[Pkg-freeipa-devel] [Git][freeipa-team/dogtag-pki][upstream] 2742 commits: Update CA test with existing DS
Timo Aaltonen (@tjaalton)
gitlab at salsa.debian.org
Sun Sep 27 08:39:24 BST 2026
Timo Aaltonen pushed to branch upstream at FreeIPA packaging / dogtag-pki
Commits:
71a38380 by Endi S. Dewata at 2023-04-20T21:45:33-05:00
Update CA test with existing DS
The test for installing CA with existing DS has been modified
to match the DS setup process in the regular CA installation.
- - - - -
1672ee86 by Endi S. Dewata at 2023-04-20T21:45:39-05:00
Clean up AAclAuthz
The methods in AAclAuthz has been updated to throw EACLsException.
- - - - -
3b009c07 by Chris Kelley at 2023-04-21T14:38:19+01:00
Fix pylint failures in upstream CI.
The new version of pylint (pylint-2.17.2-1.fc38) in F38 causes failures
due to containing a configuration setting that will become invalid in
pylint 3. The pylintrc file is future-proofed to work with pylint 3.
overgeneral-exceptions now causes test failure rather than a warning, it
has been disabled for now as there are many failures and it could take
some time to go through them all individually and catch less general
exceptions.
- - - - -
0f209a91 by Endi S. Dewata at 2023-04-21T11:37:55-05:00
Use lazy loading in DirAclAuthz
Previously the DirAclAuthz would load the ACLs from LDAP into
memory (i.e. AAclAuthz.mACLs) when the server is started. To
speed up the startup time, the DirAclAuthz has been modified
to load the ACLs only when they are actually used.
- - - - -
dc2d6095 by Chris Kelley at 2023-04-21T18:50:08+01:00
Use try-with-resources in client and logging classes
- - - - -
97e9c161 by Endi S. Dewata at 2023-04-21T18:24:32-05:00
Add --verbose/debug options for pki-server ca-config commands
- - - - -
1f094465 by Endi S. Dewata at 2023-04-21T18:24:50-05:00
Update Maven JAR file names
- - - - -
b7a4a0bf by Endi S. Dewata at 2023-04-21T18:24:50-05:00
Update version number to 11.5.0-alpha1
- - - - -
48664c86 by Endi S. Dewata at 2023-04-24T09:34:06-05:00
Add pki_ds_url param
A new pki_ds_url param has been added for pkispawn to
reduce the number of installation params.
- - - - -
194b350f by Chris Kelley at 2023-04-25T15:51:09+01:00
Use try-with-resources in more places in HttpClient
- - - - -
a6d06a11 by Endi S. Dewata at 2023-04-26T13:56:57-05:00
Fix invalid paths in pki-acme-run
- - - - -
d79c5545 by Endi S. Dewata at 2023-04-26T13:56:57-05:00
Update up log messages in ProxyRealm
- - - - -
eb24c6c9 by Endi S. Dewata at 2023-04-26T13:57:00-05:00
Update log messages in SecurityDomainProcessor
- - - - -
b5bf2d24 by Endi S. Dewata at 2023-04-26T17:33:59-05:00
Update log messages in Python clients
- - - - -
c6d70df4 by Endi S. Dewata at 2023-04-26T19:25:33-05:00
Add ServerConfig.get_service()
The ServerConfig.get_service() has been added to get the
Service element in server.xml.
- - - - -
74c18239 by Chris Kelley at 2023-04-27T09:47:22+01:00
Refactor HttpClient to not create unnecessary sockets and streams
The current implementation creates a set of null streams and sockets,
then decides part way through the send process whether to use an SSL
socket or not, creating streams from the appropriate socket accordingly.
This is incompatible with using try-with-resources as you cannot
reassign to a controlled resource. Also, it is wasteful and confusing
that the unnecessary objects exist (but understandable as the code
predates the existence of try-with-resources).
Separate SSL/non-SSL send methods are created, which only create the
necessary streams and sockets for that operation. New helper methods are
introduced to send/handle the request/response.
- - - - -
f4a4809d by Chris Kelley at 2023-04-27T14:44:41+01:00
Make use of xmvn-resolve conditional on it being installed
Drops the distro-specific code and relies only on whether xmvn is
present. The spec is updated to explicitly BuildRequires: xmvn-tools so
xmvn-resolve is there at build time for JAR resolution.
Resolves: #2188716
- - - - -
a7646975 by Chris Kelley at 2023-04-27T14:44:41+01:00
Small cleanup in AtoB.java to re-trigger the CI.
Put array designators on the type.
- - - - -
f94028e9 by Chris Kelley at 2023-04-27T14:44:41+01:00
Only BuildRequires xmvn-tools on distros that have it
- - - - -
31106fe9 by Endi S. Dewata at 2023-04-27T10:14:17-05:00
Add new servlets for CA
Some new servlets have been added to provide a separate class
for each servlet in CA's web.xml.
- - - - -
5507312a by Endi S. Dewata at 2023-04-27T14:16:16-05:00
Add CAPolicyConfig
The CAPolicyConfig has been added to encapsulate ca.Policy.*
parameters.
- - - - -
f554bc07 by Endi S. Dewata at 2023-04-27T14:25:07-05:00
Add KRAPolicyConfig
The KRAPolicyConfig has been added to encapsulate kra.Policy.*
parameters.
- - - - -
ab810db7 by Endi S. Dewata at 2023-04-27T17:07:12-05:00
Refactor UGSubsystem.removeUserCert()
The UGSubsystem.removeUserCert() has been refactored to accept
a user ID and a cert ID.
- - - - -
1af40b4c by Endi S. Dewata at 2023-04-27T18:03:01-05:00
Update log messages in UGSubsystem.buildUser()
- - - - -
e759b639 by Endi S. Dewata at 2023-04-27T18:03:01-05:00
Remove trailing spaces in pki-server <subsystem>-user-show output
- - - - -
8b0d3f6c by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update CAPortsServlet to use @WebServlet
- - - - -
9d0ff5b2 by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update ProfileListAgentServlet to use @WebServlet
- - - - -
f1e84a87 by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update ProfileListServlet to use @WebServlet
- - - - -
0c0d5696 by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update DoRevokeAgent to use @WebServlet
- - - - -
64325449 by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update MasterCAGetInfo to use @WebServlet
- - - - -
d6391723 by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update CAOCSPServlet to use @WebServlet
- - - - -
91382a7a by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update GetInfo to use @WebServlet
- - - - -
c99a9da6 by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update DoRevoke to use @WebServlet
- - - - -
a0824448 by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update CAGetCookie to use @WebServlet
- - - - -
2c85e725 by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update CATokenAuthenticate to use @WebServlet
- - - - -
8e1eb857 by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update CATokenAuthenticateAdmin to use @WebServlet
- - - - -
80dcde9d by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update ProfileSubmitProxyServlet to use @WebServlet
- - - - -
3c002226 by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update BulkIssuanceProxyServlet to use @WebServlet
- - - - -
89a69c5f by Endi S. Dewata at 2023-04-28T09:52:53-05:00
Update DoRevokeProxyServlet to use @WebServlet
- - - - -
66aa6caf by Endi S. Dewata at 2023-04-28T11:09:48-05:00
Add pki-server <subsystem>-user-cert-del
The pki-server <subsystem>-user-cert-del command has been added
to remove a cert from the user record such that the cert cannot
be used for authentication.
- - - - -
154b694b by Endi S. Dewata at 2023-04-28T11:09:48-05:00
Add test for CA admin user
A new test has been added to validate removing and restoring the
admin cert.
- - - - -
6eaaaeb0 by Endi S. Dewata at 2023-04-28T14:45:06-05:00
Move Auditor.getGroups() into CMSEngine
- - - - -
5ef226d0 by Endi S. Dewata at 2023-04-28T14:46:56-05:00
Remove unused Auditor.engine
- - - - -
34d0508a by Endi S. Dewata at 2023-04-28T14:56:35-05:00
Replace PKISocketFactory.engine with auditor
- - - - -
e132e91d by Endi S. Dewata at 2023-04-28T21:40:16-05:00
Add new servlets for CA
Some new servlets have been added to provide a separate class
for each servlet in CA's web.xml.
- - - - -
e8a3e733 by Endi S. Dewata at 2023-05-01T15:07:07-05:00
Replace BASE64_REPO secret with COPR_REPO variable
The BASE64_REPO secret has been replaced with COPR_REPO variable
since it's easier to configure.
https://github.com/dogtagpki/pki/wiki/Configuring-Test-Repository
- - - - -
1bf4b1dd by Endi S. Dewata at 2023-05-01T20:12:55-05:00
Refactor CertResource
The agent resources in CertResource have been moved into
AgentCertResource.
- - - - -
39fe85f4 by Endi S. Dewata at 2023-05-01T20:13:09-05:00
Refactor CertRequestResource
The agent resources in CertRequestResource have been moved into
AgentCertRequestResource.
- - - - -
8176b0ec by Endi S. Dewata at 2023-05-02T09:11:44-05:00
Add pki-server <subsystem>-user-role-find
The pki-server <subsystem>-user-role-find command has been added
to list the roles (which for now are identical to groups) that
the user belongs to.
- - - - -
8d00486f by Endi S. Dewata at 2023-05-02T09:11:44-05:00
Add pki-server <subsystem>-user-role-add
The pki-server <subsystem>-user-role-add command has been added
to add a role for a user.
- - - - -
1d9d4bf5 by Endi S. Dewata at 2023-05-02T09:11:44-05:00
Add pki-server <subsystem>-user-role-del
The pki-server <subsystem>-user-role-del command has been added
to remove a role from a user.
- - - - -
76cded38 by Endi S. Dewata at 2023-05-02T09:11:44-05:00
Update test for CA admin user
The test for CA admin user has been modified to validate
removing and restoring the admin role.
- - - - -
3344ed2e by Endi S. Dewata at 2023-05-02T11:08:11-05:00
Update CRSEnrollment.init() to use CAConfig
- - - - -
f6eb6647 by Endi S. Dewata at 2023-05-02T13:56:44-05:00
Update Job classes to use Job.engine
- - - - -
2cd97474 by Endi S. Dewata at 2023-05-02T17:02:28-05:00
Update ServerKeygenUserKeyDefault to use CAEngineConfig
- - - - -
d88d65d2 by Endi S. Dewata at 2023-05-03T08:43:25-05:00
Update InfoClient
The InfoClient has been updated to use JAX-RS client API instead
of the obsolete RESTEasy client API.
- - - - -
773d53b1 by Endi S. Dewata at 2023-05-03T08:43:25-05:00
Update LoginClient
The LoginClient has been updated to use JAX-RS client API instead
of the obsolete RESTEasy client API.
- - - - -
fda6e475 by Endi S. Dewata at 2023-05-03T08:43:25-05:00
Update JobClient
The JobClient has been updated to use JAX-RS client API instead
of the obsolete RESTEasy client API.
- - - - -
34cacefc by Endi S. Dewata at 2023-05-03T08:43:25-05:00
Update CASystemCertClient
The CASystemCertClient has been updated to use JAX-RS client API
instead of the obsolete RESTEasy client API.
- - - - -
844818d4 by Endi S. Dewata at 2023-05-03T08:43:25-05:00
Update KRASystemCertClient
The KRASystemCertClient has been updated to use JAX-RS client API
instead of the obsolete RESTEasy client API.
- - - - -
afd63651 by Endi S. Dewata at 2023-05-03T09:01:00-05:00
Add server-webapp module
The PKIApplication class and the services in it are supposed to
be deployed under /pki webapp only, but currently these classes
are included in pki-server.jar so they are also distributed in
all other webapps although they are not actually used there.
In Servlet 3.0 framework all application classes in the webapp
will be initialized automatically, so the current packaging
could become a problem.
To avoid the problem the files for /pki webapp need to be moved
into a new server-webapp module, and the PKIApplication with the
services in it need to be moved into pki-server-webapp.jar which
will only be deployed under /pki webapp.
- - - - -
e9f5e072 by Endi S. Dewata at 2023-05-03T13:52:10-05:00
Add EngineConfig.getUseOAEPKeyWrap()
The EngineConfig.getUseOAEPKeyWrap() has been added to read
the keyWrap.useOAEP param from CS.cfg. All code that reads this
param has been modified to use this method.
- - - - -
955856b3 by Endi S. Dewata at 2023-05-03T13:52:10-05:00
Fix OAEP config in CRSEnrollment
Previously the CRSEnrollment was trying to get the
keyWrap.useOAEP param from the authority config, but it's
actually reading a non-existent ca.keyWrap.useOAEP param.
To fix the problem the code has been modified to call the
EngineConfig.getUseOAEPKeyWrap().
- - - - -
fed16ed3 by Endi S. Dewata at 2023-05-03T21:57:57-05:00
Add RevocationCheckingConfig
The RevocationCheckingConfig has been added to encapsulate
auths.revocationChecking.* params.
- - - - -
827fb864 by Endi S. Dewata at 2023-05-04T12:12:30-05:00
Rename ServerXml to ServerConfig
- - - - -
679c07f5 by Endi S. Dewata at 2023-05-04T13:08:33-05:00
Clean up log messages in OCSPAdminServlet.getSigningAlgConfig()
- - - - -
7d6ab78f by Endi S. Dewata at 2023-05-04T17:02:28-05:00
Add PKISubsystem.get_subsystem_index()
The PKISubsystem.get_subsystem_index() has been added to get
the subsystem index in CS.cfg. The code that configures the
LDAPProfileSubsystem has been updated to use this method.
- - - - -
b87ef09a by Endi S. Dewata at 2023-05-05T12:17:09-05:00
Refactor AAclAuthz.addACLs()
The code that adds an already parsed ACL object in
AAclAuthz.addACLs() has been moved into a separate method.
- - - - -
c9f4820d by Endi S. Dewata at 2023-05-05T12:45:03-05:00
Remove duplicate algorithm in OCSPAdminServlet.getSigningAlgConfig()
Previously the OCSPAdminServlet.getSigningAlgConfig() returned
a list that contained a duplicate of the first element:
<alg1><alg1>:<alg2>:<alg3>:...
The code has been modified to remove the duplicate.
Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2193458
- - - - -
af7281ad by Endi S. Dewata at 2023-05-05T14:43:09-05:00
Add SelfTestPluginConfig
The SelfTestPluginConfig has been added to encapsulate
selftests.plugin.<plugin ID>.* params in CS.cfg.
- - - - -
778df559 by Endi S. Dewata at 2023-05-05T17:52:57-05:00
Fix NPE in CMSEngine.shutdownJobsScheduler()
- - - - -
b960017a by Endi S. Dewata at 2023-05-05T21:17:27-05:00
Replace CertUtils.toLowerCaseSubsystemType() with String.toLowerCase()
- - - - -
1cb42cbc by Endi S. Dewata at 2023-05-05T21:17:27-05:00
Move CertUtils.printRequestContent() into Request
- - - - -
d75ed488 by Endi S. Dewata at 2023-05-08T07:30:26-05:00
Move ClientCertValidateCLI.getCertificateUsage() into CertUtil
- - - - -
4aef1162 by Endi S. Dewata at 2023-05-08T07:30:26-05:00
Refactor ClientCertValidateCLI.verifySystemCertByNickname()
The code that retrieves certificate usages in
ClientCertValidateCLI.verifySystemCertByNickname() has been
moved into CertUtil.getCertificateUsages().
- - - - -
2f5c67ce by Endi S. Dewata at 2023-05-08T07:39:43-05:00
Move ClientCertValidateCLI.verifySystemCertByNickname() to CertUtil
- - - - -
b4a37a88 by Endi S. Dewata at 2023-05-08T09:33:27-05:00
Fix NPE in CMSEngine.shutdownAuthzSubsystem()
- - - - -
3c4b8d52 by Endi S. Dewata at 2023-05-08T09:34:11-05:00
Replace CertUtils.getCertificateUsage() with CertUtil.toCertificateUsage()
- - - - -
62c685d1 by Endi S. Dewata at 2023-05-08T09:35:30-05:00
Replace CertUtils.verifySystemCertByNickname() with CertUtil.verifyCertificateUsage()
- - - - -
01b8b349 by Endi S. Dewata at 2023-05-08T11:43:52-05:00
Fix Javadoc warnings
- - - - -
1aae6528 by Chris Kelley at 2023-05-09T09:48:17+01:00
Update jaxb jar location in classpath
- - - - -
e0500c58 by Endi S. Dewata at 2023-05-09T08:32:05-05:00
Move CertUtils.verifySystemCertValidityByNickname() to CertUtil
- - - - -
206bf4dd by Endi S. Dewata at 2023-05-09T13:41:45-05:00
Remove AIA extension from root CA signing cert
The bootstrap caCert.profile has been modified such that root
CA signing certs will no longer have an AIA extension. The
regular CA signing cert profiles have not been modified so
sub CA signing certs will continue to have an AIA extension.
- - - - -
9202baa8 by Endi S. Dewata at 2023-05-09T13:41:45-05:00
Update root CA and sub CA tests
Some CI tests have been updated to validate the AIA
extension removal from root CA signing certs.
The test-ca-signing-cert-ext.sh has been modified to verify
that there's no AIA extensions in root CA signing cert.
The test-subca-signing-cert-ext.sh has been modified to check
for an AIA extension in sub CA signing cert pointing to the
root CA's OCSP responder.
A new test-ms-subca-signing-cert-ext.sh has been added as a
copy of the original test-subca-signing-cert-ext.sh to check
for MS sub CA extensions.
- - - - -
357191dd by Endi S. Dewata at 2023-05-10T23:13:16-05:00
Refactor SubsystemCertValidateCLI.validate_certificate()
The code that calls pki client-cert-validate in
SubsystemCertValidateCLI.validate_certificate() has been
moved into PKISubsystem.validate_system_cert(), replacing
the code that calls pki-server subsystem-cert-validate.
- - - - -
cb98cede by Christina Fu at 2023-05-11T17:38:15+02:00
Bug2190283-AddCRLServlet-SEVERE-NOT-SUPPORTED-messages
This patch fixes the following issue:
It appears that the following parameter in ca's CS.cfg is set to true
by default:
ca.publish.rule.instance.ocsprule-ccrsa-1-rhcs10-example-com-32443.enable
which triggers the CA to attempt publishing of its CRLs directly
from CA->OCSP and causing the following SEVERE error messages:
SEVERE: CRL issuing point CN=CA Signing Certificate, nott found.
The CA->OCSP direct push of CRLs appears to not be working.
CA->ldap publishing (and ocsp pulling from ldap) is working and
should be used instead.
In addition, this patch also fixes it so that the following will no
longer appear (it has no reason to. See bug description for explanation):
[CRLIssuingPoint-MasterCRL] WARNING: LdapSimpleMap: crl issuer dn:...
org.mozilla.jss.netscape.security.x509.X509CRLImpl cannot be cast to java.security.cert.X509Certificate
fixes https://bugzilla.redhat.com/show_bug.cgi?id=2190283
- - - - -
09de883c by Marco Fargetta at 2023-05-11T17:52:56+02:00
Disable OCSP direct pushing during upgrade
The direct publishing to OCSP is not working properly and a previous
commit has change the default value for the `ca.publish.rule.instance.ocsprule-<instance-<port>.enable` attribute to false. This commit add the upgrade script to set false for the existing instances during the upgrade.
There are no problems with existing instances because the communication
with OCSP was not properly working and other mechanism were in place.
Close the issue: RHCS-4085
- - - - -
2fd33235 by Endi S. Dewata at 2023-05-11T11:48:10-05:00
Update ListRequests to use @WebServlet
- - - - -
7eaab345 by Endi S. Dewata at 2023-05-11T11:48:10-05:00
Update UpdateDirectory to use @WebServlet
- - - - -
f9a50d85 by Endi S. Dewata at 2023-05-11T11:48:10-05:00
Update SearchCert to use @WebServlet
- - - - -
ae9aefb5 by Endi S. Dewata at 2023-05-11T11:48:10-05:00
Update CADisplayBySerialAgent to use @WebServlet
- - - - -
bab868d4 by Endi S. Dewata at 2023-05-11T11:48:10-05:00
Update CADisplayBySerial to use @WebServlet
- - - - -
a45a9b18 by Endi S. Dewata at 2023-05-11T11:48:10-05:00
Update SearchRevokeCert to use @WebServlet
- - - - -
6c7cee85 by Endi S. Dewata at 2023-05-11T11:48:10-05:00
Update QueryBySerial to use @WebServlet
- - - - -
5dbbded7 by Endi S. Dewata at 2023-05-11T11:48:10-05:00
Update CADynamicVariablesAgent to use @WebServlet
- - - - -
226ea4de by Endi S. Dewata at 2023-05-11T11:48:10-05:00
Update CADynamicVariablesAdmin to use @WebServlet
- - - - -
e4089839 by Endi S. Dewata at 2023-05-11T11:48:10-05:00
Update CADynamicVariables to use @WebServlet
- - - - -
8d5fe087 by Chris Kelley at 2023-05-11T19:09:46+01:00
Remove old beaker tests
- - - - -
40323ba0 by Chris Kelley at 2023-05-11T19:09:46+01:00
Fix JUnit tests before attempting to migrate to JUnit5
Most of the failing tests were due to a SecureRandom object not
instantiating correctly due to the Mozilla-JSS security provider not
being set up for the test. Only one test actually needs the SecureRandom
so it is removed from the test base class and passed null into the
method that requires it.
One DBRegistryTest fails because it can't find a logging bundle during
the test. The log message generated only happens during the failure
condition the test is checking for, so for now catch that exception (the
test will need refactoring anyway).
- - - - -
ac4b19a8 by Endi S. Dewata at 2023-05-11T16:02:35-05:00
Add setters/getters for ProfileConfig
- - - - -
04fe036f by Chris Kelley at 2023-05-15T09:19:01+01:00
Change JUnit dependency from JUnit4 to JUnit5
We should see no difference from this change, as JUnit5 currently has
JUnit4 as a dependency so nothing should change except we pull more
dependencies.
- - - - -
fc020eee by Chris Kelley at 2023-05-15T10:02:41+01:00
Revert "Disable OCSP direct pushing during upgrade"
This reverts commit 09de883c27fde3a3c3adeda7fac08ca43281a640.
- - - - -
9f55ab68 by Chris Kelley at 2023-05-15T10:02:50+01:00
Revert "Bug2190283-AddCRLServlet-SEVERE-NOT-SUPPORTED-messages"
This reverts commit cb98cede0b1c844af8a098b4cc0718c1b8d9197b.
- - - - -
7e34517b by Endi S. Dewata at 2023-05-15T09:04:44-05:00
Replace pki-server subsystem-cert-validate with pki-server cert-validate
The pki-server subsystem-cert-validate has been deprecated and
replaced with pki-server cert-validate since the new command is
shorter and only takes one parameter so it is easier to use and
more useful, and produces simpler output as well.
Eventually all pki-server subsystem-cert-* commands will be
replaced with pki-server cert-* commands.
- - - - -
d3e84c11 by Endi S. Dewata at 2023-05-15T15:05:00-05:00
Remove redundant PrettyPrintFormat
The PrettyPrintFormat has been replaced with an identical
class in JSS.
- - - - -
7ea8d1d4 by Endi S. Dewata at 2023-05-15T15:14:39-05:00
Fix build warnings
- - - - -
b2109b96 by Endi S. Dewata at 2023-05-15T15:14:39-05:00
Fix Javadoc warnings
- - - - -
d0ce67d1 by Endi S. Dewata at 2023-05-15T15:23:47-05:00
Move CertDateCompare to pki-java
- - - - -
757aeb50 by Endi S. Dewata at 2023-05-15T16:17:47-05:00
Consolidate header/footer constants
- - - - -
e01eb1c7 by Endi S. Dewata at 2023-05-15T19:32:22-05:00
Add CryptoUtil methods
New generateRSAKeyPair() and generateECCKeyPair() methods that
accept Boolean params have been added into CryptoUtil to match
PK11KeyPairGenerator.
- - - - -
fa5be426 by Endi S. Dewata at 2023-05-15T20:11:53-05:00
Add NSSDatabase methods
New createRSAKeyPair() and createECKeyPair() methods that accept
Boolean params have been added into NSSDatabase to match
CryptoUtil.
- - - - -
4b19b420 by Endi S. Dewata at 2023-05-16T09:55:39-05:00
Add SAN option for pki nss-cert commands
The pki nss-cert-request and pki nss-cert-issue commands have
been modified to provide an option to specify a SAN extension
when generating a CSR and issuing a certificate which will make
it easier to test SAN extensions.
The NSSExtensionGenerator has been modified to support `critical`
option and specific DNS names for SAN extension.
The CI test has been updated to validate the new option.
- - - - -
5a12470e by Endi S. Dewata at 2023-05-16T16:46:09-05:00
Remove redundant CertPrettyPrint
The CertPrettyPrint has been replaced with an identical class
in JSS.
- - - - -
56614af5 by Endi S. Dewata at 2023-05-16T16:52:20-05:00
Remove redundant CrlPrettyPrint
The CrlPrettyPrint has been replaced with an identical class
in JSS.
- - - - -
90fb14ab by Endi S. Dewata at 2023-05-16T16:55:11-05:00
Remove redundant ExtPrettyPrint
The ExtPrettyPrint has been replaced with an identical class
in JSS.
- - - - -
8cd5c59c by Endi S. Dewata at 2023-05-16T17:02:52-05:00
Move ReqCertEmailResolver to pki-ca
- - - - -
e72016b9 by Endi S. Dewata at 2023-05-16T17:04:30-05:00
Move IEmailResolver to pki-ca
- - - - -
dbe05c2a by Endi S. Dewata at 2023-05-16T17:08:52-05:00
Convert IEmailResolver into EmailResolver
- - - - -
5b3dddb0 by Endi S. Dewata at 2023-05-16T17:14:11-05:00
Merge IEmailResolverKeys into EmailResolverKeys
- - - - -
e304ae97 by Endi S. Dewata at 2023-05-16T17:17:46-05:00
Merge IEmailTemplate into EmailTemplate
- - - - -
a166129d by Endi S. Dewata at 2023-05-16T17:26:03-05:00
Merge IEmailFormProcessor into EmailFormProcessor
- - - - -
16c34dff by Endi S. Dewata at 2023-05-16T18:31:14-05:00
Add new servlets for CA
Some new servlets have been added to provide a separate class
for each servlet in CA's web.xml.
- - - - -
7abfc0bd by Chris Kelley at 2023-05-17T09:44:42+01:00
Refactor com.netscape.test.TestRunner to use the JUnit 5 runner
The test launcher does automatic test discovery so we can drop the
fragile bash script that does it in cmake, which simplifies things.
This converts 103 of the 166 tests, which were the "easy" ones. The
remaining tests all extend CMSBaseTestCase which is a subclass of
JUnit's TestCase, so they will need to be reimplemented separately.
- - - - -
e88329d0 by Chris Kelley at 2023-05-17T09:44:42+01:00
Replace subclasses of TestCase with JUnit 5 style tests
- - - - -
9d222ab1 by Chris Kelley at 2023-05-17T09:44:42+01:00
Remove references to unused JUnit4 libraries
- - - - -
9ea45acb by Chris Kelley at 2023-05-17T09:44:42+01:00
Fix remaining broken tests
- - - - -
2177cabe by Endi S. Dewata at 2023-05-17T09:12:49-05:00
Add key attribute options for pki nss-key-create
The pki nss-key-create has been modified to provide temporary,
sensitive, and extractable options similar to the options in
PKCS10Client and CRMFPopClient.
The temporary option does not take any argument since a key
can only be either permanent or temporary.
The sensitive and extractable options take a boolean argument
since the value can be true, false, or unspecified (default).
RSA and EC keys support all three options, but AES keys only
support temporary and sensitive options.
- - - - -
c2003aa5 by Chris Kelley at 2023-05-17T15:30:09+01:00
Fix bug in AgentCertService.revokeCert
The current implementation always gets the CertRecord from the
RevocationProcessor instead of the provided clientRecord as the id
comparison was done between two different types, hence is always false.
The fix compares the id's as BigInteger types, and checks the
clientRecord for null first as it is dereferenced later without a null
check and is instantiated null.
- - - - -
d1aa86d1 by Endi S. Dewata at 2023-05-17T10:44:35-05:00
Update CMC servlets to use @WebServlet
- - - - -
3753ef34 by Endi S. Dewata at 2023-05-17T10:46:54-05:00
Move CertUtils.unwrapPKCS10() to CertUtil
- - - - -
5f824d5b by Endi S. Dewata at 2023-05-17T10:46:55-05:00
Move CertUtils.decodePKCS10() to CertUtil
- - - - -
839b121d by Endi S. Dewata at 2023-05-17T10:46:58-05:00
Move CertUtils.parseCRMF() into CertUtil
- - - - -
47196d7b by Chris Kelley at 2023-05-17T19:00:29+01:00
Extract the waiting for build step into a new workflow
This simplifies the top-level test files slightly. Also, I added a check
to pull the images at the end of the wait. This way, the job fails if
the build job is not finished. Currently the wait job always succeeds,
then all subsequent jobs fail as a result. We can use this fail
condition to trigger a retry.
- - - - -
36ca7a5c by Endi S. Dewata at 2023-05-17T17:50:04-05:00
Fixed constant in WBaseManualCertRequestPage
- - - - -
fe3660c4 by Endi S. Dewata at 2023-05-17T17:50:04-05:00
Replace ArgBlock.unwrap() with CertUtil.unwrapPKCS10()
- - - - -
bc6039bc by Endi S. Dewata at 2023-05-17T17:50:04-05:00
Replace ArgBlock.decodePKCS10() with CertUtil.decodePKCS10()
- - - - -
087e7f80 by Endi S. Dewata at 2023-05-17T17:50:04-05:00
Add support for query params in PKIClient
The get() and post() methods in PKIClient have been modified
to support optional query params.
- - - - -
ccb837a2 by Chris Kelley at 2023-05-22T09:36:14+01:00
Introduce a retry to wait-for-build.yml
If the waiting-for-build-job fails, run a second job. This should allow
multiple CI suites to run simultaneously again. Additional runs can be
added if needed. This is a bit of a dirty hack, but GitHub actions
doesn't allow loop control flow and there is no way to extend the
timeout of the build job.
- - - - -
1a044324 by Chris Kelley at 2023-05-22T11:31:46+01:00
Conditionally set empty subject name
The empty name is currently required for ACME, but we require it to not
be empty on some older branches.
The proposed solution is to allow a new property "defaultSubjectName",
which can be used to modify the behaviour on a per-profile basis.
- - - - -
2ca128c0 by Chris Kelley at 2023-05-22T16:12:50+01:00
Fix bug in TPSConnectorClient.getConnector()
Previously, if connectors.getTotal() < 1 then we threw
ResourceNotFoundException. Then we proceed to try access the next
element in the connectors.getEntries() iterator.
The issue here is that DataCollection offers no guarantee that the total
field is equivalent to connectors.getEntries().size(), it is left to
calling code to update the total. This causes NoSuchElementException to
be thrown on TPS startup. The connector not being present is actually
expected by the calling code, so that is fine, but it is ugly that there
is a stack trace associated with expected behaviour.
We now check connectors.getEntries().isEmpty() instead, throwing the
correct ResourceNotFoundException, which is properly handled by the
calling code.
- - - - -
dadae5aa by Endi S. Dewata at 2023-05-22T10:28:42-05:00
Update pki nss-cert-request to support empty subject
The pki nss-cert-request has been updated to no longer require
a --subject param such that it can generate a CSR without a
subject name.
- - - - -
bd2e05d8 by Endi S. Dewata at 2023-05-22T10:28:42-05:00
Update CI to validate CSR and cert without subject
- - - - -
1ed50963 by Endi S. Dewata at 2023-05-22T17:34:11-05:00
Update dependencies
- - - - -
813e2a12 by Endi S. Dewata at 2023-05-23T22:21:53-05:00
Remove redundant code in JssSubsystem
The mNicknameMapCertsTable and mNicknameMapUserCertsTable cannot
be null so the null checks for these fields have been removed.
- - - - -
43ab6ca0 by Chris Kelley at 2023-05-24T14:35:41+01:00
Code clean up in UserSubjectNameDefault
* Make logger final
* Remove unnecessary else clauses
* Remove unnecessary Boolean literal
* Invert some negation logic for readability
* Introduce CMS_INVALID_PROPERTY constant
* Rename req_sbj to match the JLS naming conventions
* Remove logging for exception that is simple re-thrown.
* Remove unnecessary null checks for logging
* Use built in formatting/specifiers for logs
- - - - -
781af82e by Endi S. Dewata at 2023-05-24T12:16:53-05:00
Update log messages in SelfTestService
- - - - -
158dc5d2 by Endi S. Dewata at 2023-05-24T12:16:53-05:00
Remove unused code in SelfTestCLI
- - - - -
03ece673 by Endi S. Dewata at 2023-05-24T14:50:30-05:00
Remove redundant Response._fCert
- - - - -
56253e63 by Endi S. Dewata at 2023-05-24T14:50:30-05:00
Refactor PKIProcessor.fillCertInfoArray()
The PKIProcessor.fillCertInfoArray() has been modified to take
a byte array instead of base64-encoded value.
- - - - -
48dd30c4 by Endi S. Dewata at 2023-05-24T14:50:30-05:00
Refactor CertUtil.parseCSR()
The CertUtil.parseCSR() has been modified to use unwrapPKCS10().
- - - - -
6d47b67f by Endi S. Dewata at 2023-05-24T14:55:36-05:00
Refactor CertUtil.parseCRMF()
The CertUtil.parseCRMF() has been modified to remove the unused
locale param.
- - - - -
5c8c2e64 by Endi S. Dewata at 2023-05-25T09:34:11-05:00
Drop legacy CSR header/footer
The code that generates a CSR has been modified to use the header
and footer described in RFC 7468.
The code that parses a CSR has been modified to use
CertUtil.parseCSR() or unwrapPKCS10() such that it can handle
both RFC 7468 and legacy headers/footers.
- - - - -
6b036fbf by Endi S. Dewata at 2023-05-25T10:55:30-05:00
Update SelfTestClient
The SelfTestClient has been updated to use JAX-RS client API
instead of the obsolete RESTEasy client API.
- - - - -
cd0cb8a4 by Endi S. Dewata at 2023-05-25T11:12:32-05:00
Update build scripts
The build scripts have been modified to include the theme files
only when building the theme package.
- - - - -
62f53deb by Endi S. Dewata at 2023-05-25T13:50:11-05:00
Fix IPA build job
The build job for IPA tests has been updated to create pki-deps
and pki-build-deps images to avoid creating an empty cache. It
also has been updated to create just the required packages for
IPA tests without re-running the unit tests.
- - - - -
564489d7 by Endi S. Dewata at 2023-05-25T17:53:11-05:00
Replace sslget examples with curl
- - - - -
872b424a by Endi S. Dewata at 2023-05-25T17:53:16-05:00
Update log messages in CRLIssuingPoint
- - - - -
a65061c2 by Endi S. Dewata at 2023-05-26T12:15:57-05:00
Consolidate PKIClient.get()/post()
The get() and post() methods in PKIClient class that return a
Response object have been replaced with the methods that take
a response type.
- - - - -
23dbdfbd by Endi S. Dewata at 2023-05-26T13:09:09-05:00
Add Client.getTargetPath()
The code that constructs the path for WebTarget has been
consolidated into Client.getTargetPath().
- - - - -
40c7158f by Endi S. Dewata at 2023-05-26T14:11:37-05:00
Add PKIClient.target()
The code that constructs a WebTarget with query params has been
consolidated into PKIClient.target().
- - - - -
d014cad0 by Endi S. Dewata at 2023-05-26T14:12:52-05:00
Add PKIClient.get() with GenericType
- - - - -
4b45eb70 by Endi S. Dewata at 2023-05-26T14:14:26-05:00
Add PKIClient.post() with Entity
- - - - -
660966c6 by Endi S. Dewata at 2023-05-26T14:15:09-05:00
Add PKIClient.put()
- - - - -
e8886f54 by Endi S. Dewata at 2023-05-26T14:15:52-05:00
Add PKIClient.patch()
- - - - -
bccc786e by Endi S. Dewata at 2023-05-26T14:16:33-05:00
Add PKIClient.delete()
- - - - -
9319ecc8 by Endi S. Dewata at 2023-05-26T16:45:37-05:00
Refactor SecurityDomainSessionTable.addEntry()
The SecurityDomainSessionTable.addEntry() has been modified
to throw an exception to help troubleshooting.
- - - - -
255f44fd by Endi S. Dewata at 2023-05-26T16:46:32-05:00
Refactor SecurityDomainSessionTable.removeEntry()
The SecurityDomainSessionTable.removeEntry() has been modified
to throw an exception to help troubleshooting.
- - - - -
b6434466 by Christina Fu at 2023-05-29T11:18:44+02:00
Bug2190283-part2_LdapSimpleMap_Invalid_cast_warning
This patch was part of the patch that was taken out earlier.
It fixes a frivilous WARNING message:
[CRLIssuingPoint-MasterCRL] WARNING: LdapSimpleMap: crl issuer dn:...
org.mozilla.jss.netscape.security.x509.X509CRLImpl cannot be cast to java.security.cert.X509Certificate
It did not attribute to the CI break so I'm putting it back.
fixes (part2) https://bugzilla.redhat.com/show_bug.cgi?id=2190283
- - - - -
62299b54 by Endi S. Dewata at 2023-05-30T14:57:17-05:00
Deprecate sslget
The sslget command is no longer used by the code so it has
been deprecated and might be removed in the future to reduce
maintenance. This command can be replaced with pki CLI or curl.
- - - - -
382e54a2 by Endi S. Dewata at 2023-05-30T18:12:04-05:00
Fix pki tps-connector-show
The pki tps-connector-show command has been modified to store
the connector data in JSON format in the output file.
- - - - -
f4f46610 by Endi S. Dewata at 2023-05-30T18:13:43-05:00
Add PKIClient.entity()
The PKIClient.entity() has been added to create an Entity object
with the correct message format.
- - - - -
2ebdde7e by Endi S. Dewata at 2023-05-30T18:13:50-05:00
Update log messages in ConnectorService
- - - - -
879f499e by Endi S. Dewata at 2023-05-31T08:44:50-05:00
Update GroupClient to use JAX-RS client API
- - - - -
ce4c7ffb by Endi S. Dewata at 2023-05-31T08:44:50-05:00
Update ActivityClient to use JAX-RS client API
- - - - -
ef952f66 by Endi S. Dewata at 2023-05-31T08:44:50-05:00
Update SecurityDomainClient to use JAX-RS client API
- - - - -
f5bfe674 by Endi S. Dewata at 2023-05-31T08:44:50-05:00
Update FeatureClient to use JAX-RS client API
- - - - -
05c85e89 by Endi S. Dewata at 2023-05-31T08:44:50-05:00
Update KRAConnectorClient to use JAX-RS client API
- - - - -
a0615882 by Endi S. Dewata at 2023-05-31T08:44:50-05:00
Update AuthenticatorClient to use JAX-RS client API
- - - - -
c74a6163 by Endi S. Dewata at 2023-05-31T08:44:50-05:00
Update CAInfoClient to use JAX-RS client API
- - - - -
71996b87 by Endi S. Dewata at 2023-05-31T08:44:50-05:00
Update KRAInfoClient to use JAX-RS client API
- - - - -
4354a910 by Endi S. Dewata at 2023-05-31T08:44:50-05:00
Update ConfigClient to use JAX-RS client API
- - - - -
f77a8264 by Endi S. Dewata at 2023-05-31T08:44:50-05:00
Update TPSCertClient to use JAX-RS client API
- - - - -
774973f8 by Endi S. Dewata at 2023-05-31T08:44:50-05:00
Update ConnectorClient to use JAX-RS client API
- - - - -
82c8fc7b by Endi S. Dewata at 2023-06-01T21:20:28-05:00
Create separate build for ACME tests
The build job in ACME tests workflow has been modified to create
just the packages required for ACME tests (without re-running the
unit tests since they are already run by the main build job),
then publish the ACME image.
This way the main build job no longer needs to build the ACME
image so other tests can start earlier, thus reducing the overall
execution time.
- - - - -
4328e585 by Endi S. Dewata at 2023-06-01T23:07:33-05:00
Fix ProfileMappingService.createProfileMappingData()
The ProfileMappingService.createProfileMappingData() has been
updated to set the ProfileMappingData.profileMappingID properly.
- - - - -
fa3c52f9 by Endi S. Dewata at 2023-06-01T23:07:33-05:00
Fix TKSEngineConfig.getTPSConnectorIDs()
The TKSEngineConfig.getTPSConnectorIDs() has been modified to
remove blank entries from the list.
- - - - -
8b15e37f by Endi S. Dewata at 2023-06-01T23:07:33-05:00
Add Client.target()
The Client.target() has been added to simplify calling
PKIClient.target().
- - - - -
79029deb by Endi S. Dewata at 2023-06-01T23:07:33-05:00
Add Client.delete() that takes query params
A new Client.delete() has been added to call HTTP DELETE
operation with query params.
- - - - -
d5072e66 by Chris Kelley at 2023-06-05T10:44:56+01:00
Code clean up in Job
* Make logger final
* Reduce visibility of public constructor
* Use built in logger formatting
* Remove unnecessary override of run()
* Remove unnecessary Boolean literal
* Combine identical catch clauses
* Rearrange logic in build methods for readability
A separate change will replace the synchronized HashTable instances
- - - - -
c725d16b by Chris Kelley at 2023-06-05T12:16:58+01:00
Upstream some spec file changes to reduce diff
- - - - -
602a238c by Endi S. Dewata at 2023-06-06T11:31:35-05:00
Update CMCRequest to support hex revRequest.serial
- - - - -
acba513b by Endi S. Dewata at 2023-06-07T08:52:19-05:00
Update test for CA with CMC shared token
The test for CA with CMC shared token has been updated to perform
a certificate revocation then validate the audit events.
- - - - -
5a69e677 by Endi S. Dewata at 2023-06-07T12:55:36-05:00
Fix stdout/stderr encoding in NSSDatabase.get_trust()
- - - - -
e83ebf66 by Endi S. Dewata at 2023-06-07T12:56:00-05:00
Fix regex in in NSSDatabase.get_trust()
- - - - -
cbeea95d by Endi S. Dewata at 2023-06-07T12:56:21-05:00
Clean up test for CA with CMC shared token
- - - - -
e916d58d by Endi S. Dewata at 2023-06-07T18:04:13-05:00
Update pki ca-cert-request-submit
The pki ca-cert-request-submit has been updated to get the
subject DN from the PKCS #10 request by default.
- - - - -
207efa5d by Endi S. Dewata at 2023-06-07T21:54:24-05:00
Remove unused Velocity templates
- - - - -
2b84210e by Endi S. Dewata at 2023-06-08T09:34:15-05:00
Update admin cert profile in tests
Previously the subject DN for admin certs in tests were
changed into uid=<username> since it's required by the
caUserCert profile.
The tests have been updated to use the AdminCert profile
which allows any subject DN, so the subject DN no longer
needs to be replaced.
- - - - -
c399a63e by Endi S. Dewata at 2023-06-08T18:44:02-05:00
Fix missing ROLE_ASSUME events
The ACLInterceptor has been updated to generate a ROLE_ASSUME
event after a successful authorization to a protected resource.
This will fix missing ROLE_ASSUME events for REST API which is
used by PKI CLI and TPS UI.
Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=1549887
- - - - -
56f2dcef by Chris Kelley at 2023-06-09T12:16:20+01:00
Use the system Python 3 for scripts
Now Python 3 is the default everywhere we can ask for the system Python
for rather forcing the shell to use what is specified in the PATH
- - - - -
0a002576 by Endi S. Dewata at 2023-06-09T10:00:54-05:00
Update AuthorityClient to use JAX-RS client API
- - - - -
98871b0c by Endi S. Dewata at 2023-06-09T10:00:54-05:00
Update TokenClient to use JAX-RS client API
- - - - -
e3be8e3e by Endi S. Dewata at 2023-06-09T10:00:54-05:00
Update TPS ProfileClient to use JAX-RS client API
- - - - -
f09acc90 by Endi S. Dewata at 2023-06-09T10:00:54-05:00
Update TPS ProfileMappingClient to use JAX-RS client API
- - - - -
b84a455a by Endi S. Dewata at 2023-06-09T10:00:54-05:00
Update TPSConnectorClient to use JAX-RS client API
- - - - -
d9519799 by Endi S. Dewata at 2023-06-09T10:00:54-05:00
Update CA ProfileClient to use JAX-RS client API
- - - - -
5dca1b2c by Endi S. Dewata at 2023-06-09T10:00:54-05:00
Update AuditClient to use JAX-RS client API
- - - - -
135645e4 by Endi S. Dewata at 2023-06-09T11:34:01-05:00
Update ServerConfig.create_listener()
The ServerConfig.create_listener() has been modified to support
adding the new listener at a specific index. If the index is not
specified, the new listener will be added at the end.
- - - - -
c69cda03 by Endi S. Dewata at 2023-06-09T14:52:02-05:00
Update pkidaemon
The pkidaemon has been modified to support both the default
"pki-tomcatd" and the "tomcat" instance types which determine
the directory structure of the instance.
https://github.com/dogtagpki/pki/wiki/PKI-Server-Directory-Structure
- - - - -
0d324ac8 by Endi S. Dewata at 2023-06-09T14:52:31-05:00
Update PKIInstance.execute()
The PKIInstance.execute() has been modified to include the
instance type if it's not the default one when calling server
startup scripts.
- - - - -
4298a668 by Endi S. Dewata at 2023-06-09T17:13:48-05:00
Fix NPE in CMSEngine.shutdown()
- - - - -
5fa7ede5 by Chris Kelley at 2023-06-12T10:04:44+01:00
Code cleanup in CertRecord
- - - - -
9614f953 by Chris Kelley at 2023-06-12T11:50:37+01:00
Code clean up in CertRecordProcessor
* Make logger final
* Remove unnecessary Boolean literals
* Invert negated if statements for readability
* Use built in logger formatting
* Rename onlySomeReasons to not hide the field
* Replace synchronized HashTable and Vector instances (Vector/HashTable
are technically still used as they are
the implementations of List/Map passed in by at least some of the
calling code)
- - - - -
7e7df9de by Chris Kelley at 2023-06-12T20:44:05+01:00
Clean up servlet methods in CMSAdminServlet
* Remove un-throwable ServletException/EBaseException from declarations
- leave empty methods for now, they need to be abstracted in the base
class or moved out into an interface.
* Most methods don't require the request, so remove it from those.
- - - - -
1975a742 by Endi S. Dewata at 2023-06-12T15:25:07-05:00
Update UserClient to use JAX-RS client API
- - - - -
cf9a9b83 by Endi S. Dewata at 2023-06-12T18:50:36-05:00
Add CAAgentCertRequestClient
The code that calls AgentCertRequestResource has been moved
into CAAgentCertRequestClient to simplify the transition to
JAX-RS client API.
The original methods in CACertClient have been modified to
forward the call to CAAgentCertRequestClient.
- - - - -
44bda4cd by Endi S. Dewata at 2023-06-12T18:50:36-05:00
Add CAAgentCertClient
The code that calls AgentCertResource has been moved into
CAAgentCertClient to simplify the transition to JAX-RS client
API.
The original methods in CACertClient have been modified to
forward the call to CAAgentCertClient.
- - - - -
433f604f by Endi S. Dewata at 2023-06-12T19:09:50-05:00
Add CACertRequestClient
The code that calls CertequestResource has been moved into
CACertRequestClient to simplify the transition to JAX-RS client
API.
The original methods in CACertClient have been modified to
forward the call to CACertRequestClient.
- - - - -
4e810f83 by Endi S. Dewata at 2023-06-12T19:09:50-05:00
Remove unused KeyClient.kraInfoClient
- - - - -
7947a4a6 by Endi S. Dewata at 2023-06-12T19:09:50-05:00
Add KeyRequestClient
The code that calls on KeyRequestResource has been moved into
KeyRequestClient to simplify the transition to JAX-RS client API.
The original methods in KeyClient have been modified to forward
the call to KeyRequestClient.
- - - - -
d9ce0629 by Endi S. Dewata at 2023-06-13T09:10:53-05:00
Update CAAgentCertRequestClient to use JAX-RS client API
- - - - -
6da29a50 by Endi S. Dewata at 2023-06-13T09:10:53-05:00
Update CAAgentCertClient to use JAX-RS client API
- - - - -
cbf98a78 by Endi S. Dewata at 2023-06-13T09:10:53-05:00
Update CACertRequestClient to use JAX-RS client API
- - - - -
803f648f by Endi S. Dewata at 2023-06-13T09:10:53-05:00
Update CACertClient to use JAX-RS client API
- - - - -
96d41fcd by Chris Kelley at 2023-06-13T15:17:21+01:00
Remove getNickName() from KeyRecoveryAuthority
This method simply calls getNickname(), which is actually implementing a
method from IAuthority, which is highly confusing. The method doesn't
look to actually be used anywhere so I removed it and added the
@Override annotation to the remaining method.
- - - - -
6aecffbd by Chris Kelley at 2023-06-13T21:31:16+01:00
Code cleanup in PKILogger
* Rename enum to not name clash java.util.logging.Level
* Remove unnecessary semicolon and fully qualified names
* Replace statically created HashMap with Map.of() generated EnumMap and
lower its visibility
- - - - -
40b589cd by Endi S. Dewata at 2023-06-13T16:53:18-05:00
Update log messages in KRAService
- - - - -
02ba2dee by Endi S. Dewata at 2023-06-13T16:54:06-05:00
Update log messages in KeyRequestService
- - - - -
d769d7a2 by Endi S. Dewata at 2023-06-13T16:54:06-05:00
Update log messages in SymKeyGenService
- - - - -
188050e8 by Endi S. Dewata at 2023-06-13T19:02:05-05:00
Add RESTMessage.toString()
- - - - -
660986fa by Endi S. Dewata at 2023-06-14T09:23:21-05:00
Update KeyRequestClient to use JAX-RS client API
- - - - -
a0423452 by Endi S. Dewata at 2023-06-14T09:23:21-05:00
Update KeyClient to use JAX-RS client API
- - - - -
949b7181 by Endi S. Dewata at 2023-06-14T09:23:48-05:00
Update GrantRecovery to use @WebServlet
- - - - -
744487e4 by Endi S. Dewata at 2023-06-14T09:23:48-05:00
Update GrantAsyncRecovery to use @WebServlet
- - - - -
19ce3b90 by Endi S. Dewata at 2023-06-14T09:23:48-05:00
Update DisplayTransport to use @WebServlet
- - - - -
236de44e by Endi S. Dewata at 2023-06-14T09:23:48-05:00
Update GetTransportCert to use @WebServlet
- - - - -
08149eeb by Endi S. Dewata at 2023-06-14T09:23:48-05:00
Update RecoverBySerial to use @WebServlet
- - - - -
3a1b43a7 by Endi S. Dewata at 2023-06-14T09:23:48-05:00
Update TokenKeyRecoveryServlet to use @WebServlet
- - - - -
57a54298 by Endi S. Dewata at 2023-06-14T09:23:48-05:00
Update GenerateKeyPairServlet to use @WebServlet
- - - - -
f91fc5c1 by Endi S. Dewata at 2023-06-14T09:23:48-05:00
Update GetApprovalStatus to use @WebServlet
- - - - -
df2380f4 by Endi S. Dewata at 2023-06-14T09:23:48-05:00
Update KeyProcessReq to use @WebServlet
- - - - -
78639ce4 by Endi S. Dewata at 2023-06-14T09:23:48-05:00
Update ExamineRecovery to use @WebServlet
- - - - -
7481db43 by Endi S. Dewata at 2023-06-14T18:26:48-05:00
Remove unused PKIClient.createProxy()
- - - - -
6254aacf by Endi S. Dewata at 2023-06-14T19:49:22-05:00
Add SCEPConfig
The SCEPConfig class has been added to encapsulate ca.scep.*
params.
