This table aggregates membership for all versions of the Enrollment object.

Versioned schema members

Any object member specific to a range of versions is indicated in its description, at what version the member was either introduced or removed. Any listed data member with no version number is common to all versions of the object.

MemberTypeDescription
Enrollment: An enrollment displays all the information about the process that your certificate goes through from the time you request it, through renewal, and as you obtain subsequent versions. CPS is a certificate life cycle management tool. Once you obtain a certificate, you use it until it expires, in most cases a year from the date the CA issued the certificate. CPS automatically starts the renewal process 90 days before the old certificate expires. It then automatically deploys the renewed certificate when it receives it from the CA. A version label indicates this member is introduced in that version. A pre-version label indicates this member is removed in that version. No version label indicates this member is present in all versions.
admin‚ÄčContactEnrollment.‚Äčadmin‚ÄčContactContact information for the certificate administrator that you want to use as a contact at your company.
assigned‚ÄčSlotsArray, Nullv11 only. Slots where the certificate either will be deployed or is already deployed.
auto‚ÄčRenewal‚ÄčStart‚ÄčTimeString, Nullv10, v11, v9 only. The specific date on which the renewal automatically starts for the enrollment.
certificate‚ÄčChain‚ÄčTypeString, Nullv10, v11, v7, v9 only. Certificate trust chain type.
certificate‚ÄčTypeStringrequired: Either san, single, wildcard, wildcard-san, or third-party. See [Enrollment.validation‚ÄčType Values for details.
change‚ÄčManagementBooleanrequired: If you turn change management on for an enrollment, it stops CPS from deploying the certificate to the network until you acknowledge that you are ready to deploy the certificate. You can test the certificate outside of CPS, on the Edge Staging Network (ESN), to make sure it works in your environment and then deploy the certificate. The ESN is a small network of Akamai edge servers built to simulate Akamai's production network to test most of your site or application functionality with current production version configuration options and functions. For more information on the ESN, see the Edge Staging Network User Guide. You can also contact your account representative with questions or issues with your service on the ESN.
csrEnrollment.‚Äčcsrrequired: When you create an enrollment, you also generate a certificate signing request (CSR) using CPS. CPS signs the CSR with the private key. The CSR contains all the information the CA needs to issue your certificate.
enable‚ÄčMulti‚ÄčStacked‚ÄčCertificatesBooleanv10, v11, v7, v9 only. Enable Dual-Stacked certificate deployment for this enrollment.
idString, Nullv11 only. The unique identifier of the enrollment.
locationString, NullThe URI path to the enrollment. The last segment of the URI path serves as a unique identifier for the enrollment.
max‚ÄčAllowed‚ÄčSan‚ÄčNamesNumber, Nullv10, v11, v7, v9 only. Maximum number of SAN names supported for this enrollment type.
max‚ÄčAllowed‚ÄčWildcard‚ÄčSan‚ÄčNamesNumber, Nullv10, v11, v7, v9 only. Maximum number of Wildcard SAN names supported for this enrollment type.
network‚ÄčConfigurationEnrollment.‚Äčnetwork‚ÄčConfigurationrequired: Settings that specify any network information and TLS Metadata you want CPS to use to push the completed certificate to the network.
orgEnrollment.‚ÄčorgYour organization information.
org‚ÄčIdNumber, Nullv11 only. The Digicert unique identifier for the organization. If an org‚ÄčId value is provided in a PUT or POST request, it is recommended to leave the org, tech‚ÄčContact, and admin‚ÄčContact fields null.
pending‚ÄčChangesArray, Nullv1, v2, v3, v4, v7, v9 only. Returns the Changes currently pending in CPS. The last item in the array is the most recent change.
pending‚ÄčChangesEnrollment.‚Äčpending‚ÄčChanges[]v10, pre-v2. Returns the Changes currently pending in CPS. The last item in the array is the most recent change.
production‚ÄčSlotsArray, Nullv11 only. Slots where the certificate is deployed on the production network.
raStringrequired: The registration authority or certificate authority (CA) you want to use to obtain a certificate. A CA is a trusted entity that signs certificates and can vouch for the identity of a website. Either symantec, lets-encrypt, or third-party.
signature‚ÄčAlgorithmString, NullThe SHA (Secure Hash Algorithm) function. NSA designed this function to produce a hash of certificate contents, which is used in a digital signature. Specify either SHA-1 or SHA-256. We recommend you use SHA-256.
staging‚ÄčSlotsArray, Nullv11 only. Slots where the certificate is deployed on the staging network.
tech‚ÄčContactEnrollment.‚Äčtech‚ÄčContactContact information for an administrator at Akamai.
third‚ÄčPartyEnrollment.‚Äčthird‚ÄčParty, NullSpecifies that you want to use a third party certificate. This is any certificate that is not issued through CPS.
validation‚ÄčTypeStringrequired: There are three types of validation. Domain Validation (DV), which is the lowest level of validation. The CA validates that you have control of the domain. CPS supports DV certificates issued by Let's Encrypt, a free, automated, and open CA, run for public benefit. Organization Validation (OV), which is the next level of validation. The CA validates that you have control of the domain. Extended Validation (EV), which is the highest level of validation in which you must have signed letters and notaries sent to the CA before signing. You can also specify third party as a type of validation, if you want to use a signed certificate obtained by you from a CA not supported by CPS. Either dv, ev, ov, or third-party.
