---
title: Charmhub | certificate_transfer interface
description: Interfaces describe the relation between two charms. This interface shows
  opinionated, standardized interface specifications for charm relations.
url: https://charmhub.io/integrations/certificate_transfer
---

# certificate\_transfer

Version 1, draft

## Usage

Some charms require knowledge of public TLS certificates for trusted communication. This relation interface describes the expected behaviour of any charm claiming to be able to authenticate (or be authenticated) through TLS communication.

**Warning**: This relation interface should not be used by charms requiring certificates for themselves. Please use the `tls-certificates` interface for this usecase.

## Direction

```
flowchart TD
    Requirer -- version --> Provider
    Provider -- certificates, version --> Requirer
```

As with all Juju relations, the `certificate_transfer` interface consists of two parties: a Provider and a Requirer.

## Behavior

Both the Requirer and the Provider need to adhere to criteria to be considered compatible with the interface.

### Provider

* Is expected to provide a list of public certificates and/or CA certificates
* Is expected to provide the used version of the interface.

### Requirer

* Is expected to provide 1 as a version number and to use the provided certificates and/or CA certificates to authenticate communications.

## Relation Data

[[Pydantic Schema]](https://github.com/canonical/charmlibs/blob/main/interfaces/certificate_transfer/interface/vv1/schema.py)

### Provider

The provider writes any number of certficates to its relation data.

#### Example

```
relation-info:
  - endpoint: certificate_transfer
    related-endpoint: certificate_transfer
    app-data:
      certificates:
      - "-----BEGIN CERTIFICATE-----\nMIIC6DCCAdCgAwIBAgIUW42TU9LSjEZLMCclWrvSwAsgRtcwDQYJKoZIhvcNAQEL\nBQAwIDELMAkGA1UEBhMCVVMxETAPBgNVBAMMCHdoYXRldmVyMB4XDTIzMDMyNDE4\nNDMxOVoXDTI0MDMyMzE4NDMxOVowPDELMAkGA1UEAwwCb2sxLTArBgNVBC0MJGUw\nNjVmMWI3LTE2OWEtNDE5YS1iNmQyLTc3OWJkOGM4NzIwNjCCASIwDQYJKoZIhvcN\nAQEBBQADggEPADCCAQoCggEBAK42ixoklDH5K5i1NxXo/AFACDa956pE5RA57wlC\nBfgUYaIDRmv7TUVJh6zoMZSD6wjSZl3QgP7UTTZeHbvs3QE9HUwEkH1Lo3a8vD3z\neqsE2vSnOkpWWnPbfxiQyrTm77/LAWBt7lRLRLdfL6WcucD3wsGqm58sWXM3HG0f\nSN7PHCZUFqU6MpkHw8DiKmht5hBgWG+Vq3Zw8MNaqpwb/NgST3yYdcZwb58G2FTS\nZvDSdUfRmD/mY7TpciYV8EFylXNNFkth8oGNLunR9adgZ+9IunfRKj1a7S5GSwXU\nAZDaojw+8k5i3ikztsWH11wAVCiLj/3euIqq95z8xGycnKcCAwEAATANBgkqhkiG\n9w0BAQsFAAOCAQEAWMvcaozgBrZ/MAxzTJmp5gZyLxmMNV6iT9dcqbwzDtDtBvA/\n46ux6ytAQ+A7Bd3AubvozwCr1Id6g66ae0blWYRRZmF8fDdX/SBjIUkv7u9A3NVQ\nXN9gsEvK9pdpfN4ZiflfGSLdhM1STHycLmhG6H5s7HklbukMRhQi+ejbSzm/wiw1\nipcxuKhSUIVNkTLusN5b+HE2gwF1fn0K0z5jWABy08huLgbaEKXJEx5/FKLZGJga\nfpIzAdf25kMTu3gggseaAmzyX3AtT1i8A8nqYfe8fnnVMkvud89kq5jErv/hlMC9\n49g5yWQR2jilYYM3j9BHDuB+Rs+YS5BCep1JnQ==\n-----END CERTIFICATE-----\n"
      - "-----BEGIN CERTIFICATE-----\nMIIC6DCCAdCgAwIBAgIUW42TU9LSjEZLMCclWrvSwAsgRtcwDQYJKoZIhvcNAQEL\nBQAwIDELMAkGA1UEBhMCVVMxETAPBgNVBAMMCHdoYXRldmVyMB4XDTIzMDMyNDE4\nNDMxOVoXDTI0MDMyMzE4NDMxOVowPDELMAkGA1UEAwwCb2sxLTArBgNVBC0MJGUw\nNjVmMWI3LTE2OWEtNDE5YS1iNmQyLTc3OWJkOGM4NzIwNjCCASIwDQYJKoZIhvcN\nAQEBBQADggEPADCCAQoCggEBAK42ixoklDH5K5i1NxXo/AFACDa956pE5RA57wlC\nBfgUYaIDRmv7TUVJh6zoMZSD6wjSZl3QgP7UTTZeHbvs3QE9HUwEkH1Lo3a8vD3z\neqsE2vSnOkpWWnPbfxiQyrTm77/LAWBt7lRLRLdfL6WcucD3wsGqm58sWXM3HG0f\nSN7PHCZUFqU6MpkHw8DiKmht5hBgWG+Vq3Zw8MNaqpwb/NgST3yYdcZwb58G2FTS\nZvDSdUfRmD/mY7TpciYV8EFylXNNFkth8oGNLunR9adgZ+9IunfRKj1a7S5GSwXU\nAZDaojw+8k5i3ikztsWH11wAVCiLj/3euIqq95z8xGycnKcCAwEAATANBgkqhkiG\n9w0BAQsFAAOCAQEAWMvcaozgBrZ/MAxzTJmp5gZyLxmMNV6iT9dcqbwzDtDtBvA/\n46ux6ytAQ+A7Bd3AubvozwCr1Id6g66ae0blWYRRZmF8fDdX/SBjIUkv7u9A3NVQ\nXN9gsEvK9pdpfN4ZiflfGSLdhM1STHycLmhG6H5s7HklbukMRhQi+ejbSzm/wiw1\nipcxuKhSUIVNkTLusN5b+HE2gwF1fn0K0z5jWABy08huLgbaEKXJEx5/FKLZGJga\nfpIzAdf25kMTu3gggseaAmzyX3AtT1i8A8nqYfe8fnnVMkvud89kq5jErv/hlMC9\n49g5yWQR2jilYYM3j9BHDuB+Rs+YS5BCep1JnQ==\n-----END CERTIFICATE-----\n"
      version: 1
```