- - - - -
d314aaed by Endi S. Dewata at 2023-06-15T18:05:32-05:00
Remove redundant CMake variables
- - - - -
5d04775f by Endi S. Dewata at 2023-06-16T15:36:00-05:00
Revert RESTMessage.toString()
- - - - -
aef379e4 by Chris Kelley at 2023-06-20T15:18:55+01:00
Introduce Packit config and upstream some spec updates
- - - - -
56efe4af by Chris Kelley at 2023-06-20T15:19:04+01:00
Upstream some spec file changes from Fedora
- - - - -
3947a651 by Chris Kelley at 2023-06-20T15:22:14+01:00
Add packit job for scratch builds for PRs
- - - - -
f34cf875 by Chris Kelley at 2023-06-20T15:27:52-05:00
Revert "Upstream some spec file changes from Fedora"
This reverts commit 56efe4af357ed646425742ef46b5733ce4b405a8.
- - - - -
7a8bf426 by Endi S. Dewata at 2023-06-20T21:42:15-05:00
Add COPR_REPO default value
The CI has been modified to define a default value for
COPR_REPO since PRs do not have access to the value.
- - - - -
228aa4c6 by Chris Kelley at 2023-06-21T10:10:33+01:00
Fix typo in .packit.yaml
- - - - -
8ee2f064 by Chris Kelley at 2023-06-21T11:03:52+01:00
Disable cf-protection test
It is causing rpminspect failures and it is not clear why. We only
have a few executables like this and they are adjunct tools that
do not form part of the main application, so ignoring it
- - - - -
0f69e195 by Chris Kelley at 2023-06-21T14:05:47+01:00
Update README.md
Drop QE tests from status badges (as we don't run those tests)
- - - - -
e7ad62eb by Endi S. Dewata at 2023-06-21T10:01:11-05:00
Add dependency on resteasy-servlet-initializer
The pki.spec, pom.xml, and CMake files have been modified
to include resteasy-servlet-initializer to enable automatic
initialization of JAX-RS applications in all webapps.
https://docs.jboss.org/resteasy/docs/3.0.24.Final/userguide/html_single/#d4e143
- - - - -
ed6b8c69 by Endi S. Dewata at 2023-06-21T10:01:11-05:00
Auto-initialize JAX-RS applications
The web.xml files in most webapps (except ACME and EST) have
been modified to drop the RESTEasy servlet declaration and
let the JAX-RS applications be initialized automatically by
resteasy-servlet-initializer.
https://docs.jboss.org/resteasy/docs/3.0.24.Final/userguide/html_single/#d4e143
- - - - -
456e81ab by Endi S. Dewata at 2023-06-21T11:41:17-05:00
Drop DRMTool
The DRMTool command, its config file, and its manual page are
actually just links to their counterparts in KRATool. Some of
those links are actually broken, but rpminspect is only
generating warnings instead of failing. Since the tool has
long been deprecated the tool and the links can be dropped.
- - - - -
59609079 by Chris Kelley at 2023-06-22T09:34:49+01:00
Allow packit to access @pki/master for dependency resolution
- - - - -
725ab593 by Chris Kelley at 2023-06-22T09:47:20+01:00
Conditionalise use of resteasy-servlet-initializer
- - - - -
8a8f3209 by Chris Kelley at 2023-06-22T10:36:16+01:00
Revert "Conditionalise use of resteasy-servlet-initializer"
This reverts commit 725ab5931d7a01c0395383c3b23c1569f2b8d097.
- - - - -
76d83323 by Chris Kelley at 2023-06-22T12:37:37+01:00
Code cleanup in UsrGrpAdminServlet
* Make logger final and log errors instead of stack traces
* Reorder modifiers to match the JLS
* Move array designators to the type
* Remove unnecessary Boolean literals and control flow jumps
* Remove commented out code
* Use pattern-matching instanceof
* Simplify logic by flattening/inverting negated ifs/unnecessary elses
* Remove declarations for exceptions that cannot be thrown
- - - - -
5ce3e63d by Endi S. Dewata at 2023-06-22T20:17:47-05:00
Fix PKIServer.deploy_webapp()
The PKIServer.deploy_webapp() has been updated to check the
wait time if the is_available() returns a False or throws
a retryable exception.
- - - - -
9bafa9eb by Endi S. Dewata at 2023-06-22T20:17:53-05:00
Fix PKIServer.undeploy_webapp()
The PKIServer.undeploy_webapp() has been updated to check the
wait time if the is_available() returns a True or throws a
retryable exception.
- - - - -
994d9321 by Endi S. Dewata at 2023-06-23T10:15:07-05:00
Auto-initialize ACME application
The ACME webapp has been modified to automatically initialize
the ACME application without an explicit dependency on RESTEasy.
Since a JAX-RS application cannot have an empty path, the ACME
application needs to be relocated to /rest and the endpoints need
to be mapped to the new location as well.
https://docs.jboss.org/resteasy/docs/3.0.24.Final/userguide/html_single/#d4e143
https://stackoverflow.com/questions/10874188/jax-rs-application-on-the-root-context-how-can-it-be-done
- - - - -
21b290e7 by Chris Kelley at 2023-06-23T19:20:40+01:00
Fix additional packit repos
- - - - -
06a3059c by Endi S. Dewata at 2023-06-23T14:52:45-05:00
Drop pki-servlet-engine dependency
The pki-servlet-engine is no longer needed since now Tomcat
is available on all platforms.
- - - - -
8c2094e9 by Chris Kelley at 2023-06-23T21:20:50+01:00
Remove unnecessary else clause from nsNKeyOutput
- - - - -
fce534bd by Chris Kelley at 2023-06-23T22:56:08+01:00
Use try-with-resources in DefStore
- - - - -
879fd4f6 by Endi S. Dewata at 2023-06-23T17:15:29-05:00
Move Web UI main page into ROOT webapp
- - - - -
3bd832ef by Endi S. Dewata at 2023-06-23T17:15:29-05:00
Move patternfly-4.35.2.css into ROOT webapp
- - - - -
be07a728 by Endi S. Dewata at 2023-06-23T17:15:29-05:00
Move jquery-3.5.1.js into ROOT webapp
- - - - -
4a9ad57a by Endi S. Dewata at 2023-06-23T20:17:56-05:00
Update build.sh output
- - - - -
6e1f5c14 by Endi S. Dewata at 2023-06-23T21:17:38-05:00
Move HttpInput to pki-server
- - - - -
29124d8a by Endi S. Dewata at 2023-06-23T21:52:23-05:00
Update Tomcat dependency
- - - - -
b189005d by Endi S. Dewata at 2023-06-26T12:58:47-05:00
Auto-initialize EST application
The EST webapp has been modified to automatically initialize
the EST application without an explicit dependency on RESTEasy.
Since a JAX-RS application cannot have an empty path, the EST
application needs to be relocated to /rest and the endpoints need
to be mapped to the new location as well.
https://docs.jboss.org/resteasy/docs/3.0.24.Final/userguide/html_single/#d4e143
https://stackoverflow.com/questions/10874188/jax-rs-application-on-the-root-context-how-can-it-be-done
- - - - -
bb5ddfca by Chris Kelley at 2023-06-27T14:24:39+01:00
Add packit copr_build job on commit
- - - - -
65d1a36e by Endi S. Dewata at 2023-06-27T09:40:35-05:00
Merge libtps.so into tpsclient
The libtps.so is used exclusively by tpsclient so it's no
longer necessary to keep it as a shared library.
- - - - -
5c385bcc by Marco Fargetta at 2023-06-27T18:08:59+02:00
Migrate EST tests to ansible
Tests based on GitHub workflow cannot easily be executed locally
before the code is pushed making more difficult to identify problems
during the development.
Additionally, there are several limitation on how workflows can be
combined.
Moving to ansible should solve the limitation and allow the
execution of test on developer machine.
This is the first step aims at converting a single workflow to ansible.
The preliminary steps of building the docker images and deploy onto the
runner are still based on github actions.
If/when all workflows will use ansible the overall CI activities could
be reorganised to optimise the execution in the available runners.
- - - - -
6ac0877d by Endi S. Dewata at 2023-06-27T19:14:47-05:00
Clean up JAR paths in CMake files
- - - - -
e8582686 by Endi S. Dewata at 2023-06-28T09:14:11-05:00
Update POM files
The POM files have been modified to use the latest dependencies.
The dependencies have been moved into the modules that actually
need them. The maven-surefire-plugin has been added to run JUnit
5 tests properly. A new POM file has also been added for EST.
The RPM spec and Azure pipelines have been updated to use the
same dependencies as in the POM files.
- - - - -
a7ad636d by Endi S. Dewata at 2023-06-28T09:58:28-05:00
Replace tomcatjss.jar
All references to tomcatjss.jar have been replaced with
tomcatjss-core.jar and tomcatjss-tomcat-9.0.jar since they
are the actual Maven build artifacts.
- - - - -
02b6fde3 by Adam Williamson at 2023-07-05T10:48:40+01:00
Handle removal of ConfigParser.readfp() in Python 3.12
Per https://docs.python.org/3.12/whatsnew/3.12.html#removed ,
configparser.ConfigParser.readfp() is removed in Python 3.12.
Assuming we still want to keep Python 2 compatibility, since
there are still a bunch of uses of six in the codebase, I've
changed this to do it the same way as it's done in freeipa
ipaserver/install/certs.py, using readfp on Python 2 and
read_file on Python 3.
Signed-off-by: Adam Williamson <awilliam at redhat.com>
- - - - -
bf3722d3 by Endi S. Dewata at 2023-07-05T14:37:35-05:00
Split pki-tomcat.jar
Previously CMake stored both generic Tomcat and Tomcat 9.0-specific
classes into a single JAR file. To simplify the transition to Maven
the CMake scripts have been updated to store those classes into
separate JAR files. PKI server code has also been updated to use
both JAR files.
Currently PKI code has direct dependencies on Tomcat 9.0 classes.
To simplify the transition to newer Tomcat versions the code needs
to be refactored to use generic Tomcat classes at compile time,
then use version-specific classes at runtime. This can be done
separately in the future.
- - - - -
a91d351f by Endi S. Dewata at 2023-07-06T12:09:46-05:00
Fix pki-tomcat.jar and pki-tomcat-9.0.jar
The CMake scripts for pki-tomcat.jar and pki-tomcat-9.0.jar have
been updated to use separate build folders. The Azure pipelines
have been updated to verify the content of the JAR files.
- - - - -
04bd9a2f by Endi S. Dewata at 2023-07-06T19:32:29-05:00
Replace WITHOUT_TEST with RUN_TESTS
The WITHOUT_TEST variable in build.sh has been replaced with
RUN_TESTS for clarity.
- - - - -
c60babb4 by Endi S. Dewata at 2023-07-07T11:26:52-05:00
Clean up CMake files
- - - - -
a002a735 by Endi S. Dewata at 2023-07-07T15:36:36-05:00
Move default pki_instance_name into default.cfg
- - - - -
7c7fdd0b by Endi S. Dewata at 2023-07-10T08:50:13-05:00
Build RPM with Maven
The RPM spec file has been modified to build Java binaries and
run unit tests with Maven, then build PKI console, Javadoc, and
native binaries with CMake. In the future it might be possible
to build everything with Maven.
The build.sh has been modified to provide an option to skip
building Java binaries. The CMake scripts have been modified to
provide separate build targets for Java binaries, PKI console,
Javadoc, and native binaries. The javac(), jar(), javadoc(),
link(), and add_junit_test() macros have been modified to no
longer be included in the default build target to provide more
controls over the build process.
- - - - -
c2eebd83 by Chris Kelley at 2023-07-10T15:37:42+01:00
Add get_current_version to Packit jobs
- - - - -
69caf95e by Endi S. Dewata at 2023-07-10T09:57:45-05:00
Move default pki_http_port and pki_https_port into default.cfg
- - - - -
6067d5b0 by Endi S. Dewata at 2023-07-10T19:47:10-05:00
Relocate console resources
- - - - -
ec21f96f by Endi S. Dewata at 2023-07-10T19:47:10-05:00
Clean up Azure pipelines
- - - - -
2b87359f by Chris Kelley at 2023-07-11T15:43:17+01:00
Simplify Packit copr_build config
- - - - -
28fa604b by Endi S. Dewata at 2023-07-11T10:13:09-05:00
Build PKI console with Maven
A new Maven module has been added for PKI console. The build
scripts have been modified to build PKI console with Maven.
The pki-console-theme.jar will continue to be built with CMake.
- - - - -
6b318a9c by Endi S. Dewata at 2023-07-11T21:06:55-05:00
Remove non-customizable pki_subsystem_profiles_path param
- - - - -
6a1df9f1 by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Remove non-customizable pki_subsystem_emails_path param
- - - - -
5f9641cb by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Remove non-customizable pki_source_subsystemcert_profile param
- - - - -
51375925 by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Remove non-customizable pki_source_servercert_profile param
- - - - -
84977d00 by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Remove non-customizable pki_source_caocspcert_profile param
- - - - -
86dd0ddc by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Remove non-customizable pki_source_cacert_profile param
- - - - -
b603f608 by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Remove non-customizable pki_source_caauditsigningcert_profile param
- - - - -
3131003f by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Remove non-customizable pki_source_admincert_profile param
- - - - -
52c54166 by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Remove non-customizable pki_source_proxy_conf param
- - - - -
b2005cc7 by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Remove non-customizable pki_source_profiles param
- - - - -
8fd82682 by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Remove non-customizable pki_source_flatfile_txt param
- - - - -
400850a5 by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Remove non-customizable pki_source_emails param
- - - - -
3c3f7902 by Endi S. Dewata at 2023-07-11T21:07:39-05:00
Add index param for ServerConfig.add_connector()
The ServerConfig.add_connector() has been updated to take an
optional param which specifies the index of the new connector.
If not specified, the new connector will be added after the
last connector.
- - - - -
5afb3c09 by Endi S. Dewata at 2023-07-12T10:34:42-05:00
Fix NPE in UsrGrpAdminServlet
In commit 11d268faa93dd3604292fa46e6895c4d6f197af9 the
UsrGrpAdminServlet's constructor was modified to get the CMSEngine
object from the servletContext before the field was initialized
which triggered a NullPointerException. To fix the problem the code
in the constructor has been moved into init() so that it will run
after the servletContext initialization.
https://issues.redhat.com/browse/RHEL-626
- - - - -
22d70012 by Endi S. Dewata at 2023-07-13T17:04:16-05:00
Remove non-configurable pki_subsystem_registry_link param
- - - - -
3c46c793 by Endi S. Dewata at 2023-07-13T17:05:30-05:00
Remove non-configurable pki_subsystem_logs_link param
- - - - -
c85d21a1 by Endi S. Dewata at 2023-07-13T17:07:56-05:00
Remove non-configurable pki_subsystem_conf_link param
- - - - -
4117c002 by Endi S. Dewata at 2023-07-13T17:12:23-05:00
Remove non-configurable pki_subsystem_database_link param
- - - - -
f51abf9f by Endi S. Dewata at 2023-07-13T17:20:02-05:00
Remove non-configurable pki_subsystem_configuration_path param
- - - - -
0efe4d16 by Endi S. Dewata at 2023-07-13T17:24:45-05:00
Remove non-configurable pki_subsystem_log_path param
- - - - -
cbed291a by Endi S. Dewata at 2023-07-13T17:35:19-05:00
Remove non-configurable pki_subsystem_path param
- - - - -
0f01dd29 by Endi S. Dewata at 2023-07-13T17:38:48-05:00
Remove unused pki_source_registry param
- - - - -
03f923f4 by Endi S. Dewata at 2023-07-13T17:43:28-05:00
Remove non-configurable pki_source_cs_cfg param
- - - - -
2e335033 by Endi S. Dewata at 2023-07-13T17:44:55-05:00
Remove unused pki_tomcat_common_webapps_path param
- - - - -
e448cfb9 by Endi S. Dewata at 2023-07-13T17:45:40-05:00
Remove unused pki_tomcat_webapps_path params
- - - - -
3ab23a6b by Endi S. Dewata at 2023-07-13T17:48:29-05:00
Remove non-configurable pki_source_tomcat_conf param
- - - - -
4d6db9db by Endi S. Dewata at 2023-07-13T17:49:25-05:00
Remove unused pki_source_context_xml param
- - - - -
897a81a4 by Endi S. Dewata at 2023-07-13T17:53:41-05:00
Remove non-configurable pki_source_server_path param
- - - - -
c54635b9 by Endi S. Dewata at 2023-07-13T17:55:18-05:00
Remove unused pki_source_setup_path param
- - - - -
3b86c6c9 by Endi S. Dewata at 2023-07-13T18:02:12-05:00
Remove non-configurable pki_source_conf_path param
- - - - -
19592e22 by Endi S. Dewata at 2023-07-13T18:11:04-05:00
Remove non-configurable pki_configuration_path param
- - - - -
1ad34c8f by Endi S. Dewata at 2023-07-13T18:11:45-05:00
Remove non-configurable pki_log_path param
- - - - -
003f92db by Endi S. Dewata at 2023-07-13T18:13:55-05:00
Remove non-configurable pki_path param
- - - - -
3a611ff2 by Rob Crittenden at 2023-07-14T15:56:33+01:00
Create temporary files to be shared between uses in /tmp
Some commands need to be executed as the pki user and not
root to retain filesystem permissions. There are a few
places where passwords are written to files as root to be
passed into commands executed by pkiuser.
If a private temporary directory is set before pkispawn
is called then this method for sharing passwords between
users will not work because the file will be unreadable.
So force these calls to use /tmp directly instead of the
private temporary directory.
Fixes: https://github.com/dogtagpki/pki/issues/4475
Signed-off-by: Rob Crittenden <rcritten at redhat.com>
- - - - -
70a4265f by Endi S. Dewata at 2023-07-14T11:41:50-05:00
Update fapolicy rules
Previously the fapolicy rules only granted the permissions
to a subfolder in Tomcat work directory corresponding to the
default engine and host defined in server.xml, so if the
admin changes the engine or the host the fapolicy rules will
need to be changed as well.
To reduce maintenance, the fapolicy rules have been updated
to grant the permissions to the entire Tomcat work directory
such that the engine or the host can be changed without
having to change the fapolicy rules.
Updating fapolicy rules has to be done during RPM upgrade
since it requires root permissions. The regular PKI server
upgrade scripts run as pkiuser so it can't be used here.
The template for the fapolicy rules has been moved into a
file such that it can be used both during installation and
upgrade.
- - - - -
318c5c32 by Endi S. Dewata at 2023-07-14T16:41:18-05:00
Remove redundant creation of work subfolders
- - - - -
f94fd53c by Endi S. Dewata at 2023-07-14T18:44:44-05:00
Remove non-configurable pki_cgroup_cpu_systemd_service param
- - - - -
7ea1c243 by Endi S. Dewata at 2023-07-14T21:28:40-05:00
Remove non-configurable pki_cgroup_cpu_systemd_service_path param
- - - - -
88076287 by Endi S. Dewata at 2023-07-14T21:28:47-05:00
Remove non-configurable pki_cgroup_systemd_service param
- - - - -
6a019ac5 by Endi S. Dewata at 2023-07-14T21:28:47-05:00
Remove non-configurable pki_cgroup_systemd_service_path param
- - - - -
717e672f by Endi S. Dewata at 2023-07-14T21:28:47-05:00
Remove non-configurable pki_systemd_service_link param
- - - - -
e80b5894 by Endi S. Dewata at 2023-07-14T21:28:47-05:00
Remove non-configurable pki_systemd_target_wants param
- - - - -
d267b1da by Endi S. Dewata at 2023-07-14T21:28:47-05:00
Remove unused pki_systemd_target param
- - - - -
ca63fc4e by Endi S. Dewata at 2023-07-14T21:29:13-05:00
Remove non-configurable pki_systemd_service param
- - - - -
f6be32b1 by Endi S. Dewata at 2023-07-14T21:29:14-05:00
Remove non-configurable pki_subsystem_registry_path param
- - - - -
6d8519f9 by Endi S. Dewata at 2023-07-14T21:29:14-05:00
Remove non-configurable pki_instance_registry_path param
- - - - -
810064a7 by Endi S. Dewata at 2023-07-14T21:29:14-05:00
Remove unused pki_registry_path param
- - - - -
aca460d7 by Endi S. Dewata at 2023-07-14T21:29:14-05:00
Remove non-configurable pki_instance_log_path param
- - - - -
f10a99ec by Endi S. Dewata at 2023-07-14T21:29:14-05:00
Remove non-configurable pki_source_subsystem_path param
- - - - -
dbaa523f by Endi S. Dewata at 2023-07-17T11:57:35-05:00
Add PKIDeployer.create_selinux_contexts()
The code that creates SELinux contexts in selinux_setup.py
has been moved into PKIDeployer.create_selinux_contexts().
- - - - -
000fc755 by Endi S. Dewata at 2023-07-17T11:57:35-05:00
Add PKIDeployer.remove_selinux_contexts()
The code that removes SELinux contexts in selinux_setup.py
has been moved into PKIDeployer.remove_selinux_contexts().
- - - - -
3953c9a2 by Endi S. Dewata at 2023-07-17T17:02:22-05:00
Add PKIServer.add_subsystem()
The PKIServer.add_subsystem() has been added to add a subsystem
object into an instance object.
- - - - -
f3ee5245 by Endi S. Dewata at 2023-07-17T18:14:06-05:00
Add PKIServer.remove_subsystem()
The PKIServer.remove_subsystem() has been added to remove a
subsystem object from an instance object.
- - - - -
eebce746 by Endi S. Dewata at 2023-07-17T18:14:06-05:00
Remove PKIDeployer.pki_instance_subsystems()
The PKIDeployer.pki_instance_subsystems() has been replaced
with PKIServer.get_subsystems().
- - - - -
21587064 by Endi S. Dewata at 2023-07-17T20:25:37-05:00
Remove PKIDeployer.tomcat_instance_subsystems()
The PKIDeployer.tomcat_instance_subsystems() has been replaced
with PKIServer.get_subsystems().
- - - - -
d8f067a1 by Endi S. Dewata at 2023-07-18T09:37:34-05:00
Hard-code version number in pom.xml
Some build systems require hard-coding the version number in
pom.xml, so the revision property has been replaced with the
actual version number. Updating the version number can be
done with the following commands:
$ mvn versions:set -DnewVersion=<version>
$ mvn versions:commit
The .gitignore has been updated to ignore the backup files
created by this command.
- - - - -
91b928c2 by Endi S. Dewata at 2023-07-18T10:22:05-05:00
Update pkidestroy to use PKIServerFactory
The code that creates the PKIInstance object in pkidestroy has
been modified to use PKIServerFactory instead.
- - - - -
fc197652 by Endi S. Dewata at 2023-07-18T10:22:06-05:00
Update pkispawn to use PKIServerFactory
The code that creates the PKIInstance object in pkispawn has
been modified to use PKIServerFactory instead.
- - - - -
5da3c59a by Endi S. Dewata at 2023-07-18T11:53:25-05:00
Merge IPasswdUserDBAuthentication into PasswdUserDBAuthentication
- - - - -
372fd6ef by Endi S. Dewata at 2023-07-18T12:39:18-05:00
Update minConns for PasswdUserDBAuthentication
The PasswdUserDBAuthentication has been updated such that it
creates a DS connection only if needed. The LdapAnonConnFactory
has been updated to allow no minimum connections.
- - - - -
eb581e13 by Endi S. Dewata at 2023-07-18T12:45:30-05:00
Replace pki_instance_path param with PKIServer.base_dir
- - - - -
13d662c3 by Endi S. Dewata at 2023-07-18T12:46:58-05:00
Remove unused IAuthInfo
- - - - -
86d6c755 by Endi S. Dewata at 2023-07-18T15:43:45-05:00
Replace pki_server_database_path with PKIServer.nssdb_dir
- - - - -
d9a29dfd by Endi S. Dewata at 2023-07-18T18:35:31-05:00
Replace pki_instance_configuration_path with PKIServer.conf_dir
- - - - -
3659baf3 by Endi S. Dewata at 2023-07-18T20:52:33-05:00
Merge webapp_deployment.py into subsystem_layout.py
- - - - -
693aa62b by Endi S. Dewata at 2023-07-18T21:04:47-05:00
Remove redundant code in subsystem_layout.py
- - - - -
e31e3b9b by Endi S. Dewata at 2023-07-18T22:44:51-05:00
Clean up keygen.py
The code that generates system cert requests have been moved
into PKIDeployer.
- - - - -
af39a919 by Christina Fu at 2023-07-19T11:27:42-07:00
Adding useful OCSP debug messages
This patch fixed and added some useful information in the OCSP area. During investigation setup procedure for ticket RHCS-4264, some debug messages can be confusing. In addition, more information should be shared for administrators to understand why things are not working as expected.
It is also useful for RHCS-4261
for RHCS-4264 and RHCS-4261
- - - - -
49455c3f by Endi S. Dewata at 2023-07-19T13:51:47-05:00
Refactor set_signing_algs_for_pss()
The code that updates RSA-PSS algorithms has been simplified
and moved into PKIDeployer.
- - - - -
49beb451 by Endi S. Dewata at 2023-07-19T14:36:50-05:00
Clean up log messages in LDAPDatabase
- - - - -
41529eea by Endi S. Dewata at 2023-07-19T14:36:50-05:00
Clean up log messages in KRARemoteRequestHandler
- - - - -
2a407d09 by Chris Kelley at 2023-07-20T06:35:33+01:00
Add Implementation-Version to Manifests via pom.xml
The /getStatus endpoints in the web UI were returning a null
version since the build was switched to Maven.
It is probably now possible to remove the individual manifest files
but I have left them as they are for now so we can still build with
cmake if we wish.
- - - - -
521863c2 by Endi S. Dewata at 2023-07-20T10:11:50-05:00
Add pki_http_enable param
A new pki_http_enable parameter has been added for pkispawn
to enable/disable the plain HTTP connector in server.xml.
Currently the plain HTTP connector is enabled by default,
but in the future it might be disabled by default such that
the server will only use the secure HTTP connector.
The security domain CLIs have been modified such that they
work without the plain HTTP connector.
The TPS test with separate instances has been modified to
verify that the system works without plain HTTP connectors.
- - - - -
c0ae6da3 by Endi S. Dewata at 2023-07-20T10:45:38-05:00
Add PKIDeployer.init_client_nssdb()
The code that initializes the client NSS database has been
moved into PKIDeployer.init_client_nssdb().
- - - - -
006fe051 by Endi S. Dewata at 2023-07-20T10:47:10-05:00
Add PKIDeployer.init_system_cert_params()
The code that initializes the system cert params has been moved
into PKIDeployer.init_system_cert_params().
- - - - -
9ba83f0d by Endi S. Dewata at 2023-07-20T13:40:09-05:00
Add PKIDeployer.init_server_nssdb()
The code that initializes the server NSS database has been
moved into PKIDeployer.init_server_nssdb().
- - - - -
d5a8cda9 by Endi S. Dewata at 2023-07-20T14:38:53-05:00
Add PKIDeployer.init_subsystem()
The code that initializes the subsystem has been moved into
PKIDeployer.init_subsystem().
- - - - -
71ccdc37 by Endi S. Dewata at 2023-07-20T16:02:55-05:00
Rename KRAConnectorServlet to CAConnectorServlet
- - - - -
9d3739e2 by Endi S. Dewata at 2023-07-20T16:02:55-05:00
Add KRAGetConfigEntries
The KRAGetConfigEntries has been added to provide a separate class
for each servlet in web.xml.
- - - - -
0e38c984 by Endi S. Dewata at 2023-07-20T16:02:55-05:00
Add KRAPortsServlet
The KRAPortsServlet has been added to provide a separate class
for each servlet in web.xml.
- - - - -
9dfa1459 by Endi S. Dewata at 2023-07-20T16:02:55-05:00
Add KRARegisterUser
The KRARegisterUser has been added to provide a separate class
for each servlet in web.xml.
- - - - -
b9bf2dde by Endi S. Dewata at 2023-07-20T16:02:55-05:00
Add KRADynamicVariables
The KRADynamicVariables has been added to provide a separate class
for each servlet in web.xml.
- - - - -
bf7146ea by Endi S. Dewata at 2023-07-20T16:02:55-05:00
Add KRAConnectorServlet
The KRAConnectorServlet has been added to provide a separate class
for each servlet in web.xml.
- - - - -
cd0bb5e9 by Endi S. Dewata at 2023-07-20T16:02:55-05:00
Add KRAAuthAdminServlet
The KRAAuthAdminServlet has been added to provide a separate class
for each servlet in web.xml.
- - - - -
a9ab3c1d by Endi S. Dewata at 2023-07-20T16:02:55-05:00
Add KRAACLAdminServlet
The KRAACLAdminServlet has been added to provide a separate class
for each servlet in web.xml.
- - - - -
a6e77afd by Endi S. Dewata at 2023-07-20T16:02:55-05:00
Add KRAUsrGrpAdminServlet
The KRAUsrGrpAdminServlet has been added to provide a separate
class for each servlet in web.xml.
- - - - -
b12c1f36 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update DisplayBySerialForRecovery to use @WebServlet
- - - - -
7584d62b by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KRAGetConfigEntries to use @WebServlet
- - - - -
b67c2c93 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KRAPortsServlet to use @WebServlet
- - - - -
88110534 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KRARegisterUser to use @WebServlet
- - - - -
5a076477 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KRADynamicVariables to use @WebServlet
- - - - -
721a39b3 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KRAConnectorServlet to use @WebServlet
- - - - -
ea7edfd5 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update GetPk12 to use @WebServlet
- - - - -
380b2908 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update GetAsyncPk12 to use @WebServlet
- - - - -
cf1ea823 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KeyQueryReq to use @WebServlet
- - - - -
1f3cbf76 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KRAPolicyAdminServlet to use @WebServlet
- - - - -
b11325d9 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KRAAuthAdminServlet to use @WebServlet
- - - - -
14dcbbbd by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KRAACLAdminServlet to use @WebServlet
- - - - -
8df1c5cf by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KRAUsrGrpAdminServlet to use @WebServlet
- - - - -
0aab23e7 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KRACMSAdminServlet to use @WebServlet
- - - - -
86613f19 by Endi S. Dewata at 2023-07-21T09:42:34-05:00
Update KRAAdminServlet to use @WebServlet
- - - - -
178fd450 by Endi S. Dewata at 2023-07-21T11:14:09-05:00
Add KRALogAdminServlet
The KRALogAdminServlet has been added to provide a separate
class for each servlet in web.xml.
- - - - -
2677883d by Endi S. Dewata at 2023-07-21T12:41:38-05:00
Add KRAMainPageServlet
The KRAMainPageServlet has been added to provide a separate
class for each servlet in web.xml.
- - - - -
da958a3e by Endi S. Dewata at 2023-07-21T12:49:30-05:00
Add KRADownloadPKCS12
The KRADownloadPKCS12 has been added to provide a separate
class for each servlet in web.xml.
- - - - -
c21953d5 by Endi S. Dewata at 2023-07-21T12:52:58-05:00
Add KRAGetStatus
The KRAGetStatus has been added to provide a separate
class for each servlet in web.xml.
- - - - -
9c12e59a by Endi S. Dewata at 2023-07-21T13:00:24-05:00
Add KRAUpdateDomainXML
The KRAUpdateDomainXML has been added to provide a separate
class for each servlet in web.xml.
- - - - -
88c2008b by Endi S. Dewata at 2023-07-21T13:00:24-05:00
Add KRAAdminUpdateDomainXML
The KRAAdminUpdateDomainXML has been added to provide a separate
class for each servlet in web.xml.
- - - - -
3e987bc0 by Endi S. Dewata at 2023-07-21T17:34:57-05:00
Update PKI_VERSION in tomcat.conf
The PKI_VERSION in tomcat.conf has been modified to use quotes
like other properties in the file so they all can be processed
more consistently.
The PropertyFile and PKIUpgradeTracker classes have been
modified to support optional quotes.
- - - - -
10acba46 by Endi S. Dewata at 2023-07-24T09:18:25-05:00
Update KRALogAdminServlet to use @WebServlet
- - - - -
27a14b08 by Endi S. Dewata at 2023-07-24T09:18:25-05:00
Update SrchKey to use @WebServlet
- - - - -
34449896 by Endi S. Dewata at 2023-07-24T09:18:25-05:00
Update SrchKeyForRecovery to use @WebServlet
- - - - -
607c133e by Endi S. Dewata at 2023-07-24T09:18:25-05:00
Update DisplayBySerial to use @WebServlet
- - - - -
132a2290 by Endi S. Dewata at 2023-07-24T09:18:25-05:00
Update KRAMainPageServlet to use @WebServlet
- - - - -
b3ce20a0 by Endi S. Dewata at 2023-07-24T09:18:25-05:00
Update KRAUpdateNumberRange to use @WebServlet
- - - - -
fb51fdd1 by Endi S. Dewata at 2023-07-24T09:18:25-05:00
Update KRADownloadPKCS12 to use @WebServlet
- - - - -
2111a8c9 by Endi S. Dewata at 2023-07-24T09:18:25-05:00
Update KRAGetStatus to use @WebServlet
- - - - -
ca35c41e by Endi S. Dewata at 2023-07-24T09:18:25-05:00
Update KRAUpdateDomainXML to use @WebServlet
- - - - -
8fe8c279 by Endi S. Dewata at 2023-07-24T09:18:25-05:00
Update KRAAdminUpdateDomainXML to use @WebServlet
- - - - -
b69ed540 by Endi S. Dewata at 2023-07-24T10:44:19-05:00
Rename ListRequests to CAListRequests
- - - - -
01c27e16 by Endi S. Dewata at 2023-07-24T10:55:25-05:00
Add KRAHeaderServlet
The KRAHeaderServlet has been added to provide a separate
class for each servlet in web.xml.
- - - - -
b9f06cca by Endi S. Dewata at 2023-07-24T10:55:50-05:00
Add KRAIndexServlet
The KRAIndexServlet has been added to provide a separate
class for each servlet in web.xml.
- - - - -
f1621e1d by Endi S. Dewata at 2023-07-24T10:56:03-05:00
Add KRASearchKeyForRecovery
The KRASearchKeyForRecovery has been added to provide a separate
class for each servlet in web.xml.
- - - - -
2d9b33b0 by Endi S. Dewata at 2023-07-24T10:56:24-05:00
Add KRASearchKey
The KRASearchKey has been added to provide a separate
class for each servlet in web.xml.
- - - - -
a67ed2e7 by Endi S. Dewata at 2023-07-24T10:57:01-05:00
Add KRAListRequests
The KRAListRequests has been added to provide a separate
class for each servlet in web.xml.
- - - - -
52016991 by Endi S. Dewata at 2023-07-24T10:57:17-05:00
Add KRAGrantRecovery
The KRAGrantRecovery has been added to provide a separate
class for each servlet in web.xml.
- - - - -
d53eb515 by Endi S. Dewata at 2023-07-24T10:57:31-05:00
Add KRAJobsAdminServlet
The KRAJobsAdminServlet has been added to provide a separate
class for each servlet in web.xml.
- - - - -
767e2fdf by Endi S. Dewata at 2023-07-24T10:57:43-05:00
Add KRAGetCookie
The KRAGetCookie has been added to provide a separate
class for each servlet in web.xml.
- - - - -
fbf99e3b by Endi S. Dewata at 2023-07-24T10:57:54-05:00
Add KRATokenAuthenticate
The KRATokenAuthenticate has been added to provide a separate
class for each servlet in web.xml.
- - - - -
0e7dcda3 by Endi S. Dewata at 2023-07-24T10:58:06-05:00
Add KRATokenAuthenticateAdmin
The KRATokenAuthenticateAdmin has been added to provide a separate
class for each servlet in web.xml.
- - - - -
ac3bf722 by Endi S. Dewata at 2023-07-24T14:31:48-05:00
Update KRAHeaderServlet to use @WebServlet
- - - - -
dfff35d1 by Endi S. Dewata at 2023-07-24T14:31:48-05:00
Update KRASearchKeyForRecovery to use @WebServlet
- - - - -
37bb447c by Endi S. Dewata at 2023-07-24T14:31:48-05:00
Update KRASearchKey to use @WebServlet
- - - - -
49fae307 by Endi S. Dewata at 2023-07-24T14:31:48-05:00
Update KRAListRequests to use @WebServlet
- - - - -
49ae2ccc by Endi S. Dewata at 2023-07-24T14:31:48-05:00
Update KRAIndexServlet to use @WebServlet
- - - - -
e8756b0d by Endi S. Dewata at 2023-07-24T14:31:48-05:00
Update KRAGrantRecovery to use @WebServlet
- - - - -
653b920f by Endi S. Dewata at 2023-07-24T14:31:48-05:00
Update KRAJobsAdminServlet to use @WebServlet
- - - - -
2c57f225 by Endi S. Dewata at 2023-07-24T14:31:48-05:00
Update KRAGetCookie to use @WebServlet
- - - - -
c321e7d8 by Endi S. Dewata at 2023-07-24T14:31:48-05:00
Update KRATokenAuthenticate to use @WebServlet
- - - - -
f3e67fa1 by Endi S. Dewata at 2023-07-24T14:31:48-05:00
Update KRATokenAuthenticateAdmin to use @WebServlet
- - - - -
64bf820f by Endi S. Dewata at 2023-07-24T14:57:34-05:00
Add PKIDeployer.import_ds_ca_cert()
The code that imports DS CA cert has been moved into
PKIDeployer.import_ds_ca_cert().
- - - - -
0b18e531 by Endi S. Dewata at 2023-07-24T15:00:07-05:00
Add PKIDeployer.install_cert_chain()
The code that installs the cert chain has been moved into
PKIDeployer.install_cert_chain().
- - - - -
3fbda330 by Endi S. Dewata at 2023-07-24T16:01:28-05:00
Add PKIDeployer.import_clone_pkcs12()
The code that imports PKCS #12 file for cloning has been moved
into PKIDeployer.install_clone_pkcs12().
- - - - -
ea952bd9 by Endi S. Dewata at 2023-07-24T16:01:38-05:00
Add PKIDeployer.import_server_pkcs12()
The code that imports PKCS #12 file for installation with existing
certs has been moved into PKIDeployer.import_server_pkcs12().
- - - - -
fbce9339 by Endi S. Dewata at 2023-07-24T16:17:20-05:00
Replace FlatFileAuth.getPropertyS() with ConfigStore.getString()
- - - - -
915cf6ae by Endi S. Dewata at 2023-07-24T16:17:20-05:00
Replace FlatFileAuth.getPropertyB() with ConfigStore.getBoolean()
- - - - -
cc328d1c by Endi S. Dewata at 2023-07-24T19:58:38-05:00
Fix CASigningUnit.init() and OCSPSigningUnit.init()
The CASigningUnit.init() and OCSPSigningUnit.init() have
been updated to no longer implicitly add new newNickname
config params during startup. Config changes should only
be done explicitly by the admin.
- - - - -
5a9056f5 by Endi S. Dewata at 2023-07-24T22:17:43-05:00
Fix preop.module.token normalization
- - - - -
9d6793e9 by Endi S. Dewata at 2023-07-25T16:53:08-05:00
Drop subsystem.select param
The subsystem.select param in CS.cfg was used to record
whether the subsystem was installed as a new subsystem or
a clone of an existing subsystem, but it does not actually
control any functionality.
Ideally a clone should be indistinguishable from a normal
subsystem, so the param has been removed to minimize the
differences in the CS.cfg.
The pki-server status CLI has been modified to no longer
use the param. An upgrade script has also been added to
remove the param from existing instances.
- - - - -
c3572ac4 by Endi S. Dewata at 2023-07-25T16:53:08-05:00
Update CA clone test
The CA clone test has been updated to compare the CS.cfg files
in the primary, secondary, and tertiary subsystems. They should
be mostly identical except for some params that do change when
cloned.
- - - - -
f216487a by Endi S. Dewata at 2023-07-25T20:47:41-05:00
Clean up dbs.enableRandomSerialNumbers initialization
The dbs.enableRandomSerialNumbers has been modified to have
a default value of 'false', then change to 'true' if the
pki_random_serial_numbers_enable is set to True.
- - - - -
7b971c69 by Endi S. Dewata at 2023-07-25T20:48:04-05:00
Fix <subsystem>.<tag>.tokenname normalization
- - - - -
003bba76 by Chris Kelley at 2023-07-26T13:56:28+01:00
spec: set ExclusiveArch on any OS with java_arches
Fedora builds are not the only ones which no longer build Java for ix86;
Fedora ELN and RHEL 10 are following that as well. This will avoid
builds landing on Java-less architecture builders and thereby failing.
Original patch by Yaakov Selkowitz <yselkowi at redhat.com>
https://github.com/dogtagpki/ldap-sdk/pull/53
- - - - -
eb0aa891 by Endi S. Dewata at 2023-07-26T12:35:04-05:00
Fix missing CSR files in CMC tests
- - - - -
d95b99f1 by Endi S. Dewata at 2023-07-26T12:35:04-05:00
Clean up log messages in PKIDeployer
- - - - -
8f896afd by Endi S. Dewata at 2023-07-26T18:19:06-05:00
Relocate system certs validation
Previously the system certs validation was only executed
in certain installation scenarios. The validation has been
moved such that it will be executed in all installation
scenarios.
- - - - -
4b39aa99 by Endi S. Dewata at 2023-07-26T18:22:11-05:00
Remove PKIDeployer.validate_system_cert()
The PKIDeployer.validate_system_cert() has been replaced with
direct calls to PKISubsystem.validate_system_cert().
- - - - -
d937dc10 by Endi S. Dewata at 2023-07-26T20:37:30-05:00
Merge PKIDeployer.configure_system_cert() into update_system_cert()
- - - - -
b093635c by Endi S. Dewata at 2023-07-27T10:04:23-05:00
Clean up CLI log messages
- - - - -
cb798fce by Endi S. Dewata at 2023-07-28T08:47:17-05:00
Add support for cloning with CSR files
Previously during cloning pkispawn would retrieve database params
and system cert params (i.e. <subsystem>.<tag>.*) from the master.
However, the clone actually already has most of these params (from
pkispawn config file and PKCS #12 file) except for the CSRs (i.e.
<subsystem>.<tag>.certreq).
The code in PKIDeployer.setup_database() that retrieves the params
from the master has been modified to retrieve only the database
params and the CSRs (unless the clone already has the them). In
the future it might be possible to not retrieve anything from the
master at all.
The configuration.py has been modified such that the code that
imports the certs and CSRs from files (if provided) will run in
all cases including cloning instead of just in specific cases.
The installation doc has been updated to show the optional steps
for installing CA clone with CSR files.
The test for CA clone has been updated to create the secondary
subsystem without CSR files like before, then create the
tertiary subsystem with CSR files.
- - - - -
01cbe5dd by Marco Fargetta at 2023-08-01T17:12:35+02:00
Enable healthcheck for IPA clone
The healthchecks were disabled for the issue https://pagure.io/freeipa/issue/9099.
This has been fixed in https://github.com/dogtagpki/pki/pull/3901
- - - - -
9e15dade by Endi S. Dewata at 2023-08-01T10:20:08-05:00
Clean up tests for CA with ECC and RSA/PSS
- - - - -
09c3c0b9 by Endi S. Dewata at 2023-08-01T12:46:40-05:00
Update test for CA clone with HSM
The test for CA clone with HSM has been updated to compare the
CS.cfg in the primary, secondary, and tertiary instances. The
test will create the secondary subsystem without CSR files like
before, then create the tertiary subsystem with CSR files.
- - - - -
12d3d64e by Endi S. Dewata at 2023-08-01T16:55:03-05:00
Add test for CA with RSA algorithm
A new test has been added to install CA with a non-default RSA
algorithm verify that the system certs and admin cert use the
same algorithm. The test will also issue an SSL server cert
and verify that the cert uses the same algorithm.
The tests for CA with ECC and RSA/PSS algorithms have also
been updated to perform the same validation.
- - - - -
62228112 by Endi S. Dewata at 2023-08-01T23:12:19-05:00
Add PKIDeployer.import_master_config()
The code in PKIDeployer.setup_database() that imports the config
params from master has been moved into import_master_config().
- - - - -
16a231fe by Endi S. Dewata at 2023-08-01T23:13:36-05:00
Clean up PKIDeployer.import_master_config()
The code in PKIDeployer.import_master_config() that checks the
pki_clone param has been moved out of the method.
- - - - -
a972f524 by Chris Kelley at 2023-08-02T07:34:57+01:00
Replace deprecated ssl.PROTOCOL_TLS in pki/client.py
Resolves #4512
- - - - -
8a8f1538 by Endi S. Dewata at 2023-08-02T13:44:22-05:00
Update tests for CA with non-default algorithms
The tests for CA with non-default algorithms (i.e. RSA, RSA/PSS,
ECC) have been modified to check the default signing algorithm
params in CS.cfg.
- - - - -
c6978c05 by Marco Fargetta at 2023-08-03T10:27:43+02:00
Health check verify all clones
`pki-healthcheck` stop its activity in case a clone is not working and
report the error. If multiple clones are configured the check should go
ahead to verify the other clones.
With this fix all clones are verified during the health check.
- - - - -
79e13b50 by Endi S. Dewata at 2023-08-03T14:01:18-05:00
Add PKIDeployer.request_ranges()
The code that requests serial number ranges from the cloning
master in PKIDeployer.import_master_config() has been moved
to request_ranges().
- - - - -
dbab6aca by Endi S. Dewata at 2023-08-03T19:25:46-05:00
Refactor PKIDeployer.import_master_config()
The PKIDeployer.import_master_config() has been modified such
that it will be executed during cloning, but it will only
retrieve and validate database config params from the master
if they are needed to set up DS replication.
- - - - -
68bcb5eb by Endi S. Dewata at 2023-08-04T09:39:38-05:00
Add test for cert enrollment with caDirUserCert profile
A new test has been added to validate cert enrollment
with caDirUserCert profile using XML and JSON.
https://github.com/dogtagpki/pki/wiki/Certificate-Enrollment-with-Directory-Authenticated-Profile
- - - - -
3d9fc76f by Endi S. Dewata at 2023-08-04T13:12:40-05:00
Drop Tomcat JSS dependency
Tomcat JSS 8.5 has been merged into JSS 5.5 so all references
to Tomcat JSS have been updated accordingly. An upgrade script
has been added to update existing instances.
- - - - -
198ca5d9 by Endi S. Dewata at 2023-08-04T16:35:30-05:00
Add test for CA clone with shared DS
A new test has been added to install multiple CA instances
sharing the same DS instance. This configuration can be used
to create CA replicas connected to a single load balancer
which will to distribute the load to multiple DS replicas.
A new GH workflow has been added for CA clone tests since
a workflow can only call up to 20 reusable workflows:
https://docs.github.com/en/actions/using-workflows/reusing-workflows
- - - - -
22a1b3db by Christina Fu at 2023-08-07T11:08:00-07:00
Bug2228209-pkidbuser-wrong-o-in-pkispawn
Ths patch addresses the issue where by default non-CA instances are
created with hardcoded ending "-CA":
pki_share_dbuser_dn=uid=pkidbuser,ou=people,o=%(pki_instance_name)s-CA
and
pki_ds_base_dn=o=%(pki_instance_name)s-<subsystem type>
where subsystem type is TKS, OCSP, TKS, or KRA,
which effictive makes the 'o' component of pki_share_dbuser_dn
not matching with that of the pki_ds_base_dn.
fixes https://bugzilla.redhat.com/show_bug.cgi?id=2228209
- - - - -
a69b35d8 by Endi S. Dewata at 2023-08-07T21:42:16-05:00
Update NSSExtensionGenerator.createSANExtension()
The NSSExtensionGenerator.createSANExtension() has been
updated to exclude reserved keywords from the result.
- - - - -
66cc88f5 by Endi S. Dewata at 2023-08-08T08:40:41-05:00
Fix incorrect default signing algorithm
The PKIDeployer.update_system_cert() was incorrectly setting
the default signing algorithm param in CS.cfg for all certs
using the key algorithm param in pkispawn which could cause
a problem if the key algorithm and signing algorithm are not
the same.
The code has been modified to set the param properly using
the signing algorithm param in pkispawn for CA/OCSP/audit
signing certs only. This param is not used by other certs so
it does not need to be set for those certs.
The pki-server ca-config-show CLI has been updated to return
a non-zero code if the param being requested doesn't exist.
The tests have been updated to use different key and signing
algorithms.
https://github.com/dogtagpki/pki/issues/4518
- - - - -
d8ace16f by Endi S. Dewata at 2023-08-08T17:28:37-05:00
Restore default value for pki_share_db
In commit 22a1b3dbbbf4003d50476a1bbf0629a5beae4405 the default
values for pki_share_db for non-CA subsystems were changed to
False since subsystems on separate instances will not share the
same database user, but apparently it causes a problem during
TPS installation with a shared instance.
To avoid changing the behavior, the default values have been
restored to True. This param can still be overridden in
pkispawn config as needed.
Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2228209
- - - - -
6cc9e0ee by Endi S. Dewata at 2023-08-09T19:23:36-05:00
Clean up PKIDeployer.setup_system_cert()
The PKIDeployer.setup_system_cert() has been modified to use
pki_issuing_ca param directly.
- - - - -
64888002 by Endi S. Dewata at 2023-08-09T19:25:35-05:00
Clean up PKIDeployer.setup_admin_cert()
The PKIDeployer.setup_admin_cert() has been modified to use
pki_issuing_ca param directly.
- - - - -
cd2f1a62 by Endi S. Dewata at 2023-08-09T19:58:08-05:00
Clean up PKIDeployer.finalize_kra()
The PKIDeployer.finalize_kra() has been modified to use
pki_issuing_ca param directly.
- - - - -
b0286f62 by Endi S. Dewata at 2023-08-09T19:58:09-05:00
Clean up PKIDeployer.finalize_ocsp()
The PKIDeployer.finalize_ocsp() has been modified to use
pki_issuing_ca param directly.
- - - - -
480c835a by Endi S. Dewata at 2023-08-09T20:08:42-05:00
Remove unused preop issuing CA params
- - - - -
1c07ef8d by Endi S. Dewata at 2023-08-10T09:10:45-05:00
Add test for subordinate CA clone
A new test has been added to test installing a subordinate CA
(using external CA method) then clone it into another instance.
The test will also compare the CS.cfg, the users, and the certs
in these instances to ensure that they are (mostly) identical.
The hierarchy.select param is incorrectly set as Root instead
of Subordinate in the clone. This will be addressed separately
later.
- - - - -
3723b0c4 by Endi S. Dewata at 2023-08-10T09:24:51-05:00
Add test for CA clone with replicated DS
A new test has been added to test installing CA with DS,
cloning the DS, then cloning the CA using the existing
DS clone.
This process allows DS cloning to happen separately from
CA cloning which could prevent pkispawn from timing out
due to long DS cloning process with large database.
https://github.com/dogtagpki/pki/wiki/Installing-CA-Clone-with-Replicated-DS
- - - - -
e620ae7d by Endi S. Dewata at 2023-08-10T10:41:20-05:00
Consolidate SystemCertData.token initialization
The code that initializes SystemCertData.token has been
consolidated into PKIDeployer.create_system_cert_info().
- - - - -
12fbe56b by Endi S. Dewata at 2023-08-10T16:59:36-05:00
Update pki pkcs7-export
The pki pkcs7-export has been modified to support redirecting
the output to the standard output and to provide an option to
specify the output format.
- - - - -
5dbd1a21 by Endi S. Dewata at 2023-08-10T19:51:30-05:00
Add NSSDatabase.export_pkcs7()
The NSSDatabase.export_pkcs7() has been added to export a cert
chain from NSS database into PKCS #7 data.
- - - - -
31fbd14c by Endi S. Dewata at 2023-08-10T20:21:44-05:00
Move CertUtil to org.dogtagpki.util.cert
- - - - -
aef96c7e by Endi S. Dewata at 2023-08-10T22:05:56-05:00
Convert IDBObj implementations into DBRecord subclasses
- - - - -
b36c32e0 by Endi S. Dewata at 2023-08-11T10:34:22-05:00
Add pki nss-cert-find --cert option
The pki nss-cert-find has been updated to provide an option to
search for a cert in NSS database based on an existing cert file.