Enrollment.admin‚ÄčContact: Contact information for the certificate administrator that you want to use as a contact at your company.
address‚ÄčLine‚ÄčOneString, Nullv10, v11, v3, v4, v7, v9 only. The address of your organization.
address‚ÄčLine‚ÄčTwoString, Nullv10, v11, v3, v4, v7, v9 only. The address of your organization.
cityString, Nullv10, v11, v3, v4, v7, v9 only. The city where your organization resides.
countryString, Nullv10, v11, v3, v4, v7, v9 only. The country where your organization resides.
emailString, NullThe email address of the administrator who you want to use as a contact at your company.
first‚ÄčNameString, NullThe first name of the administrator who you want to use as a contact at your company.
last‚ÄčNameString, NullThe last name of the administrator who you want to use as a contact at your company.
organization‚ÄčNameString, Nullv10, v11, v3, v4, v7, v9 only. The name of your organization.
phoneString, NullThe phone number of your organization.
postal‚ÄčCodeString, Nullv10, v11, v3, v4, v7, v9 only. The postal code of your organization.
regionString, Nullv10, v11, v3, v4, v7, v9 only. The region of your organization, typically a state or province.
titleString, Nullv10, v11, v3, v4, v7, v9 only. The title of the administrator who you want to use as a contact at your company.
Enrollment.csr: When you create an enrollment, you also generate a certificate signing request (CSR) using CPS. CPS signs the CSR with the private key. The CSR contains all the information the CA needs to issue your certificate.
cString, NullThe country code for the country where your organization is located.
cnStringrequired: The common name (CN) you want to use for the certificate in the Common Name field. The domain name you specify here must be owned or have legal rights to use the domain by the company you enter in the Organization field in this tab. The company that owns the domain name must be a legally incorporated entity and be active and in good standing.
lString, NullYour city in the locality (city).
oString, NullThe name of your company or organization. Enter the name as it appears in all legal documents and as it appears in the legal entity filing.
ouString, NullYour organizational unit.
preferred‚ÄčTrust‚ÄčChainString, Nullv10, pre-v2. For the Let's Encrypt Domain Validated (DV) SAN certificates, the customer may select one of the trust chain options supported by Let‚Äôs Encrypt, or not fill out this field. The preferred trust chain will be included by CPS with the leaf certificate in the TLS handshake. If the field does not have a value, whichever trust chain Akamai chooses will be used by default.
sansArray, NullAdditional common names (CN) to create a Subject Alternative Names (SAN) list. String values.
stString, NullYour state or province.
Enrollment.network‚ÄčConfiguration: Settings that specify any network information and TLS Metadata you want CPS to use to push the completed certificate to the network.
client‚ÄčMutual‚ÄčAuthenticationEnrollment.‚Äčnetwork‚ÄčConfiguration.‚Äčclient‚ÄčMutual‚ÄčAuthentication, Nullv10, v11, v9 only. The configuration for client mutual authentication. Specifies the trust chain that is used to verify client certificates and some configuration options.
disallowed‚ÄčTls‚ÄčVersionsArray, Nullv10. Specify the TLS protocol version to disallow. CPS uses the TLS protocols that Akamai currently supports as a best practice.
dns‚ÄčName‚ÄčSettingsEnrollment.‚Äčnetwork‚ÄčConfiguration.‚Äčdns‚ÄčName‚ÄčSettings, Nullv10, v11, v7, v9 only. DNS name settings.
geographyStringv10, v11, v3, v4, v7, v9 only. Set to the enum core to specify worldwide (includes China and Russia). Set to the enum china+core to specify worldwide and China. Set to the enum russia+core to specify worldwide and Russia. You can only use this setting to include China and Russia if your Akamai contract specifies your ability to do so and you have approval from the Chinese and Russian government.
must‚ÄčHave‚ÄčCiphersString, NullCiphers that you definitely want to include for your enrollment while deploying it on the network. Defaults to ak-akamai-default when it is not set. For more information on cipher profiles, see Akamai community.
network‚ÄčTypeStringv1, v2 only. Type of the network that you want to deploy your certificate in, either standard-worldwide, worldwide-russia, or worldwide.
ocsp‚ÄčStaplingEnumeration, Nullv10, v11, v7, v9 only. Enable OCSP stapling for the enrollment. OCSP Stapling improves performance by including a valid OCSP response in every TLS handshake. Specify OCSP Stapling if you want to improve performance by allowing the visitors to your site to query the Online Certificate Status Protocol (OCSP) server at regular intervals to obtain a signed time-stamped OCSP response. This response must be signed by the CA, not the server, therefore ensuring security. Disable OSCP Stapling if you want visitors to your site to contact the CA directly for an OSCP response. OCSP allows you to obtain the revocation status of a certificate. We recommend all customers enable this feature. Use on, off or not-set.
preferred‚ÄčCiphersString, NullCiphers that you preferably want to include for your enrollment while deploying it on the network. Defaults to ak-akamai-default when it is not set. For more information on cipher profiles, see Akamai community.
