[Pkg-freeipa-devel] [Git][freeipa-team/ldapjdk][upstream] 16 commits: Update CI to use packages from Quay.io

Timo Aaltonen (@tjaalton) gitlab at salsa.debian.org
Sun Sep 27 08:10:24 BST 2026



Timo Aaltonen pushed to branch upstream at FreeIPA packaging / ldapjdk


Commits:
ebace161 by Endi S. Dewata at 2024-03-04T09:17:07-06:00
Update CI to use packages from Quay.io

- - - - -
a54739f5 by Endi S. Dewata at 2024-03-04T09:17:09-06:00
Fix SPDX license

- - - - -
72f64646 by Endi S. Dewata at 2024-03-04T09:56:54-06:00
Update JSS dependency

The pom.xml files have been updated to support newer JSS.

- - - - -
5ed5c069 by Endi S. Dewata at 2024-03-06T08:51:31-06:00
Update Java dependencies

The RPM spec has been updated to use Java 21 on Fedora 40 or later
and Java 17 on other platforms.

The Dockerfile has been modified to remove any Java packages
pulled by the existing LDAP SDK package to ensure that the build
will be done using the correct Java version.

The tools-test.sh has been updated to remove hard-coded JAVA_HOME.

- - - - -
76e4ed0a by Endi S. Dewata at 2024-03-27T15:12:38-05:00
Update version number to 5.6.0-alpha1

- - - - -
8f118d0f by Endi S. Dewata at 2024-04-03T12:22:50-05:00
Refactor LDAPSearchResults

The LDAPSearchResults has been updated to no longer implement
Enumeration to simplify maintenance.

- - - - -
27d6695a by Endi S. Dewata at 2024-07-08T13:50:31-05:00
Reformat pom.xml

- - - - -
9d622f68 by Endi S. Dewata at 2024-07-09T12:16:53-05:00
Publish Maven artifacts to dogtagpki/repo

Previously LDAP SDK's Maven artifacts were published to GitHub
Packages which is a private repository so it's difficult to use.

To resolve the problem, the pom.xml has been modified to publish
the artifacts to a publicly accessible dogtagpki/repo instead.

- - - - -
e26991d7 by Endi S. Dewata at 2024-07-09T16:05:18-05:00
Replace pki client-cert-import

The CI tests has been updated to use pki nss-cert-import and
pki pkcs12-import commands to import certs and PKCS #12 files.

- - - - -
74f624b2 by Endi S. Dewata at 2024-07-10T09:38:22-05:00
Add Maven build test

A new test has been added to build the code with Maven and Ant
then verify that the artifacts are identical. In the future
the support for Ant will be dropped.

The existing RPM test has been updated to verify that the
artifacts built with XMvn and shipped in RPM are identical to
the ones built directly with Maven.

The build.sh has been updated to provide options to specify
the paths to SLF4J and JSS libraries.

- - - - -
be14db23 by Endi S. Dewata at 2024-07-11T11:37:25-05:00
Update Eclipse classpath

- - - - -
3485ec32 by Endi S. Dewata at 2024-07-24T09:15:03-05:00
Update JSSSocketFactory to use SSLContext

The JSSSocketFactory has been updated to use SSLContext to create
JSSSocket. The class also no longer implements accept() since
the peer certificate will be validated using a TrustManager.

- - - - -
fa9cd5e2 by Andrew Hughes at 2024-08-28T14:24:21-05:00
Use Java 21 on RHEL 10

- - - - -
3364569a by Endi S. Dewata at 2024-11-04T18:15:17-06:00
Fix JAVA_HOME on Fedora 42

- - - - -
95a179bc by Endi S. Dewata at 2025-02-12T10:34:40-06:00
Update version number to 5.6.0

- - - - -
41e117f0 by Endi S. Dewata at 2025-02-12T17:01:51-06:00
Fix build failure

- - - - -


18 changed files:

- .classpath
- .github/workflows/build-tests.yml
- .github/workflows/ds-tests.yml
- .github/workflows/pki-tests.yml
- .github/workflows/publish.yml
- Dockerfile
- build.sh
- java-sdk/ldapbeans/pom.xml
- java-sdk/ldapfilter/pom.xml
- java-sdk/ldapjdk/pom.xml
- java-sdk/ldapjdk/src/main/java/netscape/ldap/LDAPSearchResults.java
- java-sdk/ldapjdk/src/main/java/netscape/ldap/factory/JSSSocketFactory.java
- java-sdk/ldapsp/pom.xml
- java-sdk/ldaptools/pom.xml
- java-sdk/pom.xml
- ldapjdk.spec
- pom.xml
- tests/bin/tools-test.sh


Changes:

=====================================
.classpath
=====================================
@@ -11,7 +11,7 @@
 	<classpathentry kind="src" path="java-sdk/ldapjdk/src/main/java"/>
 	<classpathentry kind="src" path="java-sdk/ldapsp/src/main/java"/>
 	<classpathentry kind="src" path="java-sdk/ldaptools/src/main/java"/>
-	<classpathentry kind="lib" path="/usr/lib/java/jss.jar"/>
-	<classpathentry kind="lib" path="/usr/share/java/slf4j/slf4j-api.jar"/>
+	<classpathentry kind="var" path="M2_REPO/org/dogtagpki/jss/jss-base/5.6.0-SNAPSHOT/jss-base-5.6.0-SNAPSHOT.jar"/>
+	<classpathentry kind="var" path="M2_REPO/org/slf4j/slf4j-api/1.7.32/slf4j-api-1.7.32.jar"/>
 	<classpathentry kind="output" path="build/classes"/>
 </classpath>