This can be used to check whether the cert has been imported into
the NSS database and to get the nickname and trust flags assigned
to the cert.
- - - - -
e738cf74 by Endi S. Dewata at 2023-08-11T10:59:17-05:00
Add PKIDeployer.retrieve_cert_chain()
The code that retrieves the cert chain from a remote CA has
been consolidated into PKIDeployer.retrieve_cert_chain().
- - - - -
9c46b74b by Endi S. Dewata at 2023-08-11T11:46:38-05:00
Clean up cert chain retrieval
The code that retrieves the cert chain for various installation
scenarios has been reorganized which removes the dependency on
hierarcy.select param.
- - - - -
fad366b6 by Endi S. Dewata at 2023-08-11T19:34:09-05:00
Update PKIDeployer to validate pki_cert_chain_path
PKIDeployer.install_cert_chain() and import_cert_chain() have
been modified to validate that the specified cert chain exists.
- - - - -
9f648a7d by Endi S. Dewata at 2023-08-14T09:26:37-05:00
Remove hierarchy.select param
The hierarchy.select param stores a static information about
the CA hierarchy (root vs. subordinate) which was set during
installation but there is no process to update it in case
the CA is converted from root to subordinate or vice versa.
Also, the param is incorrectly set to root when cloning a
subordinate CA.
Because of these issues the param is unreliable, so it has
been removed from new and existing instances. The pki-server
status CLI has also been updated to no longer show the CA
hierarchy.
If necessary, the CA hierarchy can be determined by checking
the CA signing cert. If it is self-signed that means it is a
root CA.
- - - - -
e61817a7 by Endi S. Dewata at 2023-08-14T13:39:43-05:00
Add test for subordinate CA clone with HSM
A new test has been added to install a subordinate CA with HSM,
clone the HSM, then create a clone of the subordinate CA with
the cloned HSM.
There is a known issue: the OCSP signing cert and subsystem
cert are missing from the internal token on the clone, but it
does not actually cause a problem since the certs do exist on
the HSM.
- - - - -
e29314ec by Endi S. Dewata at 2023-08-14T15:39:30-05:00
Fix servlet name for GetApprovalStatus
In commit f91fc5c1ba8ff549f54c631db1c0e83ac5f01cb6 the
GetApprovalStatus was updated to use @WebServlet but the
servlet name was not set correctly and conflicted with
GenerateKeyPairServlet which was causing a problem for
TPS token enrollment with server-side key generation, but
for some reason the CI did not fail until recently.
Now the servlet name has been fixed so the problem should
no longer happen.
- - - - -
098441ce by Endi S. Dewata at 2023-08-14T19:58:38-05:00
Update log messages in TPSProcessor
- - - - -
f54fc99a by Endi S. Dewata at 2023-08-15T08:53:30-05:00
Move pki nss-cert-find --cert option to pki nss-cert-show
The pki nss-cert-find --cert option has been moved into pki
nss-cert-show (and renamed to --cert-file) since it can only
find a single cert instead of a collection. If the cert is not
found the command will return a non-zero code, so it will be
easier to use for automation.
- - - - -
28e945b1 by Chris Kelley at 2023-08-16T13:02:42+02:00
For unknown certificates OCSP should have unknown CertStatus
- - - - -
40ed6ae9 by Chris Kelley at 2023-08-16T13:02:42+02:00
For unknown certificates OCSP should have unknown CertStatus (part 2)
The CA's internal OCSP fails to handle certs issued by an unknown CA.
There is code in the CA's validation to handle that scenario but that
validation is never triggered as the request handling code that wraps it
considers not knowing the origin CA to be an error condition.
The code is changed to allow the validating CA to proceed even if the
origin CA is unknown, reporting Unknown for the CertStatus, while
delegating to the origin CA if it is found.
- - - - -
f8465005 by Marco Fargetta at 2023-08-16T13:02:42+02:00
Internal OCSP CA identification using request hash
In case of multiple CAs the correct one was selected using the first
certificate. This could provide inconsistent. Now the selection is based
on the request issuer name.
Additionally, the output has been made consistent with the external OCSP
for all the possibilities of subject and issuers.
- - - - -
180037b9 by Christina Fu at 2023-08-16T13:02:42+02:00
Bug2221818-ocsp-unknownCA-addendum
a couple things:
- respond with Unknown when CA can't find cert in its db
- added safety net Exception to return Unknown
- minor debug message when CA signs an object that's not a cert
fixes https://bugzilla.redhat.com/show_bug.cgi?id=2221818
- - - - -
a96c950c by Christina Fu at 2023-08-16T13:02:42+02:00
Bug2221818-ocsp-unknownCA-addendum2
minor adjustment for Exception and debug messages.
- - - - -
c39ba6a9 by Marco Fargetta at 2023-08-16T13:02:42+02:00
Fix OCSP verification of requests hashes
OCSP requests have the certificate serial number, the hash of CA DN and
the hash of the CA public key. According to the specification, in order
to recognise a request both hashes have to match but the current implementation
was verifying only the public key hash.
This commit add a check on the other hash of the request.
- - - - -
21167811 by Marco Fargetta at 2023-08-16T13:02:42+02:00
FIx OCSP DefStore for unknown CA error
- - - - -
0c307dbd by Marco Fargetta at 2023-08-16T13:02:42+02:00
Fix OCSP ldap responder output with correct logic
The OCSP responder was failing if CA or CRL were not found. This has been
modified so the responder will provide an `unknown` result in these
cases.
- - - - -
39415a3a by Marco Fargetta at 2023-08-16T13:02:42+02:00
Improve exception handling for OCSP validation
- - - - -
4d93c720 by Endi S. Dewata at 2023-08-16T13:14:52-05:00
Add log messages in FileConfigStorage
- - - - -
6c45bb0d by Endi S. Dewata at 2023-08-16T20:29:10-05:00
Simplify PKIDeployer.finalize_kra()
- - - - -
4d7590a2 by Endi S. Dewata at 2023-08-16T20:29:14-05:00
Simplify PKIDeployer.finalize_ocsp()
- - - - -
fd108d20 by Endi S. Dewata at 2023-08-16T21:07:38-05:00
Remove unused preop.clone.pkcs7
- - - - -
23739304 by Endi S. Dewata at 2023-08-16T21:47:23-05:00
Add pki.nssdb.internal_token()
The internal_token() has been added to replace normalize_token()
in boolean expressions since it's more intuitive to use.
- - - - -
05935e0d by Endi S. Dewata at 2023-08-17T00:02:19-05:00
Update cert and CSR path validation
The code that imports certs and CSRs in PKIDeployer has been
updated to no longer ignore invalid paths.
https://github.com/freeipa/freeipa/pull/6951
- - - - -
59cf404c by Marco Fargetta at 2023-08-17T19:01:31+02:00
Modify init order for OCSP subsystem
The init order for OCSP is modified to allow CRL retrieval before
creating connection with DS or other services. Secure`connections will be
verified against the CRL.
Solve RHCS-4262
- - - - -
9c488a5e by Marco Fargetta at 2023-08-17T19:01:31+02:00
Add callback for CRL validation at application level
Add new field in CMS for a callback validation of certificate
instantiated by PKISocketFactory.
This is useful for OCSP where the OCSP protocol cannot be enabled and
the verification is done on CRLs.
Solve RHCS-4262
- - - - -
68121d1b by Marco Fargetta at 2023-08-17T19:01:31+02:00
Make crl check for connection optional
Add a new parameter to enable the crl check for OCSP connection when
acting as client. The new parameter is
`ocsp.store.ldapStore.checkSubsystemConnection` and its default value is
`false`. When set to `true` connection certificate are verified using
the crl stored in the LDAP.
- - - - -
7f1e896b by Marco Fargetta at 2023-08-17T19:01:31+02:00
Add crl check for OCSP acting as server
When OCSP is acting as server certificate can be verified using CRL
internally stored.
To verify the certificates the `LDAPStore` has to be enabled with the
variable `ocsp.store.ldapStore.checkSubsystemConnection` and the
variable `auths.revocationChecking.enabled` both set to true.
Solve RHCS-4262
- - - - -
fb555d88 by Marco Fargetta at 2023-08-17T19:01:31+02:00
Move callback reference from CMS to CMSEngine
Socket callback moved to CMSEngine to avoid dependencies on global
variables.
- - - - -
0177b640 by Marco Fargetta at 2023-08-17T19:01:31+02:00
OCSP default CRL check and CA cert validation
The parameter `ocsp.store.ldapStore.checkSubsystemConnection` default
value has been modified to `true` so when LDAPStore is used certificates
are verified against the CRL.
Additionally, during the certificate verification the certificate signer
is verified with the CA certificate providing the CRL to be sure it is
the real issuer.
- - - - -
14c0e9ca by Marco Fargetta at 2023-08-17T19:01:31+02:00
Rename checkSubsystemConnection to validateConnCertWithCRL
The option `ocsp.store.ldapStore.validateConnCertWithCRL` enables the
revocation verification of peer certificates using the CRL stored in the LDAP
shared with the CA.
When it is set to `true` (default value), the peer certificate of all the outcome connections from the OCSP subsystem are verified with the CRL.
If the option `auths.revocationChecking.enabled` is also set to `true` the peer certificate ot all the income connections to the OCSP subsystem are verified with the CRL.
- - - - -
31e4d5f7 by Marco Fargetta at 2023-08-17T19:01:31+02:00
Use AKI/SKI to match peer certificate with CA CRL
Identification of CRL issuing point done by matching Authority Key
Identifier with Subject Key Identifier instead of DN matching.
This should make more reliable the check because not affected of
encoding or format changes in the DN.
- - - - -
435336c1 by Marco Fargetta at 2023-08-17T19:01:31+02:00
Add comment for the option ocsp.store.ldapStore.validateConnCertWithCRL
- - - - -
2f13276c by Marco Fargetta at 2023-08-17T19:01:31+02:00
Modify local variable names
- - - - -
fc2f203c by Marco Fargetta at 2023-08-17T19:01:31+02:00
Update log message for revoked certificate
- - - - -
eca19577 by Marco Fargetta at 2023-08-17T19:01:31+02:00
Modify the callback location
Due to refactoring the engine object is not accessible using static
reference from outside the declaring package. Therefore the callback
reference have been stored globally in the `CMSEngine` class
- - - - -
3973db71 by Marco Fargetta at 2023-08-17T19:01:31+02:00
Improve OCSP exception handling
Add stack trace for error logs when they are generated from internal
error
- - - - -
05ff27e3 by Marco Fargetta at 2023-08-17T19:01:31+02:00
Move the callback to PKISocketFactory and fix startup
Moving the callback to `PKISocketFactory` there is no need to have store
it in a static variable. However, only OCSPEngine instances have a valid
value so no other instances are used.
The startup order has been fixed.
- - - - -
87c2c07c by Endi S. Dewata at 2023-08-17T12:44:35-05:00
Add PKIDeployer.instance
The PKIDeployer.instance attribute has been added to store the
instance used for deployment.
- - - - -
65745d5f by Endi S. Dewata at 2023-08-17T12:44:35-05:00
Update PKIDeployer.create_server_xml() to use self.instance
- - - - -
a387de34 by Endi S. Dewata at 2023-08-17T12:44:35-05:00
Update PKIDeployer.update_external_certs_conf() to use self.instance
- - - - -
d865f1f5 by Endi S. Dewata at 2023-08-17T12:44:35-05:00
Update PKIDeployer.init_server_nssdb() to use self.instance
- - - - -
9e4c5145 by Endi S. Dewata at 2023-08-17T14:02:53-05:00
Update code for importing existing certs to use PKIDeployer.instance
- - - - -
0fab585b by Endi S. Dewata at 2023-08-17T14:02:53-05:00
Update code for verifying subsystems to use PKIDeployer.instance
- - - - -
4e3941b7 by Endi S. Dewata at 2023-08-17T14:02:53-05:00
Update code for generating cert requests to use PKIDeployer.instance
- - - - -
afd345e2 by Endi S. Dewata at 2023-08-17T15:15:17-05:00
Update code for setting up security domain to use PKIDeployer.instance
- - - - -
9b28f0ff by Endi S. Dewata at 2023-08-17T15:34:48-05:00
Add PKIDeployer.update_sslserver_cert_nickname()
The code that updates the SSL server cert nickname has been
moved into PKIDeployer.update_sslserver_cert_nickname().
- - - - -
8629df53 by Endi S. Dewata at 2023-08-17T21:13:53-05:00
Update code for setting up SELinux to use PKIDeployer.instance
- - - - -
bd968c5b by Endi S. Dewata at 2023-08-17T21:20:29-05:00
Update code for setting up system certs to use PKIDeployer.instance
- - - - -
7c2386dd by Endi S. Dewata at 2023-08-17T21:20:29-05:00
Update code for setting up users to use PKIDeployer.instance
- - - - -
30e274da by Endi S. Dewata at 2023-08-17T21:22:42-05:00
Update code for setting up connectors to use PKIDeployer.instance
- - - - -
3f07e890 by Endi S. Dewata at 2023-08-17T21:43:18-05:00
Update code for setting up shared secret to use PKIDeployer.instance
- - - - -
7495553e by Endi S. Dewata at 2023-08-17T21:43:40-05:00
Update code for finalizing installation to use PKIDeployer.instance
- - - - -
0272d812 by Endi S. Dewata at 2023-08-21T13:39:38-05:00
Add pki-server ca-crl-show
The pki-server ca-crl-show command has been added to make it
easier to inspect CRL configuration.
- - - - -
09ebf933 by Endi S. Dewata at 2023-08-21T13:39:38-05:00
Add pki-server ca-crl-ip-find/show
The pki-server ca-crl-ip-find/show commands have been added to
make it easier to inspect CRL issuing point configuration.
- - - - -
6fdb0aaa by Endi S. Dewata at 2023-08-21T14:21:54-05:00
Add pki nss-cert-show --output-format option
The pki nss-cert-show has been modified to provide an option
to return the cert info in JSON format to make it easier to
parse using other tools/languages.
The NSSCertInfo has been added to define the mapping between
POJO and JSON.
- - - - -
953b7ef6 by Endi S. Dewata at 2023-08-21T17:56:09-05:00
Add wrapper methods for ca.crl.pageSize
- - - - -
1dd7e4f9 by Endi S. Dewata at 2023-08-21T17:56:11-05:00
Add wrapper methods for ca.crl.<name>.startingCrlNumber
- - - - -
d60e607d by Endi S. Dewata at 2023-08-21T17:56:12-05:00
Add wrapper methods for ca.ocspUseCache
- - - - -
8cbdd755 by Endi S. Dewata at 2023-08-21T17:56:14-05:00
Add wrapper methods for ca.ocspUseCacheIssuingPointId
- - - - -
cb56b727 by Endi S. Dewata at 2023-08-21T17:56:16-05:00
Add wrapper methods for ca.ocspUseCacheCheckDeltaCache
- - - - -
ace7dd99 by Endi S. Dewata at 2023-08-21T17:56:19-05:00
Add wrapper methods for ca.ocspUseCacheIncludeExpiredCerts
- - - - -
b1f85dbe by Endi S. Dewata at 2023-08-23T12:40:31-05:00
Add pki-server ca-crl-ip-mod
The pki-server ca-crl-ip-mod has been added to allow updating
multiple CRL issuing point params at once.
- - - - -
72c635b4 by Endi S. Dewata at 2023-08-23T16:10:25-05:00
Update ProfileInput.init() to use ProfileInputConfig
- - - - -
24ca4126 by Endi S. Dewata at 2023-08-23T16:12:51-05:00
Update ProfileOutput.init() to use ProfileOutputConfig
- - - - -
a9a9d995 by Endi S. Dewata at 2023-08-23T16:18:07-05:00
Rename ProfilePoliciesConfig to ProfilePolicySetsConfig
- - - - -
e7bdaaa7 by Endi S. Dewata at 2023-08-23T16:33:36-05:00
Add ProfilePolicySetConfig to wrap profile policy set config
- - - - -
5f746101 by Endi S. Dewata at 2023-08-23T16:48:13-05:00
Add ProfilePolicyConfig to wrap profile policy config
- - - - -
950b0b7a by Marco Fargetta at 2023-08-24T16:46:30+02:00
Add additional tests for OCSP
Added tests for non existing certificate and non managed CA.
Additionally, fixed a condition which was not working properly.
- - - - -
a426aa51 by Marco Fargetta at 2023-08-24T16:46:30+02:00
Add CI test for OCSP self crl check
When LDAP store is used the OCSP can be configured to check certificate
using the stored CRL. This is implemented in PR #4545.
- - - - -
872a9254 by Marco Fargetta at 2023-08-24T17:06:26+02:00
Remove unused certificate from ansible CI
- - - - -
c5dd6631 by Endi S. Dewata at 2023-08-24T12:04:28-05:00
Add pki-server <subsystem>-user-mod --password
The pki-server <subsystem>-user-mod has been updated to provide
a way to change the user password. This could be used to restore
access to PKI server in case the current password is lost or the
user cert has expired.
The UGSubsystem.modifyUser() has been modified to remove the
userPassword attribute from the user record if the password is
blank.
The test for admin user has been updated to validate password
change and password removal.
- - - - -
6a20aa46 by Endi S. Dewata at 2023-08-24T12:16:07-05:00
Convert IPolicyProcessor into PolicyProcessor class
- - - - -
2a32c7af by Christina Fu at 2023-08-29T09:56:28+02:00
Bug2229930-crlCertValid-leaf-only
This patch addresses the issue where OCSPEngine:crlCertValid attempts to
verify up the chain and failed because when using CRL to validate certs,
the CAs up the chain are issued by different CAs.
OCSPEngine:crlCertValid should be limited to leaf certs validation only.
fixes https://bugzilla.redhat.com/show_bug.cgi?id=2229930
- - - - -
45b59b55 by Marco Fargetta at 2023-08-29T15:01:36+02:00
Read IPs from SSLEngine session
When SSLEngine is used IPs cannot be retrieved from the socket or stream
proxies so they are stored into the SSLEngine session.
This is an extension to the standard because the SSLEngine should be
unaware of the underlying communication but it is needed for the audit.
- - - - -
933d47f0 by Endi S. Dewata at 2023-09-05T21:11:36-05:00
Add LdapConnFactory.auditor
- - - - -
c4452c0c by Endi S. Dewata at 2023-09-05T21:36:02-05:00
Add LdapConnFactory.socketListener
- - - - -
8e1f3a04 by Endi S. Dewata at 2023-09-05T21:37:14-05:00
Add LdapConnFactory.approvalCallback
- - - - -
8daaea91 by Endi S. Dewata at 2023-09-05T21:37:15-05:00
Refactor CAProfileImportCLI to use LdapBoundConnFactory
- - - - -
0ac7a5c1 by Endi S. Dewata at 2023-09-05T21:37:15-05:00
Refactor LDAPConfigStorage to use LdapBoundConnFactory
- - - - -
a375c3e4 by Endi S. Dewata at 2023-09-06T16:16:26-05:00
Refactor RequestRepository.listRequestsByFilter()
Previously the RequestRepository.listRequestsByFilter() would
create a DBSession object, perform a search operation, close the
session, then return the DBSearchResults in a RequestList object
to the caller.
The problem is the DBSearchResults can only be used by the caller
as long as the database connection is still open, which is not
guaranteed once the session is closed.
To avoid potential issues, all variants of the method have been
updated to store the search results into a Collection while the
session is still active.
- - - - -
ce120d4d by Endi S. Dewata at 2023-09-06T16:22:19-05:00
Replace BASE64_OS with BASE_IMAGE
- - - - -
a1e6a3fb by Marco Fargetta at 2023-09-07T19:47:44+02:00
Fix unspecified revoke requests
This blocks IPA tests
- - - - -
10cf7682 by Endi S. Dewata at 2023-09-07T14:01:04-05:00
Remove unused RequestListByStatus
- - - - -
c66309e8 by Endi S. Dewata at 2023-09-07T14:02:01-05:00
Remove unused RequestQueue.listRequests()
- - - - -
93a07c91 by Endi S. Dewata at 2023-09-07T14:02:02-05:00
Refactor RequestQueue.findRequestBySourceId()
The RequestQueue.findRequestBySourceId() has been updated to
call RequestRepository.listRequestsByFilter() and return a
Collection<RequestRecord>.
- - - - -
5d3e4f7c by Endi S. Dewata at 2023-09-07T14:02:03-05:00
Refactor RequestQueue.listRequestsByStatus()
The RequestQueue.listRequestsByStatus() has been updated to
call RequestRepository.listRequestsByFilter() and return a
Collection<RequestRecord>.
- - - - -
aa7255c0 by Endi S. Dewata at 2023-09-07T14:02:04-05:00
Remove unused SearchEnumeration
- - - - -
9025ebad by Endi S. Dewata at 2023-09-07T14:02:05-05:00
Remove unused RequestList
- - - - -
e9720b2f by Endi S. Dewata at 2023-09-08T12:19:23-05:00
Add PublishingPublisherPluginsConfig
The PublishingPublisherPluginsConfig has been added to encapsulate
ca.publish.publisher.impl.* params.
- - - - -
6e9cd6d6 by Endi S. Dewata at 2023-09-08T12:19:25-05:00
Add PublishingPublisherInstancesConfig
The PublishingPublisherInstancesConfig has been added to
encapsulate ca.publish.publisher.instance.* params.
- - - - -
2ceb635c by Endi S. Dewata at 2023-09-08T12:24:03-05:00
Update log messages in OCSPPublisher
- - - - -
62442ccd by Endi S. Dewata at 2023-09-08T13:11:08-05:00
Update log messages in AddCRLServlet
- - - - -
650d76da by Endi S. Dewata at 2023-09-08T13:11:08-05:00
Update log messages in OCSPServlet
- - - - -
eb7fc671 by Endi S. Dewata at 2023-09-08T13:11:08-05:00
Update log messages in PKIRealm and ProxyRealm
- - - - -
4e3b4fd4 by Endi S. Dewata at 2023-09-08T15:57:45-05:00
Fix exception handling in LdapCrlPublisher
- - - - -
92bcc030 by Endi S. Dewata at 2023-09-08T15:57:49-05:00
Fix exception handling in DefStore
- - - - -
d7162de2 by Endi S. Dewata at 2023-09-08T18:20:28-05:00
Add OCSPACLAdminServlet
- - - - -
2e6d1e5f by Endi S. Dewata at 2023-09-08T18:20:30-05:00
Add OCSPJobsAdminServlet
- - - - -
05b80a01 by Endi S. Dewata at 2023-09-08T18:20:32-05:00
Add OCSPUsrGrpAdminServlet
- - - - -
5857e9ff by Endi S. Dewata at 2023-09-08T18:20:33-05:00
Add OCSPLogAdminServlet
- - - - -
a319b65e by Endi S. Dewata at 2023-09-08T18:20:35-05:00
Add OCSPAuthAdminServlet
- - - - -
4360f228 by Endi S. Dewata at 2023-09-08T18:20:36-05:00
Add OCSPGetOCSPInfo
- - - - -
1a5df787 by Endi S. Dewata at 2023-09-08T18:30:28-05:00
Add OCSPPortsServlet
- - - - -
3fb5c2bb by Endi S. Dewata at 2023-09-08T18:41:13-05:00
Add OCSPGetConfigEntries
- - - - -
5f146d22 by Endi S. Dewata at 2023-09-08T19:08:14-05:00
Add OCSPOCSPServlet
- - - - -
8ecbb989 by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update OCSPACLAdminServlet to use @WebServlet
- - - - -
5f35fa04 by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update OCSPJobsAdminServlet to use @WebServlet
- - - - -
c22a08f6 by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update OCSPUsrGrpAdminServlet to use @WebServlet
- - - - -
d0786439 by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update OCSPCMSAdminServlet to use @WebServlet
- - - - -
43d226e3 by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update OCSPLogAdminServlet to use @WebServlet
- - - - -
b6825a27 by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update OCSPAuthAdminServlet to use @WebServlet
- - - - -
f80954d8 by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update OCSPAdminServlet to use @WebServlet
- - - - -
f2289b39 by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update OCSPGetOCSPInfo to use @WebServlet
- - - - -
80354bed by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update ListCAServlet to use @WebServlet
- - - - -
85bae2bf by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update AddCRLServlet to use @WebServlet
- - - - -
24aa6278 by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update OCSPPortsServlet to use @WebServlet
- - - - -
91b0bbeb by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update CheckCertServlet to use @WebServlet
- - - - -
68c3a50c by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update OCSPGetConfigEntries to use @WebServlet
- - - - -
07ba4702 by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update AddCAServlet to use @WebServlet
- - - - -
31bb9706 by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update RemoveCAServlet to use @WebServlet
- - - - -
753a2e4d by Endi S. Dewata at 2023-09-11T10:04:15-05:00
Update OCSPOCSPServlet to use @WebServlet
- - - - -
4dc13f3d by Endi S. Dewata at 2023-09-11T14:38:33-05:00
Remove unnecessary blank line in CRL
The OCSPPublisher has been modified to remove the extra blank
line in the PEM CRL.
- - - - -
200a2cbd by Endi S. Dewata at 2023-09-12T09:19:02-05:00
Update test for IPA clone
The test for IPA clone has been modified to change the renewal
master and CRL master and also check both IPA and PKI configs
in primary and secondary servers.
There are some known issues:
https://pagure.io/freeipa/issue/9432
- - - - -
eb492a9e by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPReadCheckCertPage
- - - - -
4be35241 by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPIndexServlet
- - - - -
07345490 by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPReadAddCRLPage
- - - - -
44086d8f by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPReadAddCAPage
- - - - -
15a468f9 by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPHeaderServlet
- - - - -
73ef4052 by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPMainPageServlet
- - - - -
cb8521fa by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPDownloadPKCS12
- - - - -
50a842af by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPGetStatus
- - - - -
9905c162 by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPUpdateDomainXML
- - - - -
5eb41b8c by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPAdminUpdateDomainXML
- - - - -
8a1a0a9d by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPGetCookie
- - - - -
841d9aaf by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPTokenAuthenticate
- - - - -
06c0ba03 by Endi S. Dewata at 2023-09-12T15:06:40-05:00
Add OCSPTokenAuthenticateAdmin
- - - - -
c1b0e41d by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPReadCheckCertPage to use @WebServlet
- - - - -
46cb9b93 by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPIndexServlet to use @WebServlet
- - - - -
d73c664d by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPReadAddCRLPage to use @WebServlet
- - - - -
aad83e00 by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPReadAddCAPage to use @WebServlet
- - - - -
72fc0afb by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPHeaderServlet to use @WebServlet
- - - - -
e3d55b19 by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPMainPageServlet to use @WebServlet
- - - - -
32319d93 by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPDownloadPKCS12 to use @WebServlet
- - - - -
fcd6536b by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPGetStatus to use @WebServlet
- - - - -
a61c0a32 by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPUpdateDomainXML to use @WebServlet
- - - - -
b68db1cd by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPAdminUpdateDomainXML to use @WebServlet
- - - - -
7c298e46 by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPGetCookie to use @WebServlet
- - - - -
49e53dda by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPTokenAuthenticate to use @WebServlet
- - - - -
b68e5d3f by Endi S. Dewata at 2023-09-13T10:47:55-05:00
Update OCSPTokenAuthenticateAdmin to use @WebServlet
- - - - -
85e69410 by Endi S. Dewata at 2023-09-14T09:21:37-05:00
Add TKSUsrGrpAdminServlet
- - - - -
087356db by Endi S. Dewata at 2023-09-14T09:21:39-05:00
Add TKSLogAdminServlet
- - - - -
b169bf7d by Endi S. Dewata at 2023-09-14T09:21:40-05:00
Add TKSAuthAdminServlet
- - - - -
2536c72b by Endi S. Dewata at 2023-09-14T10:19:59-05:00
Add TKSJobsAdminServlet
- - - - -
b2c2a7fe by Endi S. Dewata at 2023-09-14T10:20:01-05:00
Add TKSACLAdminServlet
- - - - -
4abe79a8 by Endi S. Dewata at 2023-09-14T10:20:02-05:00
Add TKSRegisterUser
- - - - -
757f2691 by Endi S. Dewata at 2023-09-14T10:20:05-05:00
Add TKSEncryptData
- - - - -
501c150c by Endi S. Dewata at 2023-09-14T10:20:06-05:00
Add TKSCreateKeySetData
- - - - -
660ecbef by Endi S. Dewata at 2023-09-14T10:20:08-05:00
Add TKSSessionKey
- - - - -
49572cd3 by Endi S. Dewata at 2023-09-14T10:20:10-05:00
Add TKSRandomData
- - - - -
67e7d414 by Endi S. Dewata at 2023-09-14T10:20:11-05:00
Add TKSPortsServlet
- - - - -
4f6c4fa1 by Endi S. Dewata at 2023-09-14T10:20:13-05:00
Add TKSMainPageServlet
- - - - -
5bf09400 by Endi S. Dewata at 2023-09-14T10:20:15-05:00
Add TKSDownloadPKCS12
- - - - -
35beb87b by Endi S. Dewata at 2023-09-14T10:20:17-05:00
Add TPSGetConfigEntries
- - - - -
02148f2d by Endi S. Dewata at 2023-09-14T10:20:19-05:00
Add TKSGetStatus
- - - - -
ed8e7f59 by Endi S. Dewata at 2023-09-14T13:24:47-05:00
Fix race condition during ACME authz polling
Previously after creating an ACME order the client would call
ACMEAuthorizationService to poll the status of the authorization.
Initially the authorization did not have any challenges, so this
service would create the challenges for it. In subsequent calls
this service would just return the status of the authorization.
When the client completes a challenge, the ACMEChallengeProcessor
will update the authorization by removing the old challenges and
adding the new ones. Since these operations are not atomic there
is a risk that after the old challenges are removed the client
will call the ACMEAuthorizationService and create new challenges
which will never be completed by the client.
To avoid the problem, the code that creates the challenges has
been moved from ACMEAuthorizationService into ACMENewOrderService
so the challenges can only be created just once when the order is
initially created.
The LDAPDatabase.addAuthorization() has also been updated to add
the challenges after adding the authorization.
- - - - -
2262588a by Endi S. Dewata at 2023-09-14T14:47:32-05:00
Fix exception in ACMEFinalizeOrderService
- - - - -
2457fc36 by Fraser Tweedale at 2023-09-14T14:47:32-05:00
Fix race condition during ACME order finalization
Previously when the authorization for an order completed the
ACMEChallengeProcessor would update the authorization status
and the order status after that, then the client would call
the ACMEFinalizeOrderService to finalize the order.
However, since these updates are not atomic there is a risk
that the client will detect the new authorization status then
immediately call the ACMEFinalizeOrderService before the order
status can be updated by ACMEChallengeProcessor. Since both
both ACMEFinalizeOrderService and ACMEChallengeProcessor will
read and write the same order at the same time, there could be
a race condition and the finalization could fail.
To avoid the problem the ACMEChallengeProcessor has been
modified to update the order status first before updating the
authorization status.
- - - - -
be0e52b0 by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSUsrGrpAdminServlet to use @WebServlet
- - - - -
cc787bed by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSLogAdminServlet to use @WebServlet
- - - - -
50c9fd52 by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSAuthAdminServlet to use @WebServlet
- - - - -
e5962208 by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSJobsAdminServlet to use @WebServlet
- - - - -
371d09e1 by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSACLAdminServlet to use @WebServlet
- - - - -
d6e7367c by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSCMSAdminServlet to use @WebServlet
- - - - -
56ae2710 by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSRegisterUser to use @WebServlet
- - - - -
a62de555 by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update ImportTransportCert to use @WebServlet
- - - - -
7eaa3402 by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSEncryptData to use @WebServlet
- - - - -
7511c187 by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSCreateKeySetData to use @WebServlet
- - - - -
36136501 by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSSessionKey to use @WebServlet
- - - - -
8517c8de by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSRandomData to use @WebServlet
- - - - -
86d9ccb2 by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSPortsServlet to use @WebServlet
- - - - -
fc620ff8 by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSMainPageServlet to use @WebServlet
- - - - -
171523df by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSDownloadPKCS12 to use @WebServlet
- - - - -
a3088c2d by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TPSGetConfigEntries to use @WebServlet
- - - - -
3ed5165c by Endi S. Dewata at 2023-09-14T18:04:45-05:00
Update TKSGetStatus to use @WebServlet
- - - - -
18139f7f by Endi S. Dewata at 2023-09-15T14:21:29-05:00
Rename TPSGetConfigEntries to TKSGetConfigEntries
- - - - -
a60e3acd by Endi S. Dewata at 2023-09-15T14:21:29-05:00
Add TPSUsrGrpAdminServlet
- - - - -
ace0d35a by Endi S. Dewata at 2023-09-15T14:21:29-05:00
Add TPSLogAdminServlet
- - - - -
221bf0ae by Endi S. Dewata at 2023-09-15T14:21:29-05:00
Add TPSGetStatus
- - - - -
ed5f3cf7 by Endi S. Dewata at 2023-09-15T14:21:29-05:00
Add TPSGetConfigEntries
- - - - -
50868c1a by Chris Kelley at 2023-09-15T14:21:29-05:00
Update to use SPDX licence
- - - - -
3297b61e by Jerry James at 2023-09-15T14:21:29-05:00
Unbundle the FontAwesome font
- - - - -
85d4639f by Endi S. Dewata at 2023-09-15T14:21:29-05:00
Remove unnecessary BuildArch
- - - - -
f86cc9d2 by Endi S. Dewata at 2023-09-15T14:21:29-05:00
Improve test reliability
Some tests have been updated to improve the reliability by
extending the cert validity, forcing CRL updates, and using
longer sleep times between operations.
- - - - -
6c01ba6e by Endi S. Dewata at 2023-09-15T19:21:19-05:00
Merge common fields/methods in LdapConnFactory subclasses
- - - - -
c64d2fd1 by Endi S. Dewata at 2023-09-18T09:23:46-05:00
Add links to Maven-built JAR files
Maven installs the JAR files in /usr/share/java/<name> instead
of /usr/share/java/pki, so for backward compatibility the RPM
spec file has been modified to create links to the JAR files,
then include both of them in the RPM packages.
- - - - -
09bada58 by Endi S. Dewata at 2023-09-18T09:49:28-05:00
Update TPSUsrGrpAdminServlet to use @WebServlet
- - - - -
503836e9 by Endi S. Dewata at 2023-09-18T09:49:28-05:00
Update TPSLogAdminServlet to use @WebServlet
- - - - -
25d8ec57 by Endi S. Dewata at 2023-09-18T09:49:28-05:00
Update TPSGetStatus to use @WebServlet
- - - - -
d6da2dc1 by Endi S. Dewata at 2023-09-18T09:49:28-05:00
Update TPSGetConfigEntries to use @WebServlet
- - - - -
8ef4e86a by Endi S. Dewata at 2023-09-18T09:49:28-05:00
Update TPSPhoneHome to use @WebServlet
- - - - -
783c3414 by Endi S. Dewata at 2023-09-18T09:49:28-05:00
Update TPSServlet to use @WebServlet
- - - - -
d53cc2ca by parrjd at 2023-09-18T16:12:01+01:00
Update 01-FixSSKDirUserCertProfileAuth.py
Only update profile if exists. Currently if the file does not exist CA fails to start
- - - - -
8a509f1b by Endi S. Dewata at 2023-09-18T10:59:49-05:00
Remove CMSEngine dependency in LdapConnFactory
The LdapConnFactory has been modified to no longer dependent
on CMSEngine. Instead, the CMSEngine will provide methods to
create an LDAP connection factory that is already configured
with the engine's auditor, socket listener, and cert approval
callback.
All code that were calling LdapConnFactory.setCMSEngine() has
been modified to call the new methods, except for DBSubsystem
and UGSubsystem since they are also used by CLIs which do not
have a CMSEngine instance.
These changes will eventually allow LdapConnFactory to be used
outside of PKI server environment.
- - - - -
08ad5809 by Endi S. Dewata at 2023-09-18T14:51:32-05:00
Add PublishingQueueConfig
The PublishingQueueConfig has been added to encapsulate
ca.publish.queue.* params.
- - - - -
bf1d20f8 by Endi S. Dewata at 2023-09-18T15:09:13-05:00
Add LDAPPublishingConfig
The LDAPPublishingConfig has been modified to encapsulate
ca.publish.ldappublish.* params.
- - - - -
c5e851bf by Endi S. Dewata at 2023-09-18T20:05:29-05:00
Add PolicyDefaultConfig
The PolicyDefaultConfig has been added to encapsulate policy
default config params.
- - - - -
2f2ddf44 by Endi S. Dewata at 2023-09-18T20:05:48-05:00
Add PolicyConstraintConfig
The PolicyConstraintConfig has been added to encapsulate policy
constraint config params.
- - - - -
e558db64 by Endi S. Dewata at 2023-09-18T20:05:49-05:00
Merge common fields/methods in PolicyConstraint subclasses
- - - - -
db68cf6f by Endi S. Dewata at 2023-09-18T20:05:49-05:00
Convert LdapConnModule.mConfig into LDAPPublishingConfig
- - - - -
5fae57e1 by Endi S. Dewata at 2023-09-18T20:05:49-05:00
Convert PolicyDefault.mConfig into PolicyDefaultConfig
- - - - -
3128a441 by Endi S. Dewata at 2023-09-18T20:05:49-05:00
Convert PolicyConstraint.mConfig into PolicyConstraintConfig
- - - - -
6a88ec2a by Endi S. Dewata at 2023-09-19T14:53:27-05:00
Fix missing links for pki-console.jar and pki-console-theme.jar
- - - - -
c8fd8aac by Endi S. Dewata at 2023-09-20T09:07:49-05:00
Update cms.password.skipLdapConnTest default value
Previously each PKI subsystem would check the DS connection on
startup and fail to start if the DS is not available. To improve
PKI service reliability the subsystem needs to start regardless
of DS availability (since the subsystem can reconnect to the DS
later when needed), so the cms.password.skipLdapConnTest param
has been modified to be true by default such that it no longer
checks the DS connection on startup.
The DS connection test has been updated to remove the command
that configures the param since it's no longer needed.
- - - - -
6f50d7a6 by Marco Fargetta at 2023-09-21T16:36:59+02:00
Restart the instance when new subsystems are deployed
If a new subsystem is deployed in a existing instance this not restarted
during the installation but the new web-app is just enabled.
When the subsystem are configured to work with an HSM this could
generate problems because certificates added during the installation
with external tools are recognised. The instance restart will clean the
internal cache and reference to the HSM and all certificates are
identified.
Fix the issue #4335
- - - - -
004e90af by Chris Kelley at 2023-09-21T19:28:58+01:00
Fix cmake compilation warnings.
Move cmake_minimum_required before project to silence warning
Replace deprecated FindPythonInterp in find_package
- - - - -
d3ab85b7 by Chris Kelley at 2023-09-21T21:38:21+01:00
Add Buildrequires for fontawesome
This resolves a disparity in installed files between rpmbuild and cmake
now that fontawesome is not bundled anymore. The symlink generation to
the external font files is moved to cmake from the spec file to make it
platform agnostic.
- - - - -
02a77e48 by Marco Fargetta at 2023-09-22T09:38:33+02:00
Add dependency to java-devel for pki-server package
The CLI `pki-server ca-audit-event-find` fails because it requires the `jar` command
provided by the java devel package which is not in the dependency list.
A direct dependency added.
- - - - -
627da054 by jmagne at 2023-09-26T14:10:00-07:00
Aes v11.4 (#4555) (#4574)
* Junk change to pki.spec.
* Fix: Bug Bug 2142908 - add AES support for TMS Shared Secret on latest HSM / FIPS environment,
original bug:
Fix: Bug 2025110 - Get TMS working on latest HSM / FIPS environment (#3949)
This bug has 2 goals. The first is to get the shared secret key importation from the tks to tps working. Also
this goal invloves making the shared secret key AES instead of soon to be purged DES3.
The second goad was to get full server side keygen enrollment working under this strict environment.
This goal won't be in the commit due to the fact that this requires some work on the coolkey token applet, which is to com.
For my testing I used full PSS and OAEP support. PSS is invoked by setting the "usePSS=true" setting in the pkispawn config file.
Also for both tks and tps,after creating, we must set the keyWrap.useOAEP=true setting in the CS.cfg of both tks and tps.
Add some review comment changes.
Port to 11.4 branch.
* Fix Bug 2180922 - add AES support for TMS server-side keygen on latest HSM / FIPS environment [RHCS 10.4]. (#4451)
This fix allows the latest HSM / FIPS environment to successfully complete a token enrollment including server side
keygen functionality.
This is accomplished with TMS code and applet code that allows SCP03 tokens alone the ability to inject a private key onto the tok
using the AEK_KEYWRAP_KWP algorithm. This fix includes a new applet that must be used for scp03 tokens.
base/tps/shared/applets/1.5.64260792.ijc
The CS.cfg must be configured to use this applet as follows:
op.enroll.userKey.update.applet.requiredVersion.prot.3=1.5.64260792 for enrollment and,
op.format.userKey.update.applet.requiredVersion.prot.3=1.5.64260792 for format.
Note any other profiles including external registration must be configured to use this applet if put into play.
Note: The following must be configured in the TPS's server.xml to extend the timeout from the client
as per this example:
connectionTimeout="-1" for each connector SSL or non SSL. This is required since the KWP implementation
takes a bit longer to unwrap the keys(s) onto the token than previously.
Tested with a full FIPS / latest HSM box using PSS and OAEP for all subsystems. OAEP should be required
with PSS optional.
Tested with the g&d 7.0 smart cafe SCP03 using a max of 3072 bit keys due to the limitations of the token itself.
---------
Co-authored-by: Jack Magne <jmagne at localhost.localdomain>
- - - - -
3634545c by Marco Fargetta at 2023-09-28T10:27:40+02:00
Make profile REST API provide same information then XML API
Current profile REST API misses the information: visible, enable and
enableBy. These are needed by IPA to improve the UI.
Additionally, a filter for visible and enable has been added.
Resolve RHCS-4375
- - - - -
060bf0ea by Marco Fargetta at 2023-09-28T10:27:40+02:00
Add profile filter to the CLI
The command ca-profile-find has 3 additional filters:
- "--visible" shows only visible profiles (this is the default
behaviour for non admin users);
- "--enable" shows only the enabled profiles;
- "--enableBy <username>" shows the profiles enabled by the provided
user.
- - - - -
fa9b9522 by Endi S. Dewata at 2023-09-28T19:02:31-05:00
Clean up log messages in UniqueSubjectNameConstraint
- - - - -
f93d360a by Marco Fargetta at 2023-09-29T09:58:53+02:00
Remove not used DB session from certificate queries
- - - - -
ee9cf973 by Endi S. Dewata at 2023-09-29T09:30:11-05:00
Add test for caServerCert profile
A new CI job has been added to test cert enrollments using a
customized caServerCert profile. The first enrollment should
successfully issue an SSL server cert with user-provided SAN
extension. The second enrollment should fail to issue another
SSL server cert with the same subject name.
- - - - -
56bf3ea0 by Endi S. Dewata at 2023-10-02T20:08:13-05:00
Move CAEngine.loader to AuthorityMonitor
- - - - -
4d163506 by Endi S. Dewata at 2023-10-02T20:13:40-05:00
Move CAEngine.foundHostCA to AuthorityMonitor
- - - - -
c029f942 by Endi S. Dewata at 2023-10-02T20:14:06-05:00
Move CAEngine.deletedNsUniqueIds to AuthorityMonitor
- - - - -
f4749d27 by Endi S. Dewata at 2023-10-02T20:14:07-05:00
Move CAEngine.nsUniqueIds to AuthorityMonitor
- - - - -
fbc19519 by Endi S. Dewata at 2023-10-02T20:14:27-05:00
Move CAEngine.entryUSNs to AuthorityMonitor
- - - - -
244745e7 by Endi S. Dewata at 2023-10-02T20:14:43-05:00
Move CAEngine.keyRetrievers to AuthorityMonitor
- - - - -
f3683cf6 by Endi S. Dewata at 2023-10-02T20:14:58-05:00
Move CAEngine.authorities to AuthorityMonitor
- - - - -
4b48613e by Endi S. Dewata at 2023-10-02T20:14:59-05:00
Move CAEngine.trackUpdate() to AuthorityMonitor
- - - - -
cf1eed90 by Endi S. Dewata at 2023-10-02T20:14:59-05:00
Move CAEngine.addCA() to AuthorityMonitor
- - - - -
82f0ed0f by Endi S. Dewata at 2023-10-02T20:14:59-05:00
Move CAEngine.removeCA() to AuthorityMonitor
- - - - -
c034463e by Marco Fargetta at 2023-10-04T12:06:30+02:00
pki-server system certificate from nssdb
System certificates are stored in CS.cfg and nssdb. This is redundant,
all operations should use the same source for the certificate which is
the nssdb.
This modify the following command in order to get the certificate from
nssdb:
[root at pki /] # pki-server cert-export --cert-file <filename>
- - - - -
f54a9660 by Marco Fargetta at 2023-10-04T12:06:30+02:00
cert-export read from config file or config folder
The command pki-server cert-export will read the certificate and the
relative request from the "<instance>/config/certs" folder if not found
in other places
- - - - -
46229ab2 by Marco Fargetta at 2023-10-04T18:18:56+02:00
Fix the configuration path for certs folder
- - - - -
a74f773e by Marco Fargetta at 2023-10-04T18:23:10+02:00
Disable healthcheck CS.cfg certs match
Cert and csr will be removed from CS.cfg and stored in DB or separate
file so this check is not anymore valid. It is temporary disabled to
verify if can be removed or it should be replaced with other
checks.
- - - - -
b14b11cd by Endi S. Dewata at 2023-10-04T12:13:58-05:00
Add missing ServiceUnavailableException constructor
- - - - -
5b9607fc by Endi S. Dewata at 2023-10-04T21:10:40-05:00
Add AuthorityRecord
The AuthorityRecord has been added to encapsulate authority
records stored in LDAP.
- - - - -
cfac4037 by Endi S. Dewata at 2023-10-04T21:10:40-05:00
Add CAEngine.getAuthorityRecord()
The code that loads the authority record from an LDAP
entry in CAEngine.readAuthority() has been moved into
getAuthorityRecord().
- - - - -
2d10490a by Endi S. Dewata at 2023-10-04T21:10:40-05:00
Add CAEngine.createCA()
The code that creates the CertificateAuthority object in
CAEngine.readAuthority() has been moved into createCA().
- - - - -
726afdb6 by Endi S. Dewata at 2023-10-04T21:11:03-05:00
Replace CAEngine.ensureAuthorityDNAvailable() with getCA()
- - - - -
3e62f42c by Endi S. Dewata at 2023-10-04T21:11:03-05:00
Fix Javadoc warnings in LDAPConfigStorage
- - - - -
10200496 by Endi S. Dewata at 2023-10-04T21:14:03-05:00
Move CAEngine.readAuthority() to AuthorityMonitor
- - - - -
5a2feb7f by Birger J. Nordølum at 2023-10-06T16:40:54-05:00
chore: make test badges linkable to actual tests
- - - - -
4718f9f0 by Endi S. Dewata at 2023-10-09T09:20:40-05:00
Refactor CAEngine.addAuthorityEntry()
The code that creates the authority LDAP entry has been merged
into CAEngine.addAuthorityEntry(). This method has also been
renamed to addAuthorityRecord().
- - - - -
1955db51 by Marco Fargetta at 2023-10-09T19:12:58+02:00
Create subsystem without certificate in CS.cfg
Certificate are stored in nssdb of the instance so the copy in the file
is redundant and will be removed.
- - - - -
dc5e987f by Marco Fargetta at 2023-10-09T19:12:58+02:00
Lightweight CA read issuer certificate from nssdb
When working with HSM the Lightweight CA access the root CA certificate
from the CS.cfg. This has been modified reading the certificate from
NSSDB to allow the removal of such field from the configuration.
NOTE: Currently, Lightweight CA does not work with HSM so this change
cannot be really tested until the Github issue #2412 is fixed.
- - - - -
6a3206e2 by Marco Fargetta at 2023-10-09T19:12:58+02:00
Get cert from nssdb for all subsystems
- - - - -
369c19ff by Marco Fargetta at 2023-10-09T19:12:58+02:00
Improve message error for subsystem certificate not found
- - - - -
8f7b2c92 by Endi S. Dewata at 2023-10-10T13:32:25-05:00
Fix malformed signed audit params in CS.cfg
The CS.cfg files for all subsystems have been updated to fix
the malformed signed audit params. An upgrade script has been
added to fix the params in existing instances.
- - - - -
e865fe77 by Endi S. Dewata at 2023-10-10T13:32:25-05:00
Add test for KRA clone with HSM
A new CI test has been added to verify installing KRA with HSM,
cloning the first instance, then cloning the second instance.
The test will also verify the system certs and the CS.cfg in
all instances.
- - - - -
64548e53 by Endi S. Dewata at 2023-10-10T13:32:25-05:00
Add test for KRA clone with shared DS
A new CI test has been added to verify installing KRA with a DS
instance, then cloning the KRA using the same DS instance. The
test will also check the system certs and the CS.cfg in both
instances.
- - - - -
2402ae99 by Endi S. Dewata at 2023-10-11T15:46:12-05:00
Update dependency on Tomcat
- - - - -
8769b3a2 by Endi S. Dewata at 2023-10-12T10:03:29-05:00
Add test for IPA with sub CA
A new CI test has been added to verify installing IPA with
a subordinate CA where the signing cert is issued by an
external root CA.
- - - - -
af75c5f9 by Endi S. Dewata at 2023-10-16T09:24:23-05:00
Remove redundant 2nd attempt to wait for build
The 2nd attempt to wait for build was originally added to
improve the CI reliability in case the 1st attempt failed, but
apparently the CI would not automatically resume even if the
2nd attempt was successful, and it's also generating warnings
about skipped checks, so it has been removed.
- - - - -
d6f162f6 by Marco Fargetta at 2023-10-17T17:29:08+02:00
Remove CSR from CS.cfg and store them in certs folder
CSR are created and stored in `<instance_config>/certs` folder as `<certs_id>.csr` files.
Fix #2111
- - - - -
7e0386bc by Marco Fargetta at 2023-10-17T17:29:08+02:00
Add CSR job in IPA cline test
Add a check of CSR between CA master and clone.
- - - - -
61c3c27e by Marco Fargetta at 2023-10-17T17:29:08+02:00
Concert CSR file name to cert_id
- - - - -
634cc046 by Endi S. Dewata at 2023-10-18T12:48:16-05:00
Move subordinate CA tests into separate workflow
- - - - -
3fd3031a by Endi S. Dewata at 2023-10-18T20:27:18-05:00
Replace BASE64_DATABASE with DB_IMAGE
The BASE64_DATABASE secret has been replaced with DB_IMAGE
variable since it's easier to configure.
https://github.com/dogtagpki/pki/wiki/Configuring-Test-Database
- - - - -
aaead49f by Marco Fargetta at 2023-10-19T09:26:38+02:00
Remove cert healthcheck
Since certs will not be stored in CS.cfg in the future this test is
useless so it is removed.
- - - - -
9b961df2 by Endi S. Dewata at 2023-10-19T11:04:46-05:00
Remove unused init-workflow.sh
- - - - -
f8aecf21 by Endi S. Dewata at 2023-10-19T12:45:25-05:00
Add cert validity options/params for CLI and ACME
The pki nss-cert-issue command and the NSSIssuer in ACME have
been modified to provide options/params to specify the cert
validity in different units (e.g. minutes) which could be
useful for testing and end-users as well.
The old option/param is limited to months only so it has been
deprecated.
- - - - -
80017fcd by Endi S. Dewata at 2023-10-20T21:28:00-05:00
Update CA and IPA clone tests to check CRL params
- - - - -
1e50c67f by Endi S. Dewata at 2023-10-23T20:28:31-05:00
Update RPM spec file
The RPM spec file has been updated to install/distribute
Maven artifacts in the proper locations/packages.