quic‚ÄčEnabledBooleanv10, v11, v7, v9 only. Set to true to enable QUIC protocol.
secure‚ÄčNetworkStringv10. Set the type of deployment network you want to use. Set Standard TLS to deploy your certificate to Akamai's standard secure network. It is not PCI compliant. Set Enhanced TLS to deploy your certificate to Akamai's more secure network with PCI compliance capability.
sniEnrollment.‚Äčnetwork‚ÄčConfiguration.‚Äčsni, Nullv1, v2, v3, v4 only. SNI settings for your enrollment. When set to null, the enrollment becomes non-SNI. When it is non-null, enrollment is SNI-ONLY. This setting cannot be changed once an enrollment is created.
sni‚ÄčOnlyBooleanv10, v11, v7, v9 only. SNI settings for your enrollment. Set to true to enable SNI-only for the enrollment. This setting cannot be changed once an enrollment is created.
Enrollment.network‚ÄčConfiguration.client‚ÄčMutual‚ÄčAuthentication: The configuration for client mutual authentication. Specifies the trust chain that is used to verify client certificates and some configuration options.
authentication‚ÄčOptionsEnrollment.‚Äčnetwork‚ÄčConfiguration.‚Äčclient‚ÄčMutual‚ÄčAuthentication.‚Äčauthentication‚ÄčOptions, Nullv10, v11, v9 only. Contains the configuration options for the selected trust chain.
set‚ÄčIdString, Nullv10, v11, v9 only. The identifier of the set of trust chains, created in the Trust Chain Manager.
Enrollment.network‚ÄčConfiguration.client‚ÄčMutual‚ÄčAuthentication.authentication‚ÄčOptions: Contains the configuration options for the selected trust chain.
ocspEnrollment.‚Äčnetwork‚ÄčConfiguration.‚Äčclient‚ÄčMutual‚ÄčAuthentication.‚Äčauthentication‚ÄčOptions.‚Äčocsp, Nullv10, v11, v9 only. Whether you want to enable ocsp stapling for client certificates.
send‚ÄčCa‚ÄčList‚ÄčTo‚ÄčClientBoolean, Nullv10, v11, v9 only. Whether you want to enable the server to send the certificate authority (CA) list to the client.
Enrollment.network‚ÄčConfiguration.client‚ÄčMutual‚ÄčAuthentication.authentication‚ÄčOptions.ocsp: Whether you want to enable ocsp stapling for client certificates.
enabledBoolean, Nullv10, v11, v9 only. Whether the OCSP stapling is enabled.
Enrollment.network‚ÄčConfiguration.dns‚ÄčName‚ÄčSettings: DNS name settings.
clone‚ÄčDns‚ÄčNamesBooleanv10, v11, v7, v9 only. Enable if you want CPS to direct traffic using all the SANs listed in the SANs parameter when you created your enrollment.
dns‚ÄčNamesArray, Nullv10, v11, v7, v9 only. Names served by SNI-only enabled enrollments.
Enrollment.network‚ÄčConfiguration.sni: SNI settings for your enrollment. When set to null, the enrollment becomes non-SNI. When it is non-null, enrollment is SNI-ONLY. This setting cannot be changed once an enrollment is created.
clone‚ÄčDns‚ÄčNamesBooleanv1, v2, v3, v4 only. Enable if you want CPS to direct traffic using all the SANs listed in the SANs parameter when you created your enrollment.
dns‚ÄčNamesArray, Nullv1, v2, v3, v4 only. Names served by SNI-only enabled enrollments.
Enrollment.org: Your organization information.
address‚ÄčLine‚ÄčOneString, NullThe address of your organization.
address‚ÄčLine‚ÄčTwoString, NullThe address of your organization.
cityString, NullThe city where your organization resides.
countryString, NullThe country where your organization resides.
nameString, NullThe name of your organization.
phoneString, NullThe phone number of the administrator who you want to use as a contact at your company.
postal‚ÄčCodeString, NullThe postal code of your organization.
regionString, NullThe region where your organization resides.
Enrollment.pending‚ÄčChanges[]: Returns the Changes currently pending in CPS. The last item in the array is the most recent change.
change‚ÄčTypeEnumeration, Nullv10, pre-v2. Pending change action.
locationStringv10, pre-v2. Location to fetch related change information.
Enrollment.tech‚ÄčContact: Contact information for an administrator at Akamai.
address‚ÄčLine‚ÄčOneString, Nullv10, v11, v3, v4, v7, v9 only. The address for an administrator at Akamai.
address‚ÄčLine‚ÄčTwoString, Nullv10, v11, v3, v4, v7, v9 only. The address for an administrator at Akamai.
cityString, Nullv10, v11, v3, v4, v7, v9 only. The city for an administrator at Akamai.
countryString, Nullv10, v11, v3, v4, v7, v9 only. The country for an administrator at Akamai.
emailString, NullThe email address of the administrator who you want to use as a contact at your company.
first‚ÄčNameString, NullThe first name of the technical contact who you want to use within Akamai. This is the person you work closest with at Akamai who can verify the certificate request. This is the person the CA calls if there are any issues with the certificate and they cannot reach the administrator.
last‚ÄčNameString, NullThe last name of the technical contact who you want to use within Akamai.
organization‚ÄčNameString, Nullv10, v11, v3, v4, v7, v9 only. The name of your organization in Akamai where your technical contact works.
phoneString, NullThe phone number of the technical contact who you want to use within Akamai.
postal‚ÄčCodeString, Nullv10, v11, v3, v4, v7, v9 only. The postal code for an administrator at Akamai.
regionString, Nullv10, v11, v3, v4, v7, v9 only. The region for an administrator at Akamai.
titleString, Nullv10, v11, v3, v4, v7, v9 only. The title for an administrator at Akamai.
Enrollment.third‚ÄčParty: Specifies that you want to use a third party certificate. This is any certificate that is not issued through CPS.
exclude‚ÄčSansBooleanrequired: If this is true, then the SANs in the enrollment do not appear in the CSR that CPS submits to the CA.

