RESTful API
(Feature available only in the Enterprise Edition)

Introduction

Password Manager Pro (PMP) APIs allow you to connect, interact and integrate with PMP directly. The APIs belong to the REpresentational State Transfer (REST) category and let you add resources, accounts, retrieve passwords, retrieve resource/account details and update passwords programmatically.

Pre-requisite

Creating API user accounts is the first step in the process of configuring password management APIs for Application-to-Application password management. Click here to know how to create an API user account.

APIs Summary

Methods used to invoke APIs

GET

To fetch resources, accounts, passwords, account/resource details

PUT

To change a password

POST

To create new resource and accounts

How to make use of the APIs?

Invoking the APIs

The APIs can be invoked via HTTP POST, GET and PUT requests. All parameters in the request should be form-urlencoded. For all the APIs you need to pass the AUTH token, which is mandatory.

Supported Format

PMP supports the JSON format and the URL structure for it is as given in the table below:

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/<Resource ID>/accounts/<Account ID>?AUTHTOKEN=(The token you have generated and copied from the GUI)

Password Manager Pro provides a wide range of APIs to:

1. Get the Resources Owned and Shared to a User

Description

To get the list of resources which are owned by or shared to an API user.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

GET

Input Data

None

Sample Request

curl -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" https://192.168.xx.xx:<Port>/restapi/json/v1/resources

Sample Output

In the output (as shown in the sample below), you will get all the resources owned and shared by the specific API user.

{
"operation" : {
"name" : "GET RESOURCES" ,
"result " : {
"status" : "Success",
"message" : "Resources fetched successfully"

},
"totalRows":3,
"Details": {
{
"RESOURCE DESCRIPTION":"CentOS Machine",
"RESOURCE NAME":"CentOS Machine",
"RESOURCE ID":"301",
"RESOURCE TYPE":"Linux",
"NOOFACCOUNTS" : "3"
},
{
"RESOURCE DESCRIPTION":"Cisco IOS Device",
"RESOURCE NAME":"Cisco IOS Device",
"RESOURCE ID":"302",
"RESOURCE TYPE":"Cisco IOS",
"NOOFACCOUNTS":"2"
},
{
"RESOURCE DESCRIPTION":"Weblogic Data Source Password",
"RESOURCE NAME":"WebLogic Server",
"RESOURCE ID":"303",
"RESOURCE TYPE":"WebLogic Server",
"NOOFACCOUNTS":"2"
}
}
} }

2. Get the Accounts that are Part of a Resource

Description

To get the list of accounts and resource details present in the resource. Resource ID can be obtained from the GET RESOURCES API (explained above).

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/<Resource ID>/accounts

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

GET

Input Data

None

Sample Request

curl -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" https://192.168.xx.xx:<Port>/restapi/json/v1/resources/303/accounts


Sample Output

In the output (as shown in the sample below), you will get all the resources owned and shared by the specific API user.

{
"operation":{
"name":"GET RESOURCE ACCOUNTLIST",
"result ":{
"status": "Success ,
"message":"Resource details with account list fetched successfully"
},
"Details":{
"RESOURCE ID":"303",
"RESOURCE NAME":"MSSQL server",
"RESOURCE DESCRIPTION" :"WebLogic Data source password",
"RESOURCE TYPE":"MS SQL server",
"DNS NAME":" sqlserver-l",
"PASSWORD POLICY":"Strong",
"DEPARTMENT": "SQL Server DBA" ,
"LOCATION":"Level 10",
"RESOURCE URL":"http://sqlserver-1/",
"RESOURCE OWNER": "admin",
"CUSTOM FIELD":{
"CUSTOMFIELDVALUE":"78336298",
"CUSTOMFIELDTYPE":"Numeric",
"CUSTOMFIELDLABEL":"License No" ,
"CUSTOMFIELDCOLUMNNAME":"COLUMN_LONG1"
},
{
"CUSTOMFIELDVALUE":"Sep 10, 2013",
"CUSTOMFIELDTYPE" : "Date",
"CUSTOMFIELDLABEL":" Installed Date",
"CUSTOMFIELDCOLUMNNAME" "COLUMN_DATE1"
},
{
"CUSTOMFIELDVALUE":"Tese123$*%%,
"CUSTOMFIELDTYPE":"Password",
"CUSTOMFIELDLABEL":"Resource Password", "CUSTOMFIELDCOLUMNNAME":"COLUMN_SCHAR1"
},
{
"CUSTOMFIELDVALUE":"YES"
"CUSTOMFIELDTYPE":"Character",
"CUSTOMFIELDLABEL":"Secure Resource",
"CUSTOMFIELDCOLUMNNAME":"COLUMN_CHAR1"
}
},
"ACCOUNT LIST": {
{
"ISFAVPASS": "false",
"ACCOUNT NAME":"sysdba",
"PASSWDID":"308",
"PASSWORD STATUS":"[In Use]",
"ACCOUNT ID":"308"
},
{
"ISFAVPASS":"false",
"ACCOUNT NAME":"system",
"PASSWDID":"307"
"PASSWORD STATUS":"*****",
"ACCOUNT ID":"307"
}
}
}
}
}

Note: If password access control had been enabled AND If the password status is 'IN USE', you will see the output as [ In use ].


3. Get Details of an Account

Description

To get the details of an account that is part of a resource, you need to pass both Resource ID and Account ID to fetch the required details.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/<Resource ID>/accounts/<Account ID>

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

GET

Input Data

None

Sample Request

curl -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" https://192.168.xx.xx:<Port>/restapi/json/v1/resources/303/accounts/307

Sample Output

{
"operation":{
"name":"GET RESOURCE ACCOUNT DETAILS",
result":{
status":"Success",
message":"Account details fetched successfully"
},
"Details":{
"DESCRIPTION":"",
"LAST ACCESSED TIME":"N/A",
"LAST MODIFIED TIME":"Sep 10, 2013 3:33 PM",
"PASSWORD STATUS":"*****",
"PASSWDID":"307",
"CUSTOM FIELD":[
{
"CUSTOMFIELDVALUE": "56455567",
"CUSTOMFIELDTYPE":"Numeric",
"CUSTOMFIELDLABEL":"Account LIC Number",
"CUSTOMFIELDCOLUMNNAME":"COLUMN_LONG1"
},
{
"CUSTOMFIELDVALUE": "Sep 10, 2013",
"CUSTOMFIELDTYPE":"Date",
"CUSTOMFIELDLABEL":"Acc creation date",
"CUSTOMFIELDCOLUMNNAME":"COLUMN_DATE1"
},
{
"CUSTOMFIELDVALUE": "Test12345",
"CUSTOMFIELDTYPE":"Password",
"CUSTOMFIELDLABEL":"Secondary Password",
"CUSTOMFIELDCOLUMNNAME":"COLUMN_SCHAR1"
},
{
"CUSTOMFIELDVALUE": "YES",
"CUSTOMFIELDTYPE":"Character",
"CUSTOMFIELDLABEL":"Secure Account",
"CUSTOMFIELDCOLUMNNAME":"COLUMN_CHAR1"
}
]
}
}
}


4. Get the Password of an Account that is Part of a Resource

Description

To get the password of an account that is part of a resource, you need to pass both Resource ID and Account ID to fetch the required details.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/<Resource ID>/accounts/<Account ID>/password

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

GET

Input Data

In case the setting at your end demands a reason to be supplied for retrieving a password, you need to pass the following details as input. If the ticketing system is enabled, you need to pass ticket ID for validation.