- - - - -
56addd2b by Endi S. Dewata at 2023-10-24T21:04:38-05:00
Clean up ca.crl.MasterCRL.enable configuration
The code that configures ca.crl.MasterCRL.enable has been
moved into PKIDeployer.finalize_ca().
The IPA clone test has been modified to validate the param.
A temporarily fix was added due to pending changes in IPA:
https://github.com/freeipa/freeipa/pull/6971
- - - - -
aa8e2379 by Endi S. Dewata at 2023-10-25T12:57:07-05:00
Update Javadoc for LDAPConfig
- - - - -
b68c119b by Endi S. Dewata at 2023-10-25T14:13:27-05:00
Remove runtime dependencies on Maven plugins
The maven-compiler-plugin, maven-jar-plugin, and
maven-surefire-plugin have been moved to the modules
that actually use them, so they will no longer be
listed as runtime dependencies of the RPM packages.
- - - - -
8d382d75 by Endi S. Dewata at 2023-10-26T18:51:28-05:00
Fix dependencies in top-level subpackage
The top-level (i.e. meta) subpackage has been modified
to require all other subpackages enabled in the build.
- - - - -
402300f8 by Endi S. Dewata at 2023-10-30T13:34:30-05:00
Add test for CA system certs renewal
A new test has been added to validate the renewal procedure
for system certs in CA (except the CA signing cert itself)
and the admin cert as well.
The test will call pki-server cert-create sslserver --temp
command which will create a temporary SSL server cert using
the existing CSR.
The code that exports the CSR from CS.cfg into a file in
PKISubsystem.setup_temp_renewal() has been removed since the
CSR is now stored in <instance>/conf/certs/<cert ID>.csr so
it can be used directly.
The test will also call pki-server cert-import command which
will import the new cert into NSS database.
The PKIInstance.cert_import() has been modified to no longer
call cert_update_config() since the cert will no longer be
stored in CS.cfg.
https://github.com/dogtagpki/pki/wiki/Renewing-System-Certificates
https://github.com/dogtagpki/pki/wiki/Renewing-Admin-Certificate
- - - - -
cd80dfe4 by Endi S. Dewata at 2023-10-30T16:09:37-05:00
Rename PKIWebListener to CMSWebListener
- - - - -
9d9fd539 by Endi S. Dewata at 2023-11-02T09:34:27-05:00
Add pki nss-cert-del
The pki nss-cert-del has been added to remove a cert (and
optionally its key as well) from NSS database which can be
used to replace certutil -D and certutil -F commands.
The NSSDatabase.remove_cert() and CI tests have been updated
to use the new command.
- - - - -
80ade82d by Endi S. Dewata at 2023-11-02T11:23:07-05:00
Refactor pkispawn scriptlets
The loop that calls pkispawn scriptlets has been unrolled and
moved into PKIDeployer.spawn() to allow further refactoring.
- - - - -
781d1c86 by Endi S. Dewata at 2023-11-02T11:27:30-05:00
Refactor pkidestroy scriptlets
The loop that calls pkidestroy scriptlets has been unrolled and
moved into PKIDeployer.destroy() to allow further refactoring.
- - - - -
b2b2a543 by Endi S. Dewata at 2023-11-02T12:28:32-05:00
Merge PKIInstance.nssdb_import_cert() into cert_import()
- - - - -
e2dca04e by Endi S. Dewata at 2023-11-02T13:25:52-05:00
Convert PKISubsystem.setup_temp_renewal() into get_cert_ski()
The PKISubsystem.setup_temp_renewal() has been simplified and
converted into get_cert_ski() which takes a base64-encoded cert
and returns its SKI.
- - - - -
1d9d890c by Endi S. Dewata at 2023-11-02T16:50:31-05:00
Update PKIServer.open_nssdb()
The PKIServer.open_nssdb() has been modified to ensure that the
NSSDatabase object being created has the password.conf, the user,
and the group of PKI server such that it can be used to access
HSM and create files with the proper ownership.
- - - - -
67a3ee29 by Endi S. Dewata at 2023-11-02T19:06:52-05:00
Deprecate pki client-cert-del
- - - - -
d699d0aa by Endi S. Dewata at 2023-11-02T21:46:56-05:00
Update profile import
The code that imports the profiles into database during
installation has been moved such that it only runs if
database setup is enabled.
- - - - -
6d5d0bf1 by Endi S. Dewata at 2023-11-03T10:18:45-05:00
Fix system certs renewal with HSM
The PKISubsystem.temp_cert_create() has been updated to use
the full name of the CA signing cert such that it can find
the cert and the key properly in HSM.
A new test has been added to verify CA system certs renewal
with HSM.
Resolves: https://github.com/dogtagpki/pki/issues/4355
- - - - -
d03eb693 by Endi S. Dewata at 2023-11-03T16:12:34-05:00
Clean up PKIDeployer.get_domain_info()
The PKIDeployer.get_domain_info() has been modified to return
the domain info instead of storing it directly in PKIDeployer.
- - - - -
a1897775 by Endi S. Dewata at 2023-11-03T16:13:03-05:00
Clean up PKIDeployer.get_install_token()
The PKIDeployer.get_install_token() has been modified to return
the install token instead of storing it directly in PKIDeployer.
- - - - -
71949288 by Endi S. Dewata at 2023-11-03T16:25:36-05:00
Clean up log messages in SecurityDomainService
- - - - -
f069528f by Endi S. Dewata at 2023-11-03T16:47:10-05:00
Remove redundant service.securityDomainPort
- - - - -
ad78ff89 by Endi S. Dewata at 2023-11-03T16:47:43-05:00
Remove redundant securitydomain.httpseeport
- - - - -
aa8e6906 by Endi S. Dewata at 2023-11-03T16:49:05-05:00
Remove redundant securitydomain.httpsagentport
- - - - -
bf868db1 by Endi S. Dewata at 2023-11-03T19:03:02-05:00
Fix issues with disabled security domain
- - - - -
0dd03ce4 by Endi S. Dewata at 2023-11-03T19:28:22-05:00
Refactor PKIDeployer.setup_security_domain()
The code that configures the security domain type and name
in PKIDeployer.setup_security_domain() has been moved into
setup_security_domain_manager().
- - - - -
6dcca7e9 by Endi S. Dewata at 2023-11-06T09:37:54-06:00
Update pki nss-cert-import
The pki nss-cert-import has been updated to use the token
name in the nickname if specified, otherwise it will use
the token name specified in the --token option.
The NSSDatabase.addCertificate() in Java (which is used
by pki nss-cert-import) has been modified to call the new
PK11Store.importCert() instead of addPEMCertificate()
which depends on certutil -A.
The NSSDatabase.add_cert() in Python has been updated to
use JSS (via pki nss-cert-import) by default. It has also
been updated to provide the input cert via standard input
instead of file to avoid permission issues.
- - - - -
6c624e4e by Endi S. Dewata at 2023-11-06T14:22:19-06:00
Add getter/setter for passwordFile param
- - - - -
4f01f3ad by Endi S. Dewata at 2023-11-06T17:15:11-06:00
Update basic installation tests
The basic installation tests have been updated to verify that
the CSRs are stored under /etc/pki/<instance>/certs folder.
- - - - -
c0fd0a7f by Endi S. Dewata at 2023-11-07T10:43:29-06:00
Update KRA and OCSP tests
The test for basic KRA has been updated to check the security
domain and KRA connector in CA. The test for standalone KRA
has been updated to use a standalone CA so the CA should not
have a security domain and KRA connector.
Similarly, the test for basic OCSP has been updated to check
the security domain and OCSP publishing in CA. The test for
standalone OCSP has been updated to use a standalone CA as
well so the CA should not have a security domain and OCSP
publishing either.
Note: The KRA connector and the OCSP publishing can be added
later as a post-install task.
- - - - -
3700a599 by Endi S. Dewata at 2023-11-07T19:43:47-06:00
Update PKIDeployer.setup_system_cert()
The PKIDeployer.setup_system_cert() has been modified to
reuse the existing system certs if they already exist in
the NSS database.
- - - - -
68bc3cbe by Endi S. Dewata at 2023-11-08T11:36:51-06:00
Fix dangling link to jaxb-api.jar
The CMake script has been updated to use more specific paths
to find the proper location of jaxb-api.jar on platforms that
do not provide xmvn-resolve.
Resolves: https://issues.redhat.com/browse/RHCS-4602
- - - - -
59fd6765 by Endi S. Dewata at 2023-11-08T19:45:38-06:00
Clean up redundant code in configuration.py
- - - - -
8e01622d by Endi S. Dewata at 2023-11-08T19:45:38-06:00
Update PKIDeployer.import_system_cert_request()
The PKIDeployer.import_system_cert_request() has been updated
to skip importing the CSR if the source and the destination
paths are the same.
- - - - -
cc3987ca by Marco Fargetta at 2023-11-09T10:21:13+01:00
Fix RSA key pairs generation in FIPS environment
When FIPS is enabled and kay are not temporary then the sensitive flag
has to be true.
Flags are assigned only if not `NULL` so to enable the default values they generator is invoked with `NULL` value instead of `false` value which was assigned.
- - - - -
6eea556c by Endi S. Dewata at 2023-11-09T08:07:02-06:00
Enable RSNv3 by default
The default.cfg has been updated such that new CA and KRA
installations will have RSNv3 enabled by default. Existing
installations will not be affected.
The tests have been updated to no longer enable RSNv3
explicitly since it's redundant.
The test for CA with CMC shared token has been updated to
handle large serial numbers.
The test for CA with RSNv1 has been updated to explicitly
use the legacy ID generators.
Resolves: https://issues.redhat.com/browse/RHCS-3689
- - - - -
a4eb208b by Endi S. Dewata at 2023-11-09T10:53:48-06:00
Add PKIEngine, PKIWebListener, PKIServlet
The PKIEngine has been added to store the main code of PKI web
application. PKIWebListener has been added to initialize the
PKIEngine when the web application is started. PKIServlet has
been added as the base class for servlets that use PKIEngine.
- - - - -
5ca50b55 by Endi S. Dewata at 2023-11-09T10:53:48-06:00
Refactor InfoService
The code that constructs the Info object in InfoService has
been moved into PKIEngine such that it can be reused.
- - - - -
3058989a by Endi S. Dewata at 2023-11-09T10:53:48-06:00
Add InfoServlet
The InfoServlet has been added as a lightweight alternative to
InfoService without dependency on RESTEasy.
All clients have been modified to call the InfoServlet instead.
- - - - -
7d31c732 by Endi S. Dewata at 2023-11-10T09:37:06-06:00
Fix permission issue in pki-server ca-cert-request-import
In some cases pki-server ca-cert-request-import fails to import a
CSR since the Python code of the command runs as the current user
but the Java code runs as PKI user which might not have the
permission to read the input file.
To avoid the issue, the Python code has been modified to load the
CSR into memory, then pass the CSR to Java via the standard input.
The Java code has been updated not to throw an exception if the
CSR is provided via the standard input instead of a file.
- - - - -
6f96f699 by Endi S. Dewata at 2023-11-10T10:04:00-06:00
Drop critical_failure param from KRAConnector.deregister()
The KRAConnector.deregister() is always executed with
critical_failure=True, so the param can be dropped and the
the code that uses the param can be simplified, and also
the outer try-except block can be removed. This will also
fix pylint broad-exception-caught failure.
- - - - -
901be4a8 by Endi S. Dewata at 2023-11-10T10:04:00-06:00
Drop critical_failure param from TPSConnector.deregister()
The TPSConnector.deregister() is always executed with
critical_failure=True, so the param can be dropped and the
the code that uses the param can be simplified, and also
the outer try-except block can be removed.
- - - - -
f46d5318 by Endi S. Dewata at 2023-11-10T11:01:11-06:00
Update test for installing CA with existing NSS database
The test for installing CA with existing NSS database has been
updated to store the CSRs in /etc/pki/pki-tomcat/certs folder
directly so that it's no longer necessary to specify the CSR
paths for pkispawn.
- - - - -
712dbb9b by Endi S. Dewata at 2023-11-10T13:49:29-06:00
Update ServerConfig.get_sslhost()
For consistency, the ServerConfig.get_sslhost() has been
modified to return None if the SSL host does not exist.
All callers have been modified to check the return value.
- - - - -
d542203f by Endi S. Dewata at 2023-11-10T13:54:12-06:00
Update ServerConfig.get_sslcert()
For consistency, the ServerConfig.get_sslcert() has been
modified to return None if the SSL cert does not exist.
All callers have been modified to check the return value.
- - - - -
4093f97c by Endi S. Dewata at 2023-11-10T20:43:34-06:00
Update PKIDeployer.create_server_xml()
The PKIDeployer.create_server_xml() has been modified into
configure_server_xml() which will create a new server.xml or
update an existing one.
- - - - -
2ff05873 by Endi S. Dewata at 2023-11-10T20:47:18-06:00
Clean up RemoveUserDatabase
The RemoveUserDatabase has been updated to use ServerConfig
to update server.xml.
- - - - -
b45ed854 by Endi S. Dewata at 2023-11-13T10:50:14-06:00
Remove unnecessary workaround for certutil bug
The NSSDatabase.__add_cert() was modified recently in
6dcca7e9279db9e5e295705168ebb8340b64d9e0 to use JSS via
pki nss-cert-import instead of certutil, so the workaround
for Mozilla Bug #1782980 is no longer needed.
Resolves: https://issues.redhat.com/browse/RHCS-4601
- - - - -
317e715a by Endi S. Dewata at 2023-11-13T10:57:51-06:00
Move RequestQueue.findRequestsBySourceId() to RequestRepository
- - - - -
6a47b03d by Endi S. Dewata at 2023-11-13T10:57:52-06:00
Move RequestQueue.findRequestBySourceId() to RequestRepository
- - - - -
f3da41f0 by Endi S. Dewata at 2023-11-13T10:59:03-06:00
Remove unused RequestQueue.findRequest()
- - - - -
287a3008 by Endi S. Dewata at 2023-11-13T15:31:06-06:00
Update version number to 11.5.0-alpha2
- - - - -
7b8068f9 by Endi S. Dewata at 2023-11-13T17:04:12-06:00
Update PKIServer.create_server_xml()
The PKIServer.create_server_xml() has been updated to use
ServerConfig to create/update server.xml.
- - - - -
195056c9 by Endi S. Dewata at 2023-11-13T17:07:43-06:00
Remove unused PKIServer.remove_lockout_realm()
- - - - -
7405a0eb by Endi S. Dewata at 2023-11-13T17:08:21-06:00
Remove unused PKIServer.remove_default_user_database()
- - - - -
0222dc4f by Endi S. Dewata at 2023-11-13T17:09:43-06:00
Remove unused PKIServer.add_rewrite_valve()
- - - - -
fab99224 by Marco Fargetta at 2023-11-15T11:47:55+01:00
Implement CA Info REST v2
The code of CAInfoService.java has moved to CAEngine and used for the
current API and the new v2 API.
Introduced a base servlet for all CA APIs and the servlet for the Info
end-point.
No code changes performed.
- - - - -
d046a7ea by Endi S. Dewata at 2023-11-15T09:19:50-06:00
Add pki-server cert-request
The pki-server cert-request has been added to simplify creating
CSRs for system certs so it's no longer necessary to specify the
NSS database path, password file, CSR path, and also to fix the
file ownership.
The cert_folder(), cert_file(), and csr_file() in PKIInstance
have been moved into PKIServer so they can be reused. The
cert_folder() has been renamed to certs_dir() for consistency.
The PKIServer.create() and instance_layout.py have been updated
to create the certs folder so it's guaranteed to exist.
The RemoveCertCSRfromConfig upgrade script has been updated to
use the new methods in PKIServer.
The tests for installing CA with existing NSS database and
existing HSM have been updated to use the new command.
- - - - -
3f50096e by Endi S. Dewata at 2023-11-15T14:46:22-06:00
Update pki-server cert-create
The pki-server cert-create has been updated to simplify creating
a system cert. It will use the server's NSS database directly and
RSNv3 serial numbers so it can be used before the CA subsystem is
created or when the server is down. It will use the CSR in
/etc/pki/pki-tomcat/certs and store the new cert in that folder
as well.
The tests for installing CA with existing NSS database and HSM
have been updated to use this command.
- - - - -
bd36dbf3 by Endi S. Dewata at 2023-11-15T14:46:49-06:00
Replace pki_instance_name with PKIServer.name
- - - - -
c5bb9842 by Endi S. Dewata at 2023-11-15T14:46:49-06:00
Rename PKIDeployer.subsystem_name to subsystem_type
- - - - -
20f17993 by Endi S. Dewata at 2023-11-15T14:46:49-06:00
Replace pki_subsystem with PKIDeployer.subsystem_type
- - - - -
da09ae20 by Endi S. Dewata at 2023-11-15T14:46:49-06:00
Replace pki_user/pki_group with PKIServer.user/group
- - - - -
169c68f3 by Endi S. Dewata at 2023-11-15T22:25:45-06:00
Update pki-ca-run
The pki-ca-run has been updated to configure CA to not create
DS connections during startup.
The CA container test has been updated to start the CA before
the DS.
- - - - -
24a66c3f by Endi S. Dewata at 2023-11-16T08:29:25-06:00
Update pki-server cert-import
The pki-server cert-import has been updated to provide options
to specify the nickname and token so that the cert can be
imported before creating any subsystem in the instance.
The tests for installing CA with existing NSS database and HSM
have been updated to use this command.
- - - - -
4e42191d by Christina Fu at 2023-11-16T10:26:00-08:00
Bug 2246422 ServerSideKeygen static SKID (#4597)
This patch intends to address the bug where in the case of
ServerSide keygen, a static SKI extension was injected as
a result.
fixes https://bugzilla.redhat.com/show_bug.cgi?id=2246422
- - - - -
048becdf by Endi S. Dewata at 2023-11-16T13:11:59-06:00
Remove unused PKISubsystem.prefix
- - - - -
e94640d5 by Endi S. Dewata at 2023-11-16T13:12:42-06:00
Fix PKISubsystem.type initialization
- - - - -
ae6e19e6 by Endi S. Dewata at 2023-11-16T13:20:07-06:00
Update SubsystemCLI.getEngineConfig()
The SubsystemCLI.getEngineConfig() has been updated to use
the proper subsystem conf folder instead of the backward
compatibility link.
- - - - -
efca54c1 by Endi S. Dewata at 2023-11-16T14:38:40-06:00
Replace PKIDeployer.symlink.create() with PKIServer.symlink()
- - - - -
08153dbf by Endi S. Dewata at 2023-11-17T10:08:47-06:00
Restore support for cert bundle in pki_cert_chain_path
The NSSDatabase.import_cert_chain() has been modified
to support importing cert bundle by converting it into
a PKCS #7 file, then import it using the existing code.
The test for installing KRA on a separate instance has
been modified to use a root CA and a sub CA, then use
a cert bundle in the pki_cert_chain_path param.
The NSSCertImportCLI has been updated to avoid an NPE
if the nickname is not specified.
https://bugzilla.redhat.com/show_bug.cgi?id=2250162
- - - - -
936b26ea by Endi S. Dewata at 2023-11-17T10:37:32-06:00
Update instance_layout.py
The instance_layout.py has been updated to create the folders
and links earlier.
- - - - -
560be6e5 by Endi S. Dewata at 2023-11-17T11:30:12-06:00
Update version number to 11.5.0-alpha3
- - - - -
36e44934 by Endi S. Dewata at 2023-11-27T14:17:37+07:00
Update DS connection test
The steps that check DS backends and user have been moved into
DS connection test.
- - - - -
ace8e9b5 by Endi S. Dewata at 2023-11-27T03:16:53-06:00
Add change log for pki-server status
[skip ci]
- - - - -
25219a6c by Endi S. Dewata at 2023-11-27T07:01:51-06:00
Update test for installing CA with existing DS
The test for installing CA with existing DS has been modified
to create the system and admin certs, then set up DS (including
creating the subsystem and admin users with certs), then finally
install CA with subsystem and admin users already created in
the DS.
- - - - -
0753e8db by Marco Fargetta at 2023-11-27T15:03:43+01:00
Fix CRMFPopClient on FIPS environment
When FIPS is enabled RSA key generation cannot have both temporary and
sensitive to false.
Since temporary is defined from a command option the sensitive is set to
null so the default for the environment will be used (true if FIPS is
enabled and false if FIPS is disabled).
Fix BZ Bug 2250716
- - - - -
0ed9b8c3 by Endi S. Dewata at 2023-11-28T08:36:43+07:00
Update PKIDeployer.configure_server_xml()
The PKIDeployer.configure_server_xml() has been updated
to check whether the AprLifecycleListener exists before
removing it.
- - - - -
a15ae591 by Endi S. Dewata at 2023-11-28T08:36:43+07:00
Update instance_layout.py
The instance_layout.py has been updated to update/overwrite
existing instance config files.
- - - - -
2ac7ae17 by Endi S. Dewata at 2023-11-28T06:23:15-06:00
Add pki-server <subsystem>-create
The pki-server <subsystem>-create command has been added to
create a basic subsystem with the initial files/folders which
will allow the admin to run other pki-server <subsystem>-*
commands to prepare the subsystem database.
The test for installing CA with existing DS has been modified
to use pki-server <subsystem>-* to create the subsystem, set
up database connection, VLVs, database user, and admin user.
The initialization.py has been modified such that pkispawn
can finish the existing subsystem installation.
The PKISubsystem.create_conf() has been modified to create
the initial CS.cfg and registry.cfg.
The subsystem_layout.py has been modified to overwrite the
existing CS.cfg, but in the future it should preserve the
parameters already set in the existing file.
The PKIServer.load_subsystems() has been modified to create
the PKISubsystem object if the subsystem folder exists
regardless of its current content.
- - - - -
6adb8dd3 by Christina Fu at 2023-11-28T17:32:53-08:00
RHCS-4630 (part 2) Add SHA-2 support to Server-side Keygen
I'm adding support of SHA-2 to Server-Side keygen.
Since there was a recent ticket in similar area,
it could sort of be considered relating to it.
Adds SHA-2 support to https://bugzilla.redhat.com/show_bug.cgi?id=2246422
- - - - -
93c666ef by Endi S. Dewata at 2023-11-30T07:47:57+07:00
Add pki-server <subsystem>-db-index-add/rebuild
The code that adds and rebuilds DS database search indexes in
SubsystemDBInitCLI has been moved into SubsystemDBIndexAddCLI
and SubsystemDBIndexRebuildCLI, respectively, such that they
can be used more independently.
Similarly, the PKISubsystem.init_database() has been split
into add_indexes() and rebuild_indexes().
The pki-server <subsystem>-db-index-add/rebuild commands have
been added to execute these operations from command line.
The test for installing CA with existing DS has been updated
to use the new commands.
- - - - -
daffa765 by Fraser Tweedale at 2023-11-30T10:11:15+01:00
acme: return proper error on malformed account payload
ACMEAccountService currently throws an uncaught exception if decode
the account object payload fails. This results in the server
responding 500 Internal Server Error. Respond with status 400 and
a proper problem document instead.
- - - - -
eb5db844 by Fraser Tweedale at 2023-11-30T10:11:15+01:00
acme: implement POST-as-GET for accounts
Some ACME clients POST-as-GET the account resource, expecting to
receive the account object (for an existing account). In
particular, mod_md does this and certificate renewal fails when it
cannot read or verify the account information.
The ACME protocol does not explicitly require this behaviour. But
on the other hand, it is not surprising that clients assume they can
do it, and it arguably is surprising if an ACME server does not
provide it.
So let's implement it. The change itself is trivial: when payload
is empty, POST-as-GET is implied (RFC 8555 section 6.3). In this
case, return the ACMEAccount object (which we already have at hand)
unchanged.
- - - - -
1c631331 by Endi S. Dewata at 2023-12-01T19:24:39+07:00
Update security domain tests
Some KRA/OCSP tests have been updated to check the security
domain configuration after installation.
- - - - -
c0048dfd by Endi S. Dewata at 2023-12-04T07:05:05+07:00
Remove unused PKIDeployer.verify_subsystem_does_not_exist()
- - - - -
f55ce444 by Endi S. Dewata at 2023-12-04T07:05:05+07:00
Remove unused Namespace.collision_detection()
- - - - -
d2e6edfd by Endi S. Dewata at 2023-12-04T07:52:15+07:00
Simplify PKIDeployer.setup_security_domain()
The code in PKISubsystem.configure_security_domain() has been
merged into PKIDeployer.setup_security_domain().
- - - - -
49d8fca8 by Endi S. Dewata at 2023-12-04T07:52:17+07:00
Simplify PKIDeployer.setup_security_domain_manager()
The code for cloning a security domain manager has been moved
under pki_security_domain_type == existing since the clone
will join the existing security domain.
- - - - -
9de2d9cf by Endi S. Dewata at 2023-12-04T07:52:22+07:00
Simplify SubsystemDBReplicationCLI name
- - - - -
ef66910b by Endi S. Dewata at 2023-12-04T07:52:25+07:00
Clean up subsystem_layout.py
The code that creates the symlinks has been moved into
PKISubsystem.create(), create_conf(), and create_logs().
- - - - -
d8295738 by Endi S. Dewata at 2023-12-04T07:52:28+07:00
Update PKISubsystem.create_conf()
The PKISubsystem.create_conf() has been modified to preserve
the params in the current CS.cfg if it exists.
- - - - -
f793f0a8 by Endi S. Dewata at 2023-12-04T07:52:31+07:00
Add PKIDeployer.create_cs_cfg()
The code that creates the CS.cfg in subsystem_layout.py has been
moved into PKIDeployer.create_cs_cfg() and also modified such
that if the file already exists it will merge the params instead
of overwriting the entire file.
- - - - -
b2960647 by Endi S. Dewata at 2023-12-05T20:35:42+07:00
Clean up default security domain params
The default security domain params in CS.cfg have been moved
into PKIDeployer.setup_security_domain_manager() such that
they will be added only if security domain setup is enabled
in pkispawn.
- - - - -
30ec75d9 by Endi S. Dewata at 2023-12-05T20:35:42+07:00
Update test for installing CA with existing DS
The test for installing CA with existing DS has been updated
to set up the security domain prior to running pkispawn.
- - - - -
faedd9f9 by Endi S. Dewata at 2023-12-06T18:55:37+07:00
Add pki-server <subsystem>-db-init
The pki-server <subsystem>-db-init has been added to initialize
the subsystem database in a single step. By default this will
include configuring DS server, setting up the schema, creating
the base entry, and creating the container entries. The command
provides options to skip these steps if needed. The command also
provides an option to create a new DS backend.
The PKISubsystem.init_database() and SubsystemDBInitCLI.java have
been modified to match options in the CLI.
- - - - -
d88dc860 by Endi S. Dewata at 2023-12-07T00:43:53+07:00
Clean up PKIDeployer.create_cert_setup_request()
The PKIDeployer.create_cert_setup_request() has been modified
to check whether the CSR exists before loading the file.
- - - - -
4154441f by Endi S. Dewata at 2023-12-07T00:44:14+07:00
Clean up PKIDeployer.store_master_cert_request()
The PKIDeployer.store_master_cert_request() has been modified
to fail if the CSR cannot be stored into a file.
- - - - -
05357785 by Endi S. Dewata at 2023-12-07T00:44:23+07:00
Clean up PKIDeployer.generate_csr()
The PKIDeployer.generate_csr() has been modified to get the
CSR path using PKIServer.csr_file().
- - - - -
f340c069 by Endi S. Dewata at 2023-12-07T00:44:23+07:00
Clean up PKISubsystem.update_system_cert()
The PKISubsystem.update_system_cert() has been modified to get
the CSR path using PKIServer.csr_file().
- - - - -
cc95f31d by Christina Fu at 2023-12-06T10:07:19-08:00
Bug2253044-AKI-non-SHA1-support
This patch is to address the issue where the AKI would not match the SKI
in the case when SHA-1 is not selected for calculationg SKI for root ca.
CA profiles have also been changed so that the SKI will come before AKI
so that SKI could propagate to AKI properly in the case of a root CA.
fixes https://bugzilla.redhat.com/show_bug.cgi?id=2253044
- - - - -
bfb2add9 by Endi S. Dewata at 2023-12-11T12:00:10+07:00
Update version number to 11.5.0-alpha4
- - - - -
2534b1ab by Endi S. Dewata at 2023-12-11T16:30:29+07:00
Update getter methods in LDAPConfig
The getter methods in LDAPConfig have been modified to return
null if the params are not defined.
- - - - -
469c06af by Endi S. Dewata at 2023-12-11T16:30:48+07:00
Add setter methods in LDAPAuthenticationConfig
- - - - -
cbcf76a6 by Endi S. Dewata at 2023-12-11T17:16:34+07:00
Rename LDAPConfigurator.initializeConsumer()
The LDAPConfigurator.initializeConsumer() has been renamed to
initializeReplicationAgreement().
- - - - -
d9b0fd7f by Marco Fargetta at 2023-12-11T17:10:01+01:00
Implement GET verb for /ca/v2/certs/<id> REST end-point
This replicate the current behaviour imeplemented in
/ca/rest/certs/<id>.
- - - - -
20cfb69e by Marco Fargetta at 2023-12-11T17:10:01+01:00
Implement v2 REST end-point for /ca/v2/certs
Implement the REST operations:
- GET of /ca/v2/certs
- POST to /ca/v2/certs/search.
These implement the behaviour of the current REST operations (see [1, 2]). The new version is not based on RESTeasy framework for the REST operation and the DB searches have replaced VLV with paged queries.
The only differences with the previous implementation are:
- the total value now show the number of returned item;
- the number of returned entry is limited (this is hard-coded for now).
1. https://github.com/dogtagpki/pki/wiki/CA-List-Certificates-REST-API
2. https://github.com/dogtagpki/pki/wiki/CA-Search-Certificates-REST-API
- - - - -
dd3b9096 by Marco Fargetta at 2023-12-11T17:10:01+01:00
Tidy up CertServlet
- - - - -
1ea09855 by Marco Fargetta at 2023-12-11T17:10:01+01:00
Fix Cert REST api v2 output format
- - - - -
e9861835 by Endi S. Dewata at 2023-12-12T12:13:01+07:00
Update test for CA cloning with replicated DS
The test for CA cloning with replicated DS has been updated to
import the primary CA's system certs and keys into the secondary
CA's NSS database prior to running pkispawn so it's no longer
necessary to specify the PKCS #12 path and password for pkispawn.
The ConfigurationFile.verify_predefined_configuration_file_data()
and initialization.py have been modified such that the PKCS #12
path and password are no longer mandatory for cloning.
- - - - -
bc04a8e5 by Endi S. Dewata at 2023-12-12T12:13:01+07:00
Add pki-server <subsystem>-db-repl-agmt-init
The pki-server <subsystem>-db-repl-agmt-init has been added
to start initializing the replication agreement and wait
until it's complete.
The SubsystemDBReplicationSetupCLI has been modified to no
longer include initializing the replication agreement.
The test for CA cloning with replicated DS has been updated
to use the new command.
- - - - -
f1c880dd by Endi S. Dewata at 2023-12-12T12:50:55+07:00
Clean up SubsystemDBReplicationAgreementInitCLI
- - - - -
4f80ab69 by Endi S. Dewata at 2023-12-12T12:50:55+07:00
Refactor LDAPConfigurator.createReplicationManager()
The LDAPConfigurator.createReplicationManager() has been
modified to take a bind DN instead of a bind user.
- - - - -
654a4695 by Endi S. Dewata at 2023-12-12T12:50:55+07:00
Split LDAPConfigurator.setupReplicationAgreement()
The LDAPConfigurator.setupReplicationAgreement() has been split
into enableReplication() and createReplicationAgreement().
- - - - -
281f21c7 by Endi S. Dewata at 2023-12-12T12:50:55+07:00
Split SubsystemDBReplicationSetupCLI.setupReplicationAgreements()
The SubsystemDBReplicationSetupCLI.setupReplicationAgreements() has
been split into enableReplication() and createReplicationAgreements().
- - - - -
7f227a4e by Endi S. Dewata at 2023-12-13T11:11:21+07:00
Log running threads in subsystem
- - - - -
8adea56f by Endi S. Dewata at 2023-12-13T12:27:12+07:00
Update CA clone tests to check DS replication config
- - - - -
e37cf9c1 by Endi S. Dewata at 2023-12-13T14:00:11+07:00
Update IPA clone test to check DS replication config
- - - - -
a8bfd1d8 by Endi S. Dewata at 2023-12-13T18:01:44+07:00
Add pki-server <subsystem>-db-repl-agmt-add
The pki-server <subsystem>-db-repl-agmt-add has been added to
create DS replication agreements prior to running pkispawn.
The SubsystemDBReplicationSetupCLI has been modified to no
longer create the replication agreements.
The PKIDeployer.setup_database() has been modified to create
the replication agreements in both the master and the replica.
The test for CA cloning with replicated DS has been modified
to use the new command.
- - - - -
335c8705 by Endi S. Dewata at 2023-12-14T16:08:00+07:00
Add pki-server <subsystem>-db-create
The pki-server <subsystem>-db-create has been added to create
a DS backend for the subsystem.
The pki-server <subsystem>-db-init has been updated to no longer
provide a --create-backend option.
The test for CA cloning with replicated DS has been modified to
use the new command.
- - - - -
a9e002fd by Endi S. Dewata at 2023-12-14T19:01:43+07:00
Add pki-server <subsystem>-db-repl-enable
The pki-server <subsystem>-db-repl-enable has been added
to enable replication on a single DS instance. This command
replaces the SubsystemDBReplicationSetupCLI which enables
replication both on the DS master and the replica at the
same time.
The test for CA cloning with replicated DS has been updated
to use the new command.
- - - - -
38cd57c2 by Marco Fargetta at 2023-12-14T15:33:29+01:00
Fix the update to 11.5.0
Check and create the folder for every subsystem update, beside the
instance update.
During the update certs and csr are removed from CS.cfg file and stored
in `<config>/certs` folder if they are not in the internaldb.
The folder creation for the instance was done after update the subsystem generating an error and stopping the update.
- - - - -
efc6fc63 by Endi S. Dewata at 2023-12-14T22:04:31+07:00
Remove unused pki_theme_* params
- - - - -
211ebb50 by Endi S. Dewata at 2023-12-14T22:04:31+07:00
Fix ipa-artifacts-save.sh
- - - - -
b10869eb by Endi S. Dewata at 2023-12-14T22:04:31+07:00
Add PKIDeployer.setup_replication()
The code that sets up replication in PKIDeployer.setup_database()
has been moved into PKIDeployer.setup_replication().
- - - - -
fd79ec58 by Endi S. Dewata at 2023-12-14T22:04:31+07:00
Update clone tests to check schema replication
- - - - -
0c7cadec by Endi S. Dewata at 2023-12-15T01:07:48+07:00
Update test for CA clone with replicated DS
The test for CA clone with replicated DS has been updated
to create search and VLV indexes manually since it will call
pkispawn with pki_ds_setup=False which will skip those steps.
- - - - -
b0df74ee by Endi S. Dewata at 2023-12-15T01:59:17+07:00
Move PKIServerFactory into pki.server
- - - - -
2e5ee9c1 by Marco Fargetta at 2023-12-21T18:18:43+01:00
Update wait-for-build action to the new action version
- - - - -
6a721178 by Marco Fargetta at 2024-01-08T18:52:48+01:00
Add opsFlagMask for HSM key pair generation
Default operation flags does not work for some HSM so a new mechanism is
introduced to allow a custom flag list. The certificate generate in the
hsm can be customised in pkispawn config file with `pki_<cert>_opsFlagMask` where `<cert> is one between:
- audit_signing
- sslserver
- subsystem
- ca_signing
- ocsp_signing
- storage
- transport
- ocsp_signing
The value is a comma sepated list of flags (case insensitive) which can
be: encrypt, decrypt, sign, sign_recover, verify, verify_recover, wrap,
unwrap AND derive.
The same flags can be used with the command `pki nss-key-create` where
the new flag `--ops-flag-mask` is added. The value is the a csv as
above.
- - - - -
dd2115ec by Marco Fargetta at 2024-01-08T18:52:48+01:00
Add opsFlag for HSM key pair generation
Add the second parameter to pkispawn in other to customise the key par generation in HSM. The new config parameter is `pki_<cert>_opsFlag`. The `<cert>` is the id as defined for the parameter `pki_<cert>_opsFlagMask` and they have the same values
- - - - -
74270673 by Marco Fargetta at 2024-01-08T18:52:48+01:00
Add test for pki_*_opsFlag and pki_*_opsFlagMask
- - - - -
185a8658 by Marco Fargetta at 2024-01-08T18:52:48+01:00
Renaming the opetion ops-flag and ops-flag-mask
The option are renamed to be more coherent with their meaning as:
- op-flags
- op-flags-mask
- - - - -
95c7a42c by Endi S. Dewata at 2024-01-09T01:36:25+07:00
Clean up test for CA clone with replicated DS
- - - - -
e095113a by Endi S. Dewata at 2024-01-09T01:36:25+07:00
Clean up test for CA with existing DS
- - - - -
57548bfe by Endi S. Dewata at 2024-01-09T01:39:32+07:00
Update wait-on-check-action in publish job
- - - - -
6cbeda82 by Marco Fargetta at 2024-01-09T14:39:20+01:00
Convert ca-cert-find server command to paged search
- - - - -
68e43fdf by dependabot[bot] at 2024-01-09T15:50:52+01:00
Bump ansible from 7.0.0 to 8.5.0 in /tests/dogtag/pytest-ansible
Bumps [ansible](https://github.com/ansible-community/ansible-build-data) from 7.0.0 to 8.5.0.
- [Changelog](https://github.com/ansible-community/ansible-build-data/blob/main/docs/release-process.md)
- [Commits](https://github.com/ansible-community/ansible-build-data/compare/7.0.0...8.5.0)
---
updated-dependencies:
- dependency-name: ansible
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support at github.com>
- - - - -
3b625f2b by Endi S. Dewata at 2024-01-11T06:51:31-06:00
Add test for KRA clone with replicated DS
A new test has been added to verify installing CA and KRA
subsystem with DS, cloning the CA and KRA databases in DS,
then installing CA and KRA clones using the cloned CA and
KRA databases.
This process allows DS cloning to be done separately from
CA and KRA cloning which could prevent pkispawn from timing
out if the database is large.
https://github.com/dogtagpki/pki/wiki/Installing-CA-Clone-with-Replicated-DS
https://github.com/dogtagpki/pki/wiki/Installing-KRA-Clone-with-Replicated-DS
- - - - -
6a4648b7 by Endi S. Dewata at 2024-01-12T07:13:25-06:00
Remove preop.admin.group param
The preop.admin.group param defines the list of admin user's
default groups and provides an undocumented way to customize the
groups during installation, but this param can only be used under
certain installation scenarios. Instead of that, it's better to
use the CLI to change the groups after the installation is done.
The param has been removed and the list of admin user's default
groups has been moved into PKIDeployer.setup_admin_user().
- - - - -
043b1d31 by Endi S. Dewata at 2024-01-12T20:13:47+07:00
Clean up PKIDeployer.init_server_nssdb()
The PKIDeployer.init_server_nssdb() has been renamed to
create_server_nssdb(). The code that calls this method has
been moved into instance_layout.py. The code that creates
the link in the subsystem folder has been moved into
subsystem_layout.py.
- - - - -
28782fac by Endi S. Dewata at 2024-01-12T20:23:17+07:00
Clean up security_databases.py
The code that configures CS.cfg params in security_databases.py
has been moved into subsystem_layout.py.
- - - - -
4973677c by Endi S. Dewata at 2024-01-12T22:42:37+07:00
Remove redundant PKIDeployer.update_system_cert()
The PKIDeployer.update_system_cert() has been removed since
updating the nickname and tokenname params has been done by
init_system_cert_params().
- - - - -
aab150db by Endi S. Dewata at 2024-01-12T22:56:15+07:00
Clean up PKISubsystem.update_system_cert()
The code that configures the nickname and tokenname params in
PKISubsystem.update_system_cert() has been removed since it has
been done by PKIDeployer.init_system_cert_params(). The method
has also been renamed to store_system_cert_request().
- - - - -
0a08100e by Endi S. Dewata at 2024-01-13T07:46:31+07:00
Clean up PKIDeployer.setup_system_cert()
The PKIDeployer.setup_system_cert() has been modified to process
remote cert first, then self-signed or local cert.
- - - - -
49e5fe96 by Endi S. Dewata at 2024-01-15T11:55:01+07:00
Add PKISubsystem.csr_file()
The code that constructs the CSR path for a system cert has
been consolidated into PKISubsystem.csr_file().
- - - - -
fddf10d8 by Endi S. Dewata at 2024-01-15T11:55:02+07:00
Update PKIDeployer.setup_system_cert() to reuse existing request
- - - - -
749deba7 by Endi S. Dewata at 2024-01-15T11:55:03+07:00
Update PKIDeployer.setup_system_cert() to reuse existing key
- - - - -
840e9b24 by Endi S. Dewata at 2024-01-15T15:42:33+07:00
Update pki-server ca-cert-request-import
The pki-server ca-cert-request-import has been updated to
support an absolute bootstrap profile path.
- - - - -
e7f83ceb by Endi S. Dewata at 2024-01-15T15:42:33+07:00
Update pki-server ca-cert-import
The pki-server ca-cert-import has been updated to support
an absolute bootstrap profile path.
- - - - -
80a61fe2 by Marco Fargetta at 2024-01-15T11:32:42+01:00
Using paged search for Search Certificate Web UI
Replacing the VLV search with the paged search for WEB UI search
certificate page. The new search is not sorted by serial number but
since the new pki version is moving to random serial number this sorting
is not useful in future release.
- - - - -
d2fbc5ef by Marco Fargetta at 2024-01-15T11:32:42+01:00
Modify ListCert to replace VLV with paged search
- - - - -
d9dae8b9 by Marco Fargetta at 2024-01-15T11:32:42+01:00
Update list cert template and tidyup ListCerts
- - - - -
095a4819 by Endi S. Dewata at 2024-01-15T20:23:28+07:00
Add default ID length for RSNv3
The Repository classes have been modified to generate 128-bit
IDs for RSNv3 if the *.id.length param is not specified.
- - - - -
f4a7455f by Endi S. Dewata at 2024-01-16T08:38:57-06:00
Skip importing certs and requests when pki_ds_setup=False
If pki_ds_setup is set to False pkispawn should not modify the
DS during installation, so the PKIDeployer.setup_system_cert()
has been modified to skip importing the certs and the requests
into CA database in that scenario. With this change the certs
and the requests need to be imported separately.
The CA installation test with existing DS has been modified to
import the certs and the requests into CA database before
calling pkispawn.
https://github.com/dogtagpki/pki/wiki/Installing-CA-with-Existing-DS-Database
- - - - -
4dba7bfb by Endi S. Dewata at 2024-01-16T08:38:57-06:00
Update CA container test
The CA container test has been modified to export the certs and
requests provided to the container during startup such that they
can be imported into CA database after startup.
https://github.com/dogtagpki/pki/wiki/Deploying-CA-on-Podman
- - - - -
9e387742 by Endi S. Dewata at 2024-01-17T17:24:43+07:00
Add test for KRA with existing DS database
A new test has been added to install CA, set up KRA certs and
database, then install KRA with the existing certs and database
instead of creating new ones in pkispawn. This test simulates
restoring KRA from a backup.
https://github.com/dogtagpki/pki/wiki/Installing-KRA-with-Existing-DS-Database
- - - - -
12838ce6 by Endi S. Dewata at 2024-01-19T12:38:02+07:00
Remove redundant NSSDatabase.import_cert_chain() return values
- - - - -
fe2619fb by ut004527 at 2024-01-19T14:57:23+07:00
fix incorrect words
- - - - -
23deaf53 by Endi S. Dewata at 2024-01-19T19:59:04+07:00
Fix support for cert bundle
The NSSDatabase.import_cert_chain() has been modified to
import the cert bundle specified in pki_cert_chain_path as
individual CA certs instead of as a single PKCS #7 cert
chain. This allows the cert bundle to include multiple
unrelated cert chains.
The NSSDatabase.__convert_certs_into_pkcs7() is no longer
used so it has been removed.
The test for CA cloning with secure DS connection has been
updated to include both CA and DS signing certs into a cert
bundle to validate the above changes.
Resolves: https://issues.redhat.com/browse/RHCS-4746
- - - - -
2268461f by Marco Fargetta at 2024-01-24T10:37:41+01:00
Updating version to v11.5.0-alpha5
- - - - -
cd68b1b5 by Endi S. Dewata at 2024-01-29T23:25:17+07:00
Add HSM support for LWCA
The CAEngine.createCA() has been modified to get the token
name from LWCA's keyNickname. If the token name exists,
it will use that token to create the private key and store
the cert. Otherwise, it will use the internal token.
The CASigningUnit.init() has been modified to get the token
name from name from LWCA's keyNickname. If the token name
exists, it will use that token to load the cert and the
private key, and for signing and verification. Otherwise, it
will use the internal token.
The LWCA test with HSM has been modified to verify that the
LWCA cert and key will be created in HSM instead of internal
token.
Resolves: https://github.com/dogtagpki/pki/issues/2412
- - - - -
45200b4a by Marco Fargetta at 2024-01-29T20:34:55+01:00
Make CertRecordPagedList generic
The class `CertRecordPagedList` is renamed to `RecordPagedList` and made
generic to be used with all type of entries available.
- - - - -
b531c4f1 by Endi S. Dewata at 2024-01-29T14:11:15-06:00
Move CertificateAuthority.deleteAuthority() to CAEngine
- - - - -
4d968c78 by Endi S. Dewata at 2024-01-29T14:11:15-06:00
Split CertificateAuthority.deleteAuthorityNSSDB()
- - - - -
a1f3dfd7 by Endi S. Dewata at 2024-01-29T14:11:15-06:00
Move CertificateAuthority.renewAuthority() to CAEngine
- - - - -
2e30e765 by Endi S. Dewata at 2024-01-29T14:11:15-06:00
Move CertificateAuthority.checkForNewerCert() to CAEngine
- - - - -
80d81449 by Endi S. Dewata at 2024-01-29T14:11:15-06:00
Move CertificateAuthority.addCRLIssuingPoint() to CAEngine
- - - - -
552000a3 by Endi S. Dewata at 2024-01-29T14:11:15-06:00
Move CertificateAuthority.deleteCRLIssuingPoint() to CAEngine
- - - - -
b60920f4 by Endi S. Dewata at 2024-01-29T14:11:15-06:00
Rename SubsystemConfig to SubsystemInfoConfig
- - - - -
662eba1d by Endi S. Dewata at 2024-01-29T14:11:15-06:00
Replace SubsystemInfo with SubsystemInfoConfig
- - - - -
99d24e35 by Endi S. Dewata at 2024-01-29T14:11:15-06:00
Replace CertUserDBAuthentication.CRED_CERT with AuthManager.CRED_SSL_CLIENT_CERT
- - - - -
7b44b258 by Endi S. Dewata at 2024-01-29T14:11:15-06:00
Replace CertUserDBAuthentication.TOKEN_USERID with AuthToken.USER_ID
- - - - -
34b286d0 by Endi S. Dewata at 2024-01-29T17:02:04-06:00
Replace GetCertStatus.mCA with CAEngine.getCA()
- - - - -
8258d8fb by Endi S. Dewata at 2024-01-29T17:02:05-06:00
Replace ServiceGetCAChain.mCA with CAEngine.getCA()
- - - - -
835e19c3 by Endi S. Dewata at 2024-01-29T17:02:06-06:00
Replace LocalConnector.mSource with CAEngine.getCA()
- - - - -
452fd831 by Endi S. Dewata at 2024-01-29T17:02:08-06:00
Replace CAService.mCA with CAEngine.getCA()
- - - - -
162fad67 by Endi S. Dewata at 2024-01-29T19:30:06-06:00
Move CertificateAuthority.init() to CAEngine
- - - - -
b6a0a77f by Endi S. Dewata at 2024-01-29T19:30:06-06:00
Move CertificateAuthority.initOCSPSigningUnit() to CAEngine
- - - - -
fe28cd6d by Endi S. Dewata at 2024-01-29T19:30:06-06:00
Move CertificateAuthority.initCRLSigningUnit() to CAEngine
- - - - -
ac26bccd by Endi S. Dewata at 2024-01-29T19:30:06-06:00
Move CertificateAuthority.initCertSigningUnit() to CAEngine
- - - - -
070d6083 by Marco Fargetta at 2024-01-30T11:25:31+01:00
Updating version to v11.5.0-alpha6
- - - - -
2236be68 by Marco Fargetta at 2024-01-30T18:24:37+01:00
Updating version to v11.5.0-alpha7
- - - - -
b928136c by Endi S. Dewata at 2024-01-30T16:15:02-06:00
Split CertificateAuthority.sign()
The code that checks the CA's readiness and measure timings in
CertificateAuthority.sign() has been moved into CAEngine.
- - - - -
5d57aa94 by Endi S. Dewata at 2024-01-30T18:37:55-06:00
Add CertificateAuthority.fastSigning
- - - - -
17c299c5 by Endi S. Dewata at 2024-01-30T18:43:55-06:00
Add CertificateAuthority.ocspResponderByName
- - - - -
e8e1ee2e by Endi S. Dewata at 2024-01-30T18:44:09-06:00
Replace IOCSPService.validate() with OCSPServlet.validate()
- - - - -
ec8eb4aa by Endi S. Dewata at 2024-01-30T18:53:30-06:00
Add CAEngine.validate()
The code in CertificateAuthority.validate() that finds
the LWCA to handle the OCSP request has been moved into
CAEngine.validate().
- - - - -
62df9a60 by Endi S. Dewata at 2024-01-30T19:06:32-06:00
Add CertificateAuthority.certRepository
- - - - -
b25a6d80 by Endi S. Dewata at 2024-01-31T22:15:14+07:00
Add test for LWCA removal
The LWCA tests with internal NSS token and HSM have been
updated to test LWCA removal and validate that the
corresponding LDAP entry, NSS cert, and NSS key are also
removed.
- - - - -
4874f8ff by Endi S. Dewata at 2024-01-31T15:33:42-06:00
Move CertificateAuthority.revokeAuthority() to CAEngine
- - - - -
647a0863 by Endi S. Dewata at 2024-01-31T15:33:43-06:00
Split CertificateAuthority.generateSigningCert()
The code in CertificateAuthority.generateSigningCert() that
generates a key pair has been moved into generateKeyPair().
The code that generates a cert request has been moved into
generateCertRequest(). The code that issues the cert has
been moved into CAEngine.generateSigningCert().
- - - - -
268e32c3 by Endi S. Dewata at 2024-01-31T15:35:39-06:00
Replace CAAdminServlet.mCA with CAEngine.getCA()
- - - - -
5c0ba66b by Endi S. Dewata at 2024-01-31T18:39:57-06:00
Refactor CAEngine.initSubsystem()
The code in CAEngine.initSubsystem() that initializes the host
CA has been moved into initSubsystems().
- - - - -
02c0413c by Endi S. Dewata at 2024-01-31T18:47:43-06:00
Refactor OCSPEngine.initSubsystem()
The code in OCSPEngine.initSubsystem() that initializes the OCSP
authority has been moved into initSubsystems().
- - - - -
819837e6 by Endi S. Dewata at 2024-01-31T18:47:43-06:00
Clean up log messages in CASigningUnit
- - - - -
f534e081 by Endi S. Dewata at 2024-01-31T18:47:43-06:00
Clean up CA test artifacts
- - - - -
c3575dd7 by Endi S. Dewata at 2024-02-01T10:22:01-06:00
Split CertificateAuthority.processRequest()
The code in CertificateAuthority.processRequest() that
gets the cert status from database has been moved into
getCertStatusFromDB(). The code that gets the status
from CRL has been moved into getCertStatusFromCRL().
- - - - -
e3a4acc6 by Endi S. Dewata at 2024-02-01T10:32:00-06:00
Refactor CAEngine.addCRLIssuingPoint()
The CAEngine.addCRLIssuingPoint() has been modified to use
the host CA instead of taking a CA param which was always set
to host CA anyway.
