physical", "ip address" "10 97 8 21", "physical interface" "internal", "vlan id" "not set" } }, { "external" { "device" "ext0", "interface number" 1, "interface type" "physical", "ip address" "192 168 5 86", "physical interface" "external", "vlan id" "not set" } }, { "management" { "device" "mgt0", "interface number" 7, "interface type" "physical", "ip address" "10 96 3 91", "physical interface" "management", "vlan id" "not set" } }, { "dfs int port vlan 3" { "device" "int0 3", "interface number" 11, "interface type" "vlan", "ip address" "10 97 4 51", "physical interface" "internal", "vlan id" "3" } }, { "dfs int port vlan 3 vp" { "device" "vlan 11 vport 11 4", "interface number" "11 4", "interface type" "admin", "ip address" "10 97 4 53", "physical interface" "internal", "vlan id" "3" } } ] } ] } policy and bookmarks creating sign in policy request post /api/v1/configuration/authentication/signin/urls/access urls/access url/ http/1 1 host \<ip address> authorization basic methmxm0mmjrahpjyms0wfzcz29xb3k1nk5nl3jqadbwq05itmfhulh5st06 content type application/json { "description" "", "enabled" "true", "page" "default sign in page", "realm select" "pick list", "url pattern" "test/url3/", "user" { "enable new ux pages" "false", "meeting url" " /meeting/", "post authentication signin notification id" "none", "post authentication signin notification skip" "false", "pre authentication signin notification id" "none", "realms" \[ "users" ] } } response http/1 1 201 created content length 128 content type application/json { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } deleting sign in policy request delete /api/v1/configuration/authentication/signin/urls/access urls/access url/test%5c%2furl3%5c%2f http/1 1 host \<ip address> authorization basic methmxm0mmjrahpjyms0wfzcz29xb3k1nk5nl3jqadbwq05itmfhulh5st06 cache control no cache response http/1 1 204 no content content length 0 content type application/json disabling sign in url request put /api/v1/configuration/authentication/signin/urls/access urls/access url/test%5c%2furl1%5c%2f/enabled http/1 1 host \<ip address> authorization basic methmxm0mmjrahpjyms0wfzcz29xb3k1nk5nl3jqadbwq05itmfhulh5st06 content type application/json { "enabled" "false" } response http/1 1 200 ok content length 128 content type application/json { "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } } creating a web bookmark for a role to create a web bookmark for a role request post /api/v1/configuration/users/user roles/user role/rest userrole 1/web/web bookmarks/bookmark http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 content type application/json cache control no cache { "auto allow" "disable", "description" "", "name" "webbm", "new window" "false", "no address bar" "false", "no tool bar" "false", "parent" " none ", "standard" { "url" "http //www yahoo com" } } response http/1 1 201 created content length 122 content type application/json { "result" { "info" \[ { "message" "operation succeed without warning or error!" } ] } } reordering for re ordering existing ordered elements in the configuration, a put api can be used with an 'order' suffix this api can be used to reorder any ordered element in the configuration including role mapping rules, resource policies and acls example reorder existing role mapping rules in a specific realm request put /api/v1/configuration/users/user realms/realm/testrealm/role mapping rules/rule/order http/1 1 host \<ip address> authorization basic y1vpze1xz1zubvevvnircwwrd3ljy3f0y05wtghdvkx1m0wrdk5yr3hzvt06 content type application/json { "rule" \[ { "href" "/api/v1/configuration/users/user realms/realm/testrealm/role mapping rules/rule/rule3" }, { "href" "/api/v1/configuration/users/user realms/realm/testrealm/role mapping rules/rule/rule1" } ] } response http/1 1 200 ok content length 122 content type application/json { "result" { "info" \[ { "message" "operation succeed without warning or error!" } ] } } fetching the resource with multiple identifiers example retrieve one of snmp trap server configured on ics device request get /api/v1/configuration/system/log/snmp/localhost2/trap servers/trap server/ip=1 1 1 1,port=162 http/1 1 host \<ip address> authorization basic t0o1dzvpk3g4u0dkv0d1tkjcdwlwvzreauc0sjzvbkexmvljc0rtnu14bz06 response http/1 1 200 ok content length 65 content type application/json { "community" "public", "ip" "\<ip address>", "port" "162" } updating resource identified using multiple identifiers example updating the community string for specific snmp trap server identified by ip and port request put /api/v1/configuration/system/log/snmp/localhost2/trap servers/trap server/ip=1 1 1 1,port=162/community http/1 1 host \<ip address> authorization basic t0o1dzvpk3g4u0dkv0d1tkjcdwlwvzreauc0sjzvbkexmvljc0rtnu14bz06 content type application/json { "community" "pulsesecure" } response http/1 1 200 ok content length 122 content type application/json { "result" { "info" \[ { "message" "operation succeed without warning or error!" } ] } } restore factory defaults for user role ui options to restore ui options factory defaults for given user role request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/user