INPUT_DATA={"operation":{"Details":{"REASON":"Need the password to Login Windows Server","TICKETID":"7"}}}

Sample Request

curl -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" https://192.168.xx.xx:<Port>/restapi/json/v1/resources/303/accounts/307/password


curl -X GET -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json" --url -d 'https://192.168.xx.xx:<Port>/restapi/json/v1/resources/303/accounts/307/password?INPUT_DATA=\{"operation":\{"Details":\{"REASON":"Need the password to Login Windows Server","TICKETID":"7"\}\}\}'

Sample Output

{
"operation":{
"name":"GET PASSWORD",
"result":{
"status": "Success",
"message":"Password fetched successfully"
},
"Details":{
"PASSWORD":"fqxdB7A^)4"
}
}
}

Note: If there occurs any problem on retrieving password, the reason will be displayed as part of message.


5. Change the Password of an Account

Description

To change the password of an account that is part of a resource, you need to pass both Resource ID and Account ID to fetch the required details. If the ticketing system is enabled, you need to pass ticket ID for validation.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/<Resource ID>/accounts/<Account ID>/password

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

PUT

Input Data

You need to pass input data such as new password, reset type and reason. Reset type should be either LOCAL or REMOTE.

        INPUT_DATA={
   "operation":{
      "Details":{
         "NEWPASSWORD":"Test@12345$",
         "RESETTYPE":"LOCAL",
         "REASON":"Password Expired",
         "TICKETID":"7"
      }
   }
}

Sample Request

curl -X PUT -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json" --url https://192.168.xx.xx:<Port>/restapi/json/v1/resources/303/accounts/307/password?INPUT_DATA=\{"operation":\{"Details":\{"NEWPASSWORD":"Test12345$","RESETTYPE":"LOCAL","REASON":"test","TICKETID":"7"\}\}\}

Sample Output

{
 "operation":{
  "name":"CHANGE PASSWORD",
  "result":{
   "status":"Success",
   "message":"Password changed successfully"
  }
 }
}

Note: If there occurs any problem on changing password, the reason will be displayed as part of message.


6. Create a New Resource

Description

To create a new resource in PMP.

Input Data

You need to pass input data such as name of the resource, account name, resource type, password, URL, description, notes and any other additional fields at the resource and account levels. You can add as many as 40 custom fields (20 each at resource and account levels). Of these, resource name, account name, resource type and password are mandatory.

         INPUT_DATA={
         "operation":{
         "Details":{
         "RESOURCENAME":"Windows Server",
         "ACCOUNTNAME":"Administrator",
         "RESOURCETYPE":"Windows",
         "PASSWORD":"Test123#@!",
         "NOTES":"Testing API",
         "RESOURCEURL":"http://windowsserver/adminconsole",
         "RESOURCEPASSWORDPOLICY":"Strong",
         "ACCOUNTPASSWORDPOLICY":"Strong",
         "RESOURCECUSTOMFIELD":[
            {
               "CUSTOMLABEL":"Secure Resource",
               "CUSTOMVALUE":"YES"
            }
         ],
	"ACCOUNTCUSTOMFIELD":[
            {
               "CUSTOMLABEL":"Secure Account",
               "CUSTOMVALUE":"YES"
            }
         ]
      }
   }
}
        

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

POST

Sample Request

curl -X POST -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "content-Type: text/json" 'https://192.168.39.29:<Port>/restapi/json/v1/resources -d 'INPUT_DATA={"operation":{"Details":{"RESOURCENAME":"Windows Server","ACCOUNTNAME":"Administrator","RESOURCETYPE":"Windows","PASSWORD" :"Test123#@!","NOTES":"Testing API","RESOURCEURL":"http://windowsserver/adminconsole","RESOURCEPASSWORDPOLICY":"Strong","ACCOUNTPASSWORDPOLICY":"Strong","RESOURCECUSTOMFIEL D":[{"CUSTOMLABEL":"Secure Resource","CUSTOMVALUE":"YES"}],"ACCOUNTCUSTOMFIELD":[{ "CUSTOMLABEL":"Secure Account","CUSTOMVALUE":"YES"}]}}}

Sample Output

{
 "operation":{
  "name":"CREATE RESOURCE",
  "result":{
   "status":"Success",
   "message":"Resource Windows Server has been added successfully"
  }
 }

Note: If you want to add a new resource under Administrator/Password Administrator/Privileged Administrator an additional parameter "OWNERNAME" having the value of that particular user should be added to the resource details. While adding the resource to AD user, the username must be in the format "Domain-Name\\UserName".

 INPUT_DATA={
   "operation":{
      "Details":{
         "RESOURCENAME":"Windows Server",
         "ACCOUNTNAME":"Administrator",
         "RESOURCETYPE":"Windows",
         "PASSWORD":"Test123#@!",
         "NOTES":"Testing API",
         "RESOURCEURL":"http://windowsserver/adminconsole",
         "OWNERNAME":"admin",
         "RESOURCECUSTOMFIELD":[
            {
               "CUSTOMLABEL":"Secure Resource",
               "CUSTOMVALUE":"YES"
           }
         ],
	"ACCOUNTCUSTOMFIELD":[
            {
               "CUSTOMLABEL":"Secure Account",
               "CUSTOMVALUE":"YES"
            }
         ]
      }
   }
}


Note: If you want to add a resource to a static resource group, an additional parameter "RESOURCEGROUPNAME" having the value of that particular resource group should be added to the resource creation input. If the group already exists, this resource will be added to that group; otherwise, a new group with the name specified here will be created.

   INPUT_DATA={
   "operation":{
      "Details":{
         "RESOURCENAME":"Windows Server",
         "ACCOUNTNAME":"Administrator",
         "RESOURCETYPE":"Windows",
         "PASSWORD":"Test123#@!",
         "NOTES":"Testing API",
         "RESOURCEURL":"http://windowsserver/adminconsole",
         "RESOURCEGROUPNAME":"Windows Servers",
         "RESOURCECUSTOMFIELD":[
            {
               "CUSTOMLABEL":"Secure Resource",
               "CUSTOMVALUE":"YES"
            }
        ],
	"ACCOUNTCUSTOMFIELD":[
            {
               "CUSTOMLABEL":"Secure Account",
               "CUSTOMVALUE":"YES"
            }
         ]
      }
    }
  }

Note: You can also add files as a separate resource in PMP. To add a file as a new resource, the 'Content-Type' in the request has to be modified as shown in the sample below. Once you have modified, you just have to pass the file along with it.

  INPUT_DATA={
   "operation":{
      "Details":{
         "RESOURCENAME":"Active Directory",
         "ACCOUNTNAME":"Administrator",
         "RESOURCETYPE":"License Store",
         "PASSWORD":"Test123#@!",
         "NOTES":"Testing API",
         "RESOURCEURL":"http://windowsserver/adminconsole"
         }
    }
  }

Sample Request

curl -X POST -k -H "Content-Type: multipart/form-data"  -F 'file=@standalonesample.txt' -F 
'INPUT_DATA={"operation":{"Details":{"RESOURCENAME":"Windows erver","ACCOUNTNAME":"Administrator","RESOURCETYPE":"File Store",
"PASSWORD":"Test123#@!","NOTES":"Testing API","RESOURCEURL":"http://windowsserver/adminconsole"}}}' 'https://192.168.xx.xx:<Port>/
restapi/json/v1/resources?AUTHTOKEN=F73552FD-DDC2-415E-BF5D-06CFA519658B'

7. Get the Account ID and Resource ID

Description

To get the account ID and resource ID, you need to pass the resource name and account name in the URL.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/getResourceIdAccountId? RESOURCENAME=(Resourcename)&ACCOUNTNAME=(Account name)

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

GET

Input Data

None

Sample Request

curl -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" https://192.168.xx.xx:<Port>/restapi/json/v1/resources/getResourceIdAccountId?RESOURCENAME=MSSQLServer&ACCOUNTNAME=system

Sample Output

{
 "operation":{
  "name":"GET_RESOURCEACCOUNTID",
  "result":{
   "status":"Success",
   "message":"Resource ID and account ID fetched successfully for the given resource
name and account name."
  },
  "Details":{
   "RESOURCEID":"303",
   "ACCOUNTID":"307"
  }
 }
}

8. Get the Resource ID using the Resource Name

Description

To fetch the resource ID, you can provide the resource name alone in the URL.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/resourcename/{RESOURCENAME}

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

DELETE

Input Data

None

Sample Request

curl -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" https://192.168.xx.xx:<Port>/restapi/json/v1/resources/resourcename/test

Sample Output

{

"operation":{

"name": "GET_RESOURCEID",

"result":{

"status": "Success",

"message": "Resource ID fetched successfully for the given resource name."