- - - - -
89727ab9 by Endi S. Dewata at 2024-02-01T10:32:29-06:00
Replace CRLIssuingPoint.getCertificateAuthority() with CAEngine.getCA()
- - - - -
df80dee6 by Endi S. Dewata at 2024-02-01T10:32:29-06:00
Replace CRLIssuingPoint.mCA with CAEngine.getCA()
- - - - -
94644636 by Endi S. Dewata at 2024-02-02T18:41:11-06:00
Update log messages in CMSEngine
- - - - -
6c3e86d6 by Marco Fargetta at 2024-02-08T11:57:04+01:00
New list requests using paged search
Add paged requests without VLV to RequestRepository and a new method to list requests in CMSRequestDAO
The new method to list the requests is based on paged searches
- - - - -
1613f7c6 by Endi S. Dewata at 2024-02-14T08:50:00-06:00
Add pki-server ca-profile-find
The pki-server ca-profile-find command has been added to list
the profile records in the profile database.
- - - - -
7f48f402 by Endi S. Dewata at 2024-02-14T08:50:00-06:00
Add pki-server ca-profile-mod
The pki-server ca-profile-mod command has been added to modify
a profile record in the profile database.
- - - - -
a064ebe7 by Endi S. Dewata at 2024-02-14T08:50:00-06:00
Add test for KRA with ECC
A new test has been added to validate installing KRA with ECC
certs (except for storage and transport certs) then archive
ECC keys using CRMFPopClient and pki client-cert-request.
- - - - -
a58a63b9 by Endi S. Dewata at 2024-02-15T15:16:03-06:00
Update actions/checkout
- - - - -
d45f1c2b by Endi S. Dewata at 2024-02-15T15:16:03-06:00
Update actions/cache
- - - - -
d39e5c79 by Endi S. Dewata at 2024-02-15T16:37:49-06:00
Update actions/setup-java
- - - - -
700ecb10 by Endi S. Dewata at 2024-02-15T16:38:39-06:00
Update actions/upload-artifact
- - - - -
05099526 by Endi S. Dewata at 2024-02-15T16:39:32-06:00
Update docker/setup-buildx-action
- - - - -
7384e449 by Endi S. Dewata at 2024-02-15T16:40:21-06:00
Update docker/build-push-action
- - - - -
90a8d1ad by Endi S. Dewata at 2024-02-15T16:41:35-06:00
Update docker/login-action
- - - - -
c25f71ef by Endi S. Dewata at 2024-02-16T09:27:13-06:00
Fix test for CA with request notification
In Fedora 40 the mailx package was replaced with the s-nail
package. The test for CA with request notification has been
updated to expect different messages depending on the package
actually installed.
- - - - -
768ff136 by Endi S. Dewata at 2024-02-16T09:29:20-06:00
Refactor PKIServer.get_webapps()
The code in PKIServer.get_webapps() that gathers the info
of a webapp has been moved into PKIServer.get_webapp().
Some tests have been updated to use pki-server webapp-find
to list the webapps deployed in the instance.
- - - - -
f7e2660c by Endi S. Dewata at 2024-02-16T09:29:20-06:00
Add pki-server webapp-show
The pki-server webapp-show has been added to show the info
of a deployed webapp. Some tests have been updated to use
this command.
- - - - -
252456e7 by Endi S. Dewata at 2024-02-16T09:29:20-06:00
Fix pki-server subsystem-show
The PKIServer.load_subsystems() has been modified to skip
loading a subsystem if the subsystem folder doesn't exist
or is empty. This will restore pki-server subsystem-show
to work more consistently as in the previous PKI version.
Resolves: https://issues.redhat.com/browse/RHEL-21568
- - - - -
358aada3 by Marco Fargetta at 2024-02-19T11:54:04+01:00
Adding filters for v2 APIs
Since v2 rest API are implemented without JAX-RS support the
interceptors used in current implementation for the authentication have
been converted to filters maintaining very similar functionality.
The only difference is in the audit log because it will not be logged
the access method but the accessed REST URI.
- - - - -
442be48b by Marco Fargetta at 2024-02-19T11:54:04+01:00
Implement GET method for /ca/v2/agent/certrequests APIs
The GET method allow to list the cert requests and retrieve one for
review. The main difference with the old implementation is that the
start parameter is not anymore a request id but an index in the list of
requests.
- - - - -
664dab5f by Marco Fargetta at 2024-02-19T11:54:04+01:00
Implement POST method for /ca/v2/agent/certrequests APIs
The POST methods allow all the operation on the certrequest. These are
the same available in the previous implementation and support the same
parameters.
- - - - -
2a24da92 by Marco Fargetta at 2024-02-19T11:54:04+01:00
Tidyup /ca/v2/agent/certrequests APIs implementation
- - - - -
00fdb219 by Endi S. Dewata at 2024-02-19T22:40:07-06:00
Fix BASE_IMAGE param
The Azure pipeline has been modified to support BASE_IMAGE
param so it can be used to test different platforms.
The RPM spec file has been modified to depend specifically
on maven-local-openjdk17 to ensure that the build is done
consistently using OpenJDK 17 across platforms.
https://github.com/dogtagpki/pki/wiki/Configuring-Test-OS
- - - - -
5978a49f by Endi S. Dewata at 2024-02-20T14:57:40-06:00
Fix REGISTRY_NAMESPACE param
The CI has been updated to install packages from the specified
REGISTRY_NAMESPACE.
- - - - -
2d5051a6 by Marco Fargetta at 2024-02-21T17:54:49+01:00
Remove AuthorityMonitor tracking update
The tracking update allows to avoid reloading an authority if no changes
have been done to the record. To verify the changes it is used the
LDAP attribute `entryUSN` which is updated by DS server on any change.
The tracker update mechanism has a race condition when an entry is
modified by the `CAEngine`. When the method `modifyAuthorityEntry()` is
invoked, this will update the tracker and no CA are reloaded by the
`AuthorityMonitor` thread because the tracker is already to the newest
value. However, in case of CA clones, when a sub CA is created in the
primary CA, the clone will get the record but there is no serial.
The CA is registered and when the related keys are retrieved the
record is update with the serial. The update is done by the
`modifyAuthorityEntry()` which will update the trackers. As a result the
`AuthorityMonitor` will not update the CA object and when used
it will miss the serial so some operations will fails.
Since, the `trackerUpdate` method has not other impact has been removed so all
trackers are managed by the `AuthorityMonitor`.
Fix #4669
- - - - -
e4de367f by Endi S. Dewata at 2024-02-21T13:22:54-06:00
Fix CI failures
The Azure pipeline has been updated to install the latest JSS,
LDAP SDK, and IdM Console Framework from Quay since they might
not be released yet into the official Fedora repository.
The default value for REGISTRY_NAMESPACE has been changed from
the repository owner to 'dogtagpki' such that the pipeline can
run properly without having to set up a private repository in
Quay.
The RPM spec file has been modified to depend on maven-local
since maven-local-openjdk17 is not available on CentOS/RHEL.
- - - - -
aa8f6e14 by Marco Fargetta at 2024-02-21T15:01:40-06:00
Add test for subca in ipa clone
- - - - -
9890872e by Endi S. Dewata at 2024-02-21T15:03:00-06:00
Updating version number to 11.5.0
- - - - -
d8df8dab by Marco Fargetta at 2024-02-22T11:20:00+01:00
Update Sonar action for pull requests
Fix problem with absolete action github-script.
- - - - -
653c64d0 by Endi S. Dewata at 2024-02-26T18:23:02-06:00
Update version number to 11.6.0-alpha1
- - - - -
8686e904 by Endi S. Dewata at 2024-02-28T17:40:12-06:00
Update IPA tests to display logs
- - - - -
ddc35518 by Endi S. Dewata at 2024-02-28T21:09:04-06:00
Update CA tests to capture pkidestroy logs
- - - - -
0f12ab6a by Endi S. Dewata at 2024-03-01T10:47:19-06:00
Add tests for adding multiple LWCAs
New tests have been added to validate adding multiple LWCAs in
plain PKI environment and in IPA environment.
The CASigningUnit has been updated to no longer log an exception
if the cert or key is missing since in LWCA case the exception is
used as a mechanism to trigger the key retriever so it is actually
not a problem. Instead, the exception will only be logged by other
code where the exception indicates a real problem.
- - - - -
ec4e8028 by Endi S. Dewata at 2024-03-04T10:14:52-06:00
Update dependencies
The pom.xml files have been updated to support newer JSS,
LDAP SDK, and IDM Console Framework.
- - - - -
5fcf756e by Endi S. Dewata at 2024-03-05T09:01:28-06:00
Fix missing dnf builddep in Dockerfiles
The Dockerfiles have been modified to install dnf-plugins-core
regardless of COPR_REPO value to ensure that the dnf builddep
command will work.
Resolves: https://github.com/dogtagpki/pki/issues/4664
- - - - -
a54409e8 by Endi S. Dewata at 2024-03-05T09:51:27-06:00
Merge IDM Console Framework
To simplify package maintenance the IDM Console Framework has
been merged into PKI Console. Dependencies on IDM Console
Framework have been removed.
- - - - -
3a564d34 by Endi S. Dewata at 2024-03-06T09:46:02-06:00
Update Java dependencies
The RPM spec has been updated to use Java 21 on Fedora 40 or
later and Java 17 on other platforms.
The Dockerfile has been modified to remove any Java packages
pulled by the existing PKI package to ensure that the build
will be done using the correct Java version.
- - - - -
a6b9d869 by Endi S. Dewata at 2024-03-06T12:43:10-06:00
Clean up KRA test artifacts
- - - - -
0c447bcb by Endi S. Dewata at 2024-03-06T17:55:48-06:00
Clean up keygen.py
The keygen.py has been updated not to call subsystem.save()
after deployer.generate_system_cert_requests() since the
CSRs are no longer stored in the CS.cfg.
- - - - -
de44f51d by Endi S. Dewata at 2024-03-06T18:56:22-06:00
Refactor PKIDeployer.setup_admin_cert() (part 1)
The PKIDeployer.setup_admin_cert() has been modified to take
an optional param to specify the admin cert request.
- - - - -
0b8685ea by Endi S. Dewata at 2024-03-06T18:58:56-06:00
Refactor PKIDeployer.setup_admin_cert() (part 2)
The code in PKIDeployer.setup_admin_cert() that loads the
admin cert from a file has been modified to assume that the
file contains a valid cert.
- - - - -
2fa1722a by Endi S. Dewata at 2024-03-06T19:09:44-06:00
Refactor PKIDeployer.setup_admin_cert() (part 3)
The PKIDeployer.setup_admin_cert() has been modified to check
whether the admin cert already exists in the NSS database.
- - - - -
1aa53cfd by Endi S. Dewata at 2024-03-07T08:27:34-06:00
Refactor PKIDeployer.create_admin_csr() (part 1)
The code in PKIDeployer.create_admin_csr() that stores the
admin cert request into a file during standalone installation
has been removed since it's never executed and already done
by generate_admin_request().
- - - - -
08df9367 by Endi S. Dewata at 2024-03-07T08:27:35-06:00
Refactor PKIDeployer.create_admin_csr() (part 2)
The PKIDeployer.create_admin_csr() has been modified to use
generate_csr() to generate the CSR.
- - - - -
e3f557db by Endi S. Dewata at 2024-03-07T08:27:36-06:00
Remove unused Certutil.generate_certificate_request()
- - - - -
70ed3843 by Endi S. Dewata at 2024-03-07T12:48:17-06:00
Clean up pkispawn man page
- - - - -
bd0441a3 by Endi S. Dewata at 2024-03-07T15:34:18-06:00
Clean up NSSDatabase.get_cert_info()
The NSSDatabase.get_cert_info() has been modified to convert
the PEM cert into Base64 instead of retrieving it again from
the NSS database in Base64 format.
- - - - -
021ef09d by Endi S. Dewata at 2024-03-07T15:34:18-06:00
Update log messages in PKIDeployer.setup_admin_cert()
- - - - -
e2a18e39 by Endi S. Dewata at 2024-03-07T20:52:57-06:00
Remove unused FindMozLDAP.cmake
- - - - -
9b0993f7 by Endi S. Dewata at 2024-03-08T08:29:31-06:00
Remove unused <subsystem>.admin.cert param
The <subsystem>.admin.cert param was originally used to store
the admin cert for standalone subsystems but it's no longer
used so it has been removed.
- - - - -
fa8fb26f by Endi S. Dewata at 2024-03-08T08:45:48-06:00
Drop zlib dependency
The code in tpsclient that used zlib was dropped in PKI 11.1
so the dependency is no longer needed.
- - - - -
73fd6b97 by Marco Fargetta at 2024-03-11T12:08:23+01:00
Implement method for /ca/v2/certrequests APIs
The methods allow all the operation on the certrequests endpoint.
- - - - -
b15f520e by Marco Fargetta at 2024-03-12T17:45:08+01:00
Remove VLV query from EnrollServlet
- - - - -
a9c211b1 by Endi S. Dewata at 2024-03-12T12:53:54-05:00
Use gcc option _FORTIFY_SOURCE=3
The RPM spec has been updated to use gcc option _FORTIFY_SOURCE=3
since it's now required by rpminspect. The code that configures
this option in CMake script has been removed to reduce dependency
on CMake.
- - - - -
58cc026a by Endi S. Dewata at 2024-03-13T09:34:13-05:00
Add test for KRA with existing certs
A new test has been added to create KRA with existing system
certs and keys in a PKCS #12 file, their corresponding CSRs,
and the admin certificate.
https://github.com/dogtagpki/pki/wiki/Installing-KRA-with-Existing-Certificates
- - - - -
01ad06e9 by Endi S. Dewata at 2024-03-13T16:55:20-05:00
Drop sslget
The sslget command has been moved from pki-tools to jss-tools.
- - - - -
726c6300 by Endi S. Dewata at 2024-03-13T21:18:13-05:00
Update log messages in UGSubsystem.buildUser()
- - - - -
a2c528de by Endi S. Dewata at 2024-03-14T09:47:59-05:00
Add test for KRA with existing NSS database
A new test has been added to create KRA with existing system
certs and keys in an NSS database, their corresponding CSRs,
and the admin cert.
https://github.com/dogtagpki/pki/wiki/Installing-KRA-with-Existing-NSS-Database
- - - - -
5b99fae1 by Endi S. Dewata at 2024-03-15T09:15:02-05:00
Update pki-server status
The pki-server status command has been modified to no longer
show the subsystem "Type" field since it's redundant. Instead,
it will show an "SD Manager" field which will indicate whether
the subsystem is a security domain manager. Some CI tests have
been updated to validate this command.
- - - - -
41b524b1 by Endi S. Dewata at 2024-03-15T09:19:49-05:00
Add test for KRA with existing HSM
A new test has been added to create KRA with existing system
certs and keys in an NSS database connected to an HSM, their
corresponding CSRs, and the admin cert.
https://github.com/dogtagpki/pki/wiki/Installing-KRA-with-Existing-NSS-Database
- - - - -
e8b0de18 by Endi S. Dewata at 2024-03-15T15:10:24-05:00
Update CA tests to capture pkidestroy logs
- - - - -
da25445f by Endi S. Dewata at 2024-03-15T18:59:03-05:00
Update PKIDeployer.setup_admin_cert()
The PKIDeployer.setup_admin_cert() has been updated to fail
if the pki_admin_cert_file points to a non-existent file.
- - - - -
eda38d56 by Endi S. Dewata at 2024-03-18T08:45:42-05:00
Drop pki_existing param
The pki_existing param is actually redundant and can be removed
safely. Remaining references to this param in pkispawn have
been removed. The pkiparser.py has been modified to deprecate
this param. The CI tests have been updated to no longer use it.
- - - - -
0f141404 by Endi S. Dewata at 2024-03-19T09:09:25-05:00
Drop p12tool
The p12tool command has been moved from pki-tools to jss-tools.
- - - - -
ccb86eb2 by Endi S. Dewata at 2024-03-19T10:54:35-05:00
Remove <subsystem>.standalone param
Previously the <subsystem>.standalone param was used to
indicate whether the subsystem is standalone, and if so
the security domain service would be enabled.
This param is actually redundant since the service can
also be enabled using the securitydomain.select param so
it will be enabled by default in standalone subsystems.
Subclasses of SecurityDomainService have been replaced
by the super class which will enable the service based
on the securitydomain.select param.
Since the <subsystem>.standalone param is no longer used
the upgrade script has been updated to remove this param
from existing instances.
Note: The pki_standalone param is still in use.
- - - - -
9d26689a by Endi S. Dewata at 2024-03-19T10:57:18-05:00
Update KeyRecoveryAuthority.doKeyRecovery()
The KeyRecoveryAuthority.doKeyRecovery() has been updated to
reuse the existing Request object.
- - - - -
5f19ac52 by Endi S. Dewata at 2024-03-20T11:08:26-05:00
Add test for key archival and retrieval
The basic KRA test has been modified to perform a cert enrollment
with key archival against CA, retrieve the archive key from KRA,
then verify that the archived key belongs to the cert.
The pki kra-key-retrieve has been modified to store the PKCS #12
data returned by KRA into the output file if specified.
- - - - -
2498b4e1 by Endi S. Dewata at 2024-03-21T09:32:29-05:00
Drop p7tool
The p7tool command has been moved from pki-tools to jss-tools.
- - - - -
3353bbbe by Endi S. Dewata at 2024-03-21T11:22:29-05:00
Add test for key archival and retrieval in IPA
The basic IPA test has been modified to create a vault,
verify that it is empty initially, archive a private key,
retrieve the private key, and verify the archived key.
- - - - -
0bbcbdf4 by Marco Fargetta at 2024-03-22T13:14:58+01:00
Implement method for /ca/v2/agent/certs APIs
- - - - -
e810299c by Marco Fargetta at 2024-03-22T18:26:19+01:00
Fix log message in PKISocketFactory
- - - - -
d0100484 by Endi S. Dewata at 2024-03-25T09:27:05-05:00
Deprecate revoker tool
The original revoker tool has not been updated for a while
and doesn't seem to be working properly anymore so it has
been removed and replaced with a shell script that calls
pki ca-cert commands to revoke the certs. The shell script
will also generate a deprecation warning.
The pki ca-cert commands for revocation have been updated to
accept multiple serial numbers.
A new test has been added to verify cert revocation scenarios.
- - - - -
e496bb59 by Endi S. Dewata at 2024-03-26T11:46:25-05:00
Update ds-container-create.sh
The ds-container-create.sh has been updated to provide options
to specify the suffix and the base DN of the directory.
- - - - -
1656d4f1 by Endi S. Dewata at 2024-03-26T11:46:25-05:00
Add test for KRA migration
A new test has been added to verify KRA migration by creating
a KRA, archive a key, retrieve the key, create a second KRA,
migrate the database using KRATool, then retrieve the key again
from the second KRA.
- - - - -
9a31f33e by Endi S. Dewata at 2024-03-26T22:30:36-05:00
Update KRATool to use java.util.logging
- - - - -
9039fb32 by Marco Fargetta at 2024-03-28T11:44:47+01:00
Convert CertStatusUpdate from VLV to paged search
Note: the VLV update was done on ordered elements. With the paged search
elements are not ordered to avoid extra work since the order it is not
relevant for the update.
- - - - -
3942d22d by Marco Fargetta at 2024-03-28T11:44:47+01:00
Tidyup CertStatusUpdateTask
Removing useless temporary lists needed to work with VLV
- - - - -
13c25e50 by Endi S. Dewata at 2024-03-28T13:05:57-05:00
Update tests to use standard conf dir
Normally the Tomcat conf dir is located immediately under the
instance dir. For PKI server, which is based on Tomcat, the
location is /var/lib/pki/<instance>/conf.
Depending on the deployment scenario the config files might be
mounted from a different location (e.g. /etc/pki/<instance> on
Fedora) and the standard conf dir will be just a link to the
actual location.
To ensure that the tests are valid for all deployment scenarios
they have been updated to use the standard conf dir instead of
the Fedora-specific one.
- - - - -
176c976a by Endi S. Dewata at 2024-03-28T13:35:02-05:00
Update Dockerfile for IPA tests
- - - - -
1d043daa by Endi S. Dewata at 2024-04-01T17:25:44-05:00
Refactor CMSEngine.testLDAPConnection()
The CMSEngine.testLDAPConnection() has been modified to take
an LDAPConnectionConfig instead of LdapConnInfo.
- - - - -
ff5866be by Endi S. Dewata at 2024-04-01T17:25:44-05:00
Refactor LdapAnonConnFactory
The LdapAnonConnFactory has been modified to take an existing
LDAPSocketFactory instead of creating a new one.
- - - - -
3267b8c9 by Endi S. Dewata at 2024-04-01T17:25:44-05:00
Refactor LdapBoundConnFactory
The LdapBoundConnFactory has been modified to take an existing
LDAPSocketFactory instead of creating a new one.
- - - - -
3e74c8be by Endi S. Dewata at 2024-04-01T17:25:44-05:00
Removed unused fields in LdapConnFactory
- - - - -
a0622371 by Endi S. Dewata at 2024-04-01T17:25:44-05:00
Remove unused param in LdapAnonConnFactory.init()
- - - - -
75aceb2d by Endi S. Dewata at 2024-04-01T17:25:44-05:00
Remove unused param in LdapBoundConnFactory.init()
- - - - -
507f0045 by Endi S. Dewata at 2024-04-01T18:28:26-05:00
Refactor DBSubsystem
The DBSubsystem has been modified to take an existing
LDAPSocketFactory instead of creating a new one.
- - - - -
816d40f8 by Endi S. Dewata at 2024-04-01T18:57:28-05:00
Move KeyRecoveryAuthority.mKeyDB to KRAEngine
- - - - -
f2bb97b1 by Endi S. Dewata at 2024-04-01T19:03:35-05:00
Move KeyRecoveryAuthority.mReplicaRepot to KRAEngine
- - - - -
3a6346ef by Endi S. Dewata at 2024-04-02T13:17:44-05:00
Move SessionContext to pki-server.jar
- - - - -
f0bf163a by Endi S. Dewata at 2024-04-02T15:09:14-05:00
Consolidate constants for LDAP-based profile auth
- - - - -
f31d6ac6 by Endi S. Dewata at 2024-04-02T20:37:33-05:00
Update CA tests to show DS logs
- - - - -
103edf5f by Endi S. Dewata at 2024-04-02T20:37:33-05:00
Update IPA tests to show DS logs
- - - - -
21df31f0 by Endi S. Dewata at 2024-04-02T23:36:20-05:00
Fix IPA tests
The IPA tests have been updated to gather the logs before
removing the server to ensure that the logs exist.
- - - - -
62d550ed by Endi S. Dewata at 2024-04-03T09:32:51-05:00
Add test for CA with caDirPinUserCert profile
A new test has been added to set up the auth database using
the setpin tool, then perform PIN-authenticated enrollments
using the caDirPinUserCert profile.
The setpin tool has been modified to remove extra spaces in
the ACI attributes to make it easier to view and verify.
The pki ca-cert-request-submit command has been updated to
provide options to specify the enrollment password and PIN.
The CertRequestDAO.submitRequest() has been modified to get
the PIN from the enrollment request and store it into the
credentials object so that it can be authenticated later by
UidPwdPinDirAuthentication.
- - - - -
16ad354f by Endi S. Dewata at 2024-04-03T11:50:52-05:00
Refactor DBSearchResults
The DBSearchResults has been modified to no longer implement
Enumeration to simplify maintenance.
- - - - -
890283c6 by Endi S. Dewata at 2024-04-03T11:52:15-05:00
Update DBSearchResults.mRes
The DBSearchResults.mRes has been changed into LDAPSearchResults
to simplify maintenance.
- - - - -
1ff89653 by Endi S. Dewata at 2024-04-08T12:13:03-05:00
Update test for file-based CRL publishing
The test for file-based CRL publishing has been modified to
create a user cert and a server cert, revoke the certs, unrevoke
them, and check the cert validity using OpenSSL and NSS tools.
The cert profiles have been configured such that the user cert
has a CDP extension whereas the server cert does not. The AIA
extension has been removed to ensure the validation will be done
using CRL instead of OCSP.
- - - - -
043ab92c by Endi S. Dewata at 2024-04-08T13:01:18-05:00
Rename test for CA with non-default user
- - - - -
a54130a8 by Marco Fargetta at 2024-04-08T23:45:17+02:00
Fix building flags for C++ code
- - - - -
8dca24dd by Endi S. Dewata at 2024-04-09T08:32:11-05:00
Update docs to use standard conf dir
Similar to commit 13c25e507b1e7ee7fd69cac79c048d4ac73543b2,
the docs have been updated to use the standard Tomcat conf
dir instead of Fedora-specific dir such that the docs will
be valid for all deployment scenarios.
- - - - -
918104a8 by Mikel Olasagasti Uranga at 2024-04-09T13:16:55-05:00
Refactor validateSyntaxDNS to support wildcard DNS entries
Previously, wildcard DNS entries like '*.example.com' were failing URI
validation as they are not valid URIs. This commit separates the
wildcard validation logic to handle such cases separately, ensuring
accurate validation for wildcard DNS entries.
Fixes #4556
Signed-off-by: Mikel Olasagasti Uranga <mikel at olasagasti.info>
- - - - -
916c5801 by Endi S. Dewata at 2024-04-09T17:38:57-05:00
Add PKISubsystem.set_config()
The PKISubsystem.set_config() has been added to track
changes in CS.cfg.
- - - - -
d3e14452 by Endi S. Dewata at 2024-04-12T09:09:45-05:00
Use standard conf dir
PKI server supports two directory layouts: the PKIServer
class uses the standard Tomcat layout where the config files
are stored under the instance folder, and the PKIInstance
class uses the FHS layout where the config files are stored
separately under /etc.
Previously the conf_dir() in these classes returned different
values. The one in PKIServer returned the standard conf dir
under the instance folder and the one in PKIInstance returned
the config folder at /etc/pki/<instance>.
To ensure the code works consistently in all cases scenarios
the conf_dir() has been modified such that it will always
return the standard conf dir, then in PKIServer the conf dir
will be the an actual folder, but in PKIInstance it will be a
link to the actual folder at /etc/pki/<instance>.
https://github.com/dogtagpki/pki/wiki/PKI-Server-Directory-Structure
- - - - -
a9331953 by Endi S. Dewata at 2024-04-15T19:58:09-05:00
Update LDAP minConns in CLIs
The CLIs have been modified to create an LDAP connection only
when it's actually needed.
- - - - -
2e5688e3 by Endi S. Dewata at 2024-04-15T19:58:09-05:00
Update exception messages in LdapConnInfo
- - - - -
61839dc1 by Endi S. Dewata at 2024-04-15T19:58:09-05:00
Remove redundant AnonConnection.getFacId()
- - - - -
0ff34c49 by Endi S. Dewata at 2024-04-15T20:15:11-05:00
Remove redundant LdapBoundConnection.connectionFactory
- - - - -
bc21f154 by Endi S. Dewata at 2024-04-15T20:49:44-05:00
Remove redundant LdapBoundConnFactory.init()
- - - - -
86fd68d6 by Endi S. Dewata at 2024-04-15T20:49:44-05:00
Replace AnonConnection with LdapAnonConnection
- - - - -
75626964 by Endi S. Dewata at 2024-04-15T20:49:44-05:00
Convert LdapAnonConnFactory.mConns into List
- - - - -
f0429a74 by Endi S. Dewata at 2024-04-15T20:49:44-05:00
Convert LdapBoundConnFactory.mConns into List
- - - - -
9730d2c9 by Endi S. Dewata at 2024-04-16T08:32:30-05:00
Add tests for file types, owners, and permissions
Some CI tests have been updated to check the types (file, folder,
or link), the owners, and the permissions of the files in PKI
server and subsystems.
The test for basic PKI server installation has been updated to
test both the standard Tomcat layout and the FHS layout.
- - - - -
ec502b1a by Endi S. Dewata at 2024-04-16T20:32:45-05:00
Fix instance removal in KRA OAEP test
- - - - -
be1bc5f5 by Marco Fargetta at 2024-04-17T19:16:13+02:00
Add template profile for ServerCert with CRL-DP extension
- - - - -
656f08d1 by Endi S. Dewata at 2024-04-17T19:16:44-05:00
Clean up PKIServer.create() and remove()
The PKIServer.create() and remove() have been modified to be
more consistent with instance_layout.py.
- - - - -
a20d37b0 by Endi S. Dewata at 2024-04-18T10:29:19-05:00
Add tests to check server files after removal
The CI tests have been updated to check the files left on the
system after PKI server removal using pkidestroy and pki-server
remove commands.
Currently their behavior is inconsistent:
- pkidestroy will leave PKI server and subsystem logs files
under /var/log/pki/<instance> folder
- pki-server remove will remove all files
Ideally the behavior should be more consistent. That will be
addressed separately later.
- - - - -
469fe277 by Endi S. Dewata at 2024-04-18T12:37:08-05:00
Add PKIDeployer.remove_server_nssdb()
The code for removing the server NSS database has been
consolidated into PKIDeployer.remove_server_nssdb().
- - - - -
e3dbbcb2 by Endi S. Dewata at 2024-04-18T15:20:26-05:00
Disable upstream QE tests
The upstream QE tests are currently not working due to
dependency issues so they have been disabled.
- - - - -
2a4a271d by Endi S. Dewata at 2024-04-19T10:15:37-05:00
Update pkidestroy and pki-server remove
pkidestroy and pki-server remove commands have been modified to
work more consistently. Now by default the logs will be retained
so the following folders will remain:
- /var/lib/pki/<instance>
- /var/lib/pki/<instance>/logs
- /var/log/pki/<instance> for instances using FHS layout
The tools will also provide an option to remove the logs if they
are no longer needed.
The tests have been updated accordingly.
- - - - -
2df73f0d by Endi S. Dewata at 2024-04-19T11:19:49-05:00
Replace LDAPSearchResult.nextElement() with next()
The code that calls LDAPSearchResult.nextElement() has been
updated to call next() instead to ensure that if there is an
LDAPException the code will throw it properly instead of
generating a ClassCastException.
- - - - -
20a01c93 by Marco Fargetta at 2024-04-20T00:34:42+02:00
Remove CrlIssuer from template with CRLDP
CRLIssuer MUST not be included if the issuer is the same issuer of the
certificate. Therefore it is update the comment for the user to make it
clear.
See: https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1.13
- - - - -
d726feb4 by Endi S. Dewata at 2024-04-22T08:57:09-05:00
Use standard logs dir
The code, the tests, and the docs have been updated to use the
standard logs dir at /var/lib/pki/<instance>/logs to ensure that
they are valid in all deployment scenarios.
PKIServer.log_dir() has been renamed into logs_dir() to match the
standard logs dir name.
- - - - -
b2cdbd96 by Endi S. Dewata at 2024-04-22T10:19:05-05:00
Update log messages in PKIServer.deploy_webapp()
- - - - -
f012c43f by Endi S. Dewata at 2024-04-22T10:19:06-05:00
Update log messages in PKIServer.undeploy_webapp()
- - - - -
48e84a5d by Endi S. Dewata at 2024-04-22T10:22:15-05:00
Update log messages in PKIServer.makedirs()
- - - - -
54ec3b7a by Endi S. Dewata at 2024-04-22T10:22:23-05:00
Update log messages in PKIServer.symlink()
- - - - -
c90ce15a by Endi S. Dewata at 2024-04-22T10:22:43-05:00
Update log messages in PKIServer.store_passwords()
- - - - -
ef5c1ed4 by Endi S. Dewata at 2024-04-22T10:22:43-05:00
Add exist_ok param for PKIServer.copy()
- - - - -
218f7d28 by Endi S. Dewata at 2024-04-22T10:22:43-05:00
Add exist_ok param for PKIServer.copyfile()
- - - - -
adbf5ea4 by Endi S. Dewata at 2024-04-22T15:32:31-05:00
Update exception messages in LDAPExceptionConverter.toPKIException()
- - - - -
e6e1fe23 by Endi S. Dewata at 2024-04-22T15:32:31-05:00
Rename EDBException to DBException
- - - - -
aeb186f0 by Endi S. Dewata at 2024-04-22T15:32:31-05:00
Rename EDBNotAvailException to DBNotAvailableException
- - - - -
4e5afe3c by Endi S. Dewata at 2024-04-22T15:32:31-05:00
Rename EDBRecordNotFoundException to DBRecordNotFoundException
- - - - -
1054cf4e by Endi S. Dewata at 2024-04-22T16:14:08-05:00
Add LDAPExceptionConverter.toDBException()
- - - - -
6cbe657c by Endi S. Dewata at 2024-04-22T17:18:18-05:00
Add DBRecordAlreadyExistsException
- - - - -
0576adc4 by Endi S. Dewata at 2024-04-22T17:25:28-05:00
Update ELdapException to extend DBException
- - - - -
413098b9 by Endi S. Dewata at 2024-04-22T17:25:28-05:00
Update DBSubsystem to use DBException
- - - - -
65a156c7 by Endi S. Dewata at 2024-04-22T17:25:28-05:00
Update UGSubsystem to use DBException
- - - - -
9c20b348 by Endi S. Dewata at 2024-04-22T17:26:17-05:00
Update LDAPProfileSubsystem to use DBException
- - - - -
89ed1d5a by Endi S. Dewata at 2024-04-22T17:26:17-05:00
Update CrossCertPairSubsystem to use DBException
- - - - -
96e98862 by Endi S. Dewata at 2024-04-22T17:26:17-05:00
Update AuthorityMonitor to use DBException
- - - - -
4cdf16c2 by Endi S. Dewata at 2024-04-22T17:26:17-05:00
Update LDAPSecurityDomainSessionTable to use DBException
- - - - -
b820cd25 by Endi S. Dewata at 2024-04-22T19:23:29-05:00
Merge IPolicySet into PolicySet
- - - - -
33c99ffa by Endi S. Dewata at 2024-04-22T20:41:34-05:00
Convert IEnrollmentPolicy into EnrollmentPolicy
- - - - -
9a6a2b1c by Endi S. Dewata at 2024-04-22T20:42:30-05:00
Convert IRenewalPolicy into RenewalPolicy
- - - - -
34c074af by Endi S. Dewata at 2024-04-22T20:43:26-05:00
Convert IRevocationPolicy into RevocationPolicy
- - - - -
c4c0e5ad by Endi S. Dewata at 2024-04-22T20:53:12-05:00
Rename APolicyRule to PolicyRule
- - - - -
fe049dac by Endi S. Dewata at 2024-04-22T20:54:49-05:00
Merge IPolicyRule into PolicyRule
- - - - -
6ddb7da2 by Endi S. Dewata at 2024-04-22T22:00:08-05:00
Convert IPolicy into Policy
- - - - -
f171f56a by Endi S. Dewata at 2024-04-23T09:09:30-05:00
Remove unused IPublishRuleSet
- - - - -
1bb6ff48 by Endi S. Dewata at 2024-04-23T09:09:33-05:00
Update RequestListener to use DBException
- - - - -
c7d0d16a by Endi S. Dewata at 2024-04-23T09:09:35-05:00
Update DirBasedAuthentication to use DBException
- - - - -
1f9bd14e by Endi S. Dewata at 2024-04-23T09:09:36-05:00
Update PasswdUserDBAuthentication to use DBException
- - - - -
be13be2b by Endi S. Dewata at 2024-04-23T09:09:38-05:00
Update DirAclAuthz to use DBException
- - - - -
23ea38e3 by Endi S. Dewata at 2024-04-23T09:09:39-05:00
Update PublisherAdminServlet to use DBException
- - - - -
ccb54654 by Endi S. Dewata at 2024-04-23T09:09:41-05:00
Update UpdateDir to use DBException
- - - - -
f8ee0aa2 by Endi S. Dewata at 2024-04-23T09:09:42-05:00
Update UpdateCRL to use DBException
- - - - -
18e401bb by Endi S. Dewata at 2024-04-23T09:09:44-05:00
Update LDAPConfigStorage to use DBException
- - - - -
3f2f7b92 by Endi S. Dewata at 2024-04-23T09:09:46-05:00
Update CAEngine to use DBException
- - - - -
497fb4d0 by Endi S. Dewata at 2024-04-23T11:15:56-05:00
Remove redundant code in subsystem_layout.py
The same code that creates registry.cfg also exists
in PKISubsystem.create_conf().
- - - - -
7d9a8c69 by Endi S. Dewata at 2024-04-23T11:15:57-05:00
Update CAPublisherProcessor to use DBException
- - - - -
0dc2329f by Endi S. Dewata at 2024-04-23T11:15:58-05:00
Update PublisherProcessor to use DBException
- - - - -
6233d5e2 by Endi S. Dewata at 2024-04-23T11:16:00-05:00
Update Publisher to use DBException
- - - - -
dfd40d49 by Endi S. Dewata at 2024-04-23T11:16:01-05:00
Update LdapPublishModule to use DBException
- - - - -
59ad696b by Endi S. Dewata at 2024-04-23T11:16:03-05:00
Update LdapConnModule to use DBException
- - - - -
3f2d0202 by Endi S. Dewata at 2024-04-23T14:01:17-05:00
Update LdapExpression to use DBException
- - - - -
d8085141 by Endi S. Dewata at 2024-04-23T14:01:18-05:00
Update Mapper to use DBException
- - - - -
918237ee by Endi S. Dewata at 2024-04-23T14:01:19-05:00
Update publishing mappers to use DBException
- - - - -
b249660d by Endi S. Dewata at 2024-04-23T14:01:21-05:00
Drop unused ELdapException in CertUserLocator
- - - - -
3a75d6f3 by Endi S. Dewata at 2024-04-23T14:01:22-05:00
Drop unused ELdapException in LdapConnInfo
- - - - -
6b8698cf by Endi S. Dewata at 2024-04-23T14:01:24-05:00
Update PKIDeployer.create_server_nssdb()
The PKIDeployer.create_server_nssdb() has been updated to call
PKIServer.open_nssdb() instead of creating a new NSSDatabase
object and password file.
- - - - -
a307f32d by Endi S. Dewata at 2024-04-24T17:04:28-05:00
Update NSSDatabase.get_cert()
The NSSDatabase.get_cert() has been updated to use regex when
checking the standard error to improve its reliability.
- - - - -
9ef0c03d by Endi S. Dewata at 2024-04-24T17:04:31-05:00
Update NSSDatabase.import_pkcs7()
The NSSDatabase.import_pkcs7() has been updated to properly
support importing PKCS #7 data from memory.
- - - - -
f4698a21 by Endi S. Dewata at 2024-04-24T17:04:32-05:00
Update NSSDatabase.import_cert_chain()
The NSSDatabase.import_cert_chain() has been updated to support
importing cert chain data from memory.
- - - - -
5b87d681 by Endi S. Dewata at 2024-04-24T17:04:34-05:00
Split PKIDeployer.import_admin_cert()
The code in PKIDeployer.import_admin_cert() that loads
the admin cert has been moved into load_admin_cert().
- - - - -
a5e95b0b by Endi S. Dewata at 2024-04-24T17:04:35-05:00
Update PKIDeployer.store_admin_cert()
The PKIDeployer.store_admin_cert() has been updated to no
longer import the admin cert into NSS database. Instead, the
import_admin_cert() needs to be called separately.
- - - - -
3f42e101 by Endi S. Dewata at 2024-04-24T21:46:58-05:00
Update PKIDeployer.export_admin_pkcs12()
The PKIDeployer.export_admin_pkcs12() has been updated to use
NSSDatabase.export_pkcs12().
- - - - -
c4f895c0 by Endi S. Dewata at 2024-04-24T21:48:14-05:00
Remove unused PK12util class
- - - - -
db90efe5 by Endi S. Dewata at 2024-04-25T14:15:53-05:00
Update PKIDeployer.setup_admin_cert() (part 1)
The code that creates the admin CSR has been moved into
PKIDeployer.setup_admin_cert().
- - - - -
58a4e0bc by Endi S. Dewata at 2024-04-25T14:32:42-05:00
Update PKIDeployer.setup_admin_cert() (part 2)
The PKIDeployer.setup_admin_cert() has been modified to import
the admin cert from pki_client_admin_cert_p12 if it's specified
and the cert does not exist in the NSS database.
- - - - -
0f80857b by Endi S. Dewata at 2024-04-25T14:33:17-05:00
Update PKIDeployer.setup_admin_cert() (part 3)
The PKIDeployer.setup_admin_cert() has been modified to import
the admin cert from pki_admin_cert_file if it's specified and
the cert does not exist in the NSS database.
- - - - -
aafadaf5 by Endi S. Dewata at 2024-04-25T14:33:23-05:00
Add PKIServer.actual_conf_dir property
- - - - -
bc04be0c by Endi S. Dewata at 2024-04-25T14:33:23-05:00
Add PKIServer.actual_logs_dir property
- - - - -
c253e95b by Endi S. Dewata at 2024-04-25T16:22:20-05:00
Add ignore_duplicate param for PKISubsystem.add_user()
- - - - -
125fd384 by Endi S. Dewata at 2024-04-25T16:22:22-05:00
Add ignore_duplicate param for PKISubsystem.add_user_cert()
- - - - -
83517cf9 by Endi S. Dewata at 2024-04-25T16:22:23-05:00
Add ignore_duplicate param for PKISubsystem.add_crl_issuing_point()
- - - - -
e25887e0 by Endi S. Dewata at 2024-04-25T16:22:25-05:00
Update client NSS database objects
The client NSS database objects have been updated to use
the client password file for consistency.
- - - - -
9f18380b by Endi S. Dewata at 2024-04-26T13:07:21-05:00
Update log messages in SecurityDomainProcessor.getDomainInfo()
- - - - -
4ab00a48 by Endi S. Dewata at 2024-04-26T14:37:24-05:00
Add PKIServer.enable_rewrite()
The code that enables rewrite has been consolidated into
PKIServer.create_rewrite_config().
- - - - -
23648119 by Endi S. Dewata at 2024-04-26T14:37:37-05:00
Add PKIDeployer.enable_access_log()/disable_access_log()
The code that enables/disables the access log has been moved
into PKIDeployer.enable_access_log()/disable_access_log().
- - - - -
b464091f by Endi S. Dewata at 2024-04-26T14:37:37-05:00
Add PKIDeployer.enable_proxy()
The code that creates AJP connectors has been moved into
PKIDeployer.enable_proxy().
- - - - -
855fb5d2 by Endi S. Dewata at 2024-04-26T14:37:37-05:00
Add PKIDeployer.configure_http_connectors()
The code that configures the HTTP connectors has been moved
into PKIDeployer.configure_http_connectors().
- - - - -
0f16031b by Endi S. Dewata at 2024-04-26T14:37:37-05:00
Update PKIDeployer.configure_server_xml()
The PKIDeployer.configure_server_xml() has been modified
to require that the server.xml is already created using
PKIServer.create_server_xml().
- - - - -
06730cb8 by Endi S. Dewata at 2024-04-26T15:46:31-05:00
Replace File.copy_with_slot_substitution() with PKIServer.copyfile()
- - - - -
05c2a507 by Endi S. Dewata at 2024-04-26T18:37:21-05:00
Replace Certutil.verify_certificate_exists() with NSSDatabase.get_cert()
- - - - -
10a4b222 by Endi S. Dewata at 2024-04-26T18:39:42-05:00
Replace Certutil.import_cert() with NSSDatabase.import_cert_chain()
- - - - -
7bf6b96c by Endi S. Dewata at 2024-04-26T20:28:46-05:00
Remove temporary password file
The code that creates a temporary password file to access the
NSS database has been replaced with PKIServer.open_nssdb().
- - - - -
0e7e060e by Endi S. Dewata at 2024-04-26T20:28:53-05:00
Clean up instance_layout.py
The code in instance_layout.py that updates the value of
pki_server_database_password has been removed since it's no
longer necessary.
- - - - -
b33408e6 by Endi S. Dewata at 2024-04-29T15:12:02-05:00
Update OCSP tests to check DS and PKI logs
- - - - -
c7827d9f by Endi S. Dewata at 2024-04-29T17:36:54-05:00
Update TKS tests to check DS and PKI logs
- - - - -
55cfcda7 by Endi S. Dewata at 2024-04-29T17:36:54-05:00
Update TPS tests to check DS and PKI logs
- - - - -
df9c3aab by Endi S. Dewata at 2024-04-30T11:49:32-05:00
Add options for custom config and log folders
The pkispawn and pki-server create commands have been modified
to provide options to create an instance using custom conf and
logs folders.
The CA container has been modified to use these options to store
the config and log files under /data folder. To ensure that the
files can be accessed by the container right now they need to be
owned by the root group. In the future it might be possible to
create a root-less container.
The CA container test has been modified to create an empty /data
folder then check the config and log files after installation.
- - - - -
121d1ef2 by Endi S. Dewata at 2024-04-30T14:34:11-05:00
Remove redundant code in PKIInstance.create()
- - - - -
9eb31b7d by Endi S. Dewata at 2024-04-30T14:34:12-05:00
Clean up PKIServer.create_logging_properties()
- - - - -
b23c4a20 by Endi S. Dewata at 2024-04-30T14:34:13-05:00
Add PKIServer.create_catalina_properties()
- - - - -
1d2ea874 by Endi S. Dewata at 2024-04-30T14:34:14-05:00
Add PKIServer.create_context_xml()
- - - - -
ff6ef998 by Endi S. Dewata at 2024-04-30T14:34:19-05:00
Add PKIServer.create_web_xml()
- - - - -
87ac4552 by Marco Fargetta at 2024-05-02T16:45:51+02:00
Fix file-based CRL publishing test
- - - - -
3d58fa67 by Marco Fargetta at 2024-05-07T15:57:07+02:00
Add stack-clash protection to native code
Rpminspect is failing because the native code is compiled without the
required `-fstack-clash-protection` flag. For details:
https://sourceware.org/annobin/annobin.html/Test-stack-clash.html
- - - - -
352ca19e by Marco Fargetta at 2024-05-07T16:07:42+02:00
Convert UniqueKeyConstraint from VLV to paged search
Additional code tidyup to fix sonar complaints: array designator to the
type, compliant variable name, string message formatter, etc...
- - - - -
89531adb by Endi S. Dewata at 2024-05-07T10:46:04-06:00
Add option to remove config folder
The pkidestroy and pki-server remove commands have been modified
to keep the config folder by default but provide an option to
remove the folder. The security_databases.py has also been
modified to no longer remove the client NSS database. This will
allow the subsystem to be reinstalled with the same config files
(including the certs).
The basic installation tests have been modified to verify that
the config folder still exists after server removal.
New tests have been added to install PKI subsystems with existing
config files from previous installation.
- - - - -
21148f7e by Endi S. Dewata at 2024-05-07T12:38:58-05:00
Update lewagon/wait-on-check-action
- - - - -
bc06fffb by Endi S. Dewata at 2024-05-07T18:20:56-05:00
Move KRA clone tests into separate workflow
- - - - -
7c409930 by Endi S. Dewata at 2024-05-07T19:22:46-05:00
Update PKIDeployer.setup_admin_cert()
The PKIDeployer.setup_admin_cert() has been modified to ensure
that the admin PKCS #12 file is not empty before importing it
into the client NSS database.
- - - - -
3e338fce by Endi S. Dewata at 2024-05-08T08:01:23-06:00
Update installation tests with existing config files
The installation tests with existing config files have been
updated to verify that the config files do not get altered by
the second installation. Currently this is not entirely true
since there are timestamps stored in the config files, but in
the future these timestamps can be removed or moved into log
files instead.
The tests have also been updated to remove the config and log
files after the second installation.
- - - - -
41b4c6d1 by Endi S. Dewata at 2024-05-09T08:43:47-06:00
Update CA container
The CA container has been updated such that all files will be
owned by pkiuser:root so that it will work in Docker/Podman as
well as in OpenShift.
The test for CA container has been updated to use pki-server
commands to set up the CA database in the default DS backend
(i.e. userroot).
- - - - -
a291d14a by Endi S. Dewata at 2024-05-09T11:54:28-05:00
Fix error handling in pki nss-cert-export
The pki nss-cert-export has been modified to check for null
return values and throw CLIException which will generate a
simpler error message on the console.
- - - - -
d9e02a93 by Endi S. Dewata at 2024-05-09T13:46:33-05:00
Fix pki-ca-run
The pki-ca-run has been updated to use the correct commands to
export the SSL server cert and issue the admin cert.
- - - - -
f44b90a4 by Marco Fargetta at 2024-05-10T11:57:21+02:00
Update CertificateRepository to Paged Search
Methods to find certificates using VLV indexes have been deprecated.
All their usage inside the CertificateRepository have been replaced with
paged search based query.
- - - - -
35744360 by Marco Fargetta at 2024-05-10T11:57:21+02:00
Fix certs find in UniqueKeyConstraint
- - - - -
b9e67254 by Marco Fargetta at 2024-05-10T11:57:21+02:00
Invert last serial number find in range
To be more efficient the last used serial number in a range is identified
from the upper range limit and getting the first element in the
direction of the lower limit.
- - - - -
ee390d64 by Marco Fargetta at 2024-05-10T11:57:21+02:00
Fix LDAP paged search with sort key
When server sort and paged controls were both used only the last was
applied ignoring the sort control because applying multiple control get
overwritten.
The code has been modified to apply an array of controls when both are
present.
- - - - -
bad3adff by Marco Fargetta at 2024-05-10T18:31:31+02:00
Fix critical failure exception
- - - - -
741e0f06 by Endi S. Dewata at 2024-05-10T12:30:20-05:00
Update NuxwdogPasswordStore to implement PasswordStore
- - - - -
6f4b7c00 by Endi S. Dewata at 2024-05-10T12:30:21-05:00
Remove redundant code in DBSubsystem.configureExcludedLdapAttrs()
The DBSubsystem.excludedLdapAttrs is only used by CA and KRA and
the excludedLdapAttrs.enabled param is false by default so it's
not necessary to check the subsystem type.
- - - - -
078a33ca by Endi S. Dewata at 2024-05-10T14:08:04-05:00
Replace PasswordStore.create() with CMS.createPasswordStore()
- - - - -
f0b1c9c4 by Marco Fargetta at 2024-05-13T12:16:16+02:00
Fix pki-server subsystem-cert-export
Solve the pki-server subsystem-cert-export error when trying to export a
CSR.
Fix bz-2276139
- - - - -
441657bd by Endi S. Dewata at 2024-05-13T07:09:43-06:00
Add default values for passwordFile and passwordClass
The code that uses passwordFile and passwordClass params has
been updated to use default values if these params are not
specified, so it's no longer necessary to store these params
in the CS.cfg. The PKISubsystem.create_conf() has also been
modified to no longer add these params if they are missing.
The upgrade script has been updated to remove these params
from existing instances if they contain the default values.
- - - - -
c90e83af by Endi S. Dewata at 2024-05-13T10:36:15-05:00
Add PKIDeployer.get_key_type()
The code that obtains the subsystem cert key type from pkispawn
param has been moved into PKIDeployer.get_key_type().
- - - - -
8acf1501 by Endi S. Dewata at 2024-05-13T12:15:38-05:00
Remove preop.cert.<tag>.keytype param
The temporary preop.cert.<tag>.keytype param has been replaced
with direct calls to with PKIDeployment.get_key_type().
- - - - -
8a0e9048 by Endi S. Dewata at 2024-05-13T12:15:46-05:00
Update IPA basic test
The IPA basic test has been updated to check the DS logs before
removing IPA server since DS logs are not preserved by default.
- - - - -
1786e9f0 by Endi S. Dewata at 2024-05-13T16:51:20-05:00
Fix pki_security_domain_setup param
pkispawn has been updated to no longer call check_security_domain()
if pki_security_domain_setup is set to False.
- - - - -
4b91181f by Endi S. Dewata at 2024-05-13T20:02:07-05:00
Add PKIDeployer.get_cert_profile()
The code that determines the profiles for system certs has been
consolidated into PKIDeployer.get_cert_profile().