Sample v7 object

TBD

{
    "adminContact": {
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "country": "US",
        "email": "r1d1@akamai.com",
        "firstName": "R1",
        "lastName": "D1",
        "organizationName": "Akamai",
        "phone": "617-555-0111",
        "postalCode": "02142",
        "region": "MA",
        "title": "Administrator"
    },
    "certificateChainType": "default",
    "certificateType": "third-party",
    "changeManagement": true,
    "csr": {
        "c": "US",
        "cn": "www.example.com",
        "l": "Cambridge",
        "o": "Akamai",
        "ou": "WebEx",
        "sans": [
            "san1.example.com",
            "san2.example.com",
            "san3.example.com"
        ],
        "st": "MA"
    },
    "enableMultiStackedCertificates": false,
    "location": "/cps/v2/enrollments/10002",
    "maxAllowedSanNames": 100,
    "maxAllowedWildcardSanNames": 100,
    "networkConfiguration": {
        "disallowedTlsVersions": [],
        "dnsNameSettings": {
            "cloneDnsNames": false,
            "dnsNames": [
                "san2.example.com",
                "san1.example.com"
            ]
        },
        "geography": "core",
        "mustHaveCiphers": "ak-akamai-default",
        "ocspStapling": "not-set",
        "preferredCiphers": "ak-akamai-default-interim",
        "quicEnabled": false,
        "secureNetwork": "enhanced-tls",
        "sniOnly": true
    },
    "org": {
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "country": "US",
        "name": "Akamai Technologies",
        "phone": "617-555-0111",
        "postalCode": "02142",
        "region": "MA"
    },
    "pendingChanges": [
        "/cps/v2/enrollments/10002/changes/10002"
    ],
    "ra": "third-party",
    "signatureAlgorithm": null,
    "techContact": {
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "country": "US",
        "email": "r2d2@akamai.com",
        "firstName": "R2",
        "lastName": "D2",
        "organizationName": "Akamai",
        "phone": "617-555-0111",
        "postalCode": "02142",
        "region": "MA",
        "title": "Technical Engineer"
    },
    "thirdParty": {
        "excludeSans": false
    },
    "validationType": "third-party"
}

