---
editLink: false
lastUpdated: false
---

[@salesforce/b2c-tooling-sdk](../../../modules.md) / [operations/mtls](../index.md) / generateCaCertificate

# Function: generateCaCertificate()

> **generateCaCertificate**(`options`): [`GeneratedCertificate`](../interfaces/GeneratedCertificate.md)

Defined in: [packages/b2c-tooling-sdk/src/operations/mtls/index.ts:223](https://github.com/SalesforceCommerceCloud/b2c-developer-tooling/blob/bceb8da43dd8bc63d57932bbd905d36a1b40c949/packages/b2c-tooling-sdk/src/operations/mtls/index.ts#L223)

Generates a self-signed CA certificate for mTLS code upload.

The CA is uploaded to eCDN with [createCodeUploadCertificate](createCodeUploadCertificate.md) and used
to sign client certificates with [issueClientCertificate](issueClientCertificate.md). Keep the CA
private key secret: anyone holding it can issue trusted client certificates.

## Parameters

### options

[`GenerateCaCertificateOptions`](../interfaces/GenerateCaCertificateOptions.md) = `{}`

Subject, validity, and key size options

## Returns

[`GeneratedCertificate`](../interfaces/GeneratedCertificate.md)

The CA certificate and private key as PEM strings