},

"Details":{

"RESOURCEID": "1"

}

}

9. Delete a Resource in PMP

Description

To delete a resource for the given resource ID. Resource ID can be obtained from the GET RESOURCES API (explained above).

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/{resourceid}

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

DELETE

Input Data

None

Sample Request

curl -X -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" DELETE https://192.168.xx.xx:<Port>/restapi/json/v1/resources/307

Sample Output



{
"operation":{
"name":"DELETE RESOURCE"
"result":{"status":"Success"
"message":"Resources deleted successfully."}
}

10. Request Password Approval by the Admin

Description

Method to request the admin for password access approval. The account id has to be passed for the same in the URL.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/accounts/{accountid}/requestpassword

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

POST

Input Data

In case the setting at your end demands a reason to be supplied for requesting a password, you need to pass the following details as input. INPUT_DATA= { "operation" : { "Details" : { "REASON" : "asdefefe"}}}

Sample Input

        {
"operation":{
"Details":{
PASSWDID":"1"
"REASON":"Testing"
			}
		}
	}

Sample Request

curl -X POST -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json" https://192.168.xx.xx:<Port>/restapi/json/v1/accounts/7/requestpassword?INPUT_DATA= { "operation" : { "Details":{ "REASON" : "Testing"}}}

Sample Output


{
"operation":{

               "name":"REQUEST_PASSWORD"  ,
               "result":{    
               "status":"Success"    ,
               "message":"Request to view password have been raised successfully"
                         },
              "Details":{
                         "STATUS" : "WAITING FOR APPROVAL / CHECKOUT" ;
                         }

           }

}

11. Get the List of Password Requests

Description

Method to get the list of password requests to be approved or rejected by the admin who is logged in.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/accounts/passwordaccessrequests

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

GET

Input Data

None

Sample Input

INPUT_DATA= { "operation" : { "Details" : { "REASON" : "Testing", "TICKETID" : "7"}}}

Sample Request

curl -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" https://192.168.xx.xx:<Port>/restapi/json/v1/accounts/passwordaccessrequests

Sample Output


{
	"operation":{
	"name":"GET_PASSWORDREQUEST"
    "result":{   
    "status":"Success"  
    "message" : "Password Request fetched successfully"
    }
    "Details":  {  
    "REQUESTER USERID":"2"
    "REQUESTED BY":"guest"
	"REQUESTED BY FULLNAME" : "Guest guest"
	"PASSWORDREQUESTLIST" : [
		{
		"ACCOUNT ID"  :  "1"
       "ACCOUNT NAME" :  "ACCOUNT1"
		"RESOURCE ID":"1"
		"RESOURCE NAME":"apt-server1"
		"PASSWD ID" : "1"
		"STATUS":""
		"REQUESTED TIME":"Nov 27
		"REASON" : "For connecting the machine and update the PMP server".
		}
		{
		"ACCOUNT ID"  :  "2"
		"ACCOUNT NAME" :  "ACCOUNT2"
		"RESOURCE ID":"2"
		"RESOURCE NAME":"apt-server2"
		"PASSWD ID" : "2"
		"STATUS":""
		"REQUESTED TIME":"Nov 28
		"REASON" : "For connecting the machine and update the PMP server".
		}
		]
        }

         }

}

Note : Requester ID is the same as the ID of the user who has requested the password.


12. Reject a Password Request

Description

Method for the admin to reject the password requests. This requires the account ID and requester ID to be passed in the URL.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/accounts/{accountid}/requester/{requesterid}/reject

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

POST

Sample Input

    {
	"operation":{
	"Details":{
	"PASSWDID":"1"
    "REQUESTEDID" : "2" (userid of the request raised user)
	}
     }
	}
	

Note: Requester ID is the same as the ID of the user who has requested the password.

Sample Request

curl -X POST -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json" https://192.168.xx.xx:<Port>/restapi/json/v1/accounts/7/requester/34/reject

Sample Output


{
"operation":{
"name" : "ADMIN_REQUEST_REJECT" 
 "result" : { 
 "status" : "Success"   
 "message": "Password Rejected successfully"
   }
 }
}

13. Approve a Password Request

Description

Method for the admin to approve the password requests. Here, the account ID and the Requester ID are required to be passed in the URL.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/accounts/{accountid}/requester/{requesterid}/approve

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

POST

Input Data

None

Note: Requester ID is the same as the ID of the user who has requested the password. REQUESTEDID can be obtained from the GET PASSWORDREQUEST API(REQUESTER USERID).

Sample Request

curl -X POST -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json" https://192.168.xx.xx:<Port>/restapi/json/v1/accounts/7/requester/34/approve

Sample Output


{
"operation" : { 
"name" : "ADMIN_REQUEST_APPROVE" 
"result" : {    
"status" : "Success"   
"message": "Password Approved successfully"
           }
        }
}

14. Check-in the Password Approved by the Admin

Description

Method to check-in the password approved by the admin. The account and requester IDs have to passed in the URL for the same.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/accounts/{accountid}/requester/{requesterid}/checkin

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

POST

Input Data

    {
    "operation":{
    "Details":{
    "PASSWDID"  :  "1"
    "REQUESTEDID" : "2" (userid of the request raised user)
    }
   }
    

Note: Requester ID is the same as the ID of the user who has requested the password.


Sample Request

curl -X POST -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json" https://192.168.xx.xx:<Port>/restapi/json/v1/accounts/7/requester/34/checkin

Sample Output


{
"operation":{  
 "name"   :  "ADMIN_REQUEST_CHECKIN"   
 "result" :  {      
 "status" :  "Success"     
 "message" : "Password have been checked in successfully"  
  } 
 } 
} 

15. Checkout the Password Approved by the Admin

Description

Method to checkout the password after being approved by the admin after request. The account ID had to be passed for the same in the URL.

URL

https://:<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/accounts/{accountid}/checkout

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

POST

Input Data

On account of customized settings that demand reason for password checkout, you need to pass the following as input. INPUT_DATA= { "operation" : { "Details":{ "REASON" : "asdefefe"}}}

Sample Input

	{
	"operation":{
    "Details":{
    "REASON":"N/A"
    }
   }
}

Sample Request

curl -X POST -k-H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json" https://192.168.xx.xx:<Port>/restapi/json/v1/accounts/7/checkout?INPUT_DATA= { "operation" : { "Details" : { "REASON" : "N/A"}}}

Sample Output

{ 
"operation": { 
"name" : "REQUEST_CHECKOUT"  
"result" : {     
"status" :  "Success"    
            "message" : "Password have been checked out successfully" 
            "Details":{ 
                       "STATUS" : "***** [checkIn]" 
                       } 
                     } 
}

16. Generate Password

Description

Method to generate passwords using existing policies in PMP.