=====================================
.github/workflows/build-tests.yml
=====================================
@@ -25,8 +25,122 @@ jobs:
           wait-interval: 30
         if: github.event_name == 'pull_request'
 
-  build-test:
-    name: Build Test
+  maven-test:
+    name: Maven Test
+    runs-on: ubuntu-latest
+    steps:
+    - name: Clone repository
+      uses: actions/checkout at v4
+
+    - name: Set up Java
+      uses: actions/setup-java at v4
+      with:
+        java-version: '17'
+        distribution: 'adopt'
+
+    - name: Install dependencies
+      run: |
+        sudo apt-get update
+        sudo apt-get install -y maven ant
+
+        # get dependencies from Maven
+        mvn --batch-mode dependency:copy-dependencies
+
+    - name: Build with Maven
+      run: mvn --batch-mode package
+
+    - name: Build with Ant
+      run: |
+        SLF4J_LIB=$(find . -name "slf4j-api-*.jar" -print -quit)
+        echo "SLF4J_LIB: $SLF4J_LIB"
+
+        JSS_LIB=$(find . -name "jss-base-*.jar" -print -quit)
+        echo "JSS_LIB: $JSS_LIB"
+
+        ./build.sh \
+            --slf4j-lib=$SLF4J_LIB \
+            --jss-lib=$JSS_LIB \
+            dist
+
+    - name: Compare ldapjdk.jar
+      run: |
+        jar tvf java-sdk/ldapjdk/target/ldapjdk.jar \
+            | awk '{print $8;}' \
+            | sort \
+            | grep -v '/$' \
+            | grep -v '^META-INF/maven/' \
+            | tee maven.out
+        jar tvf ~/build/ldapjdk/packages/ldapjdk.jar \
+            | awk '{print $8;}' \
+            | sort \
+            | grep -v '/$' \
+            | tee ant.out
+        diff maven.out ant.out
+
+    - name: Compare ldapbeans.jar
+      run: |
+        jar tvf java-sdk/ldapbeans/target/ldapbeans.jar \
+            | awk '{print $8;}' \
+            | sort \
+            | grep -v '/$' \
+            | grep -v '^META-INF/maven/' \
+            | tee maven.out
+        jar tvf ~/build/ldapjdk/packages/ldapbeans.jar \
+            | awk '{print $8;}' \
+            | sort \
+            | grep -v '/$' \
+            | tee ant.out
+        diff maven.out ant.out
+
+    - name: Compare ldapfilter.jar
+      run: |
+        jar tvf java-sdk/ldapfilter/target/ldapfilter.jar \
+            | awk '{print $8;}' \
+            | sort \
+            | grep -v '/$' \
+            | grep -v '^META-INF/maven/' \
+            | tee maven.out
+        jar tvf ~/build/ldapjdk/packages/ldapfilt.jar \
+            | awk '{print $8;}' \
+            | sort \
+            | grep -v '/$' \
+            | tee ant.out
+        diff maven.out ant.out
+
+    - name: Compare ldapsp.jar
+      run: |
+        jar tvf java-sdk/ldapsp/target/ldapsp.jar \
+            | awk '{print $8;}' \
+            | sort \
+            | grep -v '/$' \
+            | grep -v '^META-INF/maven/' \
+            | tee maven.out
+        jar tvf ~/build/ldapjdk/packages/ldapsp.jar \
+            | awk '{print $8;}' \
+            | sort \
+            | grep -v '/$' \
+            | tee ant.out
+        diff maven.out ant.out
+
+    - name: Compare ldaptools.jar
+      run: |
+        jar tvf java-sdk/ldaptools/target/ldaptools.jar \
+            | awk '{print $8;}' \
+            | sort \
+            | grep -v '/$' \
+            | grep -v '^META-INF/maven/' \
+            | tee maven.out
+        jar tvf ~/build/ldapjdk/packages/ldaptools.jar \
+            | awk '{print $8;}' \
+            | sort \
+            | grep -v '/$' \
+            | tee ant.out
+        diff maven.out ant.out
+
+    # TODO: Run examples
+
+  rpm-test:
+    name: RPM Test
     needs: wait-for-build
     runs-on: ubuntu-latest
     env:
@@ -51,100 +165,83 @@ jobs:
         IMAGE: ldapjdk-builder
         HOSTNAME: ldapjdk.example.com
 
-    - name: Build with Ant
+    - name: Install RPMs
       run: |
-        docker exec ldapjdk ./build.sh
-
-    - name: Install JSS into local Maven repo
-      run: |
-        # get JSS <major>.<minor>.<update> version
-        JSS_VERSION=$(docker exec ldapjdk rpm -q --qf "%{version}" dogtag-jss)
-
-        docker exec ldapjdk mvn install:install-file \
-            -Dfile=/usr/lib/java/jss.jar \
-            -DgroupId=org.dogtagpki.jss \
-            -DartifactId=jss-base \
-            -Dversion=$JSS_VERSION-SNAPSHOT \
-            -Dpackaging=jar \
-            -DgeneratePom=true
+        docker exec ldapjdk bash -c "dnf install -y build/RPMS/*.rpm"
 