- - - - -
64406c32 by Marco Fargetta at 2024-05-14T11:15:03+02:00
Update DS container to dirsrv for OCSP ansible test
OCSP ansible test was the only one configured to use DS deployed in a
`pki-runner` container while all the other tests are currently using
`dirsrv` container from quay.io.
Since recently DS has problem to work from pki-runner container the test
has been update to dirsrv container.
- - - - -
b70f51c0 by Marco Fargetta at 2024-05-14T13:02:06+02:00
Fix log message in RecordPagedList
- - - - -
8eb98e9f by Endi S. Dewata at 2024-05-14T09:27:14-06:00
Remove unconfigurable instanceId param
The instanceId param has been removed from CS.cfg since it's
not actually changeable and also to prevent misconfiguration.
The code that uses the instance ID has been modified to call
CMS.getInstanceID() instead which gets it from the instance
dir (which comes from catalina.base property). Due to class
loading issue the NuxwdogPasswordStore class cannot call this
method so it has to get it directly from the catalina.base
property.
The PKISubsystem.create_conf() has been modified to no longer
add the param if it's missing.
The upgrade script has been modified to remove the param from
existing instances.
- - - - -
326be43d by Endi S. Dewata at 2024-05-14T09:54:18-06:00
Drop pki-server-upgrade
The pki-server-upgrade was deprecated in PKI 10.7.1 so now it
has been removed.
- - - - -
ad8602b9 by Endi S. Dewata at 2024-05-14T11:57:42-05:00
Add PKIDeployer.get_cert_type()
The code that determines the types of system certs has been
consolidated into PKIDeployer.get_cert_type().
- - - - -
09ea4f77 by Endi S. Dewata at 2024-05-14T17:00:53-05:00
Update PKIDeployer.retrieve_cert_chain()
The code that retrieves the cert chain from CA has been moved
into PKIDeployer.retrieve_cert_chain().
- - - - -
0f7647f9 by Endi S. Dewata at 2024-05-15T09:13:04-06:00
Remove cs.type param
The cs.type param has been removed from CS.cfg since subsystem
type is not actually changeable and this param might introduce
configuration issues.
The code that uses the subsystem type has been modified to call
CMSEngine.getName() (for uppercase subsystem type) and getID()
for (for lower case subsystem type) instead.
The PKISubsystem.create_conf() has been modified to no longer
add the param if it's missing. The load() has also been updated
to no longer read the param.
The upgrade script has been modified to remove the param from
existing instances.
- - - - -
abd605bf by Endi S. Dewata at 2024-05-16T11:34:55-05:00
Fix NSSDatabase.import_cert_chain()
Previously NSSDatabase.import_cert_chain() was passing PKCS #7
data as PKCS #7 filename into import_pkcs7(). The method has
been updated to use the correct param.
- - - - -
0dcbd039 by Endi S. Dewata at 2024-05-16T12:01:25-05:00
Remove unused preop.cert.<tag>.dn
- - - - -
bf893a29 by Endi S. Dewata at 2024-05-16T12:01:25-05:00
Remove unused preop.cert.<tag>.nickname
- - - - -
d763942a by Endi S. Dewata at 2024-05-16T13:35:16-05:00
Merge preop.cert.audit_signing.type into PKIDeployer.get_cert_type()
- - - - -
b83487a7 by Endi S. Dewata at 2024-05-16T13:35:16-05:00
Update pki pkcs7-cert-import
The pki pkcs7-cert-import has been updated to accept certs
specified via standard input.
- - - - -
46c9b198 by Endi S. Dewata at 2024-05-16T18:49:09-05:00
Remove unused preop.cert.<tag>.keyalgorithm
- - - - -
82ac3f58 by Endi S. Dewata at 2024-05-16T19:03:33-05:00
Remove unused preop.cert.<tag>.signingalgorithm
- - - - -
83b017a6 by Endi S. Dewata at 2024-05-16T22:48:50-05:00
Update NSSDatabase.add_ca_cert()
The NSSDatabase.add_ca_cert() has been updated to support
adding CA cert from memory.
- - - - -
7ccab05f by Endi S. Dewata at 2024-05-16T22:48:50-05:00
Add NSSDatabase.get_pkcs7_certs()
The code in NSSDatabase.import_pkcs7() that exports the certs
from a PKCS #7 has been moved into get_pkcs7_certs().
- - - - -
80519561 by Endi S. Dewata at 2024-05-16T22:48:50-05:00
Add DS params for CA container
- - - - -
76dc29c9 by Endi S. Dewata at 2024-05-16T22:48:51-05:00
Update pki-ca-run
The pki-ca-run has been updated to include the CA signing
cert into the admin.p12 file.
- - - - -
6bec07f9 by Endi S. Dewata at 2024-05-16T23:56:33-05:00
Clean up CA container test (part 1)
The CA container test has been updated to no longer set up
security domain roles and database user.
- - - - -
d94d356b by Endi S. Dewata at 2024-05-16T23:56:40-05:00
Clean up CA container test (part 2)
The CA container test has been updated to create the shared
folders earlier.
- - - - -
6dfeeca3 by Endi S. Dewata at 2024-05-17T11:52:59-05:00
Add NSSDatabase.create_pkcs7()
The NSSDatabase.create_pkcs7() has been added to create PKCS #7
from a cert chain using pki pkcs7-cert-import command.
- - - - -
c59e5004 by Endi S. Dewata at 2024-05-17T12:36:17-05:00
Update NSSDatabase.import_pkcs7()
The NSSDatabase.import_pkcs7() has been updated to use pki
pkcs7-import which can import PKCS #7 with/without nickname.
- - - - -
bbe6472d by Endi S. Dewata at 2024-05-17T12:36:17-05:00
Update PKIDeployer.finalize_ocsp()
The PKIDeployer.finalize_ocsp() has been updated to get the
CA signing PKCS #7 from the OCSP signing PKCS #7 which is
already available locally instead of from preop.cert.pkcs7
which has to be retrieved from the issuing/master CA.
- - - - -
7a4103ce by Endi S. Dewata at 2024-05-17T13:45:25-05:00
Merge PKIDeployer.retrieve_cert_chain()
The PKIDeployer.retrieve_cert_chain() has been merged into
import_cert_chain() such that the cert chain will only be
imported once, either from file, issuing CA, or master CA.
- - - - -
11a281f8 by Endi S. Dewata at 2024-05-20T09:25:04-05:00
Update ACME container deployment doc
The deployment doc for ACME container has been updated to
use a network instead of a pod.
- - - - -
baed8e33 by Endi S. Dewata at 2024-05-20T09:25:04-05:00
Update ACME container volumes
The paths of ACME container volumes have been updated to
simplify deployment and to avoid collisions with instance
files/folders.
- - - - -
b5a792d4 by Endi S. Dewata at 2024-05-20T09:25:04-05:00
Update ACME container instance
The ACME container has been updated to use the default
instance (i.e. pki-tomcat) instead of tomcat at pki which will
be more consistent with the CA container and will make it
easier to migrate from a regular deployment.
- - - - -
c4d520e5 by Endi S. Dewata at 2024-05-20T20:56:14-05:00
Add support for deprecation info
- - - - -
12aa62df by Endi S. Dewata at 2024-05-20T20:56:21-05:00
Clean up log messages
- - - - -
05bc23c1 by Endi S. Dewata at 2024-05-21T08:23:14-05:00
Add data folder for ACME container
The ACME container has been updated to support a data folder
which can be used to store the config and log files generated
by the server.
The ACME container has also been modified to store the default
config files created during the build. If the container is
started with an empty data folder the default config files will
be installed automatically.
- - - - -
998681cb by Endi S. Dewata at 2024-05-21T08:23:14-05:00
Update CA container
The CA container has been modified to extend pki-server
instead of pki-runner such that it will be more consistent
with the ACME container.
The CA container has also been modified to store the default
config files created during the build. If the container is
started with an empty data folder the default config files
will be installed automatically.
- - - - -
ac155cec by Endi S. Dewata at 2024-05-21T15:10:23-05:00
Remove unused preop.cert.<tag>.cncomponent.override
- - - - -
66ea43d1 by Endi S. Dewata at 2024-05-21T15:12:40-05:00
Remove unused preop.cert.<tag>.userfriendlyname
- - - - -
c054df72 by Endi S. Dewata at 2024-05-21T15:15:14-05:00
Remove unused preop.cert.<tag>.subsystem
- - - - -
c41360d3 by Endi S. Dewata at 2024-05-21T15:17:08-05:00
Remove unused preop.cert.<tag>.keysize.custom_size
- - - - -
b1cf4d04 by Endi S. Dewata at 2024-05-21T15:19:44-05:00
Remove unused preop.cert.<tag>.signing.required
- - - - -
c3ab15da by Endi S. Dewata at 2024-05-21T15:24:20-05:00
Remove unused preop.cert.<tag>.defaultSigningAlgorithm
- - - - -
96ab8be8 by Endi S. Dewata at 2024-05-21T15:26:39-05:00
Remove unused preop.cert.<tag>.keysize.size
- - - - -
c1ab70cf by Endi S. Dewata at 2024-05-21T15:29:33-05:00
Remove unused preop.cert.rsalist
- - - - -
7f064785 by Marco Fargetta at 2024-05-22T10:27:37+02:00
Fix mispelled "extension" word
- - - - -
392e32df by Endi S. Dewata at 2024-05-22T09:30:09-05:00
Restore pki_instance_configuration_path param
In PKI 11.5 the pki_instance_configuration_path param was
removed since it's meant to be used only internally and
has been redefined somewhere else. However, since the param
is actually used by IPA to support containers it has been
restored as an alternative to pkispawn --conf option.
- - - - -
a3de9066 by Endi S. Dewata at 2024-05-23T08:13:36-05:00
Update PKI Server container
The PKI Server container has been updated to keep the certs
and CSRs created during startup.
- - - - -
e54bddfd by Endi S. Dewata at 2024-05-23T08:13:36-05:00
Update CA container test
The CA container test has been updated to verify that the
container can be restarted successfully.
- - - - -
bef74bf5 by Endi S. Dewata at 2024-05-23T08:13:36-05:00
Update ACME container test
The ACME container test has been updated to verify that the
container can be restarted successfully.
- - - - -
ab8f2e8d by Endi S. Dewata at 2024-05-23T08:13:36-05:00
Add KRA container
The Dockerfile has been updated to define a new KRA container.
A new test has been added to create CA and KRA containers, then
verify key archival and recovery.
- - - - -
685264b3 by Endi S. Dewata at 2024-05-23T08:13:36-05:00
Add OCSP container
The Dockerfile has been updated to define a new OCSP container.
A new test has been added to create CA and OCSP containers, then
verify CRL publishing and revocation checking.
- - - - -
4830c7d9 by Endi S. Dewata at 2024-05-23T14:54:03-05:00
Add options for ds-container-start.sh
The ds-container-start.sh has been modified to provide options
to specify the container image and Directory Manager password.
- - - - -
e99a4023 by Endi S. Dewata at 2024-05-23T15:22:02-05:00
Add options for runner-init.sh
The runner-init.sh has been modified to provide options to
specify the container image, hostname, and network params.
- - - - -
cbf3856e by Endi S. Dewata at 2024-05-23T15:22:02-05:00
Add options for ds-container-create.sh
The ds-container-create.sh has been modified to provide options
to specify the container image, hostname, network params, and
the Directory Manager password.
- - - - -
d2aa5d55 by Marco Fargetta at 2024-05-27T16:34:00+02:00
Fix CI ansible tests
There is an incompatibility with latest requests package on ubuntu with
ansible docker so older version is required.
An example of error is https://github.com/dogtagpki/pki/actions/runs/9215527346/job/25354301193
For details, see https://github.com/docker/docker-py/issues/3256
- - - - -
ea072a02 by Marco Fargetta at 2024-05-28T18:17:41+02:00
Fix CA with secure ds CI failure
DS container uses pki-runner image when configured with a certificate and
this has to be specified with the start script otherwise the startup take
in account the steps for quay.io ds image which is differently configured.
- - - - -
dd5cc935 by Endi S. Dewata at 2024-05-28T14:33:47-05:00
Update PKI server container
The PKI server container (which is the base for all PKI
subsystem containers) has been updated to install the ROOT
webapp (which provides Web UI files) and PKI webapp (which
provides common PKI services), and store the default config
files.
The startup script has been modified to install the default
config files if it doesn't exist already, use PKI NSS CLI
instead of certutil to prepare the certs, and run the server
as pkiuser in Docker/Podman so that the log files will be
owned by pkiuser as well.
The test has been updated to check the files created by the
container and to verify that the container can be restarted
successfully.
- - - - -
0f062a0d by Marco Fargetta at 2024-05-29T10:30:30+02:00
Replace VLV with paged based search in HashEnrollServlet
- - - - -
b603eace by Marco Fargetta at 2024-05-29T10:30:30+02:00
Tidyup HashEnrollServlet
Fixed the following sonar identified problems:
- removed some variable not used
- merged catch exceptions
- Replaced StringBuffer with StringBuilder
- Modify the logs to use string format instead of concatenation
- - - - -
34e26e49 by Marco Fargetta at 2024-05-29T13:18:20+02:00
Update KeyRepository to Paged Search
Methods to find keys using VLV indexes have been deprecated.
All their usage inside the KeyRepository have been replaced with
paged search based query.
- - - - -
b6c56b8e by Marco Fargetta at 2024-05-29T13:18:20+02:00
Fix CertificateRepository wrong method id debug log
- - - - -
90154c77 by Marco Fargetta at 2024-05-29T13:18:20+02:00
Fix filter for lastSerial in KeyRepository and tidyup
The filter can be simplified removing the first condition in the and
('&') since it always true for all the records.
Additionally, some tidyup fixing log format, array designators and other
minor improvements.
- - - - -
c870ba24 by Endi S. Dewata at 2024-05-29T08:49:26-05:00
Fix config file owners and permissions for containers
The container startup scripts have been modified to update
the owners and permissions after the configuration is done
such that the config files will have the proper owners and
permissions.
Note: Some files created at runtime (e.g. log files) still
have inconsistent owners/permissions. These files will be
fixed separately later.
- - - - -
e17a2565 by Marco Fargetta at 2024-05-29T17:31:05+02:00
Add serial and issuer to SSL logs and audits
When creating an SSL connection, logs and audits where reporting only the
certificate subject. Since the certificate could be issued from other CAs
it could be difficult to identify.
This commit adds the issuer and the serial number of the certificate
in both the audit and log messages for a better identification.
- - - - -
95c31ea6 by Endi S. Dewata at 2024-05-29T14:48:41-05:00
Update container tests to use Podman
The container tests have been updated to use Podman instead of
Docker (except for ACME container test due to a compatibility
issue with Certbot). The docker command is now just an alias to
podman.
In Podman the containers will run as a non-root user with random
UID so the tests now will only verify the group owner of the
files.
Also in Podman the containers need to be connected to the network
as soon as it's created using docker run command instead of using
a separate docker network connect command.
The tests have also been updated to capture the files generated
by the containers in the shared folders.
- - - - -
6721762e by Endi S. Dewata at 2024-05-29T14:56:31-05:00
Add GH workflow for CA container tests
- - - - -
f1f1697e by Endi S. Dewata at 2024-05-30T12:25:27-05:00
Remove obsolete [RA] section in default.cfg
- - - - -
a411de45 by Endi S. Dewata at 2024-05-30T16:28:05-05:00
Remove unused Symlink class
- - - - -
260e4d49 by Endi S. Dewata at 2024-05-30T16:28:05-05:00
Remove unused Directory.copy()
- - - - -
da7bc16b by Endi S. Dewata at 2024-05-30T16:28:05-05:00
Remove unused Directory.modify()
- - - - -
ba96faa1 by Endi S. Dewata at 2024-05-30T17:57:03-05:00
Move enable_pki_logger() into PKIDeployer
- - - - -
c5f27a13 by Endi S. Dewata at 2024-05-30T17:57:03-05:00
Move Systemd.set_override() into PKIDeployer
- - - - -
6014e59a by Endi S. Dewata at 2024-05-30T18:05:57-05:00
Move System.write_overrides() into PKIDeployer
- - - - -
76fc0be3 by Endi S. Dewata at 2024-05-30T18:05:57-05:00
Update PKIConfigParser.validate()
The PKIConfigParser.validate() has been updated to take
a user_deployment_cfg param instead of using the global
config.user_deployment_cfg.
- - - - -
7141dd77 by Endi S. Dewata at 2024-05-30T18:05:57-05:00
Update PKIConfigParser.read_pki_configuration_file()
The PKIConfigParser.read_pki_configuration_file() has been
updated to take a user_deployment_cfg param instead of using
the global config.user_deployment_cfg.
- - - - -
43feca14 by Endi S. Dewata at 2024-05-30T18:05:58-05:00
Update PKIConfigParser.compose_pki_master_dictionary()
The PKIConfigParser.compose_pki_master_dictionary() has been
updated to take a user_deployment_cfg param instead of using
the global config.user_deployment_cfg.
- - - - -
3a68683c by Endi S. Dewata at 2024-05-30T18:05:58-05:00
Update sanitize_user_deployment_cfg()
The sanitize_user_deployment_cfg() has been converted into
validate_user_deployment_cfg() which will validate user
deployment configuration instead of fixing it silently.
- - - - -
5ecd8e65 by Endi S. Dewata at 2024-05-31T20:28:25-05:00
Remove default value for pki_server_database_password
The default.cfg has been modified to no longer define a
default value for pki_server_database_password such that
the param can be used to specify a blank password.
- - - - -
d6df5304 by Endi S. Dewata at 2024-05-31T20:31:35-05:00
Update PKIDeployer.create_server_nssdb()
The PKIDeployer.create_server_nssdb() has been updated to
update NSS database file permissions separately such that
the folder permission is only updated once.
- - - - -
092b288e by Endi S. Dewata at 2024-05-31T20:31:58-05:00
Update PKIDeployer.setup_system_certs()
The PKIDeployer.setup_system_certs() has been updated to
update NSS database file permissions separately such that
the folder permission is only updated once.
- - - - -
2794da71 by Endi S. Dewata at 2024-05-31T20:32:01-05:00
Add PKIDeployer.create_cert_id()
The code in PKIDeployer.create_cert() that creates a cert ID
has been moved into PKIDeployer.create_cert_id().
- - - - -
ecd36fdf by Endi S. Dewata at 2024-05-31T20:45:31-05:00
Add PKIServer.store_cert_request()
The code that stores CSR in PKIInstance.cert_update_config()
and PKISubsystem.store_system_cert_request() has been merged
into PKIServer.store_cert_request().
- - - - -
f9c05ce0 by Endi S. Dewata at 2024-05-31T20:45:50-05:00
Clean up log messages in pkispawn
- - - - -
7977aa59 by Endi S. Dewata at 2024-05-31T20:51:18-05:00
Update os.chown() in pki.nssdb and pki.util
The pki.nssdb and pki.util have been updated such that the
code will call os.chown() only when it's running as root user.
- - - - -
346014c4 by Endi S. Dewata at 2024-06-01T00:19:09-05:00
Add PKIServer.chown()
The PKIServer.chown() has been added such that pkispawn will
call os.chown() only when it's running as root user.
- - - - -
9e6c4b48 by Endi S. Dewata at 2024-06-03T11:44:42-05:00
Split container data folder
The /data folder in all containers has been split into /conf
and /logs which will allow them to be stored in different
volumes and will also make it easier to migrate from a regular
installation.
The container startup scripts have been modified to update the
owner and permissions twice: first, to make sure the startup
script can create/update the server config and log files, and
second, to make sure the server can access the files at runtime.
- - - - -
5a0b2c1f by Marco Fargetta at 2024-06-03T20:43:38+02:00
Modify ChallengeRevocationServlet1 to use paged search
- - - - -
686341e1 by Marco Fargetta at 2024-06-04T16:24:14+02:00
Modify CMCRevReqServlet to use paged search
- - - - -
8f5b8c80 by Marco Fargetta at 2024-06-04T16:24:14+02:00
Tidyup CMCRevReqServletFreeVLV
Fixed field access modifier, replaced literal strings and other.
- - - - -
2d158c67 by Marco Fargetta at 2024-06-04T16:47:42+02:00
Modify ServiceCheckChallenge to use paged search
The query for certificates has been converted to PagedSearch from the
deprecated VLV.
Additionally, the code has been improved removing some else conditions
which were redundant.
- - - - -
db7c5a76 by Endi S. Dewata at 2024-06-04T11:47:31-05:00
Add basic CA container test
A new test has been added to create a basic CA container with
minimal setup so it will create new certs.
The current CA container test has been converted into a test
for CA container with existing certs.
The container startup scripts have been modified to suppress
error messages when checking whether the certs already exist.
- - - - -
e41fb0df by Endi S. Dewata at 2024-06-04T11:55:29-05:00
Create home directory for default PKI user
The RPM spec has been modified to create a home directory for
the default PKI user if it does not exist. The home directory
can be used to store files that should be owned/accessible by
PKI user (e.g. SoftHSM tokens, systemd user services) so they
cannot be stored in root user's home directory.
https://github.com/dogtagpki/pki/issues/4501
- - - - -
c11fab80 by Endi S. Dewata at 2024-06-04T11:55:29-05:00
Allow non-root to run pkispawn/pkidestroy
pkispawn and pkidestroy have been modified to no longer require
the user to be running as root. Currently non-root users still
cannot complete the installation due to other permission issues,
but eventually a user should be able to create a PKI server for
a rootless systemd service.
- - - - -
92d6b505 by Endi S. Dewata at 2024-06-04T18:58:51-05:00
Fix default config file owners in container image
The Dockerfile has been updated to ensure that the instance
files (including the default config files) in the container
image are owned by pkiuser:root so that they can be accessed
properly at runtime.
- - - - -
4d8bbec5 by Endi S. Dewata at 2024-06-05T09:32:37-05:00
Add test for CA container system service
A new test has been added to run a CA container as a system
service. The container is running in Podman which runs inside
a Fedora container (i.e. pki-runner). The service is owned by
the root user but running as PKI user. In the future there
will be a separate test to run a CA container as a rootless
user service.
- - - - -
e6966dcd by Endi S. Dewata at 2024-06-05T20:18:59-05:00
Fix file owners during installation
- - - - -
b3135c7c by Endi S. Dewata at 2024-06-05T20:19:27-05:00
Fix pki-artifacts-save.sh
The pki-artifacts-save.sh has been updated to archive the config
files from the actual conf folder.
- - - - -
15a926bc by Endi S. Dewata at 2024-06-06T08:41:04-05:00
Add test for CA container with existing config
A new test has been added to install a regular CA, then reuse
the certs, database, and config files to run the same CA as a
container.
The container startup scripts have been updated to provide
params to specify the nicknames of the existing certs and to
use password.conf to access the server's NSS database.
- - - - -
e06c2d97 by Endi S. Dewata at 2024-06-06T15:32:44-05:00
Fix nickname params in pki-kra-run
- - - - -
27580cdd by Endi S. Dewata at 2024-06-06T15:33:25-05:00
Clean up container startup scripts
The container startup scripts have been updated to use the
shorter paths for NSS database directory and password file.
- - - - -
bff81c62 by Marco Fargetta at 2024-06-07T09:51:13+02:00
Move base class for REST servlet to server package
- - - - -
e2cb4ebe by Marco Fargetta at 2024-06-07T09:51:13+02:00
Implement method for /tpm/v2/activities APIs
- - - - -
2b2ab420 by Marco Fargetta at 2024-06-07T09:51:13+02:00
Fix sorkey array control and TPS ActivityServlet
Sorkey array control generation get error when it is null.
ActivityServlet reports wrong message when resource is not found
- - - - -
c444512e by Marco Fargetta at 2024-06-07T09:51:13+02:00
Add excption to PKIServlet logs
Additionally, remove the url encoder test for the TPS activity id
- - - - -
850e6b9e by Marco Fargetta at 2024-06-07T13:15:19+02:00
Move REST endpoint to v1
The current REST implemenation is associated to /v1 path and the /rest
path is a redirect to the /v1.
This would make easier to switch between REST implementations.
- - - - -
74e5f893 by Marco Fargetta at 2024-06-07T13:15:19+02:00
Move current REST APIs to v1 package
The current rest APIs are moved to a subpackage named `v1`. The new
implementation has moved to the subpackage `v1`. The new implementation
has moved to the subpackage `v2`. This will simplify the selective
building of REST implementation.
Subsystems ACME and EST have not been modified because they use REST to
implement the protocol and this requires extra effort.
- - - - -
6cefdc41 by Marco Fargetta at 2024-06-07T13:15:19+02:00
Remove printStackTrace from REST v2 filters
- - - - -
e5b208af by Marco Fargetta at 2024-06-07T13:15:19+02:00
Fix cmake build of v2 REST APIs in TPS
- - - - -
52cfef99 by Endi S. Dewata at 2024-06-07T21:03:42-05:00
Fix pylint issues
- - - - -
e4a9fb0d by Endi S. Dewata at 2024-06-10T10:27:57-05:00
Remove redundant files in containers
The containers have been updated to remove redundant files
to avoid conflicting or obsolete certs.
When the container is started the certs provided in /certs
will be the authoritative data and will be imported into
the server and admin NSS databases. If the certs are not
provided, the container will generate new certs directly in
the NSS databases. Once the container is running, the certs
in the NSS databases will be the authoritative data until
the container is restarted.
So now the container will only store certs and keys in NSS
databases and CSR files, but it will no longer store cert
files or PKCS #12 files since they are redundant. The tests
have been updated to export these files from the container
when they are needed.
- - - - -
1d9a4f31 by Marco Fargetta at 2024-06-11T13:28:19+02:00
Add handlers for all HTTP methods in PKIServlet
- - - - -
90c4a484 by Marco Fargetta at 2024-06-11T13:28:19+02:00
Make ACL filter configurable for method and path
If the servlet has different ACLs for different HTTP methods or paths
the new implementation allows to define a map to identify the correct
ACL.
The MAP will associate a key with the ACL and the key is made as
<method>:<path>
The method is one of the HTTP defined method (e.g. GET, POST, ...) and
the special value of "*" indicate all methods.
The path is internal of the servlet path and in case of path parameter
these can be identified with "{}". An example of entry could be:
key= PUT:/token/{} value= token.read
- - - - -
57cbbbb2 by Endi S. Dewata at 2024-06-11T08:18:21-05:00
Add pki-server ca-cert-import --csr option
The pki-server ca-cert-import has been updated to provide an
option to specify the CSR of the cert to be imported. This way
the cert and the CSR can be imported using a single command.
The tests have been updated to use the new option.
- - - - -
a5e513ad by Endi S. Dewata at 2024-06-11T08:18:21-05:00
Fix runner-init.sh to support Podman in container
- - - - -
1dde79cb by Endi S. Dewata at 2024-06-11T16:02:20-05:00
Remove redundant default values in CS.cfg
Some default values in CS.cfg have been removed since they
will be overwritten by pkispawn.
- - - - -
97dfad47 by Endi S. Dewata at 2024-06-12T09:45:10-05:00
Add test for CA migration to container
A new test has been added to migrate CA from a regular PKI
server (i.e. pki-tomcatd) into a Podman container running as
systemd service. The container will use PKI server's existing
config and log folders.
The container startup scripts have been modified to use the
standard CSR filenames for OCSP signing and audit signing
certs so that the container can find the existing CSRs in the
migrated config folder. The default nicknames have also been
updated for consistency.
- - - - -
b9c9f862 by Marco Fargetta at 2024-06-13T19:41:23+02:00
Add ansible step for DS setup
In CI test using ansible, after DS setup the following operation fails
because DS is not ready and the authentication bind get error.
An additional step to repeat the connection until the bind
authentication succeed is added after DS configuration.
- - - - -
3e99af1d by Marco Fargetta at 2024-06-14T10:43:00+02:00
Implement v2 TPS TokenService without vlv
The TokenService has been implemented using raw servlet. Since this
service is using different http methods and acl for the supported
methods, the base PKIServlet has been modified to support such methods.
Additionally, ACL uses the new map definition to control each method.
- - - - -
aa7161ba by Endi S. Dewata at 2024-06-17T15:54:35-05:00
CVE-2023-4727 Fix token authentication bypass vulnerability
Previously the LDAPSecurityDomainSessionTable.sessionExists()
and getStringValue() were using user-provided session ID as
is in an LDAP filter which could be exploited to bypass token
authentication.
To fix the problem the code has been modified to escape all
special characters in the session ID before using it in the
LDAP filter.
Resolves: CVE-2023-4727
- - - - -
9f19eaa0 by Endi S. Dewata at 2024-06-18T14:46:13-05:00
Add pki-server <subsystem>-user-add --cert option
The pki-server <subsystem>-user-add has been updated to provide
an option to specify the user certificate so it's not necessary
to use a separate pki-server <subsystem>-user-cert-add command.
- - - - -
311d7b4c by Endi S. Dewata at 2024-06-18T17:19:40-05:00
Add test for CA container user service
A new test has been added to run a CA container as a rootless
systemd service in user space then perform a cert enrollment.
- - - - -
0d745dc6 by Endi S. Dewata at 2024-06-19T12:39:48-05:00
Add TKS container
A new container has been added for TKS subsystem.
A new test has been added to create CA and TKS containers, then
perform some basic validations. The proper test for TKS container
will be added later as part of TPS container test.
- - - - -
b27cf237 by Endi S. Dewata at 2024-06-19T16:24:57-05:00
Fix failure in test for LWCA with HSM
- - - - -
28595ab7 by Endi S. Dewata at 2024-06-19T16:24:57-05:00
Move authdb methods into PKIDeployer
- - - - -
85255be4 by Endi S. Dewata at 2024-06-19T21:37:48-05:00
Split PKIDeployer.configure_tps()
The code that creates the CA, KRA, and TKS connectors in
PKIDeployer.configure_tps() has been moved into separate
methods.
- - - - -
2f6d70f3 by Endi S. Dewata at 2024-06-19T21:37:48-05:00
Update tests to use pki nss-cert-import
- - - - -
9f125317 by Endi S. Dewata at 2024-06-20T08:39:10-05:00
Add pki_authdb_url param
A new param has been added to specify the TPS authentication
database URL.
- - - - -
62efea39 by Endi S. Dewata at 2024-06-20T08:39:10-05:00
Add TPS container
A new container has been added to provide a basic TPS
subsystem without any connectors. The connectors need
to be set up after the container is created. This is
necessary to allow creating clones of the container
without creating duplicate connectors.
pkispawn has been updated such that it will only set up
the connectors and the shared secret if the URLs to the
CA, KRA, and TKS are provided.
A new test has been added to create the initial CA, KRA,
TKS, and TPS containers. In the future the test will be
updated to set up the connectors and the shared secret,
and then test the token format and enroll operations.
- - - - -
53a52dd2 by Endi S. Dewata at 2024-06-20T08:55:34-05:00
Fix conf and logs paths in containers
- - - - -
2e3e4cf2 by Endi S. Dewata at 2024-06-20T19:20:52-05:00
Update CASubsystem.import_cert()
The CASubsystem.import_cert() has been modified to take binary
cert data instead of string.
- - - - -
1aa259fc by Endi S. Dewata at 2024-06-20T19:20:52-05:00
Update container tests to check server info
- - - - -
8077cff3 by Endi S. Dewata at 2024-06-21T09:03:37-05:00
Update pki-server ca-cert-create
The pki-server ca-cert-create command has been updated to
provide an option to import the new cert into CA database.
The profile_id param in CASubsystem.create_cert() has been
renamed into profile_path which accepts both the profile
full path and the filename (for backward compatibility).
- - - - -
f0f39c16 by Endi S. Dewata at 2024-06-21T09:03:37-05:00
Remove default admin cert in containers
Currently if the CA container is started without any certs,
it will create an admin cert in the container's default NSS
database but it's not permanent, so every time the container
is restarted it will create a new admin cert.
To avoid problems all containers have been modified to no
longer generate or store anything in the container's default
NSS database. Instead, the admin cert will need to be created
after the CA container is started, and it will only be stored
in the client's NSS database outside of the container.
- - - - -
d4f01051 by Marco Fargetta at 2024-06-21T17:26:29+02:00
Remove VLV search from RequestRepository
- - - - -
c8d820f9 by Endi S. Dewata at 2024-06-21T18:27:18-05:00
Clean up container startup scripts
- - - - -
782f3abf by Marco Fargetta at 2024-06-24T17:16:20+02:00
Fixing race condition on close connection
LDAPConnection is closed before it is re-used. Closing the connection in
case it is not needed create a race conditions in some cases preventing
the execution. This is present in IPA cloning operations.
- - - - -
0247a52c by Endi S. Dewata at 2024-06-24T15:37:34-05:00
Fix SPDX license
- - - - -
15910f1e by Endi S. Dewata at 2024-06-24T17:17:23-05:00
Remove default audit signing cert in containers
Audit signing is disabled by default so it's not necessary to
create an audit signing cert for containers by default. The
containers have been modified such that the audit signing cert
nickname and CSR are optional.
The PKIDeployer and CMSEngine classes have been modified to
skip processing the cert if the nickname or the CSR is blank.
The container tests have been updated to no longer create or
process audit signing certs.
In the future the default audit signing cert for regular PKI
server installation might be removed as well.
- - - - -
eecc6477 by Marco Fargetta at 2024-06-25T12:17:13+02:00
Fix IPA Clone checks
Some parameber are modified after the CRL move from the primary to the
secondary. These are:
- ca.listenToCloneModifications
- ca.certStatusUpdateInterval
- - - - -
3c574a6f by Endi S. Dewata at 2024-06-25T18:37:56-05:00
Clean up log messages in ConfigStore
- - - - -
b3b8531a by Endi S. Dewata at 2024-06-25T18:37:56-05:00
Fix TPS test failure
The code that configures the connection to TPS auth database
has been updated to store a lowercase boolean value into
auths.instance.ldap1.ldap.ldapconn.secureConn.
The code that creates connectors in TPS has been updated to drop
the default blank value in target.Subsystem_Connections.list.
- - - - -
3e3993ce by Marco Fargetta at 2024-06-27T17:42:35+02:00
Remove VLV search from RequestNotifier
- - - - -
be367712 by Marco Fargetta at 2024-06-27T17:53:12+02:00
Replace Resteasy Exception with PKI equivalent in v2
- - - - -
a6096933 by Marco Fargetta at 2024-06-28T11:35:18-05:00
Enable SHA1 policy when PKICertImport is tested
Since `pki pkcs12-export` creates p12 with sha1 signature these cannot
be imported with new fedora policy. The export has to be modified to use
different algorithms or at least use sha256 as default.
- - - - -
480e2519 by Endi S. Dewata at 2024-06-28T17:48:03-05:00
Clean up CMake variables
- - - - -
b6822b29 by Endi S. Dewata at 2024-06-28T21:40:31-05:00
Consolidate symlinks
- - - - -
1bb70ebb by Endi S. Dewata at 2024-07-01T12:58:41-05:00
Consolidate links for resteasy-servlet-initializer.jar
- - - - -
0c41a006 by Endi S. Dewata at 2024-07-01T13:35:23-05:00
Add support for bundling RESTEasy
The RPM spec has been updated such that by default it will bundle
the RESTEasy library. It also provides an option to continue using
the library provided by the system.
- - - - -
a05a85b7 by Endi S. Dewata at 2024-07-01T15:47:48-05:00
Add support for bundling JBoss Logging
The RPM spec has been updated such that by default it will bundle
JBoss Logging library.
- - - - -
dc88c31a by Endi S. Dewata at 2024-07-01T18:21:39-05:00
Add support for bundling JAX-RS 2.0 API
The RPM spec has been updated such that by default it will bundle
JAX-RS 2.0 API.
- - - - -
766d58c6 by Endi S. Dewata at 2024-07-01T20:23:28-05:00
Add support for bundling Jackson
The RPM spec has been updated such that by default it will bundle
Jackson library.
- - - - -
0cd47ec4 by Endi S. Dewata at 2024-07-03T13:35:20-05:00
Fix Maven metadata file names
- - - - -
c4ee7406 by Endi S. Dewata at 2024-07-03T22:55:03-05:00
Reorganize Maven dependencies
- - - - -
cc619522 by Marco Fargetta at 2024-07-09T11:26:31+02:00
Implement v2 AccountService for CA
The implementation delegate the login/logout operation to
AccountServletBase object which is shared among the subsystems.
- - - - -
b6b2fd75 by Marco Fargetta at 2024-07-09T11:26:31+02:00
Implement v2 AccountService for KRA
- - - - -
4422e479 by Marco Fargetta at 2024-07-09T11:26:31+02:00
Implement v2 AccountService for OCSP
- - - - -
1f55b4a3 by Marco Fargetta at 2024-07-09T11:26:31+02:00
Implement v2 AccountService for TKS
- - - - -
f92a3f0c by Marco Fargetta at 2024-07-09T11:26:31+02:00
Implement v2 AccountService for TPS
- - - - -
fe9416fd by Endi S. Dewata at 2024-07-10T08:00:13-05:00
Publish Maven artifacts to dogtagpki/repo
Previously PKI's Maven artifacts were published to GitHub
Packages which is a private repository so it's difficult to
use.
To resolve the problem, the pom.xml has been modified to
publish the artifacts to a publicly accessible dogtagpki/repo
instead.
- - - - -
daa189ab by Endi S. Dewata at 2024-07-10T08:54:31-05:00
Fix fontawesome4-fonts-web dependency
- - - - -
e5624f97 by Endi S. Dewata at 2024-07-10T21:57:43-05:00
Update CMake script
The CMake script has been updated to use the imported JAR files
first if available, otherwise it will use the system JAR files.
- - - - -
dd9a8226 by Marco Fargetta at 2024-07-11T11:58:56+02:00
Add UserServletBase for user management
This is the delegated object for user operations in all subsystems.
- - - - -
b08177c6 by Marco Fargetta at 2024-07-11T11:58:56+02:00
Add UserServlet to CA subsystem
- - - - -
6eed068e by Marco Fargetta at 2024-07-11T11:58:56+02:00
Add UserServlet to KRA subsystem
- - - - -
cdadeb83 by Marco Fargetta at 2024-07-11T11:58:56+02:00
Add UserServlet to OCSP subsystem
- - - - -
e0dcc38c by Marco Fargetta at 2024-07-11T11:58:56+02:00
Add UserServlet to TKS subsystem
- - - - -
5ce56d3b by Marco Fargetta at 2024-07-11T11:58:56+02:00
Add UserServlet to TPS subsystem
- - - - -
1adc1227 by Marco Fargetta at 2024-07-11T11:58:56+02:00
Remove printStackTrace and JAX-RS classes from UserServletBase
- - - - -
2e793c3b by Marco Fargetta at 2024-07-11T18:31:05+02:00
Add SelfTestServletBase for self test v2 APIs
- - - - -
bfbbf94e by Marco Fargetta at 2024-07-11T18:31:05+02:00
Add SelfTestServlet to CA v2 APIs
- - - - -
ae137d0b by Marco Fargetta at 2024-07-11T18:31:05+02:00
Add SelfTestServlet to KRA v2 APIs
- - - - -
7b342349 by Marco Fargetta at 2024-07-11T18:31:05+02:00
Add SelfTestServlet to OCSP v2 APIs
- - - - -
fc7ac233 by Marco Fargetta at 2024-07-11T18:31:05+02:00
Add SelfTestServlet to TKS v2 APIs
- - - - -
12b3d672 by Marco Fargetta at 2024-07-11T18:31:05+02:00
Add SelfTestServlet to TPS v2 APIs
- - - - -
3296004c by Marco Fargetta at 2024-07-11T18:33:08+02:00
Fix CMake build for missing libraries
The test for jackson and resteasy library was failing because the
variable is undefined when the libraries are not provided with the
package.
Since CMake test works with variables considering false when the
variable is undefined the all the is statements have been modified to
check if the variable is defined.
https://cmake.org/cmake/help/latest/command/if.html#variable
- - - - -
d5ae2bf5 by Endi S. Dewata at 2024-07-11T11:42:57-05:00
Rename jaxrs-api.jar to jboss-jaxrs-2.0-api.jar
- - - - -
6408d1fa by Endi S. Dewata at 2024-07-11T11:42:57-05:00
Rename jaxb-api.jar to jakarta.xml.bind-api.jar
- - - - -
80ef9cb6 by Endi S. Dewata at 2024-07-11T11:42:57-05:00
Rename javax.activation.jar to jakarta.activation-api.jar
- - - - -
53a63847 by Endi S. Dewata at 2024-07-11T11:42:57-05:00
Rename javax.annotations-api.jar to jakarta.annotation-api.jar
- - - - -
501faf8a by Endi S. Dewata at 2024-07-11T13:00:43-05:00
Rename SSLClientCertAuthentication to SSLClientCertAuthManager
The SSLClientCertAuthentication class has been renamed to
SSLClientCertAuthManager to avoid possible conflicts with
SSLclientCertAuthentication.
- - - - -
50033453 by Endi S. Dewata at 2024-07-11T13:00:46-05:00
Update Eclipse classpath
- - - - -
33488fc5 by Marco Fargetta at 2024-07-12T18:47:55+02:00
Fix method name in log message
- - - - -
2d75da4f by Marco Fargetta at 2024-07-12T18:47:55+02:00
Add JobServletBase for Job v2 APIs
- - - - -
dec96774 by Marco Fargetta at 2024-07-12T18:47:55+02:00
Add JobServlet to CA, KRA, OCSP, TKS and TPS v2 APIs
- - - - -
bc86a941 by Endi S. Dewata at 2024-07-15T21:55:01-05:00
Add RPM spec option to build without Maven
The RPM spec has been modified to provide an option to build
without Maven and instead use CMake to build both Java and
native binaries.
- - - - -
843e8fe6 by Endi S. Dewata at 2024-07-16T17:31:09-05:00
Clean up RPM spec
The RPM spec file has been modified to provide an option to
disable the dependency on esc and to list bundled libraries.
The meta package has been modified to define the Obsoletes and
Conflicts when a subpackage is disabled to ensure that upgrade
will work properly.
- - - - -
eaf1f8b3 by Endi S. Dewata at 2024-07-16T21:33:15-05:00
Add RPM spec options for build and runtime dependencies
The RPM spec file has been modified to provide options to
use external or bundled build and runtime dependencies.
- - - - -
70acbfd1 by Endi S. Dewata at 2024-07-17T17:36:02-05:00
Fix Azure pipeline failure
- - - - -
ec6e87e2 by Endi S. Dewata at 2024-07-17T18:48:39-05:00
Update CMake files
The code that installs bundled libraries into the buildroot
has been moved from RPM spec into CMake files.
- - - - -
c4aff62e by Endi S. Dewata at 2024-07-17T22:33:11-05:00
Rename jboss-jaxrs JAR file
The jboss-jaxrs JAR file has been renamed to match the
Maven artifact ID.
- - - - -
e4d414c7 by Marco Fargetta at 2024-07-18T12:44:21+02:00
Add routing based the annotation WebAction
Using raw http servlet with base method it is not always possible to handle the
correct return state because the value depends on the operation of other
operation.
Using the annotation it is possible to map all the operations during the
init phase and provide the correct state in any situation.
Additionally, it is possible to split multiple operations associated to
a single http method simplifying the code.
- - - - -
b9c4eb6f by Marco Fargetta at 2024-07-18T12:44:21+02:00
Update JobServlet to WebAction annotation
- - - - -
ef9f167a by Marco Fargetta at 2024-07-18T12:44:21+02:00
Update AccountServlet to WebAction annotation
- - - - -
fa270d26 by Marco Fargetta at 2024-07-18T12:44:21+02:00
Update SelfTestServlet to WebAction annotation
Additionally, the path specification in ACL filter for the root element
has been modified from empty string to "/" to have the same format used
in the PKIServlet.
- - - - -
d16caee8 by Marco Fargetta at 2024-07-18T12:44:21+02:00
Update UserServlet to WebAction annotation
- - - - -
7839ce00 by Marco Fargetta at 2024-07-18T12:44:21+02:00
Update CA servlets to WebAction annotation
- - - - -
ae3e1c91 by Marco Fargetta at 2024-07-18T12:44:21+02:00
Update TPS servlets to WebAction annotation
- - - - -
b12487d5 by Marco Fargetta at 2024-07-18T12:44:21+02:00
Reorganise v2 APIs shared among subsystems
Code of APIs supported in multiple subsystem is moved to server package
and the subsystem have to just extend without duplicate the code.
- - - - -
f378d5de by Marco Fargetta at 2024-07-18T12:44:21+02:00
Rename v2 classes to be consistent with servlet name
- - - - -
ac519491 by Marco Fargetta at 2024-07-18T12:44:21+02:00
Make v2 WebAnnotation and ACLFilter paths relatives
All paths defined in WebAnnotation and ACLFilter for routing and
chacking the ACL are relatives to the servlet context
- - - - -
16ab4513 by Endi S. Dewata at 2024-07-18T14:09:11-05:00
Clean up Azure pipeline
The Azure pipeline has been updated to no longer install
Maven dependencies manually since they are now available
from the Maven repository.
- - - - -
7cf13511 by Endi S. Dewata at 2024-07-18T23:34:56-05:00
Bundle JAXB API
The RPM spec has been updated to bundle JAXB API for runtime
dependency by default.
- - - - -
e7a4ef05 by Endi S. Dewata at 2024-07-18T23:34:56-05:00
Bundle Jakarta Annotation API
The RPM spec has been updated to bundle Jakarta Annotation API
for runtime dependency by default.
- - - - -
59486a4b by Endi S. Dewata at 2024-07-18T23:34:56-05:00
Bundle Jakarta Activation API
The RPM spec has been updated to bundle Jakarta Activation API
for runtime dependency by default.
- - - - -
a3b0ee1c by Marco Fargetta at 2024-07-19T09:21:15+02:00
Move common methods for engine retrieve to PKIServlet
- - - - -
adcb89f7 by Marco Fargetta at 2024-07-19T09:21:15+02:00
Add AuditService to Job v2 APIs
- - - - -
feb03c6f by Marco Fargetta at 2024-07-22T11:08:36+02:00
Add SecurityDomainService to Job v2 APIs
- - - - -
ae453777 by Marco Fargetta at 2024-07-22T11:08:36+02:00
Fix v2 routing regular expression
- - - - -
96a341e8 by Marco Fargetta at 2024-07-22T17:49:08+02:00
Optimise the creation of servlet base object for v2
Base object creation has been moved from the request context to the
servlet context to optimise the execution.
- - - - -
460ee37b by Endi S. Dewata at 2024-07-23T18:23:11-05:00
Update TokenAuthentication.sendAuthRequest()
The TokenAuthentication.sendAuthRequest() has been updated
to create PKIClient directly.
- - - - -
98d7eca3 by Endi S. Dewata at 2024-07-23T18:23:11-05:00
Remove unused Configurator
- - - - -
e4556eaa by Marco Fargetta at 2024-07-24T09:20:25+02:00
Add GroupService to v2 APIs
- - - - -
e6bb0a6c by Marco Fargetta at 2024-07-24T09:20:59+02:00
Add FeatureService to v2 APIs
- - - - -
915c6228 by Endi S. Dewata at 2024-07-24T09:33:14-05:00
Clean up PKICertificateApprovalCallback
- - - - -
cbde7d15 by Endi S. Dewata at 2024-07-24T09:33:14-05:00
Move PKIClient.rejectedCertStatuses to PKICertificateApprovalCallback
- - - - -
89324e86 by Endi S. Dewata at 2024-07-24T09:33:14-05:00
Move PKIClient.ignoredCertStatuses to PKICertificateApprovalCallback
- - - - -
b6c1bf98 by Endi S. Dewata at 2024-07-24T09:33:14-05:00
Move PKIClient.statuses to PKICertificateApprovalCallback
- - - - -
f165726b by Endi S. Dewata at 2024-07-24T09:33:14-05:00
Replace ConfigCertApprovalCallback with PKICertificateApprovalCallback
- - - - -
3c7bbd48 by Endi S. Dewata at 2024-07-24T11:59:42-05:00
Add MainCLI.createCertApprovalCallback()
The MainCLI.createCertApprovalCallback() has been added to
provide a cert approval callback with the proper list of
rejected/ignored statuses for PKIClient instances created
in pki CLI.
- - - - -
b1ad6303 by Endi S. Dewata at 2024-07-24T12:04:53-05:00
Remove unused PKIClient.crypto
- - - - -
eb86172f by Endi S. Dewata at 2024-07-24T12:05:22-05:00
Remove unused PKIClient.callback
- - - - -
7f3390cc by Endi S. Dewata at 2024-07-25T08:40:08-05:00
Remove default cert approval callback in PKIClient
Previously the PKIClient class had a default cert approval
callback which would only warn the user if it receives a cert
with a BAD_CERT_DOMAIN but still allow it, or ask the user
whether to trust an UNTRUSTED_ISSUER.
On the client side (e.g. CLI, console) this is fine since the
user is actively interacting with the application, but on the
server side (e.g. authenticators) there are no users constantly
monitoring the logs so the cert verification needs to be more
stringent.
To resolve the issue, the default cert approval callback in
PKIClient has been removed such that certs with BAD_CERT_DOMAIN
or UNTRUSTED_ISSUER will automatically be rejected. On the server
side PKIClient will be used without a cert approval callback. On
the client side it will be used with an interactive callback.
Previously some of ACME tests were using the default issuer URL
which contains localhost.localdomain hostname so it actually
generated BAD_CERT_DOMAIN errors. They have been updated to use
the proper CA hostname.
- - - - -
6695a290 by Marco Fargetta at 2024-07-25T17:25:07+02:00
Add CA AuthorityService to v2 API
- - - - -
4673c3af by Endi S. Dewata at 2024-07-26T12:55:08-05:00
Replace TokenCertificate with PK11Cert
- - - - -
b3254499 by Endi S. Dewata at 2024-07-26T13:10:36-05:00
Replace InternalCertificate with PK11Cert
- - - - -
8ba03d7a by Marco Fargetta at 2024-07-29T17:26:12+02:00
Add CA CAInstallerService to v2 API
- - - - -
f2ef87a0 by Marco Fargetta at 2024-07-29T17:48:14+02:00
Add CA CASystemCertService to v2 API
- - - - -
c2322acd by Endi S. Dewata at 2024-07-29T19:59:59-05:00
Add tests for cert validation with PKI CLI
The test for HTTPS connector with NSS has been modified to
check PKI CLI with untrusted issuer and bad cert domain.
- - - - -
da0e1902 by Endi S. Dewata at 2024-07-29T20:17:27-05:00
Update SSLCertificateApprovalCallback.approve()
Subclasses of SSLCertificateApprovalCallback has been updated to
implement approve() that takes java.security.cert.X509Certificate
instead of org.mozilla.jss.crypto.X509Certificate so that it can
be used with certs coming from standard Java library.
- - - - -
44ff6250 by Endi S. Dewata at 2024-07-31T21:21:44-05:00
Update cert validation test
The cert validation test has been modified to check PKI CLI's
stdout and stderr when the server cert is untrusted, has a
wrong hostname, or is already expired.
- - - - -
6efcff00 by Endi S. Dewata at 2024-08-01T22:22:50-05:00
Add pki nss-key-show
The pki nss-key-show has been added to display key details.
- - - - -
61759595 by Endi S. Dewata at 2024-08-01T23:47:42-05:00
Update pki nss-cert-show
The pki nss-cert-show has been updated to use PK11Store.findCert()
to find a cert from its binary data.
- - - - -
c52041ed by Endi S. Dewata at 2024-08-02T20:59:30-05:00
Fix test for HTTPS connector with NSS database
- - - - -
5e9fb5bc by Endi S. Dewata at 2024-08-06T21:07:55-05:00
Add pki -D option
The pki CLI has been modified to provide an option to specify
Java properties.
- - - - -
c628f79c by Endi S. Dewata at 2024-08-06T21:07:55-05:00
Rename JSSProtocolSocketFactory to DefaultSocketFactory
The JSSProtocolSocketFactory in PKIConnection has been renamed
to DefaultSocketFactory and moved into a separate file.
The org.dogtagpki.client.socketFactory property has been added
to specify an alternative socket factory if needed.