roles/test?operation=restorefactorydefaults' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' \\ d '' response { "result" { "info" \[ { "message" "successfully restored factory defaults users" } ] } } updating password in clear text example updating password of system local user request put /api/v1/configuration/authentication/auth servers/auth server/system%20local/local/users/user/user0001/password cleartext http/1 1 host \<ip address> authorization basic t0o1dzvpk3g4u0dkv0d1tkjcdwlwvzreauc0sjzvbkexmvljc0rtnu14bz06 content type application/json { "password cleartext" "psecure" } response http/1 1 200 ok content length 128 content type application/json { "result" { "warnings" \[ { "message" "the configuration has been implicitly changed" } ] } } fetch domain for html resource profile bookmarks to fetch domain operation request curl x 'post' \\ 'https //\<ics ip>/api/v1/users/resource profile/test?operation=fetchdomain' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "username" "\<user>" }' response { "result" { "info" \[ { "message" "agent1\\\\\<user>" } ] } } license management applying authcode and downloading licenses from pcls on va spe|psa v this rest api can be used to download the license key from pcls and install on the virtual appliance request put /api/v1/license/auth code http/1 1 host \<ip address> authorization basic tnbduk1vefffqtjkzjm0s2zxv2jkulhradjawgfrynkvwvptr3hhntdmbz0= content length 35 content type application/json { "auth code" "\<auth code to apply>" } response http/1 1 200 ok content type application/json content length 191 { "result" { "info" \[ { "message" "installed new license key \\"landmark utility prestige trip mayor diesel faucet summer prestige income heritage\\"" } ] } } applying license request put /api/v1/license/license key?action=install http/1 1 host \<ip address> authorization basic tnbduk1vefffqtjkzjm0s2zxv2jkulhradjawgfrynkvwvptr3hhntdmbz0= content type application/json { "keys" \[ "key1", "key2", … ] } example { "keys" \[ "operation tree crayon holiday kingdom lasso doorway square dish modem gecko", "buffalo safety inch topaz banquet nitrogen garnish step recital wedge trace" ] } response http/1 1 200 ok content type application/json { "result" { "info" \[ { "message" "installed licenses" } ] } } getting license capacity to get license capacity info request curl x 'get' \\ 'https //\<ics ip>/api/v1/license/license capacity' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "capacity" \[ { "auto leasing" "off", "feature leased" 0, "feature name" "concurrent users for isa", "installed count" 1000000, "leased count" 0, "total count" 2 }, { "auto leasing" "off", "feature leased" 0, "feature name" "advanced html5 users", "installed count" 0, "leased count" 0, "total count" 2 } ], "feature count" 3, "on va" "false" } deleting license request put /api/v1/license/license key?action=delete http/1 1 host \<ip address> authorization basic tnbduk1vefffqtjkzjm0s2zxv2jkulhradjawgfrynkvwvptr3hhntdmbz0= content type application/json { "keys" \[ "key1", "key2", … ] } example { "keys" \[ "operation tree crayon holiday kingdom lasso doorway square dish modem gecko", "buffalo safety inch topaz banquet nitrogen garnish step recital wedge trace" ] } response http/1 1 200 ok content type application/json { "result" { "info" \[ { "message" "deleted \<number> licenses" } ] } } applying license auth code to apply license auth code request curl x 'put' \\ 'https //\<ics ip>/api/v1/license/auth code' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "auth code" "xxxxxxxxx" }' response { "result" { "info" \[ { "message" "installed new license key \\"landmark utility prestige trip mayor diesel faucet summer prestige income heritage\\"" } ] } } fetch leased license info request curl x 'get' \\ 'https //\<ics ip>/api/v1/license/leased license info' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "feature count" 0, "node feature str" null, "nodes" \[], "tbv expired across cluster" 1 } getting maximum licensed concurrent users request curl x 'get' \\ 'https //\<ics ip>/api/v1/license/max licensed concurrent users' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "max licensed concurrent users" 2 } fetch license agreement text request curl x 'get' \\ 'https //\<ics ip>/api/v1/license/license agreement text' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "agreement text" "string" } fetch last contact time request curl x 'get' \\ 'https //\<ics ip>/api/v1/license/license server last contact time' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "last contact time" "06 29 18 am on may 25, 2022" } to fetch pcls last contact time request curl x 'get' \\ 'https //\<ics ip>/api/v1/license/pcls/last contact time' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "last contact time" "06 29 18 am on may 25, 2022" } getting license clients request get /api/v1/license/license clients http/1 1 host \<ip address> authorization basic tnbduk1vefffqtjkzjm0s2zxv2jkulhradjawgfrynkvwvptr3hhntdmbz0= content type application/json response http/1 1 200 ok content type application/json { "license clients" \[ { "feature capacities" \[ { "feature name" "add user count", "leased value" 25 }, { "feature name" "onboard", "leased