Sample v9 object

TBD

{
    "adminContact": {
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "country": "US",
        "email": "r1d1@akamai.com",
        "firstName": "R1",
        "lastName": "D1",
        "organizationName": "Akamai",
        "phone": "617-555-0111",
        "postalCode": "02142",
        "region": "MA",
        "title": "Administrator"
    },
    "autoRenewalStartTime": null,
    "certificateChainType": "default",
    "certificateType": "third-party",
    "changeManagement": true,
    "csr": {
        "c": "US",
        "cn": "www.example.com",
        "l": "Cambridge",
        "o": "Akamai",
        "ou": "WebEx",
        "sans": [
            "san1.example.com",
            "san2.example.com",
            "san3.example.com",
            "www.example.com"
        ],
        "st": "MA"
    },
    "enableMultiStackedCertificates": false,
    "location": "/cps-api/enrollments/10001",
    "maxAllowedSanNames": 100,
    "maxAllowedWildcardSanNames": 100,
    "networkConfiguration": {
        "clientMutualAuthentication": {
            "authenticationOptions": {
                "ocsp": {
                    "enabled": false
                },
                "sendCaListToClient": false
            },
            "setId": "Custom_CPS-6134b_B-3-1AHBENT.xml"
        },
        "disallowedTlsVersions": [
            "TLSv1",
            "TLSv1_1"
        ],
        "dnsNameSettings": {
            "cloneDnsNames": false,
            "dnsNames": [
                "san2.example.com",
                "san1.example.com"
            ]
        },
        "geography": "core",
        "mustHaveCiphers": "ak-akamai-default",
        "ocspStapling": "on",
        "preferredCiphers": "ak-akamai-default-interim",
        "quicEnabled": false,
        "secureNetwork": "enhanced-tls",
        "sniOnly": true
    },
    "org": {
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "country": "US",
        "name": "Akamai Technologies",
        "phone": "617-555-0111",
        "postalCode": "02142",
        "region": "MA"
    },
    "pendingChanges": [
        "/cps-api/enrollments/10001/changes/10002"
    ],
    "ra": "third-party",
    "signatureAlgorithm": null,
    "techContact": {
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "country": "US",
        "email": "r2d2@akamai.com",
        "firstName": "R2",
        "lastName": "D2",
        "organizationName": "Akamai",
        "phone": "617-555-0111",
        "postalCode": "02142",
        "region": "MA",
        "title": "Technical Engineer"
    },
    "thirdParty": {
        "excludeSans": false
    },
    "validationType": "third-party"
}