- - - - -
e67221ef by Marco Fargetta at 2024-08-07T16:27:17+02:00
Add CA ProfileService to v2 API
- - - - -
b6360831 by Marco Fargetta at 2024-08-07T16:27:17+02:00
Revert the ACL check for profile APIs to v1 code.
ACL groups does not match with the embedded checks in v1 code so the
code has been reverted to the embedded check leaving the ACL update to
future commits.
- - - - -
527a671c by Marco Fargetta at 2024-08-08T09:32:54+02:00
Add KRA InfoService to v2 API
- - - - -
52011a97 by Marco Fargetta at 2024-08-08T09:36:44+02:00
Add CA KRAConnectorService to v2 APIs
- - - - -
b51e41b4 by Endi S. Dewata at 2024-08-08T08:40:40-05:00
Update test for HTTPS connector with PKCS #12 file
The test for HTTPS connector with PKCS #12 file has been updated
to create a CA signing cert, a short-lived SSL server cert, then
test cert validation using PKI CLI under various scenarios. This
test is similar to the one for HTTPS connector with NSS database.
- - - - -
e9c1af4c by Marco Fargetta at 2024-08-08T16:27:00+02:00
Add KRASystemCertService to v2 APIs
- - - - -
e7281d03 by Marco Fargetta at 2024-08-09T09:37:31+02:00
Add KRA KeyService to v2 APIs
- - - - -
0f12674d by Marco Fargetta at 2024-08-09T15:58:09+02:00
Fix content type for authorisation error message
- - - - -
ce10a949 by Endi S. Dewata at 2024-08-09T12:38:23-05:00
Rename ds-container-start.sh to ds-start.sh
- - - - -
c2b4b837 by Endi S. Dewata at 2024-08-09T12:38:43-05:00
Rename ds-container-stop.sh to ds-stop.sh
- - - - -
ede1698b by Endi S. Dewata at 2024-08-09T13:57:16-05:00
Rename ds-container-certs-import.sh to ds-certs-import.sh
- - - - -
295a4da8 by Endi S. Dewata at 2024-08-09T15:00:17-05:00
Merge ds-container-create.sh into ds-create.sh
- - - - -
fcc9256a by Endi S. Dewata at 2024-08-09T15:00:23-05:00
Merge ds-container-remove.sh into ds-remove.sh
- - - - -
782ee102 by Marco Fargetta at 2024-08-19T12:27:28+02:00
Fix log and field access for KRA KeyServlet
- - - - -
32f0378a by Marco Fargetta at 2024-08-19T12:27:28+02:00
Add KRA KeyRequestService to v2 APIs
- - - - -
eaebd8b8 by Marco Fargetta at 2024-08-19T12:33:48+02:00
Add TKS TPSConnectorService to v2 APIs
- - - - -
3d749e6f by Marco Fargetta at 2024-08-19T12:57:23+02:00
Add TPS ConnectorService to v2 APIs
- - - - -
cd070b88 by Marco Fargetta at 2024-08-19T12:58:19+02:00
Add PKI Services to v2 APIs
- - - - -
a90cae0f by Marco Fargetta at 2024-08-19T13:06:53+02:00
Replace JAX-RS with servlet status code in PKIExceptions
- - - - -
f92a8443 by Marco Fargetta at 2024-08-19T16:40:14+02:00
Fix CMake build
- - - - -
80d8a200 by Endi S. Dewata at 2024-08-19T20:20:43-05:00
Use gcc option -mbranch-protection=standard
The RPM spec has been updated to use gcc option
-mbranch-protection=standard on AArch64 since it's now required
by rpminspect.
https://sourceware.org/annobin/annobin.html/Test-dynamic-tags.html
- - - - -
eb2456af by Marco Fargetta at 2024-08-21T10:00:12+02:00
Add TPS TPSCertService to v2 APIs
- - - - -
9615892a by Marco Fargetta at 2024-08-21T11:09:57+02:00
Remove server classes from common library
Status codes were retrieved from tomcat servlet.jar package but since
the common package should be used in the server as well as the client
this dependency has been removed and the codes are retrieved from
httpcore package.
- - - - -
64f3239c by Endi S. Dewata at 2024-08-21T08:39:20-05:00
Update cert approval callback
Previously if a client tries to connect to a server but it does
not have the CA signing cert installed and trusted it will get an
UNTRUSTED_ISSUER error from NSS and the cert approval callback
will ask the user whether to trust the cert. In the latest NSS
the error has changed to UNKNOWN_ISSUER, so the callback has been
updated to handle the error in the same way. The tests have also
been updated accordingly.
- - - - -
458f1a80 by Endi S. Dewata at 2024-08-21T08:39:20-05:00
Update sub CA tests
The latest NSS requires the client to have the full cert chain
in order to validate a cert, so most of the sub CA tests have
been updated to install the sub CA signing cert in addition to
the root CA signing cert. For some reason the sub CA tests with
HSM still work without these changes. That will be investigated
separately later.
- - - - -
b4097be4 by Endi S. Dewata at 2024-08-21T13:56:38-05:00
Remove redundant code in CRSEnrollment
- - - - -
0fff4dfa by Endi S. Dewata at 2024-08-23T12:53:49-05:00
Add NonBlockingSocketFactory
The NonBlockingSocketFactory has been added to provide a
non-blocking socket factory for PKIConnection. Eventually
it will replace the DefaultSocketFactory once the support
for OCSP and CRL has been added into JSSTrustManager.
The test for HTTPS connector with NSS has been updated to
use the non-blocking socket factory and validate the new
error messages generated by JSSTrustManager. The test for
HTTPS connector with PKCS #12 file will continue to use
the blocking socket factory to prevent regressions.
- - - - -
a26cc9a6 by Marco Fargetta at 2024-08-26T10:48:29+02:00
Add TPS TPSProfileService to v2 APIs
- - - - -
6f02dd94 by Marco Fargetta at 2024-08-26T10:49:05+02:00
Add TPS AuthenticatorService to v2 APIs
- - - - -
0d5eccbd by Endi S. Dewata at 2024-08-26T14:01:10-05:00
Add pki nss-cert-find --subject and --issuer options
- - - - -
d5502a49 by Marco Fargetta at 2024-08-27T09:31:12+02:00
Fix missing location in TPS profile POST answer
- - - - -
1236a4ca by Marco Fargetta at 2024-08-27T09:31:12+02:00
Add TPS ProfileMappingService to v2 APIs
- - - - -
da25f8ae by Marco Fargetta at 2024-08-27T09:31:42+02:00
Add TPS ConfigService to v2 APIs
- - - - -
76d7686b by Marco Fargetta at 2024-08-27T18:01:15+02:00
Fix pin cert enrollment in v2 APIs
- - - - -
91484ea1 by Marco Fargetta at 2024-08-27T18:01:15+02:00
Fix routing for duplicated path
In case where the same combination of "method:path" match the routing
it was selected always the first.
E.g.: POST:{} and POST:retrieve from KRA `KeyServlet` was not working
because always the first was used.
Additionally, the routing of servlets and filters are the same and it is
not supported anymore filter routing to multiple method using "*" which
has never been used.
- - - - -
759ef9ba by Andrew Hughes at 2024-08-28T14:54:47-05:00
Use Java 21 on RHEL 10
- - - - -
fe9c2f88 by Endi S. Dewata at 2024-08-28T14:54:58-05:00
Use Java 17 on RHEL 9
- - - - -
d1f8c502 by Chris Zinda at 2024-08-29T18:39:33+02:00
Update Installing_EST.md
Added the dnf command to ensure the subsystem is installed.
- - - - -
f3c1ec9a by Endi S. Dewata at 2024-08-30T16:49:46-05:00
Reorganize Tomcat 9.0 files
- - - - -
7f86116a by Endi S. Dewata at 2024-09-04T12:39:26-05:00
Fix rpminspect test
The pki-rpminspect.yaml has been updated to expect Java 21
binaries on Fedora 40+ which matches the Java configuration
in pki.spec.
- - - - -
74dc7993 by Endi S. Dewata at 2024-09-06T10:24:41-05:00
Drop ClonesConnectivyAndDataCheck from pki-healthcheck
pki-healthcheck is a tool to check the status of an instance or
a node in a cluster so that if it reports a problem the admin can
fix it or the monitoring service can replace it with a new node.
The ClonesConnectivyAndDataCheck on the other hand is a plugin
that checks the connectivity from the instance to other clones.
This plugin will report a problem if another clone is down even
though the instance itself is fine, which would be misleading.
Since it doesn't really fit the purpose of pki-healthcheck this
plugin has been dropped.
- - - - -
d67d4d07 by Endi S. Dewata at 2024-09-06T10:25:25-05:00
Rename DB_IMAGE to DS_IMAGE
https://github.com/dogtagpki/pki/wiki/Configuring-Test-Database
- - - - -
d78316d8 by Endi S. Dewata at 2024-09-06T14:18:13-05:00
Add ds-cert-import.sh --input option
- - - - -
59ea6490 by Endi S. Dewata at 2024-09-09T11:05:27-05:00
Fix CA cloning test with secure DS connection
The tests for CA with secure DS connection (including
cloning) have been updated to use DS containers instead
of DS RPM packages from Fedora to avoid DS issue #6316.
https://github.com/389ds/389-ds-base/issues/6316
- - - - -
ace004db by Endi S. Dewata at 2024-09-10T13:07:49-05:00
Rename test for ACME with certbot into basic ACME
- - - - -
ca2674ca by Endi S. Dewata at 2024-09-11T20:48:21-05:00
Fix pki_ds_setup param
pkispawn has been updated to set up the internal database only
if the pki_ds_setup param is set to True.
- - - - -
a72c3f61 by Endi S. Dewata at 2024-09-12T09:27:38-05:00
Update pkispawn to support ACME
pkispawn has been modified to support installing ACME in a
shared PKI server (e.g. with existing CA).
New pkispawn params have been added to specify the ACME
database, issuer, and realm. A sample configuration has been
provided in acme.cfg.
The pki_ds_setup, pki_security_domain_setup, and
pki_registry_enable params in the default.cfg have been moved
from [DEFAULT] into each subsystem's section so that ACME can
skip DS setup, security domain setup, and registry setup by
default.
The templates for ACME database, issuer, and realm configs
have been modified to no longer contain passwords. The
passwords need to be specified during installation.
Some code in acme.py has been moved into subsystem.py so that
it can be reused.
The basic ACME test and the test with PostgreSQL have been
modified to install ACME using pkispawn.
- - - - -
e984ab74 by Endi S. Dewata at 2024-09-12T18:58:40-05:00
Update pkidestroy to ignore missing deployment.cfg
- - - - -
0172c1fb by Endi S. Dewata at 2024-09-13T18:23:16-05:00
Update PKIServer.remove_subsystem() to take subsystem name
- - - - -
613a6985 by Endi S. Dewata at 2024-09-13T18:33:31-05:00
Add default value for pkidestroy -i option
- - - - -
0ff1fc47 by Endi S. Dewata at 2024-09-16T09:29:22-05:00
Add test for ACME on separate instance
A new test has been added to install CA and ACME on separate
instances using pkispawn, then perform some operations using
certbot.
The code that calls spawn_acme() has been moved to run after
the instance is created by the instance_layout scriptlet.
The code that checks the existence of pki_ds_password has been
moved so that it will only run if pki_ds_setup is True.
The code that checks the existence of pki_admin_password and
pki_client_pkcs12_password has been updated so that it will
not run for ACME.
- - - - -
9dd4ea2b by Marco Fargetta at 2024-09-18T13:16:34+02:00
Modify pkispawn to deploy EST
EST deployment is included in pkispwn. The installation does not perform
all the steps done for CA and other subsystems so there is no security
domain management and user administration. During the installation there
is no DS or other DBs connection which has to be performed by the user
before or after the installation.
- - - - -
69c899c8 by Endi S. Dewata at 2024-09-18T20:26:51-05:00
Update ACME tests to check server files and folders
- - - - -
d07d0c7b by Endi S. Dewata at 2024-09-18T22:09:08-05:00
Update PKIServer.remove()
The PKIServer.remove() has been updated to remove the
/var/lib/pki/<instance>/alias symlink if it exists.
- - - - -
47414b8b by Endi S. Dewata at 2024-09-19T13:31:16-05:00
Merge NSSDatabase.create_request_with_wrapping_key() into create_request()
- - - - -
e2bd2bcf by Endi S. Dewata at 2024-09-19T15:38:06-05:00
Clean up PKISubsystem.get_subsystem_cert() param name
- - - - -
0d5138f9 by Endi S. Dewata at 2024-09-19T15:38:32-05:00
Rename PKIDeployer.get_cert_id() to get_cert_param_id()
- - - - -
1b7fd92d by Endi S. Dewata at 2024-09-19T17:17:13-05:00
Rename PKIDeployer.request_cert() to issue_cert()
- - - - -
a772c6a4 by Marco Fargetta at 2024-09-20T09:02:45+02:00
Allow pkispawn to install only EST subsystem
Deployment script has been modified to skip configuration for EST, it is
done differently from the other subsystems. The remaining steps are
performed to create and prepare the instance for EST.
- - - - -
2217c891 by Endi S. Dewata at 2024-09-20T09:50:36-05:00
Update pkidestroy to support ACME
pkidestroy has been updated to support removing ACME from
PKI server. If it is the last subsystem on the server, the
server will be removed as well.
The ACMESubsystem.create() has been modified to create a base
dir (i.e. /var/lib/pki/<instance>/<subsystem>) which is used
by PKIServer.load_subsystems() to determine if the subsystem
exists. The code that creates the conf and logs folders has
been moved into create_conf() and create_logs(), respectively.
The pki-server acme-remove has been updated to provide options
to remove the conf and logs folders.
The tests that use pkispawn to install ACME have been updated
to use pkidestroy to remove ACME.
- - - - -
46ae1346 by Endi S. Dewata at 2024-09-20T12:48:49-05:00
Update param names for PKIDeployer.issue_cert()
- - - - -
51819544 by Endi S. Dewata at 2024-09-20T17:12:48-05:00
Fix basic IPA test
- - - - -
be8e5c01 by Marco Fargetta at 2024-09-23T11:50:17+02:00
Add EST to pkidestroy
Add est to the list of subsystems and the command help.
- - - - -
5bb5342c by Endi S. Dewata at 2024-09-23T14:18:29-05:00
Rename ServerConfig.get_unsecure_port() to get_http_port()
- - - - -
75c28c00 by Endi S. Dewata at 2024-09-23T14:18:50-05:00
Rename ServerConfig.get_secure_port() to get_https_port()
- - - - -
d9ad64f8 by Endi S. Dewata at 2024-09-23T17:45:25-05:00
Add ServerConfig.get_<protocol>_connector()
The code in ServerConfig.get_<protocol>_port() that finds
the connector for a specific protocol has been moved into
get_<protocol>_connector().
- - - - -
c5f4f475 by Endi S. Dewata at 2024-09-23T17:45:28-05:00
Add IPA KRA test
The code that tests IPA KRA in the basic IPA test has been
moved into a separate IPA KRA test.
- - - - -
56c4a063 by Endi S. Dewata at 2024-09-24T09:21:05-05:00
Fix problem reinstalling CA with custom ports
The code that calls ServerConfig.get_connector() to find
a connector with a specific name or port number has been
modified to call get_<protocol>_connector() instead such
that it can always find the connector for the protocol
regardless of the name or the port number.
A new test has been added to install CA with custom port
numbers, remove it, install it again, and remove it again.
- - - - -
33a139ab by Endi S. Dewata at 2024-09-24T10:13:09-05:00
Add pki ca-cert-issue
The pki ca-cert-request-submit command can be used in two ways.
If it's invoked with an install token, the cert will be issued
immediately. If it's invoked without an install token, it will
submit the request to the CA, but then the request will need to
be approved, and the cert will need to be retrieved separately.
To make it easier to issue a cert, a new pki ca-cert-issue has
been added which is similar to pki ca-cert-request-submit but
it can approve the request and retrieve the cert immediately if
invoked with the proper credentials.
pkispawn and most CI tests have been updated to use the new
command. The pki ca-cert-request-submit options that take an
install token have been deprecated.
- - - - -
fcfa2adf by Endi S. Dewata at 2024-09-24T15:12:29-05:00
Update PKIDeployer.import_cert_chain()
The PKIDeployer.import_cert_chain() has been updated to skip
retrieving and importing the cert chain if it already exists
in NSS database.
- - - - -
90537d48 by Endi S. Dewata at 2024-09-24T15:12:29-05:00
Add token param for PKIDeployer.generate_csr()
- - - - -
81b273ae by Endi S. Dewata at 2024-09-24T15:12:29-05:00
Add NSS database param for PKIDeployer.generate_<cert>_request()
- - - - -
9f04b768 by Endi S. Dewata at 2024-09-24T15:12:29-05:00
Add request format param for PKIDeployer.issue_cert()
- - - - -
5c1d2015 by Marco Fargetta at 2024-09-25T16:18:02+02:00
Fix log message from GroupServlet
- - - - -
64ed4cc8 by Endi S. Dewata at 2024-09-25T09:19:35-05:00
Auto-create SSL server cert for ACME on separate instance
pkispawn has been updated to use the ACME's issuer to
provide the cert chain and to automatically issue an SSL
server cert for ACME on separate instance.
The PKIDeployer.import_cert_chain() has been modified to
retrieve the cert chain from the ACME issuer.
The PKIDeployer.get_ca_signing_cert() has been modified
to ignore UNKNOWN_ISSUER error.
The PKIDeployer.issue_cert() has been modified to support
optional install token, subject DN, and issuer credentials.
The test for ACME on separate instance has been modified
to automatically issue an SSL server cert.
The original test with manual SSL server cert creation has
been moved into a separate test.
- - - - -
9781a58c by Marco Fargetta at 2024-09-25T18:40:53+02:00
Remove setup from Postgresql realm authentication
The realm should not modify the user database but it has to be provided
and configured in advance.
However, if a file is provided it is used during the initialisation and
not during the authentication.
- - - - -
142568c2 by Marco Fargetta at 2024-09-25T18:40:53+02:00
Add est test for Postgresql realm
Adding a new test to verify the connection between the EST subsystem
and a realm user database handled with Postgresql.
Additionally, the realm test on separate instance has been modified to
authenticate the EST subsystem into the CA using a certificate.
- - - - -
5f28b991 by Marco Fargetta at 2024-09-25T18:40:53+02:00
Revert DB setup to the connection method
Since DB could be not available before the connection the setup is moved
back to the connection method.
- - - - -
7086d337 by Endi S. Dewata at 2024-09-25T16:50:17-05:00
Replace Directory.exists() with os.path.exists()
- - - - -
267b8512 by Endi S. Dewata at 2024-09-25T16:50:20-05:00
Replace Directory.create() with pki.util.makedirs()
- - - - -
527a0296 by Endi S. Dewata at 2024-09-25T17:32:23-05:00
Replace Directory.delete() with pki.util.rmtree()
- - - - -
68783eb0 by Endi S. Dewata at 2024-09-25T17:32:23-05:00
Remove unused Directory class
- - - - -
0d545b8a by Endi S. Dewata at 2024-09-25T17:32:23-05:00
Replace File.exists() with os.path.exists()
- - - - -
6859c63a by Endi S. Dewata at 2024-09-25T18:28:03-05:00
Replace File.copy() with PKIServer.copy()
- - - - -
e4202da9 by Endi S. Dewata at 2024-09-25T18:28:08-05:00
Replace File.modify() with os.chmod()
- - - - -
a3514761 by Endi S. Dewata at 2024-09-25T18:30:34-05:00
Replace File.create() with Path.touch()
- - - - -
318c1b48 by Endi S. Dewata at 2024-09-25T18:30:37-05:00
Remove unused File class
- - - - -
1e2c26e6 by Endi S. Dewata at 2024-09-25T18:30:37-05:00
Remove unused Certutil class
- - - - -
175e3722 by Endi S. Dewata at 2024-09-25T18:30:37-05:00
Remove unused Namespace class
- - - - -
fe6567d1 by Endi S. Dewata at 2024-09-25T18:30:37-05:00
Remove redundant code in PKISubsystem.remove_logs()
- - - - -
dc14e3e1 by Endi S. Dewata at 2024-09-25T18:30:37-05:00
Replace default_deployment_cfg with DEFAULT_DEPLOYMENT_CFG
- - - - -
5fa0ac4a by Endi S. Dewata at 2024-09-26T08:48:33-05:00
Enable registry for ACME
The default pki_registry_enable for ACME has been changed
to True. This allows pkispawn and pkidestroy to create and
remove ACME properly.
The PKIDeployer.create_acme_subsystem() has been modified
to create the registry. The remove_acme_subsystem() has
been modified to remove the registry.
The PKISubsystem.remove_registry() has been modified to
check whether the files/folders exist before removing them
in case the subsystem was created without registry.
The test for ACME on separate instance has been modified to
no longer create the server and NSS database before calling
pkispawn. Some file/folder permissions have also changed due
to these changes.
- - - - -
174076a8 by Endi S. Dewata at 2024-09-27T10:59:16-05:00
Update test for CA with caDirUserCert profile
The test for CA with caDirUserCert profile has been updated
to perform enrollments using pki ca-cert-issue command and
also manually using XML and JSON messages.
https://github.com/dogtagpki/pki/wiki/Configuring-Directory-Authenticated-Certificate-Profiles
- - - - -
7a13e699 by Marco Fargetta at 2024-09-30T10:15:43+02:00
Fix EST sslserver key name
Key name for sslserver was not correctly configured in server.xml.
Additionally, the EST setup operations have been moved to match the
operation done for the other subsystem.
- - - - -
611d34b0 by Marco Fargetta at 2024-09-30T10:15:43+02:00
Update EST CI to consider the file generated
After modifying the EST installation with pkispawn there are several
differences in the generated files which are verified in the CI tests.
- - - - -
eddb83ba by Marco Fargetta at 2024-09-30T10:15:43+02:00
Generate SSL certificate for EST subsystem
pkispawn will create the sslserver certificate for EST if it is not
provided with a PKCS12 bundle containing the certificate.
To generate the certificate the EST user credentials and profile are
used so these should be configured in the CA before EST installation.
- - - - -
bbd66645 by Endi S. Dewata at 2024-09-30T08:40:13-05:00
Update test for CA with caDirPinUserCert profile
The test for CA with caDirPinUserCert profile has been updated
to perform enrollments using pki ca-cert-issue command and also
manually using XML and JSON messages.
https://github.com/dogtagpki/pki/wiki/Certificate-Enrollment-with-PIN-Authenticated-Profile
- - - - -
f21fea78 by Endi S. Dewata at 2024-09-30T18:22:20-05:00
Update caServerCert profile test to use pki ca-cert-issue
- - - - -
f0e1d653 by Endi S. Dewata at 2024-10-01T20:03:31-05:00
Update IPA tests to check access logs
- - - - -
e62f2c69 by Endi S. Dewata at 2024-10-02T09:43:47-05:00
Update rpminspect test
The pom.xml files have been updated to define the target
Java version using maven.compiler.release property. The
maven-compiler-plugin is no longer used so it has been
removed.
The pki-rpminspect.yaml has been updated to no longer
define the javabytecode requirement so it will use the
standard requirement for the platform.
The rpminspect test has been updated to call rpminspect
directly in separate steps to make it easier to inspect
the failures. The rpminspect.sh is no longer used so it
has been removed.
Currently the test is failing because some dependencies
were built with older Java bytecode versions. They need
to be rebuilt with the proper version.
- - - - -
93013c27 by Endi S. Dewata at 2024-10-02T10:22:20-05:00
Add pki --api option
The pki CLI has been updated to provide an option to specify
the REST API version to use when communicating with the server.
By default the CLI will use API v1, but it might change in the
future.
The PKIClient class has been modified to store the API version
which will automatically be used by other client classes (e.g.
InfoClient).
The basic CA test has been updated to run pki info with the
default API and API v2 and verify the access logs generated by
these commands.
- - - - -
269745d6 by Endi S. Dewata at 2024-10-02T10:22:20-05:00
Update pki ca-cert-find for API v2
The CertServlet.listCerts() has modified to no longer
return the total certs found to allow future performance
optimization. Calculating the total certs found with Simple
Paged Results requires retrieving the full search results
from the database so it should be avoided.
The basic CA test has been updated to test pki ca-cert-find
with the default API and API v2 then verify the access logs
generated by these commands. The test-ca-certs.sh script is
no longer used so it has been removed.
- - - - -
2f0ba3ff by Endi S. Dewata at 2024-10-02T16:58:29-05:00
Update IPA tests to check HTTPD error logs
- - - - -
d474d834 by Endi S. Dewata at 2024-10-02T21:09:04-05:00
Fix broken publishing workflow due to Maven compiler properties
- - - - -
a773182f by Endi S. Dewata at 2024-10-03T10:31:34-05:00
Update test for pki ca-user-show
The basic CA test has been updated to run pki ca-user-show
with default API and API v2 then verify the access logs
generated by these commands.
The AccountClient has been updated to use the API version
from PKIClient.
The AccountServlet.logout() has been updated to return
NO_CONTENT status for consistency with API v1.
- - - - -
a310a549 by Marco Fargetta at 2024-10-03T17:54:05+02:00
Fix profiles for EST certificate and re-enrollment
Generate EST certificates with same profile of other subsystems.
Additionally, add EST generate certificate to the user and test both
enrollment with certificate and re-enrollment.
- - - - -
c91e0624 by Endi S. Dewata at 2024-10-03T15:07:14-05:00
Update CA DS connection test to use pki ca-cert-issue
- - - - -
22e674e7 by Endi S. Dewata at 2024-10-03T15:07:14-05:00
Update CA renewal tests to use pki ca-cert-issue
- - - - -
da36e97d by Endi S. Dewata at 2024-10-03T15:42:25-05:00
Update IPA tests to check logs before removing server
- - - - -
76267d9a by Endi S. Dewata at 2024-10-04T21:02:04-05:00
Move SerialNumberUpdateTask.updateSerialNumbers() to CAEngine
- - - - -
4e474ace by Endi S. Dewata at 2024-10-08T08:47:00-05:00
Add SerialNumberUpdateJob
The SerialNumberUpdateJob has been added to update the ranges
for sequential serial numbers, similar to SerialNumberUpdateTask.
The job can be scheduled to run automatically at specific times,
or can be run immediately by calling pki ca-job-start, whereas
the task only supports a fixed interval.
An upgrade script has been added to add the default config params
for SerialNumberUpdateJob into existing instances. In the future
it might be possible to replace SerialNumberUpdateTask with
SerialNumberUpdateJob automatically.
https://github.com/dogtagpki/pki/wiki/Configuring-SerialNumberUpdateJob
- - - - -
2dd79f4c by Endi S. Dewata at 2024-10-08T08:47:00-05:00
Update test for CA with sequential serial numbers
pkispawn has been modified to provide more params to configure the
sequential serial numbers in CA. The params can also be added for
KRA if needed later.
The test for CA with sequential serial numbers has been updated to
perform more detailed steps and verification. The test will now use
small ranges to make it easier to verify the changes in the CS.cfg
and DS. The test will also use SerialNumberUpdateJob to update the
ranges immediately instead of waiting for SerialNumberUpdateTask
to run.
A more complex test with CA clones will be added separately later.
- - - - -
cd305480 by Endi S. Dewata at 2024-10-09T10:54:48-05:00
Add test for sequential serial number gaps
The test for CA with sequential serial numbers has been updated
to perform additional enrollments and check the request IDs and
cert serial numbers. Ideally the numbers should be contiguous,
but currently the cert serial numbers sometimes have gaps. This
issue will be fixed separately later.
- - - - -
13e241b2 by dependabot[bot] at 2024-10-10T15:33:31+02:00
Bump commons-io:commons-io from 2.11.0 to 2.14.0 in /base/common
Bumps commons-io:commons-io from 2.11.0 to 2.14.0.
---
updated-dependencies:
- dependency-name: commons-io:commons-io
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support at github.com>
- - - - -
34150e16 by Endi S. Dewata at 2024-10-11T20:30:20-05:00
Add test for CA clone with sequential serial numbers
A new test has been added to create a CA with sequential serial
numbers, create a clone with the same config, perform enrollments,
and update the serial number ranges with pki ca-job-start
serialNumberUpdate.
Ideally the serial numbers should be contiguous, but currently
the code creates a gap between the ranges. The steps for fixing
an existing gap and migrating to RSNv3 may be added later.
- - - - -
41465e2e by Marco Fargetta at 2024-10-15T10:03:51+02:00
Reverting the test-ca-certs.sh
The file is currently used for JSS tests
- - - - -
b5e9c749 by Endi S. Dewata at 2024-10-16T09:58:29-05:00
Add ca-<type>-range-config.sh scripts
The ca-<type>-range-config.sh scripts have been added to
simplify range config verification.
- - - - -
0c1cd6ab by Endi S. Dewata at 2024-10-16T09:58:29-05:00
Add ca-<type>-range-objects.sh scripts
The ca-<type>-range-objects.sh scripts have been added to
simplify range object verification.
- - - - -
696472a9 by Endi S. Dewata at 2024-10-16T09:58:29-05:00
Add ca-<type>-next-range.sh scripts
The ca-<type>-next-range.sh scripts have been added to simplify
next range verification.
- - - - -
a76eb4b8 by Endi S. Dewata at 2024-10-17T10:32:20-05:00
Update test for CA with sequential serial numbers
The test for CA with sequential serial numbers has been updated
to use a different cert range configuration to verify how it
handles mismatching range size and increment and also hexadecimal
numbers in the CS.cfg.
- - - - -
72b508ee by Endi S. Dewata at 2024-10-22T12:58:55-05:00
Add tests for next begin/end numbers
The tests for CA with sequential serial numbers have been
updated to verify the dbs.nextBegin... and dbs.nextEnd...
parameters.
- - - - -
ff78d2a6 by Endi S. Dewata at 2024-10-22T13:00:55-05:00
Clean up Repository classes
The Repository classes have been updated to no longer use
class fields to store the names of the parameters that define
the boundaries of the ranges. Instead, the classes will use
the setter & remover methods of the parameters directly.
This will make it easier to find the code that modifies the
parameters.
- - - - -
b85f88e6 by Marco Fargetta at 2024-10-24T19:23:20+02:00
Add a new sequential number generator: legacy2
The current generator has a problem with converting from hex to decimal
the range boundaries creating gaps between ranges. This a problem when
third parties tools are used to with certificates because contiguous
range are expected.
This commit introduce the generator legacy2. This uses same
configuration parameter but hex value are specified by the prefix '0x'.
When value are written to the configuration value it is possible to set
the radix with the options:
- dbs.cert.id.radix (default to 16)
- dbs.key.id.radix (default to 16)
- dbs.request.id.radix (default to 10)
Additionally, the new command `pki-server <subsystem>-id-generator-*`
has been added to migrate from the legacy generator to the legacy2 or to
random.
- - - - -
16e42fd3 by Marco Fargetta at 2024-10-24T19:23:20+02:00
Add legacy2 generator test to sequential tests
- - - - -
d8f2465d by Endi S. Dewata at 2024-10-24T17:18:15-05:00
Update CA clone test to check the logs
- - - - -
6ae10a52 by Endi S. Dewata at 2024-10-24T20:41:04-05:00
Rename SSNv1 tests
- - - - -
6026ef01 by Endi S. Dewata at 2024-10-28T10:47:15-05:00
Add tests for SSNv2
New tests have been added to verify a single CA and CA clones
with SSNv2. New test scripts for SSNv2 have also been added to
make it easier to change the location of the range objects and
nextRange attributes later.
The test for CA with Nuxwdog has been relocated due to GitHub
workflow limit.
- - - - -
d138ee6d by Marco Fargetta at 2024-10-28T18:17:28+01:00
Move legacy2 ranges in a new tree
When an instance is updated from legacy generator to the new legacy2
generator the ranges will be stored in a new tree. The default tree
name is "ou=range_v2,<subsystem_base_db>".
The name of the ranges entry can be customised with the option `-r` (or
--range) to the command `pki-server <subsystem>-id-generator-update`.
- - - - -
1e1e7e77 by Marco Fargetta at 2024-10-28T18:17:28+01:00
Update ssnv2 tests to support new ranges object for legacy2 migration
- - - - -
9785b3fa by Endi S. Dewata at 2024-10-29T17:03:35-05:00
Clean up log messages in PKISocketFactory
- - - - -
250c3474 by Endi S. Dewata at 2024-10-29T17:14:44-05:00
Remove duplicate test scripts
- - - - -
9fd6f3f8 by Marco Fargetta at 2024-10-30T11:40:43+01:00
Fix pageSize in AgentCertRequestServlet
- - - - -
a02aebae by Marco Fargetta at 2024-10-30T20:05:49+01:00
Update Dockerfile to work with F41
Some dnf options have been modified/removed in fedora 41 and the
Dockerfile has been update to the new options.
- - - - -
23144cca by Endi S. Dewata at 2024-10-31T10:20:00-05:00
Relocate SSNv2 range objects for new CA instances
pkispawn has been modified to create ou=ranges subtree for SSNv1
and optionally ou=ranges_v2 subtree for SSNv2 if it's enabled for
new CA instances. The pki-server <subsystem>-db-init and
<subsystem>-range-update commands have been updated to use the
proper subtree to store the range objects. Hard-coded subtrees in
the create.ldif have been removed.
Similar changes are made to KRA as well, but since there are no
tests for KRA with SSNv2 it's not officially supported yet.
- - - - -
830de109 by Endi S. Dewata at 2024-10-31T10:20:00-05:00
Update test scripts for SSNv2
The test scripts have been updated to use ou=ranges_v2 subtree
for SSNv2 range objects.
- - - - -
a59b015a by Marco Fargetta at 2024-10-31T17:44:09+01:00
Fix mime type for authority chain rest API
- - - - -
1ee8f346 by Endi S. Dewata at 2024-10-31T14:54:34-05:00
Update SSNv1 tests
SSNv1 tests have been updated to execute all steps regardless
of test failures to make it eaasier to maintain the tests and
troubleshoot issues.
- - - - -
60d5348d by Marco Fargetta at 2024-11-01T10:23:47-05:00
Command file required for PrettyPrintCert
F41 does not include the `file` command in the default installation and
need to be installed because it is used by PrettyPrintCert to
distinguish between pem and der certificates.
- - - - -
a666e1af by Endi S. Dewata at 2024-11-01T13:50:07-05:00
Drop abrt-java-connector dependency
abrt-java-connector is no longer available in Fedora 41 and is
actually not required to run ACME container so the dependency
has been dropped.
- - - - -
4e6c7a62 by Endi S. Dewata at 2024-11-01T14:48:51-05:00
Drop update-crypto-policies dependency
update-crypto-policies is no longer available by default in
Fedora 41 and is actually not required to run PKICertImport
test so the dependency has been dropped.
- - - - -
596ea567 by Endi S. Dewata at 2024-11-01T17:44:51-05:00
Fix deprecation warnings in NSSDatabase
The NSSDatabase class has been updated to use timezone-aware
fields and methods for cert validity.
- - - - -
116ef362 by Endi S. Dewata at 2024-11-04T09:11:57-06:00
Relocate SSNv2 nextRange attribute
The nextRange attribute for SSNv2 has been moved to
ou=requests,ou=ranges_v2 for requests and
ou=certificateRepository,ou=ranges_v2 for certs such that
the nextRange for SSNv1 is unchanged during migration.
This will simplify the recovery process in case there's
an issue during migration.
The SubsystemIdGeneratorUpdateCLI has been updated to
compute the request nextRange for SSNv2 with the same
process used to compute the cert nextRange for SSNv2.
- - - - -
678b8d00 by Endi S. Dewata at 2024-11-04T09:11:57-06:00
Update SSNv1 and SSNv2 tests
The SSNv1 and SSNv2 tests have been updated to use the new
SSNv2 nextRange location.
- - - - -
16a10040 by Endi S. Dewata at 2024-11-04T13:38:34-06:00
Add fallback for Certificate.not_valid_before/after_utc
The NSSDatabase.get_cert_info() has been modified so that it will
use Certificate.not_valid_before/after_utc attributes which are
available since Python Cryptography 42, otherwise it will use the
deprecated not_valid_before/after then convert them into UTC.
- - - - -
bb4b078e by Endi S. Dewata at 2024-11-04T16:43:37-06:00
Fix variable name in NSSDatabase.get_cert_info()
- - - - -
7407f408 by Endi S. Dewata at 2024-11-04T18:15:28-06:00
Fix JAVA_HOME on Fedora 42
- - - - -
bb333757 by Marco Fargetta at 2024-11-05T12:24:25+01:00
Force SSNv2 to require configuration with 0x format
Since SSNv2 ranges number requires the format `0x...` to be correctly
interpreted as hex number, an exception is introduced when a decimal
number is provided. This approach make explicit the hex or dec number
are in use and avoid later problems.
- - - - -
aa99ce61 by Marco Fargetta at 2024-11-05T12:24:25+01:00
Add SSNv2 test deploymend with range format error
- - - - -
e28470ae by Marco Fargetta at 2024-11-05T12:26:33+01:00
Fix builddep in azure pipeline
Fedora 41 moved to dnf5 and the builddep command do not support the
parameter `--spec` but it becomes a positional parameter so it is removed.
- - - - -
70c58e6d by Marco Fargetta at 2024-11-05T12:59:06+01:00
Explicitely assign `theme` global property in pki.spec
The theme property is read from `build.sh` using a regular expression
and the output provided to CMake. If the value is replaced with a
variable then the CMake build cannot work.
- - - - -
4d594218 by Endi S. Dewata at 2024-11-06T13:25:48-06:00
Add tests for conflicts for CA with SSNv2
The test for CA with SSNv2 has been modified to check how the
CA handles conflicting requests and certs in the database.
- - - - -
9cad7466 by Endi S. Dewata at 2024-11-06T17:23:23-06:00
Update basic CA test to check DS entries
- - - - -
847ddbc9 by jmagne at 2024-11-06T17:03:07-08:00
Address Test Port final TMS fixes for rhel7 to master branch, phase 2, RHCS-5403 (#4894)
This checkin coincides with the final sub task of porting the rhel7 tms to the master branch.
Once this code makes it to the testing phase, every feature present in the lastest version of the rhel7 tms
system should be present in any releases taken from the master branch.
Add some more TPS CS.cfg comments for newer features.
Fix tps docker test to include the cfg variable needed to allow tpsclient enrollments to complete.
Update call to CryptoUtil.exportSharedSecretWithAES in TPSConnectorProcessor.java to reflect change to
TPSConnectorService.java.
Addresss github code security concerns.
Change-Id: I7c98ddeffafd912debb908c9efc7a6bb591807ee
- - - - -
62d2052e by jmisset-cb at 2024-11-07T13:25:19-06:00
fix createUserNotice parameter order
The usernotice certificate policy extensions qualifier can contain an
organizationname, noticenumbers and explicittext field. The explicittext
and noticenumbers fields are not handled correctly, causing the error
"wrong notice numbers" when submitting a CSR on a certificate profile
that contains a value in explicittext.
- - - - -
1e824d97 by Endi S. Dewata at 2024-11-08T15:14:38-06:00
Fix test for request ID conflict with SSNv2
The test for request ID conflict with SSNv2 has been updated
to create a duplicate request record with the proper requestId
attribute. With this change the CLI is no longer failing, but
the CA is still updating the duplicate request record instead
of creating a new one as expected.
- - - - -
475b58c9 by Marco Fargetta at 2024-11-14T20:03:20+01:00
Fix range update to legacy2 with clone
When a new clone is deployed it get the initial allocation from the
current range or the next range already allocated. The code was not
considering the case of next range so it could generate a range overlap.
The fix will check if the next range is totally allocate for the service
or it is partial and in this case only the remaining part is used.
- - - - -
d357aed6 by Alexander Bokovoy at 2024-11-18T15:18:10+01:00
ACME PKI issuer: add support for Authority ID or DN
Allow issuing ACME certificates using a specific authority.
This would allow FreeIPA to specify a particular subCA to handle ACME
certificates.
Fixes: https://github.com/dogtagpki/pki/issues/4902
Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>
- - - - -
4d07685f by Alexander Bokovoy at 2024-11-18T15:18:10+01:00
Add a test to specify authority ID in ACME configuration
Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>
- - - - -
ae7b3c20 by Marco Fargetta at 2024-11-21T10:21:12+01:00
fcf-protection only available for x86_64
- - - - -
2547014c by Alexander Bokovoy at 2024-11-21T11:20:41+01:00
doc: update ACME PKI issuer documentation for authority ID support
Fixes: https://github.com/dogtagpki/pki/issues/4902
Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>
- - - - -
79c10849 by Marco Fargetta at 2024-12-04T10:45:10+01:00
Updating version to v11.6.0-alpha2
- - - - -
ceb4d225 by Endi S. Dewata at 2024-12-06T05:56:12+07:00
Fix PKIServer.create()
The PKIServer.create() has been updated to set the properties
in /var/lib/pki/<instance>/conf/tomcat.conf and in its copy at
/etc/sysconfig/<type>@<instance> properly.
- - - - -
50f41a72 by Endi S. Dewata at 2024-12-06T07:59:07+07:00
Fix server tests
- - - - -
6d3bd1dc by Christina Fu at 2024-12-06T10:01:00-08:00
Create Installing_CA.adoc
This asciidoc file is converted from Installing_CA.md with minor changes.
- - - - -
75acc75d by Christina Fu at 2024-12-06T10:59:18-08:00
fixed ca.cfg link in Installing_CA.adoc
- - - - -
29ba8503 by Christina Fu at 2024-12-06T12:02:49-08:00
Update ca.cfg to include instance name and port numbers with default values
This is to make the more common customizable parameters readily available for users to modify.
- - - - -
29eec4a7 by Christina Fu at 2024-12-06T13:56:59-08:00
[skip ci]
- - - - -
4829bc34 by Christina Fu at 2024-12-06T14:19:30-08:00
Replacing Installing_CA.md with link to Installing_CA.adoc message
[skip ci]
- - - - -
00831999 by Christina Fu at 2024-12-06T16:19:15-08:00
Create Installing_DS_Packages.adoc
[skip ci]
- - - - -
cc435f64 by Christina Fu at 2024-12-06T16:28:05-08:00
Create Creating_DS_instance.adoc
[skip ci]
- - - - -
4739cb0d by Christina Fu at 2024-12-06T16:30:22-08:00
Update Installing_DS_Packages.adoc
[skip ci]
- - - - -
40c5592b by Christina Fu at 2024-12-06T16:37:31-08:00
Update Installing_CA.adoc
[skip ci]
- - - - -
ff87fef4 by Christina Fu at 2024-12-06T16:48:30-08:00
Update Creating_DS_instance.adoc
[skip ci]
- - - - -
0c9bed59 by Christina Fu at 2024-12-06T16:50:35-08:00
Update Creating_DS_instance.adoc
[skip ci]
- - - - -
c1265b0b by Christina Fu at 2024-12-06T16:54:50-08:00
Update Creating_DS_instance.adoc
[skip ci]
- - - - -
229ad096 by Christina Fu at 2024-12-06T17:19:09-08:00
Update Creating_DS_instance.adoc
[skip ci]
- - - - -
c9176278 by Christina Fu at 2024-12-09T09:15:13-08:00
Create Installing_DS_Packages.adoc
[skip ci]
- - - - -
3ca63232 by Christina Fu at 2024-12-09T09:17:48-08:00
Create Creating_DS_instance.adoc
[skip ci]
- - - - -
7ca01fc1 by Christina Fu at 2024-12-09T09:18:47-08:00
Update Creating_DS_instance.adoc
[skip ci]
moved to another folder: "others"
- - - - -
deee0c8c by Christina Fu at 2024-12-09T09:19:16-08:00
Update Installing_DS_Packages.adoc
[skip ci]
moved to another folder: "others"
- - - - -
83e5af63 by Christina Fu at 2024-12-09T09:26:01-08:00
Create FQDN_Configuration.adoc
[skip ci]
- - - - -
1b844a92 by Christina Fu at 2024-12-09T09:26:55-08:00
Update FQDN_Configuration.adoc
[skip ci]
- - - - -
9048e055 by Christina Fu at 2024-12-09T09:28:27-08:00
Update Installing_CA.adoc
[skip ci]
changed some link folder reference to "others" instead of "server"
- - - - -
a92a019e by Christina Fu at 2024-12-09T10:24:59-08:00
Update Installing-CA-with-Random-Serial-Numbers-v3.adoc
[skip ci]
modified link to the CA installation .adoc copy (instead of .md copy)
- - - - -
dd0c7418 by Christina Fu at 2024-12-09T15:02:35-08:00
Update Installing_CA.adoc
[skip ci]
- - - - -
d1916173 by Christina Fu at 2024-12-09T15:25:22-08:00
Create Installing_CA_Clone.adoc
[skip ci]
first draft
- - - - -
d76cf1eb by Christina Fu at 2024-12-09T15:30:43-08:00
Update Installing_CA_Clone.md
[skip ci]
Conversion completed.
Will remove the content after the "moved" message after finalizing.
- - - - -
24e9c0ac by Christina Fu at 2024-12-09T15:38:18-08:00
Update Installing-CA-with-RSA-PSS.adoc
[skip ci]
adjust url to asciidoc version of Installing_CA
- - - - -
70d58861 by Christina Fu at 2024-12-09T15:46:09-08:00
Create Installing_CA_Clone_with_HSM.adoc
[skip ci]
converted from Installing_CA_Clone_with_HSM.md with modifications.
- - - - -
8aa53508 by Christina Fu at 2024-12-09T15:49:40-08:00
Update Installing_CA_Clone_with_HSM.md
[skip ci]
conversion to asciidoc completed.
.md file content to be removed after finalizing.
- - - - -
ee1cfeac by Christina Fu at 2024-12-09T15:51:15-08:00
Update Installing_CA.md
[skip ci]
- - - - -
ccd5dea7 by Christina Fu at 2024-12-09T15:52:37-08:00
Update Installing_CA_Clone.md
[skip ci]
- - - - -
e5ea3e26 by Christina Fu at 2024-12-09T16:29:09-08:00
Create Installing_CA_Clone_with_Secure_Database_Connection.adoc
[skip ci]
initial .md to .adoc conversion
- - - - -
da2596a6 by Christina Fu at 2024-12-09T16:36:57-08:00
Create Enabling-SSL-Connection-in-DS.adoc
[skip ci]
moved from https://github.com/dogtagpki/pki/wiki/Enabling-SSL-Connection-in-DS
- - - - -
b1874771 by Christina Fu at 2024-12-09T16:43:34-08:00
Update Enabling-SSL-Connection-in-DS.adoc
[skip ci]
link adjustment
- - - - -
3ff16bee by Christina Fu at 2024-12-09T16:43:51-08:00
Update Installing_CA_Clone_with_Secure_Database_Connection.adoc
[skip ci]
link adjustment
- - - - -
dbca7867 by Christina Fu at 2024-12-09T16:46:11-08:00
Create PKI-NSS-CLI.adoc
[skip ci]
initial content copied from https://github.com/dogtagpki/pki/wiki/PKI-NSS-CLI
- - - - -
28f6698c by Christina Fu at 2024-12-09T16:49:29-08:00
Create Exporting-DS-Certificates.adoc
[skip ci]
initial content copied from https://github.com/dogtagpki/pki/wiki/Exporting-DS-Certificates
- - - - -
7a7964d5 by Christina Fu at 2024-12-09T16:51:17-08:00
Update Installing_CA_Clone_with_Secure_Database_Connection.adoc
[skip ci]
link adjustment
- - - - -
1f44a9c5 by Christina Fu at 2024-12-09T16:55:22-08:00
Update Installing_CA_Clone_with_Secure_Database_Connection.md
[skip ci]
message with converted/moved to Installing_CA_Clone_with_Secure_Database_Connection.adoc
.md content is to be removed after finalizing
- - - - -
abe49da2 by Endi S. Dewata at 2024-12-11T21:16:08+07:00
Update Python API to support REST API v2
The PKIClient class has been added to replace PKIConnection
as the main access point to PKI services. By default it will
use REST API v2, then fall back to v1 if it's not available.
Optionally, PKIClient can be configured to use a specific
REST API version.
The InfoClient, CertClient, AccountClient, and UserClient
classes have been added/updated to construct the proper REST
URL according to the REST API version in PKIClient.
The pki-healthcheck has been updated to use PKIClient. Some
simple Python scripts have also been added to demonstrate
how to use PKIClient.
New tests have been added to run these scripts against the
current CA and KRA which support both REST API v1 and v2
and also against an older CA that only supports REST API v1.
- - - - -
1c159dfc by Christina Fu at 2024-12-12T15:41:56-08:00
Create Installing_CA_with_Custom_CA_Signing_Key.adoc
[skip ci]
converted/modified from Installing_CA_with_Custom_CA_Signing_Key.md
- - - - -
1e477de2 by Christina Fu at 2024-12-12T16:05:23-08:00
Update Installing_CA.adoc
[skip ci]
fixed missing title
- - - - -
338791c7 by Christina Fu at 2024-12-12T16:06:00-08:00
Update Installing_CA_Clone.adoc
[skip ci]
fixed missing title
- - - - -
05a2c2ab by Christina Fu at 2024-12-12T16:07:18-08:00
Create Installing_CA_with_ECC.adoc
[skip ci]
copied/converted from Create Installing_CA_with_ECC.md
- - - - -
ca74a560 by Christina Fu at 2024-12-12T16:11:06-08:00
Update ca-ecc.cfg to include instance name and port numbers with default values
[skip ci]
This is to make the more common customizable parameters readily available for users to modify.
- - - - -
bb610ea5 by Christina Fu at 2024-12-12T16:13:09-08:00
Update Installing_CA_with_ECC.adoc
[skip ci]
copied/converted from Installing_CA_with_ECC.md
- - - - -
0b8e2827 by Christina Fu at 2024-12-12T16:39:00-08:00
Create Installing_CA_with_Existing_Keys_in_HSM.adoc
[skip ci]
content copied/converted from Installing_CA_with_Existing_Keys_in_HSM.md
- - - - -
5b97f4b7 by Christina Fu at 2024-12-12T16:53:48-08:00
Create Installing_CA_with_Existing_Keys_in_Internal_Token.adoc
[skip ci]
copied/converted from Installing_CA_with_Existing_Keys_in_Internal_Token.md
- - - - -
3445c253 by Christina Fu at 2024-12-12T16:55:57-08:00
Update ca-existing-certs-step1.cfg to include instance name and port numbers with default values
[skip ci]
This is to make the more common customizable parameters readily available for users to modify.
- - - - -
3f57d203 by Christina Fu at 2024-12-12T16:57:52-08:00
Update ca-existing-certs-step2.cfg to include instance name and port numbers with default values
[skip ci]
This is to make the more common customizable parameters readily available for users to modify.
- - - - -
2ec162f5 by Christina Fu at 2024-12-12T17:15:02-08:00
Create Installing_CA_with_External_CA_Signing_Certificate.adoc
[skip ci]
copied/converted from Installing_CA_with_External_CA_Signing_Certificate.md
- - - - -
b6410f4e by Christina Fu at 2024-12-12T17:16:35-08:00
Update ca-external-cert-step1.cfg to include instance name and port numbers with default values
[skip ci]
This is to make the more common customizable parameters readily available for users to modify.
- - - - -
1a7e1cfd by Christina Fu at 2024-12-12T17:18:06-08:00
Update ca-external-cert-step2.cfg to include instance name and port numbers with default values
[skip ci]
This is to make the more common customizable parameters readily available for users to modify.