URL

https:// <Host-Name-of-PMP-Server OR IP address> :<Port>/restapi/json/v1/passwords/generate

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

GET

Input Data

INPUT_DATA={ "operation" : { "Details" : { "POLICY" : "Strong"}}}

Sample Output

{
"operation": {
"name": "GENERATE PASSWORD",
"result": {
"status": "Success",
"message": "Password generated successfully."
},
"Details": {
"PASSWORD": "u%mdh7gfN"
}
}
}

17. Create a New User

Description

Method to add a user.

URL

https:// <Host-Name-of-PMP-Server OR IP address> :<Port>/restapi/json/v1/user

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

POST

Input Data

INPUT_DATA={"operation": {"Details":{"USERNAME":"jason1", "FIRSTNAME":"Jason","LASTNAME":"J","FULLNAME":"JasonThomas","EMAIL":"jason@opmanager.com","POLICY":"Strong","ROLE":"Password User","ISSUPERADMIN":"true|false","PASSWORD":"Test@123","DEPARTMENT":"NOC","LOCATION":"Level 10 - South Wing","ISAPIUSER":"false","HOSTNAME":"admin-2100","EXPIRYDATE":"yyyy-mm-dd|NeverExpires"}}}

Sample Output

{
"operation": {
"name": "CREATE_USER",
"result": {
"status": "Success",
"message": "User Created Successfully"
}
}
}


18. Edit Resources

Description

Method to edit resources.

URL

https://severname:port/restapi/json/v1/resources/{RESOURCEID}

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

PUT

Input Data

(Optional inputs are given in grey)

Sample Input

Note: If you want to edit resource type, an additional parameter "RESOURCETYPE" having the value of that particular resource type should be added to the input. While editing 'Resource Type' cannot be changed from Key Store, File Store, License Store, Rackspace, and AWS IAM to other resource types and viceversa.

{
"operation"    :    {
"Details":   {
"RESOURCENAME"  :  "Test",
"LOCATION" : "4th floor",
"RESOURCEURL" : "http://test",
"RESOURCEPASSWORDPOLICY":"Strong",
"DEPARTMENT" : "Test",
"RESOURCEDESCRIPTION" : "Created for quality assurance",
"RESOURCETYPE" : "Windows",
"RESOURCECUSTOMFIELD" : [
	{
	"CUSTOMLABEL" : "Secure Resource",
	"CUSTOMVALUE" : "YES"
	}
	]
	}
}
}

Sample Request

curl -X PUT -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json" 'https://192.168.39.29:<Port>/restapi/json/v1/resources/1? -d 'INPUT_DATA={"operation":{"Details":{"RESOURCENAME":"Test","LOCATION":"4thfloor","RESOURCEURL":"http://test","RESOURCEPASSWORDPOLICY":"Strong","DEPARTMENT": "Test", RESOURCEDESCRIPTION" : "Created for quality assurance", "RESOURCECUSTOMFIELD" : [{"CUSTOMLABEL" : "Secure Resource", "CUSTOMVALUE" : "YES" }]}}}'


Sample Output

{"operation":{
	"name":"EDIT RESOURCE",
	"result":{"status":"Success","message":"Resource Test modified successfully."}}}


19. Delete an Account under a Specific Resource

Description

To delete an account under a specific resource.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/<Resource ID>/accounts/<Account ID>/

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

DELETE

Sample Request

curl -X DELETE -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json" 'https://192.168.xx.xx:<Port>/restapi/json/v1/resources/1/accounts/1

Sample Output

{
"operation":{
"name":"DELETE ACCOUNT",
"result":{"status":"Success","message":"Account Test123 deleted successfully."}}}

20. Get License Keys, Files, Digital Certificates, Documents, Images, etc.

Description

To get files, keys, certificates, etc. that are either an individual resource or a part of other resources.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/<Resource ID>/accounts/<Account ID>/downloadfile

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

GET

Input Data

In case the setting at your end demands a reason to be supplied for downloading the file, you need to pass the following details as input. If the ticketing system is enabled, you need to pass ticket ID for validation.

{"operation":{
   "Details":{
     "REASON":"Need the key file to connect the remote host", //optional when reason is forced
     "TICKETID":"7", // optional when ticketing system is enabled
     "ISCUSTOMFIELD":"TRUE" //optional  Need to be given if the file to be downloaded is account/resource additional field file type
     "CUSTOMFIELDTYPE":"ACCOUNT / RESOURCE" // optional -If its account additional field it must be ACCOUNT or if its resource 
     			                       additional field it must be RESOURCE
     "CUSTOMFIELDLABEL" : "LicenseFIle" // optional - Name of the resource/account additional field
           }
        }

}

Sample Request

curl -i -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" https://192.168.xx.xx:<Port>/restapi/json/v1/resources/1501/accounts/3601/downloadfile


21. Create Accounts under a Specific Resource

Description

To create multiple accounts that are associated with a specific resource ID.

Input Data

You need to pass input data such as account list, name of the accounts, passwords, description.

        INPUT_DATA={"operation":{
                    "Details":{
                    "ACCOUNTLIST": [
                     {
                      "ACCOUNTNAME":"bestest047",
                      "PASSWORD":"Pa$$Word@123",
                      "ACCOUNTPASSWORDPOLICY":"Strong",
                      "NOTES":"IT Security - BES PMP API Test"
                      },
                     {
                     "ACCOUNTNAME":"bestest048",
                     "PASSWORD":"Pa$$Word@123",
                     "ACCOUNTPASSWORDPOLICY":"Strong",
                     "NOTES":"IT Security - BES PMP API Test"
                     }	
                        ]
                       }
                      }

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/<Resource ID>/accounts

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

POST

Sample Request

curl -X POST -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json" 'https://192.168.xx.xx:<Port>/restapi/json/v1/resources/1/accounts INPUT_DATA= {"operation":{ "Details":{ "ACCOUNTLIST": [{ "ACCOUNTNAME": "bestest047","PASSWORD":"Pa$$Word@123","ACCOUNTPASSWORDPOLICY":"Strong","NOTES":"IT Security - BES PMP API Test"},{"ACCOUNTNAME":"bestest048", "PASSWORD":"Pa$$Word@123","ACCOUNTPASSWORDPOLICY":"Strong","NOTES":"IT Security - BES PMP API Test"}]}}

Sample Output

{"operation":
{"name":"ADD ACCOUNTS","result":
{"status":"Success","message":"Account added successfully"},
"Details":[
{"bestest047":{"STATUS":"Account added successfully"},
"bestest048":{"STATUS":"Account added successfully"}}]}}

22. Edit an Account under a Specific Resource

Description

To edit an account under a specific resource.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/<Resource ID>/accounts/<Account ID>/

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

PUT

Sample Input

{
"operation" : {
      "Details" : {
         "ACCOUNTNAME" : "Test account",
         "ACCOUNTPASSWORDPOLICY":"Strong",
         "NOTES":"Created for quality assurance",        
         "ACCOUNTCUSTOMFIELD" : [
            {
               "CUSTOMLABEL" : "Secure Account",
               "CUSTOMVALUE" : "YES"
            }
         ]
      }
   }
}

Sample Request

curl -X PUT -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json" 'https://192.168.xx.xx:<Port>/restapi/json/v1/resources/1/accounts/1?-d INPUT_DATA= {"operation":{ "Details":{"ACCOUNTNAME" : "Test account","ACCOUNTPASSWORDPOLICY":"Strong","NOTES":"Created for quality assurance", ACCOUNTCUSTOMFIELD" : [{"CUSTOMLABEL" : "Secure Account", "CUSTOMVALUE" : "YES"}]}}}

Sample Output

{"operation":{ "name":"EDIT ACCOUNT", "result":{"status":"Success","message":"Account Test account modified successfully"}}}


23. Delete a User

Description

Method to delete a specific user.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/user/{userid}

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

DELETE

Sample Request

curl -X DELETE -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>"
-H "Content-Type: text/json" https://192.168.xx.xx:<Port>/restapi/json/v1/user/307

Sample Output

{"operation":{"name":"DELETE USER","result":{"status":"Success","message":"User Michael deleted Successfully"} } }


24. Create an API User

Description

Method to create an API user.