     - name: Build with Maven
       run: |
-        docker exec ldapjdk mvn package
+        docker exec ldapjdk mvn --batch-mode package
 
     - name: Compare ldapjdk.jar
       run: |
         docker exec ldapjdk \
-            jar tvf /root/build/ldapjdk/packages/ldapjdk.jar \
+            jar tvf /usr/share/java/ldapjdk/ldapjdk.jar \
             | awk '{print $8;}' \
             | sort \
-            | tee ldapjdk.ant
+            | tee rpm.out
         docker exec ldapjdk \
             jar tvf java-sdk/ldapjdk/target/ldapjdk.jar \
             | awk '{print $8;}' \
-            | grep -v '^META-INF/maven/' \
             | sort \
-            | tee ldapjdk.maven
-        diff ldapjdk.ant ldapjdk.maven
+            | tee maven.out
+        diff rpm.out maven.out
 
     - name: Compare ldapbeans.jar
       run: |
         docker exec ldapjdk \
-            jar tvf /root/build/ldapjdk/packages/ldapbeans.jar \
+            jar tvf /usr/share/java/ldapjdk/ldapbeans.jar \
             | awk '{print $8;}' \
             | sort \
-            | tee ldapbeans.ant
+            | tee rpm.out
         docker exec ldapjdk \
             jar tvf java-sdk/ldapbeans/target/ldapbeans.jar \
             | awk '{print $8;}' \
-            | grep -v '^META-INF/maven/' \
             | sort \
-            | tee ldapbeans.maven
-        diff ldapbeans.ant ldapbeans.maven
+            | tee maven.out
+        diff rpm.out maven.out
 
     - name: Compare ldapfilter.jar
       run: |
         docker exec ldapjdk \
-            jar tvf /root/build/ldapjdk/packages/ldapfilt.jar \
+            jar tvf /usr/share/java/ldapjdk/ldapfilter.jar \
             | awk '{print $8;}' \
             | sort \
-            | tee ldapfilt.ant
+            | tee rpm.out
         docker exec ldapjdk \
             jar tvf java-sdk/ldapfilter/target/ldapfilter.jar \
             | awk '{print $8;}' \
-            | grep -v '^META-INF/maven/' \
             | sort \
-            | tee ldapfilt.maven
-        diff ldapfilt.ant ldapfilt.maven
+            | tee maven.out
+        diff rpm.out maven.out
 
     - name: Compare ldapsp.jar
       run: |
         docker exec ldapjdk \
-            jar tvf /root/build/ldapjdk/packages/ldapsp.jar \
+            jar tvf /usr/share/java/ldapjdk/ldapsp.jar \
             | awk '{print $8;}' \
             | sort \
-            | tee ldapsp.ant
+            | tee rpm.out
         docker exec ldapjdk \
             jar tvf java-sdk/ldapsp/target/ldapsp.jar \
             | awk '{print $8;}' \
-            | grep -v '^META-INF/maven/' \
             | sort \
-            | tee ldapsp.maven
-        diff ldapsp.ant ldapsp.maven
+            | tee maven.out
+        diff rpm.out maven.out
 
     - name: Compare ldaptools.jar
       run: |
-        docker exec ldapjdk jar tvf /root/build/ldapjdk/packages/ldaptools.jar \
+        docker exec ldapjdk \
+            jar tvf /usr/share/java/ldapjdk/ldaptools.jar \
             | awk '{print $8;}' \
             | sort \
-            | tee ldaptools.ant
+            | tee rpm.out
         docker exec ldapjdk \
             jar tvf java-sdk/ldaptools/target/ldaptools.jar \
             | awk '{print $8;}' \
-            | grep -v '^META-INF/maven/' \
             | sort \
-            | tee ldaptools.maven
-        diff ldaptools.ant ldaptools.maven
+            | tee maven.out
+        diff rpm.out maven.out
 
     - name: Install RPMInspect
       run: |


=====================================
.github/workflows/ds-tests.yml
=====================================
@@ -2,6 +2,9 @@ name: DS Tests
 
 on: [push, pull_request]
 
+env:
+  NAMESPACE: ${{ vars.REGISTRY_NAMESPACE || 'dogtagpki' }}
+
 jobs:
   build:
     name: Waiting for build
@@ -100,8 +103,17 @@ jobs:
         env:
           HOSTNAME: server.example.com
 
-      - name: Install DS package
-        run: docker exec server dnf install -y 389-ds-base dogtag-pki
+      - name: Import PKI packages
+        run: |
+          docker create --name=pki-dist quay.io/$NAMESPACE/pki-dist:latest
+          docker cp pki-dist:/root/RPMS/. /tmp/RPMS/
+          docker rm -f pki-dist
+
+      - name: Install packages
+        run: |
+          docker exec server dnf install -y 389-ds-base
+          docker cp /tmp/RPMS/. server:/root/RPMS/
+          docker exec server bash -c "dnf install -y /root/RPMS/*"
 
       - name: Create DS instance
         run: docker exec server ${SHARED}/tests/bin/ds-create.sh


=====================================
.github/workflows/pki-tests.yml
=====================================
@@ -2,6 +2,9 @@ name: PKI Tests
 
 on: [push, pull_request]
 