value" 0 }, { "feature name" "embeddedrdpapplet", "leased value" 0 }, { "feature name" "vm cores leasable", "leased value" 4 }, { "feature name" "add meeting user count", "leased value" 0 }, { "feature name" "cloudsecure count", "leased value" 0 }, { "feature name" "named user count", "leased value" 0 }, { "feature name" "ueba", "leased value" 0 } ], "last renewal" "wed, 04 dec 2019 06 32 26 gmt", "machine id" "vasph3944m9d8551s", "name" "va spe 3 3 125 4" }, { "feature capacities" \[ { "feature name" "add user count", "leased value" 25 }, { "feature name" "onboard", "leased value" 0 }, { "feature name" "embeddedrdpapplet", "leased value" 0 }, { "feature name" "vm cores leasable", "leased value" 4 }, { "feature name" "add meeting user count", "leased value" 0 }, { "feature name" "cloudsecure count", "leased value" 0 }, { "feature name" "named user count", "leased value" 0 }, { "feature name" "ueba", "leased value" 0 } ], "last renewal" "thu, 05 dec 2019 13 45 31 gmt", "machine id" "vasphxvk2e117pm8s", "name" "va spe 3 3 125 8" }, ] } getting license report from license server request get /api/v1/license/report http/1 1 host \<ip address> authorization basic tnbduk1vefffqtjkzjm0s2zxv2jkulhradjawgfrynkvwvptr3hhntdmbz0= content type application/json response http/1 1 200 ok content type application/json license usage report { "licenseusagereport" { "machineid" "vaspmmxxxxxxxx", "build number" "4762", "cumulative report" {…}, "granular report" {…}, "cluster granular report" {…}, "time stamp" "mon jan 13 20 04 40 2020", "version" "9 1" } } cumulative report https //\<license server>/api/v1/license/report/cumulative report { "cumulative report" { "add meeting user count" { "year" \[ { "month" \[ { "date" \[ { "leased" "0", "maximum" "30", "id" "06" } {…}, {…}, {…}, {…} ] "leased" "0", "maximum" "30", "id" "jan", } {…} ] "id" "2020" } {…} ] } } } granular report https //\<license server>/api/v1/license/report/granular report { "license client" \[ { "add user count" { "year" \[ { "month" \[ { "date" \[ {…}, {…}, {…}, {…} ] "leased" "0", "maximum" "0", "id" "jan" } ], "id" "2020" } ] }, "name" "isa v 10 209 125 101", "software version" "7 4" }, {…} ] } cluster granular report https //\<license server>/api/v1/license/report/cluster granular report { "add user count" { "year" \[ { "month" \[ { "date" \[ { "leased" "40", "maximum" "21", "client node" "node63lc,node66lc", "id" "24" }, { "leased" "40", "maximum" "1", "client node" "node63lc,node66lc", "id" "25" }, { "leased" "40", "maximum" "1", "client node" "node63lc,node66lc", "id" "26" } ], "leased" "40", "maximum" "21", "id" "feb" } ], "id" "2020" } ] }, "cluster name" "liccluster" } the following extensions of the api are supported 1\ /api/v1/license/report – entire license report in json 2\ /api/v1/license/report/cumulative report – the cumulative report • following trace down options available here i /api/v1/license/report/cumulative report/\<license feature type> ii /api/v1/license/report/cumulative report/\<license feature type>/\<year> iii /api/v1/license/report/cumulative report/\<license feature type>/\<year>/\<month> iv /api/v1/license/report/cumulative report/\<license feature type>/\<year>/\<month>/\<day> 3\ /api/v1/license/report/granular report – license usage report per license client • following trace down options available here /api/v1/license/report/granular report/\<license client> ii /api/v1/license/report/granular report/\<license client>/\<add user count> iii /api/v1/license/report/granular report/\<license client>/\<add user count>/\<year> iv /api/v1/license/report/granular report/\<license client>/\<add user count>/\<year>/\<month> v /api/v1/license/report/granular report/\<license client>/\<add user count>/\<year>/\<month>/\<day> example api /api/v1/license/report/granular report/node63lc/add user count/2020/mar/20 { "leased" 40, "maximum" 14, "id" "20" } 4\ /api/v1/license/report/cluster granular report – license usage report per license client cluster • following trace down options available here i /api/v1/license/report/cluster granular report/\<license client> ii /api/v1/license/report/cluster granular report/\<license client>/\<add user count> iii /api/v1/license/report/cluster granular report/\<license client>/\<add user count>/\<year> iv /api/v1/license/report/cluster granular report/\<license client>/\<add user count>/\<year>/\<month> v /api/v1/license/report/cluster granular report/\<license client>/\<add user count>/\<year>/\<month>/\<day> • example api /api/v1/license/report/cluster granular report/liccluster/add user count/2020/mar/22 { "leased" 40, "maximum" 16, "cluster member" \[ "node63lc", "node66lc" ], "id" "22" } enable/disable license enforcement request curl x 'put' \\ 'https //10 10 10 10/api/v1/license/enforcement' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "state" "on" }' response { "result" { "info" \[ { "message" "set enforcement on" } ] } } enabling/disabling ice license enabling ice license content of ice enable json file more ice enable json { "mode" "enabled" } request curl k u \<api key> https //\<ics ip>/api/v1/license/ice x put h "content type application/json" d @ice enable json example curl k u