URL

https:// <Host-Name-of-PMP-Server OR IP address> :<Port>/restapi/json/v1/user

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

POST

Input Data

INPUT_DATA={"operation":{"Details":{"USERNAME":"jason","FULLNAME":"Jason 
Thomas","EMAIL":"jason@opmanager.com","POLICY":"Strong","ROLE":"Password
User","ISSUPERADMIN":"true|false","DEPARTMENT":"NOC","LOCATION":"Level 10 - South
Wing","ISAPIUSER":"true","HOSTNAME":"sankar-2100","EXPIRYDATE":"yyyy-mm-dd|NeverExpires"}}}

Sample Output

{"operation":{"name":"CREATE_USER","result":{"status":"Success","message":"SUCCESS"},
"Details":{"AUTHTOKEN":"7D94BAAB-CA3B-44F5-8ED9-9317DAB5AEF0"}}}

25. Create a New SSH Key

Description

To create a new SSH key.

URL

https:// <Host-Name-of-PMP-Server OR IP address> :<Port>/api/pki/restapi/createsshkey?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

POST

Input Data

The following data has to be passed as input:

{"operation":{"Details":{"keyName":"keytest",
"passPhrase":"passPhrase",
"comment":"comment",
"length":"2048",
"keyType":"ssh-rsa"}}}

Sample Request

https://<HostName>:<Port>/api/pki/restapi/createsshkey?AUTHTOKEN=99AE42A9-02E0-4638-888A-D4D19225C3FE&INPUT_DATA={"operation":{"Details":{"keyName":"keytest","passPhrase":"passPhrase","comment":"comment","length":"2048","keyType":"ssh-rsa"}}}

Sample Response

{ "name": "CreateSSHKey",
"result": {
"status": "Success",
"message": "New SSH key created successfully" }
}


Note: Following are the key types that can be used to create new SSH keys:
  • ssh-rsa (key length: 1024/2048/4096)
  • ssh-dss (key length: 1024)
  • ed25519 (no specific key length)
  • ecdsa (key length: 256/384/521)

26. Delete an SSH Key

Description

To delete a particular SSH key.

URL

https://< Host-Name-of-PMP-Server OR IP address >:<Port>/api/pki/restapi/deleteSSHKey?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

DELETE

Input Data

The following data has to be passed as input:

{"operation":{"Details":{"key_name":"newkey1","withoutDisassociation":"true"}}}

Sample Request

https://< Host-Name-of-PMP-Server OR IP address >:<Port>/api/pki/restapi/deleteSSHKey?AUTHTOKEN=(The token you have generated and copied from the GUI)&INPUT_DATA={"operation":{"Details":{"key_name":"newkey1","withoutDisassociation":"true"}}}

Sample Response

{ "name": "DeleteSSHKey",

"result": { "status": "Success",

"message": "SSH keys newkey1 deleted successfully"}}

27. Fetch All the SSH Keys

Description

To fetch all the discovered SSH keys.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/getAllSSHKeys?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

GET

Input Data

None

Sample Request

https://<HostName>:<Port>/api/pki/restapi/getAllSSHKeys?AUTHTOKEN=99AE42A9-02E0-4638-888A-D4D19225C3FE

Sample Response

{
"name": "GetAllSSHKeys",
"result": {
"status": "Success",
"message": "All SSH Keys fetched successfully"
},
"totalRows": 2,
"SSHKeys": [
{
"KeyName": "key",
"KeyType": "ssh-rsa",
"KeyLength": "2048",
"FingerPrint": "4b:97:8d:aa:8d:73:89:7c:96:69:7d:10:df:b2:d0:af",
"CreatedBy": "admin",
"CreationTime": "1 days"
},
{
"KeyName": "keytest",
"KeyType": "ssh-rsa",
"KeyLength": "2048",
"FingerPrint": "69:ff:8d:8e:4d:a3:79:da:fc:09:6c:e8:01:15:66:9b",
"CreatedBy": "admin",
"CreationTime": "Today"
}
]
}


28. Fetch a Particular SSH Key

Description

To fetch a particular SSH key from the discovered keys.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/getSSHKey?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

POST

Input Data

The name of the operation and key to be passed as input

{"operation":{"Details":{"keyName":"key"}}}

Sample Request

https://<HostName>:<Port>/api/pki/restapi/getSSHKey?AUTHTOKEN=99AE42A9-02E0-4638-888A-D4D19225C3FE&INPUT_DATA={"operation":{"Details":{"keyName":"key"}}}

Sample Response

{
"name": "GetSSHKey",
"result": {
"status": "Success",
"message": "SSH Key key fetched successfully"
},
"SSHKey": [
{
"KeyName": "key",
"KeyType": "ssh-rsa",
"KeyLength": "2048",
"FingerPrint": "4b:97:8d:aa:8d:73:89:7c:96:69:7d:10:df:b2:d0:af",
"CreatedBy": "admin",
"CreationTime": "1 days"
}
]
}


29. Export an SSH Key

Description

To export a particular SSH key.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/exportSSHKey?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

POST

Input Data

The name of the operation and key have to be passed as input.

{"operation":{"Details":{"keyName":"key"}}}

Sample Request

https://<HostName>:<Port>/api/pki/restapi/exportSSHKey?AUTHTOKEN=99AE42A9-02E0-4638-888A-D4D19225C3FE&INPUT_DATA={"operation":{"Details":{"keyName":"key"}}}

Sample Response

Key file


30. Get SSH Keys for a User

Description

To get all the SSH keys associated with a particular user.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/getSSHkeysforuser?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

GET

Input Data

The username and resource name have to be passed as input.

{"operation":{"Details":{"userName":"test","resourceName":"172.21.147.80"}}}

Sample Request

https://<HostName>:<Port>/api/pki/restapi/getSSHkeysforuser?AUTHTOKEN=99AE42A9-02E0-4638-888A-D4D19225C3FE&INPUT_DATA={"operation":{"Details":{"userName":"test","resourceName":"172.21.147.80"}}}

Sample Response

{
"name": "GetSSHKeysForUser",
"result": {
"status": "Success",
"message": "SSH keys for user test of resource 172.21.147.80 fetched successfully"
},
"Keys": "key,keytest"
}


31. Fetch all Associated Users

Description

To fetch all the users associated with SSH keys.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/getAllAssociatedUsers?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

GET

Input Data

None

Sample Request

https://<HostName>:<Port>/api/pki/restapi/getAllAssociatedUsers?AUTHTOKEN=99AE42A9-02E0-4638-888A-D4D19225C3FE

Sample Response

{
"name": "GetAllAssociatedUsers",
"result": {
"status": "Success",
"message": "All associated users fetched successfully"
},
"totalRows": 1,
"AllAssociatedUsers": [
{
"UserName": "test",
"ResourceName": "172.21.147.80"
}
]


32. Get a Certificate

Description

To obtain a certificate from PMP's certificate repository.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/getCertificate?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

GET

Input Data

The operation details and the name of the certificate fetched have to be passed as input.