+env:
+  NAMESPACE: ${{ vars.REGISTRY_NAMESPACE || 'dogtagpki' }}
+
 jobs:
   build:
     name: Waiting for build
@@ -50,8 +53,17 @@ jobs:
         env:
           HOSTNAME: pki.example.com
 
-      - name: Install DS and PKI packages
-        run: docker exec pki dnf install -y 389-ds-base pki-ca
+      - name: Import PKI packages
+        run: |
+          docker create --name=pki-dist quay.io/$NAMESPACE/pki-dist:latest
+          docker cp pki-dist:/root/RPMS/. /tmp/RPMS/
+          docker rm -f pki-dist
+
+      - name: Install packages
+        run: |
+          docker exec pki dnf install -y 389-ds-base
+          docker cp /tmp/RPMS/. pki:/root/RPMS/
+          docker exec pki bash -c "dnf install -y /root/RPMS/*"
 
       - name: Install DS
         run: docker exec pki ${SHARED}/tests/bin/ds-create.sh
@@ -65,10 +77,16 @@ jobs:
       - name: Verify CA admin
         run: |
           docker exec pki pki-server cert-export ca_signing --cert-file ca_signing.crt
-          docker exec pki pki client-cert-import ca_signing --ca-cert ca_signing.crt
-          docker exec pki pki client-cert-import \
+
+          docker exec pki pki nss-cert-import \
+              --cert ca_signing.crt \
+              --trust CT,C,C \
+              ca_signing
+
+          docker exec pki pki pkcs12-import \
               --pkcs12 /root/.dogtag/pki-tomcat/ca_admin_cert.p12 \
               --pkcs12-password Secret.123
+
           docker exec pki pki -n caadmin ca-user-show caadmin
 
       - name: Gather artifacts


=====================================
.github/workflows/publish.yml
=====================================
@@ -14,6 +14,11 @@ jobs:
     name: Publishing Maven artifacts
     runs-on: ubuntu-latest
     steps:
+      - name: Install dependencies
+        run: |
+          sudo apt-get update
+          sudo apt-get -y install xmlstarlet
+
       - name: Clone repository
         uses: actions/checkout at v4
 
@@ -23,15 +28,23 @@ jobs:
           java-version: '17'
           distribution: 'adopt'
 
-      - name: Check settings.xml
+      - name: Configure settings.xml
         run: |
+          xmlstarlet edit --inplace \
+              -u "/_:settings/_:servers/_:server[_:id='github']/_:password" \
+              -v "$REPO_TOKEN" \
+              ~/.m2/settings.xml
           cat ~/.m2/settings.xml
+        env:
+          REPO_TOKEN: ${{ secrets.REPO_TOKEN }}
 
-      - name: Update pom.xml
+      - name: Configure pom.xml
         run: |
-          sed -i \
-              -e "s/OWNER/$NAMESPACE/g" \
-              -e "s/REPOSITORY/ldap-sdk/g" \
+          xmlstarlet edit --inplace \
+              -u "/_:project/_:build/_:plugins/_:plugin[_:artifactId='site-maven-plugin']/_:configuration/_:repositoryOwner" \
+              -v "$NAMESPACE" \
+              -u "/_:project/_:repositories/_:repository[_:id='dogtagpki']/_:url" \
+              -v "https://raw.githubusercontent.com/$NAMESPACE/repo/maven" \
               pom.xml
           cat pom.xml
 
@@ -41,8 +54,6 @@ jobs:
               --batch-mode \
               --update-snapshots \
               deploy
-        env:
-          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
 
   wait-for-images:
     if: vars.REGISTRY != ''


=====================================
Dockerfile
=====================================
@@ -26,7 +26,7 @@ RUN if [ -n "$COPR_REPO" ]; then dnf copr enable -y $COPR_REPO; fi
 
 # Install LDAP SDK runtime dependencies
 RUN dnf install -y dogtag-ldapjdk \
-    && dnf remove -y dogtag-* --noautoremove \
+    && rpm -e --nodeps $(rpm -qa | grep -E "^java-|^dogtag-") \
     && dnf clean all \
     && rm -rf /var/cache/dnf
 
@@ -50,7 +50,7 @@ FROM ldapjdk-builder-deps AS ldapjdk-builder
 COPY --from=quay.io/dogtagpki/jss-dist:latest /root/RPMS /tmp/RPMS/
 
 # Install build dependencies
-RUN dnf localinstall -y /tmp/RPMS/* \
+RUN dnf install -y /tmp/RPMS/* \
     && dnf clean all \
     && rm -rf /var/cache/dnf \
     && rm -rf /tmp/RPMS
@@ -78,7 +78,7 @@ COPY --from=quay.io/dogtagpki/jss-dist:latest /root/RPMS /tmp/RPMS/
 COPY --from=ldapjdk-dist /root/RPMS /tmp/RPMS/
 
 # Install runtime packages
-RUN dnf localinstall -y /tmp/RPMS/* \
+RUN dnf install -y /tmp/RPMS/* \
     && dnf clean all \
     && rm -rf /var/cache/dnf \
     && rm -rf /tmp/RPMS


=====================================
build.sh
=====================================
@@ -15,6 +15,10 @@ WORK_DIR=
 JAVA_LIB_DIR="/usr/share/java"
 JAVADOC_DIR="/usr/share/javadoc"
 MAVEN_POM_DIR="/usr/share/maven-poms"
+
+SLF4J_LIB=
+JSS_LIB=
+
 INSTALL_DIR=
 