tvgj9xv9xvua1jdb1npkjc5bilaqahumn2dphlzgp/o= https //10 209 125 4/api/v1/license/ice x put h "content type application/json" d @ice enable json response http/1 1 200 ok content type application/json { "result" { "info" \[ { "message" "ice license is enabled" } ] } } disabling ice license content of ice disable json file more ice disable json { "mode" "disabled" } request curl k u tvgj9xv9xvua1jdb1npkjc5bilaqahumn2dphlzgp/o= https //\<ip address>/api/v1/license/ice x put h "content type application/json" d @ice disable json response http/1 1 200 ok content type application/json { "result" { "info" \[ { "message" "ice license is disabled" } ] } } getting the current status of ice license request curl k u \<api key> https //\<ics ip>/api/v1/license/ice example curl k u tvgj9xv9xvua1jdb1npkjc5bilaqahumn2dphlzgp/o= https //\<ip address>/api/v1/license/ice response ice license enabled http/1 1 200 ok content type application/json { "mode" "enabled" } ice license disabled http/1 1 200 ok content type application/json { "mode" "disabled" } getting key status request curl x 'get' \\ 'https //\<ics ip>/api/v1/license/keys status' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "ive liccount" 5, "ive maxccu" 2, "ive maxnuc" 0, "ive struct" { "node data" \[ { "gracestr" "", "hardware id" "0153m05c007pm08g", "isreachable" 1, "ive cl count" 0, "ive hostid" "localhost2", "ive name" "localhost2", "ive named user count" 0, "ive user count" 0, "license keys" \[ { "actdate" 0, "drfeature" 0, "drmode" 0, "expired" 0, "expiry day" 0, "expiry hour" 0, "expiry min" 0, "goodmid" "0153m05c007pm08g", "ingrace" 0, "inactive" 0, "key" "motto system violin tanker prestige copper furnace levee dimple speaker hercules", "ltl" 0, "mismatch" 0, "name" "add onboarding license for 1,000 users", "node" "localhost2", "time day" 0, "time hour" 0, "time min" 0, "type" "permanent" }, { "actdate" 0, "drfeature" 0, "drmode" 0, "expired" 0, "expiry day" 357, "expiry hour" 16, "expiry min" 52, "goodmid" "0153m05c007pm08g", "ingrace" 0, "inactive" 0, "key" "cuisine kayak platinum latte stadium studio tofu office razor floor faucet", "ltl" 1, "mismatch" 0, "name" "add onboarding license for 1,000 users 1 year subscription", "node" "localhost2", "time day" 357, "time hour" 16, "time min" 52, "type" "subscription" }, { "actdate" "inactive till may 25, 2022", "drfeature" 0, "drmode" 0, "expired" 0, "expiry day" 0, "expiry hour" 0, "expiry min" 0, "goodmid" "0153m05c007pm08g", "ingrace" 0, "inactive" 1, "key" "cuisine windmill piston text success radiator gusto mountain officer invoice factory", "ltl" 1, "mismatch" 0, "name" "add onboarding license for 1,000 users 1 year subscription", "node" "localhost2", "time day" 6, "time hour" 0, "time min" 0, "type" "subscription/inactive" }, { "actdate" 0, "drfeature" 0, "drmode" 0, "expired" 0, "expiry day" 7, "expiry hour" 16, "expiry min" 52, "goodmid" "0153m05c007pm08g", "ingrace" 0, "inactive" 0, "key" "jaguar hydrogen mule toolbox cameo standard jacket sunglass calendar invoice factory", "ltl" 1, "mismatch" 0, "name" "subscribe 1000 simultaneous users to access for 1 year", "node" "localhost2", "time day" 7, "time hour" 0, "time min" 11, "type" "subscription" }, { "actdate" 0, "drfeature" 1, "drmode" 0, "expired" 0, "expiry day" 0, "expiry hour" 0, "expiry min" 0, "goodmid" "0153m05c007pm08g", "ingrace" 0, "inactive" 0, "key" "suburb nirvana tent hinge people meadow cashew", "ltl" 1, "mismatch" 0, "name" "in case of emergency license with instant virtual system for sa 4000", "node" "localhost2", "time day" 56, "time hour" 0, "time min" 0, "type" "permanent" } ], "num lic" 5, "serial num" "0123456789" } ], "num node" 1 } } delete watermarks clears all the monthly and daily watermarks for the particular feature in cache request curl x 'delete' \\ 'https //\<ics ip>/api/private/v1/license/watermarks/test' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept / ' response { "result" { "info" \[ { "message" "deleted successsfully" } ] } } server monitoring ntp status to monitor ntp status request get https //{{ip}}/api/v1/system/status/ntp response { "content type" "application/json", "content length" "1129" } "{ "ntp server status" { "\<ip address>" { "delay" "0 000", "jitter" "0 000", "offset" "0 000", "pool" "64", "reach" "0", "refid" " init ", "remote ntp server" "\<ip address>", "stratum" "16", "type" "u", "when" " " }, "\<ip address>\\" { "delay" "0 000", "jitter" "0 000", "offset" "0 000", "pool" "64", "reach" "0", "refid" " init ", "remote ntp server" "\<ip address>", "stratum" "16", "type" "u", "when" " " }, "\<ip address>" { "delay" "0 000", "jitter" "0 000", "offset" "0 000", "pool" "64", "reach" "0", "refid" " init ", "remote ntp server" "\<ip address>", "stratum" "16", "type" "u", "when" " " }, "\<ip address>" { "delay" "0 000", "jitter" "0 000", "offset" "0 000", "pool" "64", "reach" "0", "refid" " init ", "remote ntp server" "\<ip address>", "stratum" "16", "type" "u", "when" " " } } }" validate scep server configuration request curl x 'post' \\ 'https //\<ics ip>/api/v1/enterprise onboard/scep configuration?operation=validate' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "scep url" "https //www google