> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apinizer.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Certificates

> You can define and manage certificates used in policies and connections. You can perform operations such as receiving via HTTPS/LDAPS connection, importing from file, pasting from clipboard, and truststore management.

## Creating a New Certificate

<Steps>
  <Step title="Filling Definition Information">
    Click the **Create** button from the **Management → Secrets Management → Certificates** screen. Fill in the information under **Definition**. Then click the **New Certificate Definition** button.

    <img src="https://mintcdn.com/apinizer/-D5M2RGzFaEFXP51/images/yonetici/sertifika1.png?fit=max&auto=format&n=-D5M2RGzFaEFXP51&q=85&s=6dee2b57b6a3a697b5838489fd39f435" alt="Certificate Definition Information" width="1000" height="600" data-path="images/yonetici/sertifika1.png" />

    The fields used for certificate creation configuration are shown in the table below.

    | Field       | Description                                                                               |
    | ----------- | ----------------------------------------------------------------------------------------- |
    | Name        | Name information of the created certificate.                                              |
    | Description | A description can be written to facilitate management related to the created certificate. |
  </Step>

  <Step title="Filling Certificate Configuration Information">
    Fill in the configuration information for the Certificate in the opened window. Then click the **Apply** button. The saved **Certificate Definition** is listed in the table opened under **Configuration**.

    <img src="https://mintcdn.com/apinizer/-D5M2RGzFaEFXP51/images/yonetici/sertifika2.png?fit=max&auto=format&n=-D5M2RGzFaEFXP51&q=85&s=f96b19840e0484a429737895e529c3a2" alt="Certificate Configuration Information" width="1000" height="600" data-path="images/yonetici/sertifika2.png" />

    The fields used for certificate definition configuration are shown in the table below.

    | Field                                         | Açıklama                                                                                                                                                                           |
    | --------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
    | Environments (Environments)                   | The previously defined environment where the certificate will be used is selected.                                                                                                 |
    | Source Of Certificate (Source Of Certificate) | The source from which the certificate will be obtained. Three options are available:<br />- Receive via HTTPS/LDAPS Connection<br />- Import from File<br />- Paste from Clipboard |
    | URL                                           | When the Receive via HTTPS/LDAPS Connection option is selected, the HTTPS or LDAPS URL connection address is entered in the URL field and the button next to it is clicked.        |
    | File (File)                                   | When the Import from File option is selected, the file containing the certificate is selected by clicking the "Select File" button.                                                |
    | Certificate (Certificate)                     | When the Paste from Clipboard option is selected, this is the field where the certificate will be pasted.                                                                          |
    | Encoding Type (Encoding Type)                 | When the Paste from Clipboard option is selected, the encoding type of the pasted certificate is selected. Two options are available:<br />- BASE64<br />- BASE64PEM               |
    | Alias                                         | The alias information of the certificate is entered.                                                                                                                               |
    | Content (Content)                             | This is the field where the content of the certificate is displayed.                                                                                                               |
    | Certificate (Certificate)                     | Obtained from the certificate.                                                                                                                                                     |
  </Step>

  <Step title="Save and Deploy">
    After completing the definition and configuration information, click the **Save and Deploy** button to deploy.

    <img src="https://mintcdn.com/apinizer/-D5M2RGzFaEFXP51/images/yonetici/sertifika3.png?fit=max&auto=format&n=-D5M2RGzFaEFXP51&q=85&s=a3a2680a35207077f74319868f909beb" alt="Certificate Save and Deploy" width="1000" height="600" data-path="images/yonetici/sertifika3.png" />
  </Step>
</Steps>

## API Manager Environment and JVM TrustStore Synchronization

In certificate environment selection, the **API Manager** environment has a special meaning. Certificates assigned to this environment are automatically added to the API Manager application's JVM TrustStore. This ensures that server certificates are validated during HTTPS calls made from API Manager (spec download, test console, OIDC discovery, etc.).

