@tak-ps/node-tak
    Preparing search index...

    Class Certificate

    Hierarchy

    • default
      • Certificate
    Index
    api: TAKAPI
    schema: {} = {}
    • Returns Promise<string | object>

    • Delete Certificates by Id

      TAK Server Docs.

      Parameters

      • ids: string[]

      Returns Promise<
          {
              data: {
                  certificate: string;
                  clientUid: string;
                  creatorDn: string;
                  effectiveDate: string;
                  expirationDate: string;
                  hash: string;
                  id: number;
                  issuanceDate: string;
                  revocationDate?: string;
                  serialNumber: string;
                  subjectDn: string;
                  token: string;
                  userDn: string;
              };
              messages?: string[];
              nodeId?: string;
              type: string;
              version: string;
          },
      >

    • Download Certificates by Id

      Returns a ZIP archive stream containing one {n}_{userDn}_ClientCert.pem entry per certificate

      TAK Server Docs.

      Parameters

      • ids: (string | number)[]

      Returns Promise<Readable>

    • Get Single Certificate

      TAK Server Docs.

      Parameters

      • hash: string

      Returns Promise<
          {
              data: {
                  certificate: string;
                  clientUid: string;
                  creatorDn: string;
                  effectiveDate: string;
                  expirationDate: string;
                  hash: string;
                  id: number;
                  issuanceDate: string;
                  revocationDate?: string;
                  serialNumber: string;
                  subjectDn: string;
                  token: string;
                  userDn: string;
              };
              messages?: string[];
              nodeId?: string;
              type: string;
              version: string;
          },
      >

    • List Certificates

      TAK Server Docs.

      Parameters

      • Optionalusername: string

      Returns Promise<
          {
              data: {
                  certificate: string;
                  clientUid: string;
                  creatorDn: string;
                  effectiveDate: string;
                  expirationDate: string;
                  hash: string;
                  id: number;
                  issuanceDate: string;
                  revocationDate?: string;
                  serialNumber: string;
                  subjectDn: string;
                  token: string;
                  userDn: string;
              }[];
              messages?: string[];
              nodeId?: string;
              type: string;
              version: string;
          },
      >

    • List Active Certificates

      The most recently issued certificate for each Client UID / User DN pair

      TAK Server Docs.

      Returns Promise<
          {
              data: {
                  certificate: string;
                  clientUid: string;
                  creatorDn: string;
                  effectiveDate: string;
                  expirationDate: string;
                  hash: string;
                  id: number;
                  issuanceDate: string;
                  revocationDate?: string;
                  serialNumber: string;
                  subjectDn: string;
                  token: string;
                  userDn: string;
              }[];
              messages?: string[];
              nodeId?: string;
              type: string;
              version: string;
          },
      >

    • List Expired Certificates

      TAK Server Docs.

      Returns Promise<
          {
              data: {
                  certificate: string;
                  clientUid: string;
                  creatorDn: string;
                  effectiveDate: string;
                  expirationDate: string;
                  hash: string;
                  id: number;
                  issuanceDate: string;
                  revocationDate?: string;
                  serialNumber: string;
                  subjectDn: string;
                  token: string;
                  userDn: string;
              }[];
              messages?: string[];
              nodeId?: string;
              type: string;
              version: string;
          },
      >

    • List Replaced Certificates

      TAK Server Docs.

      Returns Promise<
          {
              data: {
                  certificate: string;
                  clientUid: string;
                  creatorDn: string;
                  effectiveDate: string;
                  expirationDate: string;
                  hash: string;
                  id: number;
                  issuanceDate: string;
                  revocationDate?: string;
                  serialNumber: string;
                  subjectDn: string;
                  token: string;
                  userDn: string;
              }[];
              messages?: string[];
              nodeId?: string;
              type: string;
              version: string;
          },
      >

    • List Revoked Certificates

      TAK Server Docs.

      Returns Promise<
          {
              data: {
                  certificate: string;
                  clientUid: string;
                  creatorDn: string;
                  effectiveDate: string;
                  expirationDate: string;
                  hash: string;
                  id: number;
                  issuanceDate: string;
                  revocationDate?: string;
                  serialNumber: string;
                  subjectDn: string;
                  token: string;
                  userDn: string;
              }[];
              messages?: string[];
              nodeId?: string;
              type: string;
              version: string;
          },
      >

    • Probe whether the TAK Server accepts the credentials this API instance was created with

      The X509 filter runs on every request and rethrows on failure, so GET /Marti/api/version (an anonymous, DB-free endpoint returning a short string) is the cheapest authoritative check - unlike validate it reflects the server's actual enforcement (e.g. whether x509checkRevocation is enabled) and requires no admin credentials. An expired client certificate is rejected during the TLS handshake and surfaces as reason: 'tls'.

      Only authentication failures are returned as a verdict - any other error (server unreachable, unexpected status) is rethrown so it is not mistaken for a rejection

      Returns Promise<
          {
              accepted: boolean;
              message?: string;
              reason?: "revoked"
              | "rejected"
              | "tls";
              version?: string;
          },
      >

    • Revoke Single Certificate

      TAK Server Docs.

      Parameters

      • hash: string

      Returns Promise<
          {
              data: {
                  certificate: string;
                  clientUid: string;
                  creatorDn: string;
                  effectiveDate: string;
                  expirationDate: string;
                  hash: string;
                  id: number;
                  issuanceDate: string;
                  revocationDate?: string;
                  serialNumber: string;
                  subjectDn: string;
                  token: string;
                  userDn: string;
              };
              messages?: string[];
              nodeId?: string;
              type: string;
              version: string;
          },
      >

    • Revoke Certificates by Id

      TAK Server Docs.

      Parameters

      • ids: string[]

      Returns Promise<
          {
              data: {
                  certificate: string;
                  clientUid: string;
                  creatorDn: string;
                  effectiveDate: string;
                  expirationDate: string;
                  hash: string;
                  id: number;
                  issuanceDate: string;
                  revocationDate?: string;
                  serialNumber: string;
                  subjectDn: string;
                  token: string;
                  userDn: string;
              };
              messages?: string[];
              nodeId?: string;
              type: string;
              version: string;
          },
      >

    • Validate a PEM encoded client certificate against local expiry and the TAK Server revocation record

      Expiry is evaluated locally from the certificate. Revocation is looked up via the Certificate Admin API using the same SHA-256 fingerprint the TAK Server X509Authenticator consults - get(hash) first (a single cached row) falling back to the user's certificate list when the TAK Server answers 500, which is how it reports an unknown hash.

      Note: The TAK Server only enforces revocation when auth.x509checkRevocation (or x509TokenAuth) is enabled in CoreConfig - revoked reports the stored state regardless

      Parameters

      • pem: string
      • opts: { now?: Date } = {}

      Returns Promise<
          {
              certificate?: {
                  certificate: string;
                  clientUid: string;
                  creatorDn: string;
                  effectiveDate: string;
                  expirationDate: string;
                  hash: string;
                  id: number;
                  issuanceDate: string;
                  revocationDate?: string;
                  serialNumber: string;
                  subjectDn: string;
                  token: string;
                  userDn: string;
              };
              expired: boolean;
              fingerprint: string;
              known: boolean;
              revocationDate?: string;
              revoked: boolean;
              subject: string;
              username: string;
              valid: boolean;
              validFrom: string;
              validTo: string;
          },
      >