com", "scep challenge" "challenge123", "scep retries" 0, "scep delay" 0, "chkenrollment" "on", "csr template name" "test csr template 1", "encryption certificate pem" "miidjtccag2gawibagijaj0fuz9at2oima0gcsqgsib3dqebbquamckxczajbgnv", "use saved config" "true" }' response { "result" { "info" \[ { "message" "successfully received a test certificate from the server which will be discarded more details are available in the event log scep configuration is saved " } ] } } to check csr template status request curl x 'get' \\ 'https //\<ics ip>/api/v1/enterprise onboard/csr template status' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' response { "num1024keys" 0, "num2048keys" 10000, "num4096keys" 0 } testing server connection returns result for aws and azure test connection request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/maintenance/archiving/cloud server test connection' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "type" "aws", "txts3server" "\<aws s3 bucket name>", "txts3directory" "\<aws s3 bucket location>", "txts3user" "\<aws access key>", "txts3password" "\<aws secret key>", "txts3path" "\<aws path>" } response { "result" "connection ok" } telemetry toggling the telemetry settings to toggle the telemetry settings request get /api/v1/configuration/system/configuration/telemetry response { "content type" "application/json", "content length" "62" } "{ "crash analytics" "false", "google analytics" "true" }" request put /api/v1/configuration/system/configuration/telemetry "{ "crash analytics" "true", "google analytics" "true" }" response { "content type" "application/json", "content length" "124" } "{ "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } }" enabling read only mode for the administrator to enable read only mode for the adminstrator request get /api/v1/configuration/system/configuration/telemetry response { content type application/json content length 61 } "{ "crash analytics" "true", "google analytics" "true" }" request put /api/v1/configuration/system/configuration/telemetry response status 403 forbidden logs fetch logs request curl location 'https //\<ip address>/api/v1/logs/events' \\ \ header 'content type application/json' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' \\ \ data '{ "action" "fetch", "lines" 3, "query" "id != ('\\''sys10306'\\'' or '\\''nwc13978'\\'' or '\\''nwc13979'\\'')", "filter" "standard", "begin date" "2023 07 08", "end date" "2023 07 09" }' response { "result" { "logs" \[ { "id" "sys32083", "message" "2023 07 09 23 11 23 ive \[127 0 0 1] system()\[]\[] lmdb shards usage stats shard 0 1% 1 1% 2 1% 3 1% 4 1% 5 1% 6 1% 7 1% 8 1% 9 1% a 1% b 1% c 1% d 1% e 1% f 1% ", "severity" "info" }, { "id" "sts30667", "message" "2023 07 09 23 00 01 ive \[127 0 0 1] system()\[]\[] number of ncp connections 0", "severity" "info" }, { "id" "sts20642", "message" "2023 07 09 23 00 01 ive \[127 0 0 1] system()\[]\[] number of concurrent mail users logged in to the email proxy 0", "severity" "info" } ] } } api cannot save files to local machine, it returns the raw file contents, which the user can redirect to a file they want to save save logs request //( parameters query, filter, begin date, end date, filter) curl location 'https //\<ip address>/api/v1/logs/events' \\ \ header 'content type application/json' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' \\ \ data '{ "action" "save", "query" "id != ('\\''sys10306'\\'' or '\\''nwc13978'\\'' or '\\''nwc13979'\\'')", "filter" "standard", "begin date" "2023 07 08", "end date" "2023 07 09" }' response saved single log 2023 04 09 21 26 37 ive \[127 0 0 1] system()\[]\[] starting services session server 2023 04 09 21 26 37 ive \[127 0 0 1] system()\[]\[] starting services postgresd 2023 04 09 21 26 37 ive \[127 0 0 1] system()\[]\[] starting services name user coordinator daemon save all logs request curl location 'https //\<ip address>/api/v1/logs/all' \\ \ header 'content type application/json' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' \\ \ data '{ "action" "save" }' response raw file contents in tar gz format clear logs request curl location request put 'https //\<ip address>/api/v1/logs/events' \\ \ header 'content type application/json' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' \\ \ data '{ "action" "clear" }' response "{ "result" { "info" \[ { "message" "successfully cleared logs for events" } ] } }" fetch debug log to get debug log configuration settings request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/maintenance/debuglog' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' h 'accept application/json' response { "enabled" true, "size" 1024, "detail level" 0, "include logs" true, "process names" \[ "string" ], "event codes" \[ "string" ] } update debug log enable or disable debug log, configure debug log settings or clear debug log request curl x 'post' \\ 'https //\<ics ip>/system/maintenance/debuglog' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "enabled" true, "clear" true, "size" 250, "detail level" 0, "include logs" true, "process names" \[ "string" ], "event codes" \[ "string" ] }' response { "result" { "info" \[ { "message" "successfully updated debug log