<Info>
  Certificates assigned to the API Manager environment are automatically loaded into the JVM when the application starts. When a certificate is added, updated, or deleted, the JVM TrustStore is updated immediately; no restart is required.
</Info>

<Warning>
  If API Manager connects to servers using self-signed certificates (e.g., spec URL or OIDC provider), the relevant certificate must be assigned to the **API Manager** environment here. Otherwise, a PKIX certificate error will occur during connection.
</Warning>

## Certificate Editing

<Steps>
  <Step title="Clicking Edit Button">
    To edit an existing certificate, click the **Edit** button from that certificate's menu.

    <img src="https://mintcdn.com/apinizer/-D5M2RGzFaEFXP51/images/yonetici/sertifika4.png?fit=max&auto=format&n=-D5M2RGzFaEFXP51&q=85&s=03f2d0cbf08b414a5b1da5ff4f4ad011" alt="Certificate Editing" width="1000" height="600" data-path="images/yonetici/sertifika4.png" />
  </Step>

  <Step title="Update or Cancel Operations">
    In the screen opened when you click the **Edit** field, you can perform **update** and **cancel** operations on the certificate.
  </Step>

  <Step title="Saving Changes">
    Click the **Apply** button to save the changes you made.

    <img src="https://mintcdn.com/apinizer/-D5M2RGzFaEFXP51/images/yonetici/sertifika5.png?fit=max&auto=format&n=-D5M2RGzFaEFXP51&q=85&s=6b71265d47b7fc6da0e38d60225f65b0" alt="Certificate Saving Changes" width="1000" height="600" data-path="images/yonetici/sertifika5.png" />
  </Step>
</Steps>

### Updating Related JWKs

When a certificate is updated and the **Save and Deploy** button is clicked, if there are JWKs created from this certificate, the system automatically detects related JWKs and presents the user with options.

<Info>
  When a certificate is updated, JWKs created from this certificate can also be automatically updated or the relationship can be disconnected.
</Info>

#### JWK Connection Dialog

When a certificate is updated and related JWKs are detected, the following dialog opens:

<img src="https://mintcdn.com/apinizer/Gg0kSw8S7n4NUarZ/images/yonetici/jwk.png?fit=max&auto=format&n=Gg0kSw8S7n4NUarZ&q=85&s=3dafa95bce928b4d26c5eaf34f6931b2" alt="JWK Connection Dialog" width="600" height="400" style={{ borderRadius: '0.5rem' }} data-path="images/yonetici/jwk.png" />

**Dialog Content:**

* **Title**: "JWK Connection"
* **Warning Message**: "This Certificate is used in X JWK(s). What would you like to do?"
* **Options**:
  * **Update related JWKs**: Ensures that changes in the certificate are reflected to related JWKs as well. When this option is selected, related JWKs are automatically updated when the certificate is updated.
  * **Update certificate only and disconnect**: Updates the certificate but disconnects the relationship with JWKs. When this option is selected, the certificate is updated but JWKs remain in their previous state and the relationship is removed.
  * **Cancel**: Cancels the operation and no changes are made.

#### Update Flow

<Steps>
  <Step title="Certificate Update">
    Edit the certificate information and click the **Save and Deploy** button.
  </Step>

  <Step title="Related JWK Check">
    The system checks for JWKs created from this certificate.
  </Step>

  <Step title="Dialog Display">
    If there are related JWKs, the JWK Connection dialog opens.
  </Step>

  <Step title="Making Selection">
    The user selects one of three options:

    * **Update**: Update related JWKs as well
    * **Disconnect**: Update only the certificate, disconnect the relationship
    * **Cancel**: Cancel the operation
  </Step>

  <Step title="Confirmation Dialog">
    When Update or Disconnect is selected, a confirmation dialog opens. The user confirms the operation by entering the certificate name.
  </Step>

  <Step title="Completing Operation">
    After confirmation, the selected operation is performed and the certificate is updated.
  </Step>
</Steps>

<Warning>
  Updating related JWKs may affect all policies and connections using these JWKs. Evaluate the impacts before proceeding.
</Warning>

## Certificate Deletion

<Steps>
  <Step title="Clicking Delete Button">
    To delete an existing certificate, click the **Delete** button from that certificate's menu.