 SOURCE_TAG=
@@ -40,6 +44,8 @@ usage() {
     echo "    --java-lib-dir=<path>  Java library directory (default: $JAVA_LIB_DIR)."
     echo "    --javadoc-dir=<path>   Javadoc directory (default: $JAVADOC_DIR)."
     echo "    --maven-pom-dir=<path> Maven POM directory (default: $MAVEN_POM_DIR)."
+    echo "    --slf4j-lib=<path>     Path to SLF4J library"
+    echo "    --jss-lib=<path>       Path to JSS library"
     echo "    --install-dir=<path>   Installation directory."
     echo "    --source-tag=<tag>     Generate RPM sources from a source tag."
     echo "    --spec=<file>          Use the specified RPM spec (default: $SPEC_TEMPLATE)."
@@ -187,6 +193,12 @@ while getopts v-: arg ; do
         maven-pom-dir=?*)
             MAVEN_POM_DIR="$(readlink -f "$LONG_OPTARG")"
             ;;
+        slf4j-lib=?*)
+            SLF4J_LIB="$(readlink -f "$LONG_OPTARG")"
+            ;;
+        jss-lib=?*)
+            JSS_LIB="$(readlink -f "$LONG_OPTARG")"
+            ;;
         install-dir=?*)
             INSTALL_DIR="$(readlink -f "$LONG_OPTARG")"
             ;;
@@ -225,7 +237,8 @@ while getopts v-: arg ; do
         '')
             break # "--" terminates argument processing
             ;;
-        name* | work-dir* | java-lib-dir* | javadoc-dir* | maven-pom-dir* | install-dir* | source-tag* | spec* | version* | release* | dist*)
+        name* | work-dir* | java-lib-dir* | javadoc-dir* | maven-pom-dir* | slf4j-lib* | jss-lib | \
+        install-dir* | source-tag* | spec* | version* | release* | dist*)
             echo "ERROR: Missing argument for --$OPTARG option" >&2
             exit 1
             ;;
@@ -260,6 +273,8 @@ if [ "$DEBUG" = true ] ; then
     echo "JAVA_LIB_DIR: $JAVA_LIB_DIR"
     echo "JAVADOC_DIR: $JAVADOC_DIR"
     echo "MAVEN_POM_DIR: $MAVEN_POM_DIR"
+    echo "SLF4J_LIB: $SLF4J_LIB"
+    echo "JSS_LIB: $JSS_LIB"
     echo "INSTALL_DIR: $INSTALL_DIR"
     echo "BUILD_TARGET: $BUILD_TARGET"
 fi
@@ -296,7 +311,21 @@ if [ "$BUILD_TARGET" = "dist" ] ; then
     fi
 
     pushd $SRC_DIR/java-sdk
-    ant -Ddist=$WORK_DIR dist
+
+    OPTIONS=()
+
+    OPTIONS+=(-Ddist="$WORK_DIR")
+
+    if [ "$SLF4J_LIB" != "" ] ; then
+        OPTIONS+=(-Dslf4j.lib="$SLF4J_LIB")
+    fi
+
+    if [ "$JSS_LIB" != "" ] ; then
+        OPTIONS+=(-Djss.lib="$JSS_LIB")
+    fi
+
+    ant "${OPTIONS[@]}" dist
+
     popd
 
     echo


=====================================
java-sdk/ldapbeans/pom.xml
=====================================
@@ -8,7 +8,7 @@
     <parent>
         <groupId>org.dogtagpki.ldap-sdk</groupId>
         <artifactId>java-sdk-parent</artifactId>
-        <version>5.5.0-SNAPSHOT</version>
+        <version>5.6.0-SNAPSHOT</version>
     </parent>
 
     <artifactId>ldapbeans</artifactId>
@@ -31,7 +31,7 @@
         <dependency>
             <groupId>org.dogtagpki.jss</groupId>
             <artifactId>jss-base</artifactId>
-            <version>5.5.0-SNAPSHOT</version>
+            <version>[5.6.0-SNAPSHOT,)</version>
         </dependency>
 
         <dependency>


=====================================
java-sdk/ldapfilter/pom.xml
=====================================
@@ -8,7 +8,7 @@
     <parent>
         <groupId>org.dogtagpki.ldap-sdk</groupId>
         <artifactId>java-sdk-parent</artifactId>
-        <version>5.5.0-SNAPSHOT</version>
+        <version>5.6.0-SNAPSHOT</version>
     </parent>
 
     <artifactId>ldapfilter</artifactId>


=====================================
java-sdk/ldapjdk/pom.xml
=====================================
@@ -8,7 +8,7 @@
     <parent>
         <groupId>org.dogtagpki.ldap-sdk</groupId>
         <artifactId>java-sdk-parent</artifactId>
-        <version>5.5.0-SNAPSHOT</version>
+        <version>5.6.0-SNAPSHOT</version>
     </parent>
 
     <artifactId>ldapjdk</artifactId>
@@ -31,7 +31,7 @@
         <dependency>
             <groupId>org.dogtagpki.jss</groupId>
             <artifactId>jss-base</artifactId>
-            <version>5.5.0-SNAPSHOT</version>
+            <version>[5.6.0-SNAPSHOT,)</version>
         </dependency>
 