settings " } ] } } fetch diagnostic log get state of the supported diagnostic log types as well as maximum configured log size request curl x 'get' \\ 'https //\<ics ip>/api/v1/system/maintenance/diagnostic logs' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' h 'accept application/json' response { "radius log enabled" true, "profiler log enabled" true, "snmp log enabled" true, "html5 adv log enabled" true, "samba log enabled" true, "pulseone nsa log enabled" true, "attack audit log enabled" true, "attack audit log size" 100 } update diagnostic log enable or disable supported diagnostic log types and configure maximum log size request curl x 'post' \\ 'https //\<ics ip>/api/v1/system/maintenance/diagnostic logs' \\ \ header 'authorization basic wujyz0wvtfbnnedetui3nnzlngd6atrzwmr5ejnvoutiewzsvk5jzdzlst06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "radius log enabled" true, "profiler log enabled" true, "snmp log enabled" true, "html5 adv log enabled" true, "samba log enabled" true, "pulseone nsa log enabled" true, "attack audit log enabled" true, "attack audit log size" 100 }' response { "result" { "info" \[ { "message" "successfully updated diagnostic log settings " } ] } } toggling syslog fault tolerance setting to toggle syslog fault tolerance settings request get /api/v1/configuration/system/log/syslog settings/syslog setting/node1 response { "content type" "application/json", "content length" "197" } "{ "node" "node1", "syslog servers" { "syslog server" \[ { "communication type" "tcp", "fault tolerant" "false", "name" "\<ip address>" } ] } }" request put /api/v1/configuration/system/log/syslog settings/syslog setting "{ "node" "node1", "syslog servers" { "syslog server" \[ { "communication type" "tcp", "fault tolerant" "true", "name" "\<ip address>" } ] } }" response { "content type" "application/json", "content length" "124" } "{ "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } }" client download installer configuration to download installer configuration for ivanti secure access client component sets request curl x 'post' \\ 'https //\<ics ip>/api/v1/pulse client/component settings/download installer config' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "configs" \[ "default", "compset1" ], "url" "10 204 52 75", "user agent" "mozilla/5 0 (windows nt 10 0; win64; x64) applewebkit/537 36 (khtml, like gecko) chrome/87 0 4280 88 safari/537 36" }' response { "config data" "schema version { version \\"1\\"}machine settings { version \\"3\\" guid \\"58e2cd0f fc22 4b73 bacf 8ca282f1b600\\" connection source \\"preconfig\\" server id \\"vasph327i49so7wcs\\" connection set owner \\"\\" connection set name \\"default\\" connection set last modified \\"2023 10 30 21 22 20 utc\\" connection set download host \\"\\" lock down \\"false\\" block traffic on vpn disconnect \\"false\\" allow save \\"true\\" user connection \\"true\\" splashscreen display \\"true\\" dynamic trust \\"false\\" dynamic connection \\"true\\" eap fragment size \\"1400\\" captive portal detection \\"false\\" enable browser \\"true\\" captive portal engine \\"edge\\" embedded browser saml \\"false\\" embedded browser engine \\"edge\\" embedded cef browser saml \\"false\\" fipsclient \\"false\\" wireless suppression \\"false\\" clear smart card pin cache \\"false\\" lockdown exceptions configured \\"false\\"}ive \\"823f2c43 bd2a 4e95 8369 1f3871a32c8c\\" { friendly name \\"sa\\" version \\"3\\" guid \\"823f2c43 bd2a 4e95 8369 1f3871a32c8c\\" client certificate selection rule \\"auto\\" client certificate matching rule smartcard logon enabled \\"true\\" client certificate matching rule eku oid \\"\\" client certificate matching rule eku text \\"\\" server id \\"vasph327i49so7wcs\\" connection source \\"preconfig\\" factory default \\"true\\" uri \\"10 204 52 75\\" connection policy override \\"true\\" connection lock down \\"false\\" enable stealth mode \\"false\\" show stealth connection \\"false\\" use for connect \\"true\\" uri list use last connected \\"false\\" uri list randomize \\"false\\" sso cached credential \\"false\\" connection identity \\"user\\" connection policy \\"automatic\\" client certificate location system \\"false\\" reconnect at session timeout \\"true\\"}" } client configuration request curl x 'post' \\ 'https //\<ics ip>/api/v1/pulse client?operation=assume ownership' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' \\ h 'content type application/json' \\ d '{ "configs" \[ "default", "isaone" ] }' response { "result" { "info" \[ { "message" "client configuration table updated successfully " } ] } } nsa apis fetch nsa registration status request curl x 'get' \\ 'https //\<ics ip>/api/v1/nsa/register' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "gateway id" "21477b2c3b694194bfceaa4124e7206a", "notification status" "success", "notification status message" "the notification channel is connected ", "notification url" "wss\ //tenant e cluster pzt dev perfsec com/api/v1/notifications", "reg status" "success", "reg status message" "" } register with nsa request curl x 'post' \\ 'https //\<ics ip>/api/v1/nsa/register' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' \\ h 'content type