{

"operation": {

"Details" : {

"common_name" : "*.google.com",

"serial_number":"XXXXXXXXXXXXXX" // optional to provide serial number to fetch certificate details

}

}

}

Sample Request

https://<HostName>:<Port>/api/pki/restapi/getCertificate?AUTHTOKEN=3E014D78-E603-413A-AC24-6392F0001283&INPUT_DATA={"operation":{"Details":{"common_name":"*.google.com","serial_number":"XXXXXXXXXXXXXX"}}}

Sample Response

Certificate object


33. Get all Certificates

Description

To obtain all the certificates from PMP's certificate repository.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/getAllSSLCertificates?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

GET

Input Data

None

Sample Request

https://<HostName>:<Port>/api/pki/restapi/getAllSSLCertificates?AUTHTOKEN=3E014D78-E603-413A-AC24-6392F0001283

Sample Response

{"name":"GetAllSSLCertificates","result":{"status":"Success","message":"All SSL
Certificates fetched successfully"},"totalRows":1,"SSLCertificates":[{"CertID":1,"DNS
Name/FQDN":"ec2-54-243-44-216.compute-1.amazonaws.com","Port":443,"Common Name":"*.acquia-sites.com",
"Issuer":"Acquia Inc","FromDate":"Sep 3, 2009","ExpiryDate":"Sep 3,
2010","KeyStrength":"1024"}]}


34. Get all Certificate Expiry

Description

To get the expiry dates of all the certificates.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/getAllSSLCertsExpiryDate?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

GET

Input Data

None

Sample Request

https://<HostName>:<Port>/api/pki/restapi/getAllSSLCertsExpiryDate?AUTHTOKEN=1B2BF6FA-8511-47A8-867D-CE7FFE4BFBD0

Sample Response

{"name":"GetAllSSLCertificatesExpiryDate","result":{"status":"Success","message":"Certificates expiry date fetched successfully"},"totalRows":1,"SSLCertificates_Expiry_Date":[{"Common Name":"*.acquia-sites.com","ExpiryDate":"Sep 3, 2010"}]}


35. Get Certificate Details

Description

To get the details of a particular certificate.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/getCertificateDetails?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

GET

Input Data

The operation details and the name of the certificate have to be passed as input.

{"operation": {"Details":{"common_name":"*.google.com"}}}

Sample Request

https://<HostName>:<Port>/api/pki/restapi/getCertificateDetails?AUTHTOKEN=3E014D78-E603-413A-AC24-6392F0001283&INPUT_DATA={"operation": {"Details":{"common_name":"*.google.com"}}}

Sample Response

{
"name": "GetCertificateDetails",
"result": {
"status": "Success",
"message": "Details of certificate *.google.com fetched successfully"
},
"39": {
"certtype": "MSStore",
"endpoint": {
"hostName": "*.google.com",
"port": "443",
"expiry_date": "2019-10-21 23:53:00.0",
"from_date": "2019-07-30 00:14:27.0",
"certSignAlg": "SHA256withRSA",
"Sans": "*.google.com,*.android.com,*.appengine.google.com,*.cloud.google.com,*.crowdsource.google.com,*.g.co,*.gcp.gvt2.com,*.gcpcdn.gvt1.com,*.ggpht.cn,*.google-analytics.com,*.google.ca,*.google.cl,*.google.co.in,*.google.co.jp,*.google.co.uk,*.google.com.ar,*.google.com.au,*.google.com.br,*.google.com.co,*.google.com.mx,*.google.com.tr,*.google.com.vn,*.google.de,*.google.es,*.google.fr,*.google.hu,*.google.it,*.google.nl,*.google.pl,*.google.pt,*.googleadapis.com,*.googleapis.cn,*.googlecnapps.cn,*.googlecommerce.com,*.googlevideo.com,*.gstatic.cn,*.gstatic.com,*.gstaticcnapps.cn,*.gvt1.com,*.gvt2.com,*.metric.gstatic.com,*.urchin.com,*.url.google.com,*.youtube-nocookie.com,*.youtube.com,*.youtubeeducation.com,*.youtubekids.com,*.yt.be,*.ytimg.com,android.clients.google.com,android.com",
"serial": "74515d3afb5928632715eac96afeb697",
"fingerPrint": "683b0240699d1ca51b0c337b047c6baf32eceffb",
"keyalg": "EC",
"PublicKeyLength": 256,
"PrivateKey": false
},
"isCertInstalledMulipleServers": false,
"issuer": {
"cname": "Google Internet Authority G3",
"org": "Google Trust Services",
"orgunit": "-"
},
"issuedto": {
"cname": "*.google.com",
"org": "Google LLC",
"orgunit": "-"
},
"intermediate": {},
"ipaddress": "NA"
}
}

36. Get Certificate Keystore

Description

To get the key store file of a particular certificate.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/getCertificateKeyStore?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

GET

Input Data

The name of the operation and the common name of the keystore file have to be passed as input.

{

"operation" : {

"Details" : {

"common_name" : "apitest",

"serial_number":"XXXXXXXXXXXXXX" //optional to provide serial number to fetch the keystore file

}

}

}

Sample Request

https://<HostName>:<Port>/api/pki/restapi/getCertificateKeyStore?AUTHTOKEN=3E014D78-E603-413A-AC24-6392F0001283&INPUT_DATA={"operation":{"Details":{"common_name":"apitest","serial_number":"XXXXXXXXXXXXXX"}}}

Sample Response

KeyStore File Object


37. Get Certificate Passphrase

To get the private key passphrase of a certificate.

URL

https://< Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/getCertificatePassphrase?AUTHTOKEN=(The token you have generated and copied from the GUI)  

HTTP Method

GET

Input Data

The following data has to be passed as input:

{"operation":{"Details":{"common_name":"mycert","serial_number":"XXXXXXXXXXXXXX"}}}

Sample Request

https://< Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/getCertificatePassphrase?AUTHTOKEN=(The token you have generated and copied from the GUI)&INPUT_DATA={"operation":{"Details":{"common_name":"mycert","serial_number":"XXXXXXXXXXXXXX"}}}

Sample Response

{

"name": "GetCertificatePassphrase",

"result": {

"status": "Success",

"message": "Private key passphrase of certificate mycert is 123456789"

}

}

38. Add a Certificate

To add a certificate to PMP's certificate repository.

URL

https://< Host-Name-of-PMP-Server OR IP address >:<Port>/api/pki/restapi/addCertificate

 

HTTP Method

POST

Input Data

The following data has to be passed as input:

input data: {"operation":{"Details":{"fileType":"KEYSTORE","PASSWORD":"PASSWORD"}}}


Note: The fileType specified in the input data can be either CERTFILE or KEYSTORE. For CERTFILE fileType, the PASSWORD field need not be specified. 

Sample Request

curl -X POST -k -H 'Content-Type: multipart/form-data' -F INPUT_DATA='{"operation":{"Details":{"fileType":"KEYSTORE","PASSWORD":"PASSWORD"}}}' -F File=@D:/certs/newcert.keystore https://< Host-Name-of-PMP-Server OR IP address >:<Port>/api/pki/restapi/addCertificate

Sample Response

{ "name": "AddCertificate",
"result":
{{"Status":"Success",
"Message": "Certificate newcert.com added successfully"} } }


39. Delete a Certificate

Description

To delete a certificate from PMP's certificate repository.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/deleteCertificate?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

DELETE

Input Data

The operation name and the common name of the certificate have to be passed as input.