     </dependencies>


=====================================
java-sdk/ldapjdk/src/main/java/netscape/ldap/LDAPSearchResults.java
=====================================
@@ -37,7 +37,7 @@
  * ***** END LICENSE BLOCK ***** */
 package netscape.ldap;
 
-import java.util.Enumeration;
+import java.io.Serializable;
 import java.util.Vector;
 
 /**
@@ -55,7 +55,7 @@ import java.util.Vector;
  * @see netscape.ldap.LDAPConnection#search(java.lang.String, int, java.lang.String, java.lang.String[], boolean)
  * @see netscape.ldap.LDAPConnection#abandon(netscape.ldap.LDAPSearchResults)
  */
-public class LDAPSearchResults implements Enumeration<Object>, java.io.Serializable {
+public class LDAPSearchResults implements Serializable {
 
     static final long serialVersionUID = -501692208613904825L;
     private Vector<Object> entries = null;


=====================================
java-sdk/ldapjdk/src/main/java/netscape/ldap/factory/JSSSocketFactory.java
=====================================
@@ -41,11 +41,16 @@ import java.io.Serializable;
 import java.net.Socket;
 import java.net.UnknownHostException;
 
+import javax.net.ssl.KeyManager;
+import javax.net.ssl.KeyManagerFactory;
+import javax.net.ssl.SSLContext;
+import javax.net.ssl.SSLSocketFactory;
+import javax.net.ssl.TrustManager;
+import javax.net.ssl.TrustManagerFactory;
+
 import org.mozilla.jss.CryptoManager;
 import org.mozilla.jss.crypto.AlreadyInitializedException;
-import org.mozilla.jss.crypto.X509Certificate;
-import org.mozilla.jss.ssl.SSLCertificateApprovalCallback;
-import org.mozilla.jss.ssl.SSLSocket;
+import org.mozilla.jss.ssl.javax.JSSSocket;
 
 import netscape.ldap.LDAPConnection;
 import netscape.ldap.LDAPException;
@@ -67,10 +72,7 @@ import netscape.ldap.LDAPTLSSocketFactory;
  * @see LDAPConnection#LDAPConnection(netscape.ldap.LDAPSocketFactory)
  */
 
-public class JSSSocketFactory implements Serializable,
-                                         LDAPTLSSocketFactory,
-                                         SSLCertificateApprovalCallback
-{
+public class JSSSocketFactory implements Serializable, LDAPTLSSocketFactory {
 
     static final long serialVersionUID = -6926469178017736903L;
 
@@ -138,17 +140,20 @@ public class JSSSocketFactory implements Serializable,
      * @exception LDAPException on error creating socket
      */
     public Socket makeSocket( String host, int port ) throws LDAPException {
-        SSLSocket socket = null;
+        JSSSocket socket = null;
         try {
+            KeyManagerFactory kmf = KeyManagerFactory.getInstance("NssX509", "Mozilla-JSS");
+            KeyManager[] kms = kmf.getKeyManagers();
+
+            TrustManagerFactory tmf = TrustManagerFactory.getInstance("NssX509", "Mozilla-JSS");
+            TrustManager[] tms = tmf.getTrustManagers();
 
-            socket = new SSLSocket( host, // address
-                                    port, // port
-                                    null, // localAddress
-                                    0,    // localPort
-                                    this, // certApprovalCallback
-                                    null  // clientCertSelectionCallback
-            );
+            SSLContext ctx = SSLContext.getInstance("TLS", "Mozilla-JSS");
+            ctx.init(kms, tms, null);
 
+            SSLSocketFactory socketFactory = ctx.getSocketFactory();
+
+            socket = (JSSSocket) socketFactory.createSocket(host, port);
             socket.forceHandshake();
 
         }
@@ -166,24 +171,6 @@ public class JSSSocketFactory implements Serializable,
         return socket;
     }
 
-    /**
-     * The default implementation of the SSLCertificateApprovalCallback
-     * interface.
-     * <P>
-     * This default implementation always returns true. If you need to
-     * verify the server certificate validity, then you should override
-     * this method.
-     * <P>
-     * @param serverCert X509 Certificate
-     * @param status The validity of the server certificate
-     * @return <CODE>true</CODE>, by default we trust the certificate
-     */
-    public boolean approve(X509Certificate serverCert,
-                           ValidityStatus status) {
-
-        return true;
-    }
-
     /**
      * Creates an SSL socket layered over an existing socket.
      *
@@ -195,16 +182,22 @@ public class JSSSocketFactory implements Serializable,
      * @since LDAPJDK 4.17
      */
     public Socket makeSocket(Socket s) throws LDAPException {
-        SSLSocket socket = null;
+        JSSSocket socket = null;
         String host = s.getInetAddress().getHostName();
         int port = s.getPort();
         try {
-            socket = new SSLSocket( s,
-                                    host,
-                                    this, // certApprovalCallback
-                                    null  // clientCertSelectionCallback
-            );
+            KeyManagerFactory kmf = KeyManagerFactory.getInstance("NssX509", "Mozilla-JSS");
+            KeyManager[] kms = kmf.getKeyManagers();
+
+            TrustManagerFactory tmf = TrustManagerFactory.getInstance("NssX509", "Mozilla-JSS");
+            TrustManager[] tms = tmf.getTrustManagers();
+
+            SSLContext ctx = SSLContext.getInstance("TLS", "Mozilla-JSS");
+            ctx.init(kms, tms, null);
+
+            SSLSocketFactory socketFactory = ctx.getSocketFactory();
 