application/json' \\ d '{ "reg host fqdn" "tenant cluster pzt dev perfsec com", "reg code" "hx7ezvvvzt", "nw interface" "internal" }' response { "success" "successfully triggered registration" } delete nsa registration request curl x 'delete' \\ 'https //\<ics ip>/api/v1/nsa/register' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "success" "successfully cleared ivanti neurons for secure access configuration" } fetch status of tenant to get status of tenant and check if user login requests are being allowed or blocked request curl x 'get' \\ 'https //\<ics ip>/api/v1/tenant/status' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "code" 200, "status" "active" } pulse one retrieve pulse one status request curl x 'get' \\ 'https //\<ics ip>/api/v1/pulse one' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "credentials exchange time" "2023 12 21t12 34 56", "hashing algorithm" "sha256", "client device id" "abc123", "notification url" "https //example com/notification", "registration status" "connected", "notification channel status" "in progress" } actions on pulse one perform actions on pulse one request curl x 'put' \\ 'https //\<ics ip>/api/v1/pulse one' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' \\ h 'content type application/json' \\ d '{ "action" "renegotiate credentials" }' response { "result" { "info" \[ "successfully triggered action with pulse one" ] } } snmp fetch snmp details fetch the content of mib file request curl x 'get' \\ 'https //\<ics ip>/api/v1/snmp/download mib' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "snmp mib log" "ufvmu0vtrunvukutufnhlu1jqiberuzjtklusu9ouya6oj0gqkvhsu4kicagicagicbjtvbpulrtiaogicagicagialot1rjrkldqvrjt04tvflqrswgtu9evuxfluleru5us vrzlcblbnrlcnbyaxnlcwogicagicagiakjrljptsbttk1qdjitu01jciagicagicagcu5ldhdvcmtbzgryzxnzciagicagicagcqlguk9nifjgqzexntutu01jciagicagic agculwqwrkcmvzcwogicagicagiakjrljptsbsrkmxmtu1lvnnstskicagicagicakchvsc2vzzwn1cmutz2f0zxdhesbnt0rvteutsurftlrjvfkkicagiexbu1qtvvbeqvr frcaimjaymja1mdkxnjmzwiikicagie9sr0fosvpbvelptiaiuhvsc2ugu2vjdxjligogicagq09ovefdvc1jtkzpicagiaojicjjbnrlcm5lddogahr0chm6ly93d3cuchvs c2vzzwn1cmuubmv0igogicagrevtq1jjufrjt04kcsjuaglzigzpbgugzgvmaw5lcyb0agugchjpdm " } fetch snmpv3 details to fetch the agent engine id and trap engine id details request curl x 'get' \\ 'https //\<ics ip>/api/v1/snmpv3' \\ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' response { "agent engine id" "0x800030f405a927fbb86f048665", "trap engine id" "0x800030f405a927fbb86f048665" } automatic version monitoring to automate version monitoring request put /api/v1/configuration/system/maintenance/options "{ "automatic version monitoring" \\"false\\" }" response { "content type" "application/json", "content length" "124" } "{ "result" { "info" \[ { "message" "operation succeeded without warning or error!" } ] } }" run external ict scan this api provides an option to ics admin to run external ict scans and obtain the results in an automated method here's a concise summary of api's functionality automated scanning workflow uploads the external ict package validates, extracts, and executes the scanner tool snapshot generation creates an external ict snapshot with a file name to download using snapshot api docid\ tefgymbzjpphrdnf qdqz includes an anomaly details file located at `/data/runtime/anomaly details` only one external ict scan can run at a time, whether triggered via admin ui or api request curl x 'post' \\ 'https //\<serverip>/api/v1/system/maintenance/upgrade?operation=run ict' \\ h 'accept application/json' \\ h 'content type multipart/form data' \ form 'file=@"/users/user1/downloads/external ict package pkg"' sample response { "result" { "ictstats" { "counts" { "matched files count" 36667, "mismatched files count" 1, "new files count" 2 }, "snapshot name" "pulsesecure state integrityscanner admin scanner localhost2 20250228 223052" } } } fetch virtual desktops list to fetch virtual desktops list for citrix xendesktop or vmware view manager request curl x 'post' \\ 'https //\<ics ip>/api/v1/users/resource profile/virtual desktops list' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06' h 'accept application/json' \\ h 'content type application/json' \\ d '{ "type" "vmware view manager", "user name" "vdiadmin", "password" "pulse 123", "domain" "pcsauto com", "server name" "10 96 224 70", "use ssl" 1 }' response { "desktop list" \[ "displayname1 (as4d89f)", "displayname2 (m9n456h)" ] } enable auto update for hostchecker to enable auto update for hostchecker virus signature version monitoring and then download and import the latest virus signatures file request curl x 'post' \\ 'https //\<ics ip>/api/v1/host checker/live update/validate credentials' \\ \ header 'authorization basic dmt5m3zjzmnpcwzqejd0zct1ewsvexrjylm4vkizk0kwdhhlvupzugryrt06 h 'accept application/json' \\ h 'content type application/json' \\ d '{ "av liveupdate" { "enabled" "true", "portal password cleartext" "password", "portal user name" "username", "proxy address" "1 1 1 1", "proxy enabled" "true", "proxy password cleartext" "password", "proxy port" 80, "proxy user name" "username", "update freq" 30, "update url" "https //download pulsesecure