### Requirer

The requirer writes the version number of the interface to its application databag as soon as feasible.

#### Example

```
relation-info:
  - endpoint: certificate_transfer
    related-endpoint: certificate_transfer
    app-data:
      version: 1
```

## Charms implementing this interface

### Providers

### Requirers

## Other charms using this interface

### Providers

* [vault-k8s](https://charmhub.io/vault-k8s)
* [openfga-k8s](https://charmhub.io/openfga-k8s)
* [vault](https://charmhub.io/vault)
* [lego](https://charmhub.io/lego)
* [self-signed-certificates](https://charmhub.io/self-signed-certificates)
* [glauth-k8s](https://charmhub.io/glauth-k8s)

### Requirers

* [kafka](https://charmhub.io/kafka)
* [kafka-k8s](https://charmhub.io/kafka-k8s)
* [mongodb](https://charmhub.io/mongodb)
* [mongodb-k8s](https://charmhub.io/mongodb-k8s)
* [traefik-k8s](https://charmhub.io/traefik-k8s)
* [postgresql](https://charmhub.io/postgresql)
* [prometheus-k8s](https://charmhub.io/prometheus-k8s)
* [grafana-k8s](https://charmhub.io/grafana-k8s)
* [postgresql-k8s](https://charmhub.io/postgresql-k8s)
* [loki-k8s](https://charmhub.io/loki-k8s)
* [alertmanager-k8s](https://charmhub.io/alertmanager-k8s)
* [kratos](https://charmhub.io/kratos)
* [grafana-agent-k8s](https://charmhub.io/grafana-agent-k8s)
* [juju-jimm-k8s](https://charmhub.io/juju-jimm-k8s)
* [identity-platform-login-ui-operator](https://charmhub.io/identity-platform-login-ui-operator)
* [blackbox-exporter-k8s](https://charmhub.io/blackbox-exporter-k8s)
* [parca-agent](https://charmhub.io/parca-agent)
* [microceph](https://charmhub.io/microceph)
* [charmed-etcd](https://charmhub.io/charmed-etcd)
* [oauth2-proxy-k8s](https://charmhub.io/oauth2-proxy-k8s)
* [kyuubi-k8s](https://charmhub.io/kyuubi-k8s)
* [lego](https://charmhub.io/lego)
* [catalogue-k8s](https://charmhub.io/catalogue-k8s)
* [cos-configuration-k8s](https://charmhub.io/cos-configuration-k8s)
* [opentelemetry-collector-k8s](https://charmhub.io/opentelemetry-collector-k8s)
* [opentelemetry-collector](https://charmhub.io/opentelemetry-collector)