{

"operation": {

"Details":{

"common_name" : "apitest",

"serial_number" : "XXXXXXXXXXXXXX" //optional to provide serial number to delete a certificate

}

}

}

Sample Request

https://<HostName>:<Port>/api/pki/restapi/deleteCertificate?AUTHTOKEN=3E014D78-E603-413A-AC24-6392F0001283&INPUT_DATA={"operation": {"Details":{"common_name":"apitest","serial_number":"XXXXXXXXXXXXXX"}}}

Sample Response

{"name":"DeleteCertificate","result":{"status":"Success","message":"Certificate apitest deleted successfully."}}


40. Perform Resource Discovery

Description

To discover a particular resource for SSL certificates.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/sslCertSingleDiscovery?AUTHTOKEN=(The token you have generated and copied from the GUI) from the GUI)

HTTP Method

POST

Input Data

The name/IP address of the host and port number have to be passed as input.

{"operation":{"Details":{"HOST":"de-ubuntu10-1","TIMEOUT":"300","PORT":"<Port>"}}}

Sample Request

https://<HostName>:<Port>/api/pki/restapi/sslCertSingleDiscovery?AUTHTOKEN=3E014D78-E603-413A-AC24-6392F0001283&INPUT_DATA={"operation":{"Details":{"HOST":"de-ubuntu10-1","TIMEOUT":"300","PORT":"<Port>"}}}

Sample Response

{
"name": "Get SSL Discovery",
"totalRows": 1,
"de-ubuntu10-1": [
"SUCCESS",
"SSL Certificate discovered, demo.keymanager.com certificate found at port <Port>"
]
}


41. Perform Resource Discovery (For a Range of IP Addresses)

Description

To discover a set of resources for SSL certificates.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/sslCertRangeDiscovery?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

POST

Input Data

The start and end IP addresses, port number and time-out have to be passed as input.

{"operation":{"Details":{"StartIpAddress":"192.168.216.0",
"EndIpAddress":"192.168.216.3",
"TIMEOUT":"3",
"PORT":"443"}}}

Sample Request

https://<HostName>:<Port>/api/pki/restapi/sslCertRangeDiscovery?AUTHTOKEN=7EDC4ED5-E684-4413-9848-F0016C114874&INPUT_DATA={"operation":{"Details":{"StartIpAddress":"192.168.216.0","EndIpAddress":"192.168.216.3","TIMEOUT":"3","PORT":"443"}}}

Sample Response

{ "name": "Get SSL Discovery",
"totalRows": 4,
"192.168.216.1": [
"FAILURE",
"Connection failed,no certificate found at port 443"
],
"192.168.216.0": [
"FAILURE",
"Connection timed out,no certificate found at port 443"
],
"192.168.216.3": [
"FAILURE",
"Connection timed out,no certificate found at port 443"
],
"192.168.216.2": [
"FAILURE",
"Connection timed out,no certificate found at port 443"
]
}


42. Create CSR

Description

To create a certificate signing request.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/createCSR?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

POST

Input Data

The following data need to be passed as input.

{"operation":{"Details":{"CNAME":"mytestcert",
"ALT_NAMES":"test",
"ORGUNIT":"zohocorp",
"ORG":"manageengine",
"LOCATION":"chennai",
"STATE":"Tamilnadu",
"COUNTRY":"IN",
"PASSWORD":"zohocorp",
"VALIDITY":"888",
"ALG":"RSA",
"LEN":"4096",
"SIGALG":"SHA256",
"StoreType":"PKCS12"}}}

Sample Request

https://<HostName>:<Port>/api/pki/restapi/createCSR?AUTHTOKEN=C6506112-6113-42C9-AD3
F-4A3AEF9476C9&INPUT_DATA={"operation":{"Details":{"CNAME":"mytestcert", "ALT_NAMES":"test", "ORGUNIT":"zohocorp", "ORG":"manageengine", "LOCATION":"chennai", "STATE":"Tamilnadu","COUNTRY":"IN", "PASSWORD":"zohocorp", "VALIDITY":"888", "ALG":"RSA", "LEN":"4096", "SIGALG":"SHA256", "StoreType":"PKCS12"}}}

Sample Response

{"name":"CreateCertificate","result":{"status":"Success","message":"CSR saved successfully"}}


43. Create Certificate

Description

To create an SSL certificate.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/api/pki/restapi/createCertificate?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

POST

Input Data

The following data have to be passed as input:

{"operation":{"Details":{"CNAME":"mytestcert",
"ALT_NAMES":"test",
"ORGUNIT":"zohocorp",
"ORG":"manageengine",
"LOCATION":"chennai",
"STATE":"Tamilnadu",
"COUNTRY":"IN",
"PASSWORD":"zohocorp",
"VALIDITY":"888",
"ALG":"RSA",
"LEN":"4096",
"SIGALG":"SHA256",
"StoreType":"PKCS12"}}}

Sample Request

https://<Host-Name-of-PMP-Server OR IP address> :<Port>/api/pki/restapi/createCertificate?AUTHTOKEN=C6506112-6113-42C9-AD3 F-4A3AEF9476C9&INPUT_DATA={"operation":{"Details":{"CNAME":"mytestcert", "ALT_NAMES":"test", "ORGUNIT":"zohocorp", "ORG":"manageengine", "LOCATION":"chennai", "STATE":"Tamilnadu","COUNTRY":"IN", "PASSWORD":"zohocorp", "VALIDITY":"888", "ALG":"RSA", "LEN":"4096", "SIGALG":"SHA256", "StoreType":"PKCS12"}}}

Sample Response

{"name":"CreateCertificate","result":{"status":"Success","message":"Certificate saved successfully"}}


44. Get the ID of a User

Description

To get the ID of a user by passing their username.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/user/getUserId

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

orgName= <<org display name>>

HTTP Method

GET

Input Data

None

Sample Request

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/user/getUserId?USERNAME=user1


Sample Response

{
"operation": {
"name":"get_USERID",
"result": { "status":"Success","message":"User Id for the specified username  have been fetched successfully"},"Details":{"USERID":"1"}}}


45. Delete a User with their Username

Description

To delete a user by passing their username.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/user?USERNAME=(username)

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

orgName= <<org display name>>

HTTP Method

DELETE

Input Data

None

Sample Request

https://<Host-Name-of-PMP-Server OR IP  address>:<Port>/restapi/json/v1/user?USERNAME=admin1


Sample Response

{"operation":{"name":"DELETE USER","result":{"status":"Success","message":"User admin1 deleted successfully"}}}


46. Add a User to a User Group

Description

To add a user to a user group by passing their username and the user group to which they should be added.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/user/addUserToUserGroup?USERNAME=(username)&USERGROUPNAME=(usergroupname)

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

orgName= <<org display name>>

HTTP Method

POST

Input Data

None

Sample Request

https://<Host-Name-of-PMP-ServerORIP address>:<Port>/restapi/json/v1/user/addUserToUserGroup?=admin1&USERGROUPNAME=TestGroup


Sample Response

{"operation":{"name":"ADD USER TO USERGROUP","result":{"status":"Success","message":"User admin1 added to User Group TestGroup successfully"}}}


47. Lock a User

Description

To lock a user by passing their username.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/user/lock?USERNAME=(username)

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

orgName= <<org display name>>

HTTP Method

PUT

Input Data

None

Sample Request

https://<Host-Name-of-PMP-Server OR IP  address>:<Port>/restapi/json/v1/user/lock?USERNAME=apiuser


Sample Response

{"operation":{"name":"LOCK USER","result":{"status":"Success","message":"User account apiuser locked successfully."}}}


48. Unlock a User

Description

To unlock a user by passing their username.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/user/unlock?USERNAME=(username)

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

orgName= <<org display name>>

HTTP Method

PUT

Input Data

None

Sample Request

https://<Host-Name-of-PMP-Server OR IP  address>:<Port>/restapi/json/v1/user/unlock?USERNAME=apiuser


Sample Response

{"operation":{"name":"UNLOCK USER","result":{"status":"Success","message":"User account apiuser unlocked successfully. "}}}


49. Import an SSH Key

Description

To import an SSH key.