+            socket = (JSSSocket) socketFactory.createSocket(host, port);
             socket.forceHandshake();
 
         } catch (Exception e) {


=====================================
java-sdk/ldapsp/pom.xml
=====================================
@@ -8,7 +8,7 @@
     <parent>
         <groupId>org.dogtagpki.ldap-sdk</groupId>
         <artifactId>java-sdk-parent</artifactId>
-        <version>5.5.0-SNAPSHOT</version>
+        <version>5.6.0-SNAPSHOT</version>
     </parent>
 
     <artifactId>ldapsp</artifactId>


=====================================
java-sdk/ldaptools/pom.xml
=====================================
@@ -8,7 +8,7 @@
     <parent>
         <groupId>org.dogtagpki.ldap-sdk</groupId>
         <artifactId>java-sdk-parent</artifactId>
-        <version>5.5.0-SNAPSHOT</version>
+        <version>5.6.0-SNAPSHOT</version>
     </parent>
 
     <artifactId>ldaptools</artifactId>
@@ -31,7 +31,7 @@
         <dependency>
             <groupId>org.dogtagpki.jss</groupId>
             <artifactId>jss-base</artifactId>
-            <version>5.5.0-SNAPSHOT</version>
+            <version>[5.6.0-SNAPSHOT,)</version>
         </dependency>
 
         <dependency>


=====================================
java-sdk/pom.xml
=====================================
@@ -8,7 +8,7 @@
     <parent>
         <groupId>org.dogtagpki.ldap-sdk</groupId>
         <artifactId>ldap-sdk-parent</artifactId>
-        <version>5.5.0-SNAPSHOT</version>
+        <version>5.6.0-SNAPSHOT</version>
     </parent>
 
     <artifactId>java-sdk-parent</artifactId>


=====================================
ldapjdk.spec
=====================================
@@ -2,11 +2,12 @@
 Name:             ldapjdk
 ################################################################################
 
-%global           product_id dogtag-ldapjdk
+%global           vendor_id dogtag
+%global           product_id %{vendor_id}-ldapjdk
 
 # Upstream version number:
 %global           major_version 5
-%global           minor_version 5
+%global           minor_version 6
 %global           update_version 0
 
 # Downstream release number:
@@ -25,7 +26,7 @@ Name:             ldapjdk
 
 Summary:          LDAP SDK
 URL:              https://github.com/dogtagpki/ldap-sdk
-License:          MPL-1.1 or GPL-2.0-or-later or LGPL-2.1-or-later
+License:          MPL-1.1 OR GPL-2.0-or-later OR LGPL-2.1-or-later
 Version:          %{major_version}.%{minor_version}.%{update_version}
 Release:          %{release_number}%{?phase:.}%{?phase}%{?timestamp:.}%{?timestamp}%{?commit_id:.}%{?commit_id}%{?dist}
 
@@ -53,10 +54,22 @@ ExclusiveArch:    %{java_arches} noarch
 # Java
 ################################################################################
 
+%if 0%{?fedora} && 0%{?fedora} <= 39 || 0%{?rhel} && 0%{?rhel} <= 9
+
+# use Java 17 on Fedora 39 or older and RHEL 9 or older
 %define java_devel java-17-openjdk-devel
 %define java_headless java-17-openjdk-headless
 %define java_home %{_jvmdir}/jre-17-openjdk
 
+%else
+
+# otherwise, use Java 21
+%define java_devel java-21-openjdk-devel
+%define java_headless java-21-openjdk-headless
+%define java_home %{_jvmdir}/jre-21-openjdk
+
+%endif
+
 ################################################################################
 # Build Dependencies
 ################################################################################
@@ -66,7 +79,7 @@ BuildRequires:    %{java_devel}
 BuildRequires:    maven-local
 BuildRequires:    mvn(org.slf4j:slf4j-api)
 BuildRequires:    mvn(org.slf4j:slf4j-jdk14)
-BuildRequires:    mvn(org.dogtagpki.jss:jss-base) >= 5.5.0
+BuildRequires:    mvn(org.dogtagpki.jss:jss-base) >= 5.6.0
 
 %description
 The Mozilla LDAP SDKs enable you to write applications which access,
@@ -81,7 +94,7 @@ Summary:          LDAP SDK
 Requires:         %{java_headless}
 Requires:         mvn(org.slf4j:slf4j-api)
 Requires:         mvn(org.slf4j:slf4j-jdk14)
-Requires:         mvn(org.dogtagpki.jss:jss-base) >= 5.5.0
+Requires:         mvn(org.dogtagpki.jss:jss-base) >= 5.6.0
 
 Obsoletes:        ldapjdk < %{version}-%{release}
 Provides:         ldapjdk = %{version}-%{release}


=====================================
pom.xml
=====================================
@@ -6,11 +6,12 @@
     <modelVersion>4.0.0</modelVersion>
     <groupId>org.dogtagpki.ldap-sdk</groupId>
     <artifactId>ldap-sdk-parent</artifactId>
-    <version>5.5.0-SNAPSHOT</version>
+    <version>5.6.0-SNAPSHOT</version>
     <packaging>pom</packaging>
 