Sample v10 object

TBD

{
    "adminContact": {
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "country": "US",
        "email": "r1d1@akamai.com",
        "firstName": "R1",
        "lastName": "D1",
        "organizationName": "Akamai",
        "phone": "617-555-0111",
        "postalCode": "02142",
        "region": "MA",
        "title": "Administrator"
    },
    "autoRenewalStartTime": null,
    "certificateChainType": "default",
    "certificateType": "third-party",
    "changeManagement": true,
    "csr": {
        "c": "US",
        "cn": "www.example.com",
        "l": "Cambridge",
        "o": "Akamai",
        "ou": "WebEx",
        "preferredTrustChain": "dst-root-ca-x3",
        "sans": [
            "san1.example.com",
            "san2.example.com",
            "san3.example.com",
            "www.example.com"
        ],
        "st": "MA"
    },
    "enableMultiStackedCertificates": false,
    "location": "/cps-api/enrollments/10001",
    "maxAllowedSanNames": 100,
    "maxAllowedWildcardSanNames": 100,
    "networkConfiguration": {
        "clientMutualAuthentication": {
            "authenticationOptions": {
                "ocsp": {
                    "enabled": false
                },
                "sendCaListToClient": false
            },
            "setId": "Custom_CPS-6134b_B-3-1AHBENT.xml"
        },
        "disallowedTlsVersions": [
            "TLSv1",
            "TLSv1_1"
        ],
        "dnsNameSettings": {
            "cloneDnsNames": false,
            "dnsNames": [
                "san2.example.com",
                "san1.example.com"
            ]
        },
        "geography": "core",
        "mustHaveCiphers": "ak-akamai-default",
        "ocspStapling": "on",
        "preferredCiphers": "ak-akamai-default-interim",
        "quicEnabled": false,
        "secureNetwork": "enhanced-tls",
        "sniOnly": true
    },
    "org": {
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "country": "US",
        "name": "Akamai Technologies",
        "phone": "617-555-0111",
        "postalCode": "02142",
        "region": "MA"
    },
    "pendingChanges": [
        {
            "changeType": "new-certificate",
            "location": "/cps-api/enrollments/10001/changes/10002"
        }
    ],
    "ra": "third-party",
    "signatureAlgorithm": null,
    "techContact": {
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "country": "US",
        "email": "r2d2@akamai.com",
        "firstName": "R2",
        "lastName": "D2",
        "organizationName": "Akamai",
        "phone": "617-555-0111",
        "postalCode": "02142",
        "region": "MA",
        "title": "Technical Engineer"
    },
    "thirdParty": {
        "excludeSans": false
    },
    "validationType": "third-party"
}

Sample v11 object

TBD

{
    "id": "10001",
    "location": "/cps-api/enrollments/10001",
    "ra": "third-party",
    "validationType": "third-party",
    "certificateType": "third-party",
    "certificateChainType": "default",
    "networkConfiguration": {
        "geography": "core",
        "secureNetwork": "enhanced-tls",
        "mustHaveCiphers": "ak-akamai-default",
        "preferredCiphers": "ak-akamai-default-interim",
        "disallowedTlsVersions": [
            "TLSv1",
            "TLSv1_1"
        ],
        "sniOnly": true,
        "quicEnabled": false,
        "dnsNameSettings": {
            "cloneDnsNames": false,
            "dnsNames": [
                "san2.example.com",
                "san1.example.com"
            ]
        },
        "ocspStapling": "on",
        "clientMutualAuthentication": {
            "setId": "Custom_CPS-6134b_B-3-1AHBENT.xml",
            "authenticationOptions": {
                "sendCaListToClient": false,
                "ocsp": {
                    "enabled": false
                }
            }
        }
    },
    "signatureAlgorithm": null,
    "changeManagement": true,
    "csr": {
        "cn": "www.example.com",
        "c": "US",
        "st": "MA",
        "l": "Cambridge",
        "o": "Akamai",
        "ou": "WebEx",
        "preferredTrustChain": "dst-root-ca-x3",
        "sans": [
            "san1.example.com",
            "san2.example.com",
            "san3.example.com",
            "www.example.com"
        ]
    },
    "org": {
        "name": "Akamai Technologies",
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "region": "MA",
        "postalCode": "02142",
        "country": "US",
        "phone": "617-555-0111"
    },
    "orgId": "645263546",
    "adminContact": {
        "firstName": "R1",
        "lastName": "D1",
        "phone": "617-555-0111",
        "email": "r1d1@akamai.com",
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "country": "US",
        "organizationName": "Akamai",
        "postalCode": "02142",
        "region": "MA",
        "title": "Administrator"
    },
    "techContact": {
        "firstName": "R2",
        "lastName": "D2",
        "phone": "617-555-0111",
        "email": "r2d2@akamai.com",
        "addressLineOne": "150 Broadway",
        "addressLineTwo": null,
        "city": "Cambridge",
        "country": "US",
        "organizationName": "Akamai",
        "postalCode": "02142",
        "region": "MA",
        "title": "Technical Engineer"
    },
    "thirdParty": {
        "excludeSans": false
    },
    "assignedSlots": [
        1234
    ],
    "productionSlots": [
        1234
    ],
    "stagingSlots": [
        1234
    ],
    "enableMultiStackedCertificates": false,
    "autoRenewalStartTime": null,
    "pendingChanges": [
        {
            "location": "/cps-api/enrollments/10001/changes/10002",
            "changeType": "new-certificate"
        }
    ],
    "maxAllowedSanNames": 100,
    "maxAllowedWildcardSanNames": 100
}