    <img src="https://mintcdn.com/apinizer/-D5M2RGzFaEFXP51/images/yonetici/sertifika6.png?fit=max&auto=format&n=-D5M2RGzFaEFXP51&q=85&s=0b8cd6d098ee94abf90c32b058538efd" alt="Certificate Deletion" width="1000" height="600" data-path="images/yonetici/sertifika6.png" />
  </Step>

  <Step title="Related JWK Check">
    The system checks for JWKs created from this certificate. If there are related JWKs, the JWK Connection dialog opens.
  </Step>

  <Step title="Deletion Options">
    If there are related JWKs, the following options are presented:

    * **Delete JWKS**: Delete related JWKs as well
    * **Delete Disconnect**: Delete only the certificate, keep JWKs (relationship is disconnected)
    * **Cancel**: Cancel the operation
  </Step>

  <Step title="Confirmation Dialog">
    When Delete JWKS or Delete Disconnect is selected, a confirmation dialog opens. The user confirms the operation by entering the certificate name.
  </Step>

  <Step title="Confirming Deletion Operation">
    Click the **Delete** button again in the opened window to confirm.

    <img src="https://mintcdn.com/apinizer/-D5M2RGzFaEFXP51/images/yonetici/sertifika7.png?fit=max&auto=format&n=-D5M2RGzFaEFXP51&q=85&s=84a9d2e7b0be43ad2551af4d83624db1" alt="Certificate Deletion Confirmation" width="1000" height="600" data-path="images/yonetici/sertifika7.png" />
  </Step>
</Steps>

### Deleting Related JWKs

When a certificate is deleted, if there are JWKs created from this certificate, the system automatically detects related JWKs and presents the user with options.

<Warning>
  When a certificate is deleted, related JWKs may also be deleted or the relationship may be disconnected. This operation cannot be undone. Evaluate the impacts before proceeding.
</Warning>

#### Deletion Flow

<Steps>
  <Step title="Certificate Deletion Request">
    Start the certificate deletion operation.
  </Step>

  <Step title="Related JWK Check">
    The system checks for JWKs created from this certificate.
  </Step>

  <Step title="Dialog Display">
    If there are related JWKs, the JWK Connection dialog opens.
  </Step>

  <Step title="Making Selection">
    The user selects one of three options: Delete JWKS, Delete Disconnect, or Cancel.
  </Step>

  <Step title="Confirmation Dialog">
    When Delete JWKS or Delete Disconnect is selected, a confirmation dialog opens. The user confirms the operation by entering the certificate name.
  </Step>

  <Step title="Completing Operation">
    After confirmation, the selected operation is performed and the certificate is deleted.
  </Step>
</Steps>

## Certificate Export

Two different export options are available on the certificate view screen:

<Steps>
  <Step title="Selecting Export Type">
    On the certificate view screen, two export buttons are available in the top menu:

    * **Export as Certificate**: Exports the certificate in certificate file format.
    * **Export**: Exports the certificate configuration in JSON/ZIP format. This format is suitable for importing into another Apinizer environment.

    <img src="https://mintcdn.com/apinizer/-D5M2RGzFaEFXP51/images/yonetici/sertifika8.png?fit=max&auto=format&n=-D5M2RGzFaEFXP51&q=85&s=25a516065f33c6d81074a048d1c0c737" alt="Certificate Export" width="1000" height="600" data-path="images/yonetici/sertifika8.png" />
  </Step>

  <Step title="Downloading the File">
    The file is automatically downloaded based on the selected export type. The ZIP format export file is named with date information and can be imported into other environments.
  </Step>
</Steps>

<Info>
  The JSON/ZIP format export contains the complete certificate configuration and can be used for migration to different Apinizer environments. The certificate format export downloads the certificate directly as a certificate file.
</Info>

## Truststore

In the Truststore tab, digital certificates used in Apinizer and trusted root certificate authorities (CA) are listed.

<img src="https://mintcdn.com/apinizer/-D5M2RGzFaEFXP51/images/yonetici/sertifika9.png?fit=max&auto=format&n=-D5M2RGzFaEFXP51&q=85&s=fb03d8ee45fae97f6d9555ee8911e568" alt="Truststore" width="1000" height="600" data-path="images/yonetici/sertifika9.png" />