URL

https://<hostname>:6565/api/pki/restapi/addSSHKey?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

POST

Input Data

The following data is to be passed as input:

{
"operation":
{
"Details":
{
"keyName":"testkey","passphrase":"passtrix"
}
}
}

Sample Request

curl -X POST -k -H 'Content-Type: multipart/form-data' -F INPUT_DATA={"operation":{"Details":{"keyName":"testkey","passphrase":"passtrix"}}} -F File=@D:/certs/keys/test1-passtrix/test1_Jul-21-2017-15_56.key https:// <hostname>:6565/api/pki/restapi/addSSHKey?AUTHTOKEN=A3164150-4C15-4AA4-918E-F258F38149F8

Sample Response

{
"name":"addSSHKey","result":
{
"status":"SUCCESS","message":"Key imported successfully"
}
}


50. Associate an SSH Key

Description

To associate an SSH key.

URL

https://<hostname>:6565/api/pki/restapi/associateKey?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

POST

Input Data

The following data is to be passed as input:||

{
"operation":
{
"Details":
{
"keyName":"testkey","resourceName":"test.csez.zohocorpin.com","userName":"test"
}
}
}

Sample Request

https://<hostname>:6565/api/pki/restapi/associateKey?AUTHTOKEN=A3164150-4C15-4AA4-918E-F258F38149F8&INPUT_DATA={"operation":{"Details":{"keyName":"testkey","resourceName":"test.csez.zohocorpin.com","userName":"test"}}}

Sample Response

{
"name": "associateKey", "result":
{ "status": "Success", "message": "Key associated successfully"
}
}


51. Dissociate an SSH Key

Description

To dissociate an SSH key.

URL

https://<hostname>:6565/api/pki/restapi/dissociateKey?AUTHTOKEN=(The token you have generated and copied from the GUI)

HTTP Method

POST

Input Data

The following data is to be passed as input:||

{
"operation":
{
"Details":
{
"keyName":"testkey","resourceName":"test.csez.zohocorpin.com","userName":"test"
}
}
}

Sample Request

||
https://<hostname>:6565/api/pki/restapi/dissociateKey?AUTHTOKEN=A3164150-4C15-4AA4-918E-F258F38149F8&INPUT_DATA={"operation":{"Details":{"keyName":"testkey","resourceName":"test.csez.zohocorpin.com","userName":"test"}}}
||

Sample Response

{
"name": "dissociateKey", "result":
{
"status": "SUCCESS", "message": "Key dissociated successfully."
}
}


52. Create a Dynamic Resource Group

Description

To create a dynamic resource group in PMP.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resourcegroup

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

POST

Input Data

The following data is to be passed as input:

{
"operation": {
"Details": {
"critgroup": "CG1",
"critdesc": "description about CG1",
"RuleCriteria": "Low",
"NoHelpDeskRetrieval": "false",
"andor": "and",
"NoOfCriteria": 2,
"condition_1": "RESOURCENAME",
"operator_1": "CONTAINS",
"valuefield_1": "win",
"condition_2": "LOGINNAME",
"operator_2": "CONTAINS",
"valuefield_2": "PMP"
}
}
}

Sample Request

curl -X POST -k -H "AUTHTOKEN=<<Authtoken_generated_from_PMP>>" -H "Content-Type: text/json"
'https://192.168.39.29:<Port>/restapi/json/v1/resourcegroup -d
'INPUT_DATA={
"operation": {
"Details": {
"critgroup": "CG1",
"critdesc": "description about CG1",
"RuleCriteria": "Low",
"NoHelpDeskRetrieval": "false",
"andor": "and",
"NoOfCriteria": 2,
"condition_1": "RESOURCENAME",
"operator_1": "CONTAINS",
"valuefield_1": "win",
"condition_2": "LOGINNAME",
"operator_2": "CONTAINS",
"valuefield_2": "PMP"
}
}
}

Sample Output

{
"operation":
{
"name":"CREATE RESOURCE GROUP",
"result":
{
"status":"Success",
"message":"Group CG1 has been added successfully."
}
}
}


53. Get Audit Details

Description

To get the audit details in PMP.

URL

https://<Host-Name-of-PMP-ServerORIPaddress>:<Port>/api/pki/restapi/createCSR?AUTHTOKEN=<<Authtoken_generated_from_PMP>>&AUDITTYPE=<<Resource/User>>&STARTINDEX=&LIMIT=&DURATION=<<TODAY / YESTERDAY/ LAST_7_DAYS >>

HTTP method

GET

Input Data

None

Sample Request

https://localhost:<Port>/restapi/json/v1/audit?AUTHTOKEN=F73552FD-DDC2-415E-BF5D-06CFA519658B&AUDITTYPE=Resource&STARTINDEX=1&LIMIT=2&DURATION=YESTERDAY

Sample Response

{
"operation":
"name": "GET_AUDIT",
"result":
"status": "Success",
"message": "Audits fetched successfully." },
"totalRows": 2,
"Details":
"AUDITID": "3002",
"RESOURCENAME": "Not Applicable",
"ACCOUNTNAME": "N/A",
"OPERATIONTYPE": "CI/CD Settings Updated",
"OPERATEDBY": "admin",
"IPADDRESS": "localhost",
"USERNAME": "N/A",
"LASTACCESSEDTIME": "2019-01-03 14:51:06.666",
"REASON": "Jenkins Authtoken Modified.",
"NAME": "N/A",
"CLIENT": "Web Client"
},
"AUDITID": "2113",
"RESOURCENAME": "test",
"ACCOUNTNAME": "test",
"OPERATIONTYPE": "Password Verification Failed",
"OPERATEDBY": "System",
"IPADDRESS": "localhost",
"USERNAME": "N/A",
"LASTACCESSEDTIME": "2019-01-03 01:45:00.107",
"REASON": "PMP could not verify the password integrity.",
"NAME": "N/A",
"CLIENT": "Web Client"
}
]
}
}

54. Share a Resource to a User

Description

To share a resource to a user.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/<resourceid>/share

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

PUT

Input Data

{

"operation":

{

"Details":

{

"ACCESSTYPE": "modify","USERID":"1"

}

}

}

Allowed accesstypes: view, modify, fullaccess, revoke


Sample Request

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/resources/1/share

Sample Response

{

"operation":

{

"name":

"SHARE RESOURCE","result":

{

"status":"Success","message":"Read and Modify permission granted to user successfully."

}

}

}

55. Share an Account to a User

Description

To share an account to a user.

URL

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/accounts/<accountid>/share

Header

AUTHTOKEN=<<Authtoken_generated_from_PMP>>

HTTP Method

PUT

Input Data

{

"operation":

{

"Details":

{

"ACCESSTYPE":"modify","USERID":"1"

}

}

}

Allowed accesstypes: view, modify, fullaccess, revoke

Sample Request

https://<Host-Name-of-PMP-Server OR IP address>:<Port>/restapi/json/v1/accounts/11/share

Sample Response

{

"operation":

{

"name":

"SHARE ACCOUNT","result":

{

"status":"Success","message":"Read and Modify permission granted to user successfully."

}

}

}

 

©2014, ZOHO Corp. All Rights Reserved.

Top