net/software/av/uac/epupdate hist xml" } }' response { "result" {"info" \[ { "message" "download successful" } ] } } sample error responses 400 bad request request put /api/v1/configuration/users/user realms/realm/testrealm/role mapping rules/rule/rule1 http/1 1 host \<ip address> authorization basic y1vpze1xz1zubvevvnircwwrd3ljy3f0y05wtghdvkx1m0wrdk5yr3hzvt06 content type application/json { "name" "rule1", "roles" \[ "users" ], "stop rules processing" "false", "user name" { "test" "is", "user names" \[ " ", ] } } response http/1 1 400 bad request content length 92 content type application/json { "message" "the browser (or proxy) sent a request that this server could not understand " } solution invalid json body content in request please check if json is valid request put /api/v1/configuration/users/user roles/user role/rest userrole 1 http/1 1 host \<ip address> authorization basic mvhdbdjtsuhkv3zjukd6wxm1t1v3mu5wbhnmemjpbtjxshi2nvzcdxp5bz06 { "name" "rest userrole 1", "web" { "web bookmarks" { "bookmark" \[ { "auto allow" "disable", "description" "", "name" "web bm 1", "new window" "false", "no address bar" "false", "no tool bar" "false", "parent" " none ", "standard" { "url" "http //www yahoo com" } } ] }, "web options" { "browsing untrusted sslsites" "true", "flash content" "false", "hpxproxy connection timeout" "1800", "http connection timeout" "240", "java applets" "true", "mask hostname" "false", "persistent cookies" "false", "rewrite file urls" "false", "rewrite links pdf" "false", "unrewritten page newwindow" "false", "user add bookmarks" "false", "user enter url" "false", "users bypass warnings" "false", "warn certificate issues" "true", "websocket connection timeout" "900" } } } response http/1 1 400 bad request content length 99 content type application/json { "result" { "errors" \[ { "message" "accepts only json " } ] } } include the “content type” header in the request with a value “application/json” as used in the examples above 403 forbidden request get /api/v1/auth http/1 1 host \<ip address> authorization basic ywrtaw5kyjpkyw5hmtiz content type application/json response http/1 1 403 forbidden cache control no store connection keep alive content type text/html; charset=utf 8 expires 1 keep alive timeout=15 strict transport security →max age=31536000 transfer encoding chunked solutions make sure admin user used for authentication has "allow access to rest apis" option enabled frm admin ui admin username and password passed in authorization header are correct if api key is available, use api key value as username and password as empty in authorization header 404 not found request get /api/v1/configuration/users/user realms/realm/testrealm/role mapping rules/rule http/1 1 host \<ip address> authorization basic y1vpze1xz1zubvevvnircwwrd3ljy3f0y05wtghdvkx1m0wrdk5yr3hzvt06 response http/1 1 404 not found content length 213 content type application/json { "result" { "errors" \[ { "message" "invalid resource path; use \\"users/user realms/realm/testrealm/role mapping rules/rule/\<resource id>\\" to access a specific resource" } ] } } solution resource id should be passed in resource path as shown in example below request get /api/v1/configuration/users/user realms/realm/testrealm/role mapping rules/rule/rule1 http/1 1 host \<ip address> authorization basic y1vpze1xz1zubvevvnircwwrd3ljy3f0y05wtghdvkx1m0wrdk5yr3hzvt06 response http/1 1 200 ok content length 167 content type application/json { "name" "rule1", "roles" \[ "users" ], "stop rules processing" "false", "user name" { "test" "is", "user names" \[ " " ] } } solution invalid json body content in request please check if json is valid 422 unprocessable entity request post /api/v1/configuration/users/user realms/realm/testrealm/role mapping rules/rule/ http/1 1 host \<ip address> authorization basic y1vpze1xz1zubvevvnircwwrd3ljy3f0y05wtghdvkx1m0wrdk5yr3hzvt06 content type application/json { "name" "rule2", "roles" \[ "users", "testrole1" ], "stop rules processing" "false", "user name" { "test" "is", "user names" \[ "user1" ] } } response http/1 1 422 unprocessable entity content length 368 content type application/json { "result" { "errors" \[ { "message" "\[/users/user realms/realm\[name=testrealm]/role mapping rules/rule\[name=rule2]/roles] invalid reference no 'user roles' object found with identifier 'testrole1' " }, { "message" "failed to resolve path references" }, { "message" "commit failed" } ] } } solution make sure to have all the referenced resources are created first using post call and then repeat expand command expand is useful command to retrieve complete output when used in the base of the url (example /api/v1/configuration/users/resource policies/network connect policies/network connect acls?expand) at the root level, using the?expand command (example /api/v1/configuration?expand) is not advised since it may cause a crash and abruptly terminate the system limitations \<font color="#58595b">configuration of large data objects is not qualified esap, client package, custom sign in page, applets, and so on \</font>\<font color="#58595b">resource names similar to resource tags e g vlans, roles, etc should be avoided while creating new resources \</font>