     <properties>
         <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
+        <github.global.server>github</github.global.server>
     </properties>
 
     <modules>
@@ -18,56 +19,81 @@
     </modules>
 
     <build>
-      <plugins>
-        <plugin>
-          <groupId>org.codehaus.mojo</groupId>
-          <artifactId>flatten-maven-plugin</artifactId>
-          <version>1.1.0</version>
-          <configuration>
-            <updatePomFile>true</updatePomFile>
-            <flattenMode>resolveCiFriendliesOnly</flattenMode>
-          </configuration>
-          <executions>
-            <execution>
-              <id>flatten</id>
-              <phase>process-resources</phase>
-              <goals>
-                <goal>flatten</goal>
-              </goals>
-            </execution>
-            <execution>
-              <id>flatten.clean</id>
-              <phase>clean</phase>
-              <goals>
-                <goal>clean</goal>
-              </goals>
-            </execution>
-          </executions>
-        </plugin>
-        <plugin>
-          <groupId>org.apache.maven.plugins</groupId>
-          <artifactId>maven-surefire-plugin</artifactId>
-          <version>3.1.2</version>
-        </plugin>
-      </plugins>
+        <plugins>
+            <plugin>
+                <groupId>org.codehaus.mojo</groupId>
+                <artifactId>flatten-maven-plugin</artifactId>
+                <version>1.1.0</version>
+                <configuration>
+                    <updatePomFile>true</updatePomFile>
+                    <flattenMode>resolveCiFriendliesOnly</flattenMode>
+                </configuration>
+                <executions>
+                    <execution>
+                        <id>flatten</id>
+                        <phase>process-resources</phase>
+                        <goals>
+                            <goal>flatten</goal>
+                        </goals>
+                    </execution>
+                    <execution>
+                        <id>flatten.clean</id>
+                        <phase>clean</phase>
+                        <goals>
+                            <goal>clean</goal>
+                        </goals>
+                    </execution>
+                </executions>
+            </plugin>
+            <plugin>
+                <groupId>org.apache.maven.plugins</groupId>
+                <artifactId>maven-surefire-plugin</artifactId>
+                <version>3.1.2</version>
+            </plugin>
+            <plugin>
+                <groupId>org.apache.maven.plugins</groupId>
+                <artifactId>maven-deploy-plugin</artifactId>
+                <version>2.8.2</version>
+                <configuration>
+                    <altDeploymentRepository>local::default::file://${project.build.directory}/repo</altDeploymentRepository>
+                </configuration>
+            </plugin>
+            <plugin>
+                <groupId>com.github.github</groupId>
+                <artifactId>site-maven-plugin</artifactId>
+                <version>0.12</version>
+                <configuration>
+                    <message>Deploy ${project.groupId}:${project.artifactId}:${project.version}</message>
+                    <outputDirectory>${project.build.directory}/repo</outputDirectory>
+                    <includes>
+                        <include>**/*</include>
+                    </includes>
+                    <repositoryOwner>dogtagpki</repositoryOwner>
+                    <repositoryName>repo</repositoryName>
+                    <branch>refs/heads/maven</branch>
+                    <merge>true</merge>
+                </configuration>
+                <executions>
+                    <execution>
+                        <goals>
+                            <goal>site</goal>
+                        </goals>
+                        <phase>deploy</phase>
+                    </execution>
+                </executions>
+            </plugin>
+        </plugins>
     </build>
 
     <repositories>
         <repository>
-            <id>github</id>
-            <url>https://maven.pkg.github.com/OWNER/*</url>
+            <id>dogtagpki</id>
+            <url>https://raw.githubusercontent.com/dogtagpki/repo/maven</url>
             <snapshots>
                 <enabled>true</enabled>
+                <updatePolicy>always</updatePolicy>
             </snapshots>
         </repository>
     </repositories>
 
-    <distributionManagement>
-        <repository>
-            <id>github</id>
-            <name>GitHub Packages</name>
-            <url>https://maven.pkg.github.com/OWNER/REPOSITORY</url>
-        </repository>
-    </distributionManagement>
-
 </project>


=====================================
tests/bin/tools-test.sh
=====================================
@@ -1,6 +1,5 @@
 #!/bin/bash
 
-JAVA_HOME=/usr/lib/jvm/jre-17-openjdk
 CLASSPATH=/usr/share/java/ldapjdk.jar:/usr/share/java/ldaptools.jar:/usr/share/java/slf4j/slf4j-api.jar:/usr/share/java/slf4j/slf4j-jdk14.jar
 
 echo "Checking Root DSE"



View it on GitLab: https://salsa.debian.org/freeipa-team/ldapjdk/-/compare/35a0d2c5ab7f55476aa9e87af90cf90408dcfc0e...41e117f08d38c69b3ea3ea5f4782b60a43c41b10

-- 
View it on GitLab: https://salsa.debian.org/freeipa-team/ldapjdk/-/compare/35a0d2c5ab7f55476aa9e87af90cf90408dcfc0e...41e117f08d38c69b3ea3ea5f4782b60a43c41b10
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/pkg-freeipa-devel/attachments/20260927/a8f9c9df/attachment-0001.htm>


More information about the Pkg-freeipa-devel mailing list