---
editLink: false
lastUpdated: false
---

[@salesforce/b2c-tooling-sdk](../../modules.md) / operations/mtls

# operations/mtls

mTLS code upload certificate operations for B2C Commerce.

Two-factor (mTLS) code upload to staging via eCDN works with a private
certificate authority (CA):

1. Generate a CA certificate and key ([generateCaCertificate](functions/generateCaCertificate.md)).
2. Upload the CA to eCDN ([createCodeUploadCertificate](functions/createCodeUploadCertificate.md)). The response
   includes the code upload hostname associated with the staging zone.
3. Issue one or more client certificates signed by the CA, bundled as PKCS12
   (`.p12`) files ([issueClientCertificate](functions/issueClientCertificate.md)). Each user (named after their
   Business Manager username) or CI pipeline (named after its API client ID)
   gets its own client certificate for WebDAV uploads; the CA itself is never
   used as a client certificate.

The CA certificate may be valid for at most [MAX\_CODE\_UPLOAD\_CA\_VALIDITY\_DAYS](variables/MAX_CODE_UPLOAD_CA_VALIDITY_DAYS.md)
days. To rotate, upload a new CA before the old one expires, re-issue client
certificates from it, then delete the old CA.

## Usage

```typescript
import {createCdnZonesClient} from '@salesforce/b2c-tooling-sdk/clients';
import {
  createCodeUploadCertificate,
  generateCaCertificate,
  issueClientCertificate,
} from '@salesforce/b2c-tooling-sdk/operations/mtls';

const ca = generateCaCertificate({commonName: 'My Code Upload CA'});
const client = createCdnZonesClient({shortCode, tenantId}, auth, {readWrite: true});
const uploaded = await createCodeUploadCertificate(client, organizationId, {
  name: 'code-upload',
  certificatePem: ca.certificatePem,
  privateKeyPem: ca.privateKeyPem,
});

const clientCert = issueClientCertificate({ca, commonName: 'build-server'});
await fs.writeFile('build-server.p12', clientCert.pkcs12);
// clientCert.passphrase protects the .p12; uploaded.mtlsAssociatedCodeUploadHostname
// is the WebDAV hostname to use with it.
```

## Interfaces

- [CertificateKeyPair](interfaces/CertificateKeyPair.md)
- [CreateCodeUploadCertificateOptions](interfaces/CreateCodeUploadCertificateOptions.md)
- [GenerateCaCertificateOptions](interfaces/GenerateCaCertificateOptions.md)
- [GeneratedCertificate](interfaces/GeneratedCertificate.md)
- [IssueClientCertificateOptions](interfaces/IssueClientCertificateOptions.md)
- [IssuedClientCertificate](interfaces/IssuedClientCertificate.md)

## Type Aliases

- [MtlsCertificate](type-aliases/MtlsCertificate.md)

## Variables

- [DEFAULT\_CA\_VALIDITY\_DAYS](variables/DEFAULT_CA_VALIDITY_DAYS.md)
- [DEFAULT\_CLIENT\_VALIDITY\_DAYS](variables/DEFAULT_CLIENT_VALIDITY_DAYS.md)
- [DEFAULT\_KEY\_SIZE](variables/DEFAULT_KEY_SIZE.md)
- [MAX\_CODE\_UPLOAD\_CA\_VALIDITY\_DAYS](variables/MAX_CODE_UPLOAD_CA_VALIDITY_DAYS.md)

## Functions

- [createCodeUploadCertificate](functions/createCodeUploadCertificate.md)
- [generateCaCertificate](functions/generateCaCertificate.md)
- [generatePassphrase](functions/generatePassphrase.md)
- [issueClientCertificate](functions/issueClientCertificate.md)
- [validateCodeUploadCaCertificate](functions/validateCodeUploadCaCertificate.md)