- - - - -
6b0507ec by Endi S. Dewata at 2024-12-13T21:35:26+07:00
Update pki.server.cli.banner to use argparse
- - - - -
0286c6ee by Endi S. Dewata at 2024-12-13T21:35:26+07:00
Update pki.server.cli.group to use argparse
- - - - -
ccbbf5da by Endi S. Dewata at 2024-12-13T21:35:26+07:00
Update pki.server.cli.jss to use argparse
- - - - -
7678489d by Endi S. Dewata at 2024-12-13T21:35:26+07:00
Update pki.server.cli.listener to use argparse
- - - - -
fc6ec3b0 by Endi S. Dewata at 2024-12-13T21:35:26+07:00
Update pki.server.cli.migrate to use argparse
- - - - -
079455b0 by Endi S. Dewata at 2024-12-13T21:35:26+07:00
Update pki.server.cli.nss to use argparse
- - - - -
aa8a770a by Endi S. Dewata at 2024-12-13T21:35:26+07:00
Update pki.server.cli.password to use argparse
- - - - -
f35483c3 by Christina Fu at 2024-12-13T16:30:21-08:00
Create Installing_CA_with_HSM.adoc
[skip ci]
content copied/converted from Installing_CA_with_HSM.md
- - - - -
0201ad2e by Christina Fu at 2024-12-13T16:34:25-08:00
Update Installing_CA_with_Custom_CA_Signing_Key.md
[skip ci]
added "moved to" message
will remove content after finalizing.
- - - - -
0157bb21 by Christina Fu at 2024-12-13T16:35:45-08:00
Update Installing_CA_with_ECC.md
[skip ci]
added "moved to" comment.
will remove content once finalized
- - - - -
ae530663 by Christina Fu at 2024-12-13T16:36:55-08:00
Update Installing_CA_with_Existing_Keys_in_HSM.md
[skip ci]
added "moved to" comment
content will be removed after finalizing
- - - - -
4673ae3e by Christina Fu at 2024-12-13T16:38:31-08:00
Update Installing_CA_with_Existing_Keys_in_Internal_Token.md
[skip ci]
added "moved to" message.
content will be removed after finalizing
- - - - -
ac4ce8ae by Christina Fu at 2024-12-13T16:39:25-08:00
Update Installing_CA_with_External_CA_Signing_Certificate.md
[skip ci]
added "moved to" message.
content will be removed after finalizing
- - - - -
9bb596ca by Christina Fu at 2024-12-13T16:40:29-08:00
Update Installing_CA_with_HSM.md
[skip ci]
added "moved to" message.
content will be removed after finalizing
- - - - -
0b393dd2 by Christina Fu at 2024-12-13T17:08:13-08:00
Create Installing_CA_with_Secure_Database_Connection.adoc
[skip ci]
copied/converted from Installing_CA_with_Secure_Database_Connection.md
- - - - -
d74587b8 by Christina Fu at 2024-12-13T17:09:51-08:00
Update Installing_CA_with_Secure_Database_Connection.md
[skip ci]
added the "moved to" message.
content will be removed once finalized
- - - - -
a60f6ded by Christina Fu at 2024-12-13T17:13:40-08:00
Update ca-secure-ds.cfg to include instance name and port numbers with default values
[skip ci]
This is to make the more common customizable parameters readily available for users to modify.
- - - - -
57d9e95a by Christina Fu at 2024-12-13T17:19:05-08:00
Create Installing_Subordinate_CA.adoc
[skip ci]
copied/converted from Installing_Subordinate_CA.md
- - - - -
ac0ff597 by Christina Fu at 2024-12-13T17:21:00-08:00
Update subca.cfg to include instance name and port numbers with default values
[skip ci]
This is to make the more common customizable parameters readily available for users to modify.
- - - - -
c5cfd08b by Christina Fu at 2024-12-13T17:23:10-08:00
Update Installing_Subordinate_CA.md
[skip ci]
added the "moved to" message.
content will be removed once finalized.
- - - - -
287698c8 by Endi S. Dewata at 2024-12-16T20:55:29+07:00
Update pki.server.cli.config to use argparse
- - - - -
7be71587 by Endi S. Dewata at 2024-12-16T20:55:29+07:00
Update pki.server.cli.id to use argparse
- - - - -
c3fe6029 by Endi S. Dewata at 2024-12-16T20:55:29+07:00
Update pki.server.cli.nuxwdog to use argparse
- - - - -
a01f1602 by Endi S. Dewata at 2024-12-16T20:55:29+07:00
Update pki.server.cli.range to use argparse
- - - - -
fef009a4 by Endi S. Dewata at 2024-12-16T20:55:29+07:00
Update pki.server.cli.selftest to use argparse
- - - - -
a2fffa1b by Endi S. Dewata at 2024-12-16T20:55:29+07:00
Update pki.server.cli.upgrade to use argparse
- - - - -
d1c38d49 by Endi S. Dewata at 2024-12-16T20:55:29+07:00
Update pki.server.cli.webapp to use argparse
- - - - -
2b3d75bd by Marco Fargetta at 2024-12-16T14:59:50+01:00
Fix compiling option in RHEL-10
RHEL-10 requires cf protection and lto flags, similar to Fedora
- - - - -
23fd7f51 by Endi S. Dewata at 2024-12-17T00:36:21+07:00
Fix pki-server selftest-enable/disable
- - - - -
b34f31d9 by Endi S. Dewata at 2024-12-17T20:57:22+07:00
Update pki.server.cli.audit to use argparse
- - - - -
2b1ae68a by Endi S. Dewata at 2024-12-17T20:57:22+07:00
Update pki.server.cli.cert to use argparse
- - - - -
538b9f40 by Endi S. Dewata at 2024-12-17T20:57:22+07:00
Update pki.server.cli.db to use argparse
- - - - -
262d49ce by Endi S. Dewata at 2024-12-17T20:57:22+07:00
Update pki.server.cli.http to use argparse
- - - - -
44d9629a by Endi S. Dewata at 2024-12-17T20:57:22+07:00
Update pki.server.cli.sd to use argparse
- - - - -
6be90d23 by Endi S. Dewata at 2024-12-18T21:36:14+07:00
Update pki.server.cli.instance to use argparse
- - - - -
d0215311 by Endi S. Dewata at 2024-12-18T21:36:14+07:00
Update pki.server.cli.subsystem to use argparse
- - - - -
fe37f420 by Endi S. Dewata at 2024-12-18T21:36:14+07:00
Update pki.server.cli.user to use argparse
- - - - -
4dd5145a by Marco Fargetta at 2024-12-18T19:05:34+01:00
Fix container restart issue
When container are restarted with podman the restart will send the TERM
signal to the entry process. Since the main entry for these container is
a script running other script and waiting the signal are not propagated
to the thread group making the restart hanging until a KILL signal is
used but these return with an error code making the automation failing.
- - - - -
b13594e2 by Marco Fargetta at 2024-12-18T19:05:34+01:00
CI Restart network interface in podman container
When a podman container restarts the network interface does not always
get updated correctly, making the following communications with the container
fail.
Reload the network solve the problems when it is present.
- - - - -
ff87f39d by Endi S. Dewata at 2024-12-19T20:59:56+07:00
Update pki.server.cli.ca to use argparse
- - - - -
b1a13810 by Endi S. Dewata at 2024-12-19T20:59:56+07:00
Update pki.server.cli.kra to use argparse
- - - - -
40f19b26 by Endi S. Dewata at 2024-12-19T20:59:56+07:00
Update pki.server.cli.ocsp to use argparse
- - - - -
df5344fa by Endi S. Dewata at 2024-12-19T20:59:56+07:00
Update pki.server.cli.tks to use argparse
- - - - -
07af1e84 by Endi S. Dewata at 2024-12-19T20:59:56+07:00
Update pki.server.cli.tps to use argparse
- - - - -
7c5fe8d4 by Endi S. Dewata at 2024-12-19T20:59:56+07:00
Update pki.server.cli.acme to use argparse
- - - - -
52cefa42 by Endi S. Dewata at 2024-12-19T20:59:56+07:00
Update pki.server.cli.est to use argparse
- - - - -
66fe97ab by Endi S. Dewata at 2024-12-20T22:01:03+07:00
Update pki.cli.password to use argparse
- - - - -
fa240b97 by Endi S. Dewata at 2024-12-20T22:01:03+07:00
Update pki.cli.pkcs12 to use argparse
- - - - -
761f086c by Endi S. Dewata at 2024-12-20T22:01:03+07:00
Update pki.cli.upgrade to use argparse
- - - - -
4e6a0314 by Endi S. Dewata at 2024-12-20T22:01:03+07:00
Update drmtest.py to use argparse
- - - - -
bfb5a8eb by Endi S. Dewata at 2024-12-20T22:01:03+07:00
Update pki.server.cli to use argparse
The classes in pki.server.cli have been updated to use argparse
except for PKIServerCLI since it needs to use subparsers which
requires additional investigation.
- - - - -
65ac9ce9 by Marco Fargetta at 2024-12-23T11:02:56+01:00
Add pkispawn EST deployment documentation
- - - - -
dd6ca1a0 by Christina Fu at 2024-12-23T10:29:46-08:00
Create Installing_OCSP.adoc
copied/converted from Installing_OCSP.md
- - - - -
77fe5900 by Christina Fu at 2024-12-23T10:32:24-08:00
Update Installing_OCSP.md
[skip ci]
added the "moved to adoc" message.
- - - - -
5880ed47 by Christina Fu at 2024-12-23T10:33:51-08:00
Update Installing_OCSP.md
[skip ci]
adjusted comment designator
- - - - -
3913093c by Christina Fu at 2024-12-23T10:42:02-08:00
Create Installing_OCSP_Clone.adoc
[skip ci]
asciidoc converted/modified from Installing_OCSP_Clone.md
- - - - -
405b87d6 by Christina Fu at 2024-12-23T10:46:06-08:00
Update Installing_OCSP_Clone.md
[skip ci]
added the "converted/moved to adoc" message
- - - - -
6884e60d by Christina Fu at 2024-12-23T10:53:30-08:00
Create Installing_OCSP_Clone_with_HSM.adoc
[skip ci]
initial copy/convert from Installing_OCSP_Clone_with_HSM.md
- - - - -
cd23a25d by Christina Fu at 2024-12-23T10:55:29-08:00
Update Installing_OCSP_Clone_with_HSM.md
[skip ci]
added the copied/converted to Installing_OCSP_Clone_with_HSM/adoc message
- - - - -
bfed58c3 by Christina Fu at 2024-12-23T10:56:22-08:00
Update Installing_OCSP.md
[skip ci]
added link
- - - - -
957bc1ae by Christina Fu at 2024-12-23T11:00:22-08:00
Create Installing_OCSP_with_Custom_Keys.adoc
[skip ci]
copied/converted from Installing_OCSP_with_Custom_Keys.md
- - - - -
742427fc by Christina Fu at 2024-12-23T11:01:46-08:00
Update Installing_OCSP_with_Custom_Keys.md
[skip ci]
added the copied/converted to asciidoc message.
- - - - -
6ab8feed by Christina Fu at 2024-12-23T11:04:53-08:00
Create Installing_OCSP_with_ECC.adoc
[skip ci]
initial copy/convert from Installing_OCSP_with_ECC.md
- - - - -
d89afaf5 by Christina Fu at 2024-12-23T11:06:39-08:00
Update Installing_OCSP.adoc
[skip ci]
- added Prerequisites
- remove the top comment. It belongs to the commit message.
- - - - -
1bfc84b6 by Christina Fu at 2024-12-23T11:07:30-08:00
Update Installing_OCSP_Clone.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
9f99439b by Christina Fu at 2024-12-23T11:08:03-08:00
Update Installing_OCSP_Clone_with_HSM.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
bdefb010 by Christina Fu at 2024-12-23T11:08:21-08:00
Update Installing_OCSP_with_Custom_Keys.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
bed3ff3a by Christina Fu at 2024-12-23T11:08:50-08:00
Update Installing_CA.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
16eec5a1 by Christina Fu at 2024-12-23T11:09:06-08:00
Update Installing_CA_Clone.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
24073887 by Christina Fu at 2024-12-23T11:09:36-08:00
Update Installing_CA_Clone_with_HSM.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
4091c076 by Christina Fu at 2024-12-23T11:10:13-08:00
Update Installing_CA_Clone_with_Secure_Database_Connection.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
4a0d8ca8 by Christina Fu at 2024-12-23T11:10:33-08:00
Update Installing_CA_with_Custom_CA_Signing_Key.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
ad48e691 by Christina Fu at 2024-12-23T11:10:48-08:00
Update Installing_CA_with_ECC.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
7105ad12 by Christina Fu at 2024-12-23T11:11:02-08:00
Update Installing_CA_with_Existing_Keys_in_HSM.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
75c9c577 by Christina Fu at 2024-12-23T11:11:19-08:00
Update Installing_CA_with_Existing_Keys_in_Internal_Token.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
0914fb31 by Christina Fu at 2024-12-23T11:11:32-08:00
Update Installing_CA_with_External_CA_Signing_Certificate.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
1ce7ddff by Christina Fu at 2024-12-23T11:11:44-08:00
Update Installing_CA_with_HSM.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
88c23136 by Christina Fu at 2024-12-23T11:11:56-08:00
Update Installing_CA_with_Secure_Database_Connection.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
f20b83de by Christina Fu at 2024-12-23T11:12:16-08:00
Update Installing_Subordinate_CA.adoc
[skip ci]
removed top comment. It belongs to the commit message.
- - - - -
47ae95e7 by Christina Fu at 2024-12-23T13:45:07-08:00
Create Installing_OCSP_with_External_Certificates.adoc
[skip ci]
initial copy/convert from Installing_OCSP_with_External_Certificates.md to asciidoc
- - - - -
24155559 by Christina Fu at 2024-12-23T13:47:44-08:00
Update Installing_OCSP_with_External_Certificates.md
[skip ci]
added the copied/converted to asciidoc message
- - - - -
29d9b9ff by Christina Fu at 2024-12-23T13:49:14-08:00
Update Installing_OCSP_with_External_Certificates.md
[skip ci]
fixed missing postfix of file name in link.
- - - - -
a8fb7aa3 by Christina Fu at 2024-12-23T13:52:14-08:00
Create Installing_OCSP_with_HSM.adoc
[skip ci]
initial copy/convert from Installing_OCSP_with_HSM.md to asciidoc
- - - - -
142b3018 by Christina Fu at 2024-12-23T13:55:54-08:00
Update Installing_OCSP_with_HSM.md
[skip ci]
added copied/converted to asciidoc message.
- - - - -
afc63e72 by Christina Fu at 2024-12-23T14:00:14-08:00
Create Installing_OCSP_with_Secure_Database_Connection.adoc
[skip ci]
initial copy/convert from Installing_OCSP_with_Secure_Database_Connection.md to asciidoc
- - - - -
80a0b94e by Christina Fu at 2024-12-23T14:02:04-08:00
Update Installing_OCSP_with_Secure_Database_Connection.md
[skip ci]
added the "converted to ascii" message.
- - - - -
5fbe5e4e by Christina Fu at 2025-01-02T15:05:03-08:00
Update ocsp.cfg
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
d98e42b3 by Christina Fu at 2025-01-02T15:19:39-08:00
Update ocsp-clone.cfg
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
ad1c748c by Christina Fu at 2025-01-02T15:21:29-08:00
Update Installing_OCSP_Clone.adoc
[skip ci]
point reference to Installing_CA.adoc instead of the mid copy
- - - - -
5f179202 by Christina Fu at 2025-01-02T15:22:49-08:00
Update Installing_OCSP_Clone.md
[skip ci]
conversion complete.
- - - - -
68bab8b6 by Christina Fu at 2025-01-02T15:32:06-08:00
Update Installing_OCSP.md
[skip ci]
conversion complete.
- - - - -
652f446e by Christina Fu at 2025-01-02T15:39:30-08:00
Update Installing_OCSP_Clone_with_HSM.adoc
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
8b2b135e by Christina Fu at 2025-01-02T15:44:41-08:00
Update Installing_OCSP_Clone_with_HSM.md
[skip ci]
conversion complete
- - - - -
fd6130a7 by Christina Fu at 2025-01-02T15:59:34-08:00
Update Installing_OCSP_with_Custom_Keys.adoc
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
30d568f8 by Christina Fu at 2025-01-02T15:59:59-08:00
Update Installing_OCSP_with_Custom_Keys.md
[skip ci]
conversion complete.
- - - - -
f95f7b80 by Christina Fu at 2025-01-02T16:05:13-08:00
Update Installing_OCSP_with_ECC.adoc
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
4cbec55d by Christina Fu at 2025-01-02T16:08:17-08:00
Update Installing_OCSP_with_ECC.md
[skip ci]
conversion complete
- - - - -
7fa0186c by Christina Fu at 2025-01-02T16:11:19-08:00
Update ocsp-external-certs-step1.cfg
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
d96ce0d2 by Christina Fu at 2025-01-02T16:22:40-08:00
Update Installing_OCSP_with_External_Certificates.adoc
[skip ci]
fixed sample links.
- - - - -
0a8bc4b9 by Christina Fu at 2025-01-02T16:24:07-08:00
Update ocsp-external-certs-step2.cfg
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
9bba0ad4 by Christina Fu at 2025-01-02T16:26:57-08:00
Update Installing_OCSP_with_Custom_Keys.adoc
[skip ci]
fixed links
- - - - -
1945d239 by Christina Fu at 2025-01-02T16:27:50-08:00
Update Installing_OCSP_with_External_Certificates.md
[skip ci]
conversion complete.
- - - - -
5d5dfe1c by Christina Fu at 2025-01-02T16:56:02-08:00
Update Installing_OCSP_with_HSM.adoc
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
9d6ad3db by Christina Fu at 2025-01-02T16:56:37-08:00
Update Installing_OCSP_with_HSM.md
[skip ci]
conversion complete
- - - - -
fbd00415 by Christina Fu at 2025-01-02T17:00:13-08:00
Update Installing_OCSP_with_Secure_Database_Connection.adoc
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
also fixed a link.
- - - - -
3da8843b by Christina Fu at 2025-01-02T17:00:40-08:00
Update Installing_OCSP_with_Secure_Database_Connection.md
[skip ci]
conversion complete
- - - - -
173b37eb by Christina Fu at 2025-01-02T17:03:33-08:00
Update Installing_Standalone_OCSP.adoc
[skip ci]
changed regular OCSP installation link to the adoc copy.
- - - - -
5a2f40bc by Christina Fu at 2025-01-02T17:04:37-08:00
Update ocsp-standalone-step1.cfg
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
cd7e0904 by Christina Fu at 2025-01-02T17:05:33-08:00
Update ocsp-standalone-step2.cfg
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
4f11eaf9 by Christina Fu at 2025-01-03T10:11:20-08:00
Update Installing_OCSP_Clone_with_HSM.adoc
[skip ci]
added Prerequisites
- - - - -
355216a5 by Christina Fu at 2025-01-03T10:12:28-08:00
Update Installing_OCSP_with_Custom_Keys.adoc
[skip ci]
added Prerequisites
- - - - -
02f0b29e by Christina Fu at 2025-01-03T10:13:27-08:00
Update Installing_OCSP_with_ECC.adoc
[skip ci]
added Prerequisites
- - - - -
d48a55d2 by Christina Fu at 2025-01-03T10:14:11-08:00
Update Installing_OCSP_with_External_Certificates.adoc
[skip ci]
added Prerequisites
- - - - -
b07ef9f6 by Christina Fu at 2025-01-03T10:15:33-08:00
Update Installing_OCSP_with_HSM.adoc
[skip ci]
added Prerequisites
- - - - -
d00c75e2 by Christina Fu at 2025-01-03T10:18:43-08:00
Update Installing_OCSP_with_Secure_Database_Connection.adoc
[skip ci]
added Prerequisites
- - - - -
7b37f6a4 by Christina Fu at 2025-01-03T10:22:21-08:00
Update Creating_DS_instance.adoc
[skip ci]
replace DS ssl link with https://github.com/dogtagpki/389-ds-base/wiki/Configuring-SSL-Connection
- - - - -
771bfb56 by Christina Fu at 2025-01-03T14:09:12-08:00
Update Creating_DS_instance.adoc
[skip ci]
fixed link
- - - - -
cd481c99 by Christina Fu at 2025-01-03T14:12:38-08:00
Update Installing_DS_Packages.adoc
[skip ci]
fixed link
- - - - -
54e752d9 by Christina Fu at 2025-01-03T14:18:02-08:00
Create PKI-LDAP-Tree.adoc
[skip ci]
copied from https://github.com/dogtagpki/pki/wiki/PKI-LDAP-Tree
- - - - -
e8eb5136 by Christina Fu at 2025-01-03T14:22:16-08:00
Update Creating_DS_instance.adoc
[skip ci]
fixed links
- - - - -
f9b63735 by Christina Fu at 2025-01-03T14:25:51-08:00
Update Installing_OCSP_with_Secure_Database_Connection.adoc
[skip ci]
grouped DS secure setup with DS instance setup under Prerequisites.
- - - - -
98d66c6f by Christina Fu at 2025-01-03T15:14:16-08:00
Update Installing_CA_Clone.adoc
[skip ci]
added missing subject.
- - - - -
c9f2bf25 by Christina Fu at 2025-01-03T15:15:08-08:00
Update Installing_CA_Clone.md
[skip ci]
conversion complete
- - - - -
38eb592f by Christina Fu at 2025-01-03T15:20:18-08:00
Update Installing_CA_Clone_with_HSM.adoc
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
984afc7e by Christina Fu at 2025-01-03T15:22:24-08:00
Update Installing_CA_Clone_with_HSM.md
[skip ci]
conversion complete.
- - - - -
624812b0 by Christina Fu at 2025-01-03T16:13:29-08:00
Update ca-secure-ds-secondary.cfg
[skip ci]
Adding the more common customizable parameters (with default values) readily available for users to modify: instance name, port numbers, and ds ports.
- - - - -
ccc75041 by Christina Fu at 2025-01-03T16:16:48-08:00
Update Installing_CA_Clone_with_Secure_Database_Connection.adoc
[skip ci]
added clarification.
- - - - -
7d996d23 by Christina Fu at 2025-01-03T17:26:11-08:00
Update Installing_CA_with_Custom_CA_Signing_Key.md
[skip ci]
conversion complete
- - - - -
3a938eeb by Christina Fu at 2025-01-03T17:28:06-08:00
Update Installing_CA_with_ECC.md
[skip ci]
conversion complete.
- - - - -
f1b422c6 by Christina Fu at 2025-01-03T17:29:46-08:00
Update Installing_CA_with_Existing_Keys_in_HSM.md
[skip ci]
conversion complete
- - - - -
64b8f2c4 by Christina Fu at 2025-01-06T16:16:15-08:00
Update Installing_CA_with_Existing_Keys_in_Internal_Token.adoc
[skip ci]
fixed bullets
- - - - -
06222b57 by Christina Fu at 2025-01-06T16:20:05-08:00
Update Installing_CA_with_External_CA_Signing_Certificate.adoc
[skip ci]
added missing subject
- - - - -
d7d6f148 by Christina Fu at 2025-01-06T16:20:52-08:00
Update Installing_CA_with_External_CA_Signing_Certificate.md
[skip ci]
conversion complete
- - - - -
eefde773 by Christina Fu at 2025-01-06T16:22:11-08:00
Update Installing_CA_with_HSM.adoc
[skip ci]
fixed bullets.
- - - - -
aabe2075 by Christina Fu at 2025-01-06T16:22:39-08:00
Update Installing_CA_with_HSM.md
[skip ci]
conversion complete
- - - - -
e3615ff1 by Christina Fu at 2025-01-06T16:27:59-08:00
Update Installing_Subordinate_CA.md
[skip ci]
conversion complete
- - - - -
c0cd231d by Marco Fargetta at 2025-01-07T10:41:42+01:00
Fix mail notification CI
The notification was not working because of a CVE in postfix required to
modify the default policy becoming more restrictive.
The fix is documented here: https://bugzilla.redhat.com/show_bug.cgi?id=2255563
This is a workaround which put back the original policy. The proper fix
would be to update the code communicating with smtp server.
- - - - -
21871b72 by Marco Fargetta at 2025-01-07T19:15:00+01:00
Update changes for pkispawn/pkidestroy
- - - - -
6332bf07 by Christina Fu at 2025-01-08T16:01:40-08:00
Update PKI-NSS-CLI.adoc
[skip ci]
added missing subject
- - - - -
385bdfff by Christina Fu at 2025-01-08T16:02:58-08:00
Update PKI-LDAP-Tree.adoc
[skip ci]
added missing subject
- - - - -
84ea2ca8 by Christina Fu at 2025-01-08T16:04:30-08:00
Update Exporting-DS-Certificates.adoc
[skip ci]
added missing subject
- - - - -
05831d86 by Christina Fu at 2025-01-08T16:06:15-08:00
Update Enabling-SSL-Connection-in-DS.adoc
[skip ci]
added missing subject
- - - - -
7441a73a by Christina Fu at 2025-01-08T16:22:38-08:00
Create Generating-Certificate-Request.adoc
[skip ci]
original content copied from https://github.com/dogtagpki/pki/wiki/Generating-Certificate-Request
- - - - -
26ce07be by Christina Fu at 2025-01-08T16:33:43-08:00
Create Certificate-Profiles.adoc
[skip ci]
content copied from https://github.com/dogtagpki/pki/wiki/Certificate-Profiles
- - - - -
ffcc46a3 by Christina Fu at 2025-01-08T16:37:44-08:00
Create Certificate-Profiles.adoc
[skip ci]
moved from https://github.com/dogtagpki/pki/new/master/docs/design
- - - - -
9794ce58 by Christina Fu at 2025-01-08T16:40:24-08:00
Update Certificate-Profiles.adoc
[skip ci]
moved under Cert_Enrollment_Profiles
- - - - -
ea447235 by Christina Fu at 2025-01-08T16:45:11-08:00
Create Bootstrap-Profiles.adoc
[skip ci]
content copied from https://github.com/dogtagpki/pki/wiki/Bootstrap-Profiles
- - - - -
34e85202 by Christina Fu at 2025-01-08T16:48:40-08:00
Create CA-Certificate-Profiles.adoc
[skip ci]
content copied from https://github.com/dogtagpki/pki/wiki/CA-Certificate-Profiles
- - - - -
c190a6d4 by Christina Fu at 2025-01-08T16:53:29-08:00
Update CA-Certificate-Profiles.adoc
[skip ci]
updated one link that's been moved over. More to come
- - - - -
9bab02e3 by Christina Fu at 2025-01-09T10:39:17-08:00
moved Certificate-Profiles.adoc under docs/design/Cert_Enrollment_Profiles
moved docs/installation/others/CSR/Generating-Certificate-Request.adoc to
docs/user/tools/Generating-CSR/Generating-Certificate-Request.adoc
Coming up: more effort to move relevant wiki pages over to the repo.
- - - - -
2c50a209 by Christina Fu at 2025-01-09T14:32:11-08:00
[skip ci]
copied PKI-NSS-* from https://github.com/dogtagpki/pki/wiki/ to
docs/user/tools/
- - - - -
ea07d20b by Christina Fu at 2025-01-09T15:32:07-08:00
[skip ci]
copied Generating-Certificate-Request* and related docs from
https://github.com/dogtagpki/pki/wiki/ to
pki/docs/user/tools and pki/docs/user/tools/Generating-CSR
- - - - -
93b95181 by Christina Fu at 2025-01-09T15:53:39-08:00
[skip ci]
copied over PKI-Client-CLI and Submitting-Certificate-Request-with-Key-Archival
More adjustments are still needed.
- - - - -
53d9c84c by Christina Fu at 2025-01-09T16:05:14-08:00
[skip ci]
copied more files from https://github.com/dogtagpki/pki/wiki/
and fixed link.
- - - - -
25eeb6bc by Christina Fu at 2025-01-09T16:07:37-08:00
[skip ci]
fixed links
- - - - -
aa3ba8da by Marco Fargetta at 2025-01-14T11:49:42+01:00
Fix logrotate error
If the log rotate is invoked following a log using slf4j-impl the current
policy denied the accees to the log folder and the rotate fails.
This is always the case with the change to the SessionTimer class.
To solve the problem the policy is updated to grant slf4j-impl
read/write access to log folders.
- - - - -
2817b436 by Marco Fargetta at 2025-01-14T18:52:22+01:00
Fix est doc formatting
- - - - -
919db96b by Endi S. Dewata at 2025-01-15T09:34:49-06:00
Temporary workaround for Podman issue on Ubuntu 24
To avoid a known issue in Podman on Ubuntu 24 the non-rootless
container tests have been modified to update the graph driver in
the SQLite backend manually. However, this method does not work
for the rootless container test so it has has been hard-coded to
use Ubuntu 22 for now.
https://github.com/containers/podman/issues/21683
- - - - -
7204ae0f by Marco Fargetta at 2025-01-15T17:44:51+01:00
Replace libselinux restorecon API with CLI
The restorecon API in libselinux has a problem fixing the context if it
is update from the same script.
The bug is present in several RHEL releases and it is documented here:
https://issues.redhat.com/browse/RHEL-73348
Following the advice in the issue, the API call has been temporarily replaced
with the equivalent CLI.
- - - - -
12b34284 by Christina Fu at 2025-01-15T15:52:53-08:00
cfu testing out the wiki pages ported over to the repo.
- - - - -
6a24bd5c by Christina Fu at 2025-01-15T15:52:53-08:00
[skip ci]
pki/docs/installation/kra
phase 1 md->adoc conversion:
- title format
- add blank line above bullets
- use Prerequisites links instead
existing links will be fixed in follow-up commit
- - - - -
daa0e2e3 by Christina Fu at 2025-01-15T15:52:53-08:00
[skip ci]
pki/docs/installation/pki
phase 2 md->adoc conversion
- replaced Markdown-style links with Asciidoc-style links
- - - - -
9a19e179 by Christina Fu at 2025-01-15T16:33:31-08:00
[skip ci]
pki/docs/installation/tks
phase 1
- title format
- add blank line above bullets
- use Prerequisites links instead
existing links will be fixed in follow-up commit
- - - - -
9ac397d1 by Christina Fu at 2025-01-15T16:36:18-08:00
[skip ci]
pki/docs/installation/tks
phase 2 md->adoc conversion
- replaced Markdown-style links with Asciidoc-style links
- - - - -
b251e7c1 by Christina Fu at 2025-01-15T16:49:59-08:00
[skip ci]
pki/docs/installation/tps
- title format
- add blank line above bullets
- use Prerequisites links instead
- replaced Markdown-style links with Asciidoc-style links
- - - - -
ccedb20b by Christina Fu at 2025-01-15T16:57:50-08:00
[skip ci]
fixed top subject level on 3 adoc files under pki/docs/installation/kra
- - - - -
f390245e by Adam Williamson at 2025-01-17T10:14:38+01:00
Make sbin install dir configurable
We need it now we're doing sbin merge in Fedora.
Signed-off-by: Adam Williamson <awilliam at redhat.com>
- - - - -
53704202 by Christina Fu at 2025-01-17T09:46:10-08:00
docs/installation/ca replaced "moved to" messages
- - - - -
48823cef by Christina Fu at 2025-01-17T09:51:55-08:00
docs/installation/[ocsp,kra.tks.tps]
replaced .md files with "Converted/moved to" message
- - - - -
28b5bd02 by Christina Fu at 2025-01-17T10:19:12-08:00
[skip ci]
docs/installation/server cleanup
- - - - -
10312f5c by Christina Fu at 2025-01-17T10:38:53-08:00
[skip ci]
docs/installation/server md -> adoc conversion
- - - - -
bda45812 by Endi S. Dewata at 2025-01-17T20:47:29-05:00
Update CLI.execute()
The CLI.execute() has been updated to optionally take an object
that stores the arguments parsed by ArgumentParser. If the object
is provided, the code will not call parse_args().
- - - - -
424fb542 by Endi S. Dewata at 2025-01-17T20:48:08-05:00
Add CLI.create_parser()
The CLI code that creates ArgumentParser has been moved into
create_parser().
- - - - -
b4f48681 by Endi S. Dewata at 2025-01-17T20:48:09-05:00
Use CLI.get_full_name()
The CLI.create_parser() has been modified to create the
ArgumentParser with the module's full name.
- - - - -
7c6c7763 by Marco Fargetta at 2025-01-20T10:59:30+01:00
Updating version to v11.6.0-alpha3
- - - - -
07ddd037 by Christina Fu at 2025-01-20T08:59:02-08:00
[skip ci]
pki/docs/installation
removed .md files that had been moved away a long time ago.
- - - - -
bb22542e by Endi S. Dewata at 2025-01-21T11:33:03-05:00
Update pki-server to use ArgumentParser
The PKIServerCLI has been modified to create a main parser
using ArgumentParser then create a subparser for each sub-
command.
The CLI.create_parser() has been modified to take an optional
subparsers object and pass it down to the modules.
The PKICLI, PasswordGenerateCLI, and PKCS12ImportCLI will be
updated separately later.
- - - - -
0c5c7e4d by Endi S. Dewata at 2025-01-22T08:55:46-06:00
Update pki CLI to use ArgumentParser
The pki CLI has been updated to parse the main arguments (which
are also defined in MainCLI.java) using ArgumentParser, determine
the subcommand, then pass the remaining arguments to the Python
or Java module corresponding to the subcommand.
It does not use subparsers like in pki-server since the pki CLI
does not have the list of Java subcommands.
The pki CLI have options that might conflict with other options
in some subcommands. That will be addressed separately later.
The help message for default message format in MainCLI.java has
also been updated.
- - - - -
7c7dd125 by Endi S. Dewata at 2025-01-22T09:17:54-06:00
Update Python lint test
The pki-lint script has been split into python-lint.py and
python-flake8.py such that they can run independently. This
way a failure in one test will not prevent the other test
from running.
- - - - -
c0ceb9b0 by Endi S. Dewata at 2025-01-22T09:17:54-06:00
Fix Python flake8 issues
- - - - -
bdcd55aa by Endi S. Dewata at 2025-01-22T10:11:22-06:00
Fix typo in CertFixCLI
Resolves: https://github.com/dogtagpki/pki/issues/4917
- - - - -
1dac2b87 by Endi S. Dewata at 2025-01-22T11:26:17-06:00
Fix build failure on Fedora Rawhide
See also commit f390245e092f66467c34f99eb8517eed85885f60.
- - - - -
6005cc0c by Marco Fargetta at 2025-01-22T18:48:44+01:00
Add doc for TLS mutual auth in EST
[skip ci]
- - - - -
ba785b6c by Marco Fargetta at 2025-01-22T18:48:44+01:00
Split EST doc between installation and admin
[skip ci]
- - - - -
400f412e by jmagne at 2025-01-23T15:38:54+01:00
Fix: RHEL-45539 (#4795)
CA Clone Installation is failing with 'Error verifying PKCS12 MAC; no PKCS12KDF support.' in FIPS mode.
This very simple fix only does the following.
The process fails when trying to export a cert out of the pkcs12 file into a pem file.
Currently the cmd fails becuase fips doesn't like the mac verfication alg.
Here, since we've already imported the p12 files into the nss db, using other cmds, it should be safe to do
this operation without asking openssl to do the mac verify.
Change-Id: I134c01ca4f15ef9093e9ff5aaa6c9c1bb820d9ac
- - - - -
930248a7 by Christina Fu at 2025-01-23T10:23:16-08:00
[skip ci]
- updated pki/docs/acme/ to rely on Installing_DS_Packages.adoc and Creating_DS_instance.adoc in pki/docs/others instead of pki.wiki's DS-Installation.asciidoc.
- Deploying-DS-Container is not included in Creating_DS_instance.adoc. Will add later
- removed version-specific link reference to DS-1.3-Installation in Creating_DS_instance.adoc
- - - - -
58bd7fc8 by Endi S. Dewata at 2025-01-23T13:01:49-06:00
Update IPA tests to check CA database config
- - - - -
6dfe36ac by Endi S. Dewata at 2025-01-23T13:32:46-06:00
Update cert renewal doc
The IPA-specific content in Offline System Certificate Renewal
has been moved into a separate page:
https://github.com/dogtagpki/freeipa/wiki/Renewing-System-Certificates
- - - - -
f833be0f by Endi S. Dewata at 2025-01-23T14:19:35-06:00
Clean up cert renewal doc [skip ci]
- - - - -
2f8e9573 by Endi S. Dewata at 2025-01-23T15:38:22-06:00
Fix pki-server nss-create --password-file
- - - - -
550b2c12 by Endi S. Dewata at 2025-01-24T10:37:04-06:00
Add pki-server password-set/unset
The pki-server password-set/unset have been added to replace
pki-server password-add/del for managing the passwords in
password.conf.
The pki-server password-add will only work if the password
does not exist already, whereas the pki-server password-set
will overwrite the existing password.
The pki-server password-set will also support reading the
password from file and from console.
- - - - -
3770a7f4 by Endi S. Dewata at 2025-01-24T12:45:02-06:00
Clean up log messages in pki CLI
- - - - -
62a382e2 by Endi S. Dewata at 2025-01-24T12:45:37-06:00
Clean up log messages in pki-server cert-fix
- - - - -
0a9fd5d4 by Endi S. Dewata at 2025-01-27T09:18:13-06:00
Fix pki-server cert-fix
The pki-server cert-fix has been updated to skip ACME and EST
subsystems since they don't have CS.cfg and are not needed to
renew expired system certificates.
The --cert and --extra-cert options have also been updated to
accept multiple values which are required by ipa-cert-fix.
A new --dm-password option has been added for specifying the
Directory Manager password to simplify testing.
See also:
* https://github.com/dogtagpki/pki/blob/master/docs/admin/Offline_System_Certificate_Renewal.md
* https://github.com/dogtagpki/freeipa/wiki/Renewing-System-Certificates
Resolves: https://github.com/dogtagpki/pki/issues/4873
- - - - -
c4a889b4 by Endi S. Dewata at 2025-01-27T09:18:13-06:00
Add IPA renewal test
A new test has been added to install IPA with short-lived system
certs then renew the certs using ipa-cert-fix which internally
calls pki-server cert-fix.
- - - - -
4ba57a0b by Endi S. Dewata at 2025-01-27T09:22:03-06:00
Add tests for CA admin cert
Some tests have been updated to check the ca_admin.cert.
Apparently IPA is creating the file with an invalid format.
https://pagure.io/freeipa/issue/9735
- - - - -
cb70541e by Endi S. Dewata at 2025-01-27T09:35:48-06:00
Update test for CA with existing config
The test for CA with existing config has been updated to verify
that the CA can be installed and re-installed with a non-default
instance name.
- - - - -
c85a3ce5 by Marco Fargetta at 2025-01-28T15:02:16+01:00
Fix request range creation bug for ssnv2
In some condition a new request range was created at every range update
task. The error was generated by a wrong method name which was creating
error in reading the existing next range
- - - - -
9ccccb90 by Endi S. Dewata at 2025-01-28T08:30:35-06:00
Fix pki-server instance-find
The pki-server instance-find has been updated to find instances
existing on the system based on PKIServer.exists().
The PKIServer.exists() has also been updated to check whether the
instance actually exists based on the <instance>/bin folder. It
does not use the <instance> folder itself since there might be
files (e.g. config files, logs) left in the folder after removing
the instance.
The test for installing CA with existing config has been updated
to validate pki-server instance-* commands.
- - - - -
a0c6cdbe by Endi S. Dewata at 2025-01-28T09:07:53-06:00
Update pkiconsole script
The pkiconsole script has been updated to use the JVM specified
in JAVA_HOME so it will be more consistent with other PKI tools
(e.g. pki, pki-server, pkispawn).
- - - - -
25cb21a6 by Endi S. Dewata at 2025-01-28T09:13:30-06:00
Fix pki-server subsystem-cert-find
The PKISubsystem.get_cert_infos() has been updated to return
a list instead of a generator object such that the number of
entries can be counted using len().
The pki-server subsystem-cert-find/show commands have been
deprecated since some of the certs returned by these commands
are shared with other subsystems (e.g. sslserver, subsystem)
which could cause some confusions. It's recommended to use
pki-server cert-find/show instead.
The test for basic OCSP installation has been updated to
check the above commands.
- - - - -
ca443ec7 by Endi S. Dewata at 2025-01-28T13:56:30-06:00
Fix serial handling in PKIServer.renew_certificate()
Resolves: https://github.com/dogtagpki/pki/issues/4873
- - - - -
080cc976 by Marco Fargetta at 2025-01-29T10:01:51+01:00
Fix error message for exhausted range
The exception message was reporting wrong numbers for requests because
there was a non correct hex conversion. Additionally, it was reporting the
wrong value because it was increasing even no new requests could be
generated.
Fix BZ#2332610
- - - - -
9f2ef0b3 by Endi S. Dewata at 2025-01-29T19:47:33-06:00
Refactor PKIInstance.read_external_certs()
The PKIInstance.read_external_certs() has been renamed into
load_external_certs_conf() for clarity. The load_external_certs()
has been modified to load external certs from standard location.
- - - - -
4c329e32 by Endi S. Dewata at 2025-01-29T19:47:33-06:00
Refactor PKIInstance.save_external_cert_data()
The PKIInstance.save_external_cert_data() has been renamed into
store_external_certs_conf() for clarity. The store_external_certs()
has been added to store external certs into the standard location.
- - - - -
3b86f3dd by Endi S. Dewata at 2025-01-29T19:47:33-06:00
Refactor PKIInstance.add_external_cert() and delete_external_cert()
The PKIInstance.add_external_cert() and delete_external_cert()
have been updated such that the store_external_certs() will be
invoked by the caller to avoid repetitive invocations.
- - - - -
3f3eedb5 by Endi S. Dewata at 2025-01-29T23:00:26-06:00
Clean up log messages in pki-server instance-externalcert-add/del
- - - - -
90701b94 by Endi S. Dewata at 2025-01-29T23:00:26-06:00
Clean up log messages in pki pkcs12-import
- - - - -
917a4c4e by Marco Fargetta at 2025-01-30T10:58:04+01:00
Fix SSNv2 clone workflows
- - - - -
c12dd264 by Marco Fargetta at 2025-01-31T11:48:36+01:00
Fix SSNv2 CA workflows
- - - - -
fb5c4273 by Endi S. Dewata at 2025-01-31T09:20:03-06:00
Fix pki_server_external_certs_path
Previously if the pki_server_pkcs12_path was not specified
the external certs specified in pki_server_external_certs_path
would not be imported either. This is incorrect since these
parameters are unrelated.
To address the issue the code that imports the external certs
in PKIDeployer.import_server_pkcs12() has been moved into
import_external_certs() which will always be invoked during
installation. The update_external_certs_conf() has been merged
into this method as well.
The PKIInstance.load_external_certs() has been modified to add
the external cert using add_external_cert() to avoid creating
duplicate entries in the external_certs.conf.
The PKIInstance.store_external_certs() has been modified to
remove the external_certs.conf if it's empty.
In the future the pki_server_external_certs_path param and the
pki-server instance-externalcert-* commands might be deprecated
and eventually removed since there are other ways to deal with
external certs without having to maintain external_certs.conf.
- - - - -
0a88a9be by Endi S. Dewata at 2025-01-31T09:20:03-06:00
Add test for pki-server instance-externalcert-add/del
The test for CA cloning with LDAPS connection has been updated
to create a CA, add an external cert, clone the CA, remove and
reinstall the clone, then remove the external cert.
- - - - -
5a472223 by Endi S. Dewata at 2025-02-04T08:05:41-06:00
Fix CLI help messages
Previously if a user called pki-server CLI with a wrong
sub-command the ArgumentParser would show an auto-generated
error message which looks significantly different from the
help message already defined in print_help().
To fix the issue the PKIServerCLI.create_parser() and
execute() have been modified to use remainder instead of
subparsers, and the create_parser() in the sub-commands has
been modified to create a regular ArgumentParser instead of
a subparser.
Similar changes were made to the CLI base class to fix the
help messages for sub-commands (e.g. pki-server ca).
The pki-server has also been modified to provide a --version
option to show the version number of the tool.
A new CLIException has been added to distinguish a normal
CLI error (which will generate a simple error message such
as "Invalid module") from an unexpected exception which will
generate a full stack trace.
Resolves: https://github.com/dogtagpki/pki/issues/4932
- - - - -
4719da0b by Endi S. Dewata at 2025-02-04T08:05:41-06:00
Add tests for CLI help and error messages
Some tests have been added to check the help and error messages
generated by pki and pki-server CLIs.
- - - - -
5bc99570 by Endi S. Dewata at 2025-02-04T10:17:46-06:00
Clean up PKIDeployer.setup_admin_cert()
The PKIDeployer.setup_admin_cert() has been reorganized to
clarify the process of setting up an admin cert.
- - - - -
d1c5850b by Endi S. Dewata at 2025-02-04T18:58:48-06:00
Update pki.nssdb.convert_data()
The pki.nssdb.convert_data() has been updated to normalize
the input and output formats.
- - - - -
d7540acb by Endi S. Dewata at 2025-02-04T20:07:40-06:00
Update PKIDeployer.init_client_nssdb()
The PKIDeployer.init_client_nssdb() has been updated to allow
pre-existing ~/.dogtag/<instance>/<subsytem> folder.
- - - - -
e4cfd4c6 by Endi S. Dewata at 2025-02-04T20:11:59-06:00
Add pki pkcs12-cert-export --cert-format
The pki pkcs12-cert-export has also been updated to provide an
option to specify the cert format.
- - - - -
57387d87 by Endi S. Dewata at 2025-02-04T20:40:54-06:00
Add PKCS12.get_cert()
The PKCS12.get_cert() has been added to export a cert from a
PKCS #12 file using pki pkcs12-cert-export.
- - - - -
cd0daf61 by Endi S. Dewata at 2025-02-05T14:02:26-06:00
Update pkispawn to verify admin cert
The pki nss-cert-verify has been added to verify that a cert
is issued by a trusted CA. The cert can be provided in an NSS
database, in a file, or via standard input.
The PKITrustManager class has been moved into pki-common.jar
such that it can be used by the CLI. This class is not yet
officially supported so it's not necessary to provide an
upgrade script.
The NSSDatabase.verify_cert() has been added to verify a cert
using pki nss-cert-verify.
The PKIDeployer.import_system_certs() and setup_admin_cert()
have been modified to verify the admin cert provided during
installation.
The test for installing CA with existing certs has been updated
to install the CA with a self-signed admin cert (which should
fail), then install it again with a CA-signed cert (which should
work).
- - - - -
f1f894af by Endi S. Dewata at 2025-02-05T14:02:48-06:00
Fix missing sys.exit() in pki-server
- - - - -
61a469da by Endi S. Dewata at 2025-02-06T08:58:32-06:00
Rebuild search indexes during cloning
Since 389 DS 3.0 the search indexes need to be rebuilt
on the clone
Resolves: https://issues.redhat.com/browse/RHEL-63015
- - - - -
8fc88c56 by Endi S. Dewata at 2025-02-06T09:02:52-06:00
Add test for installing CA with obsolete admin cert
The test for installing CA with existing config has been updated
to reinstall the CA with new system certs but with an old admin
cert from the previous installation (which should fail). Then the
test will remove the admin cert and reinstall the CA again (which
should succeed) and a new admin cert should be created.
pkispawn was updated to indicate that the installation failure
might be caused by an obsolete admin cert.
- - - - -
fd518392 by Endi S. Dewata at 2025-02-06T21:06:47-06:00
Move CRMFPopClient.getKeyWrapAlgotihm() to CAInfoClient
- - - - -
fd4ee777 by Endi S. Dewata at 2025-02-06T21:07:17-06:00
Move CRMFPopClient.isEncoded() to CryptoUtil
- - - - -
9ec1dccd by Endi S. Dewata at 2025-02-06T21:07:17-06:00
Move CRMFPopClient.createAVA() to CryptoUtil
- - - - -
fb815b70 by Endi S. Dewata at 2025-02-06T21:07:17-06:00
Move CRMFPopClient.createName() to CryptoUtil
- - - - -
5f87e1fe by Endi S. Dewata at 2025-02-06T21:07:17-06:00
Move CRMFPopClient.getWrappingParams() to CryptoUtil
- - - - -
2efc5611 by Endi S. Dewata at 2025-02-06T21:07:17-06:00
Move CRMFPopClient.createCRMFRequest() to CryptoUtil
- - - - -
c73a1230 by Endi S. Dewata at 2025-02-06T21:07:17-06:00
Move CRMFPopClient.createPop() to CryptoUtil
- - - - -
f011ccf0 by Endi S. Dewata at 2025-02-06T21:07:17-06:00
Move CRMFPopClient.createSigner() to CryptoUtil
- - - - -
ef49dcf1 by Endi S. Dewata at 2025-02-06T21:07:17-06:00
Move CRMFPopClient.createCertTemplate() to CryptoUtil
- - - - -
2b0484d9 by Endi S. Dewata at 2025-02-06T21:07:17-06:00
Move CRMFPopClient.createCertRequest() to CryptoUtil
- - - - -
4248adaf by Endi S. Dewata at 2025-02-07T08:54:34-06:00
Update ACME tests to create DS indexes
The ACME tests have been updated to create DS indexes as
described in the docs.
The tests have also been updated to no longer upload test
artifacts to save space and reduce execution time.
The runner-init.sh has been updated to support multiple
network aliases.
https://github.com/dogtagpki/pki/wiki/Installing-ACME-Responder-using-pkispawn
https://github.com/dogtagpki/pki/wiki/Installing-ACME-Responder-using-PKI-Server-ACME-CLI
- - - - -
6e89b628 by Endi S. Dewata at 2025-02-07T15:40:54-06:00
Consolidate CryptoUtil.createCertificationRequest()
- - - - -
591ccca5 by Endi S. Dewata at 2025-02-07T17:07:58-06:00
Refactory CryptoUtil.createSigner()
The CryptoUtil.createSigner() has been modified to take a
SignatureAlgorithm object.
- - - - -
465671f6 by Endi S. Dewata at 2025-02-07T17:07:58-06:00
Refactory CryptoUtil.createPop()
The CryptoUtil.createPop() has been modified to take a
SignatureAlgorithm object.
- - - - -
e86084a3 by Endi S. Dewata at 2025-02-07T17:09:49-06:00
Refactor ClientCertRequestCLI.generatePkcs10Request()
The ClientCertRequestCLI.generatePkcs10Request() has been
modified to create a PKCS #10 request directly instead of
calling PKCS10Client.
- - - - -
8eee35af by Endi S. Dewata at 2025-02-07T17:10:09-06:00
Refactor ClientCertRequestCLI.generateCrmfRequest()
The ClientCertRequestCLI.generateCrmfRequest() has been
modified to take a key pair generated using generateRSAKeyPair()
or generateECCKeyPair().
- - - - -
b431e985 by Marco Fargetta at 2025-02-10T10:58:19+01:00
Move realm DB set up for EST in a separate file
Additionally, realm configurations have been splitted in different
folders.
- - - - -
6f9a9f0a by Marco Fargetta at 2025-02-10T10:58:19+01:00
Update EST doc to separte RELM config from user management
- - - - -
f3ce5123 by Marco Fargetta at 2025-02-10T10:58:19+01:00
Update EST doc and CI to create group during installation
- - - - -
25a7e7a4 by Marco Fargetta at 2025-02-10T10:58:19+01:00
Rename default est group from estclient to EST Users
Additionally, update docs reference.
- - - - -
4c5d7683 by Marco Fargetta at 2025-02-10T21:46:16+01:00
Move ServerSide pkcs12 key derivation to enrollment
Key derivation from pkcs12 password was implemented during the default
population operation and then the password was deleted. To implement a
new constraint for the password this operation has to move to a later
step so no computation is wasted in case the password do not satisfy its
constraints.
- - - - -
fc70cfc0 by Marco Fargetta at 2025-02-10T21:46:16+01:00
A new policy constraint to enforce p12 password quality.
The new *p12ExportPasswordConstraintImpl* constraint allows to check:
* `password.minSize` - the minimum size for the password;
* `password.minUpperLetter` - the minimum number of capital letters;
* `password.minLowerLetter` - the minimum number of lower letters;
* `password.minNumber` - the minimum number of digits;
* `password.minSpecialChar` - the minimum number of punctuation characters;
* `password.seqLength` - the size of substring sequence which cannot be repeated;
* `password.maxRepeatedChar` - maximum number of repeating for each character;
* `password.cracklibCheck` - a boolean to request an additional check with *cracklib* (it has to be installed if not present).
The same option can be configured in the CS.cfg replacing `password.*`
with `passwordChecker.*`. The configuration in CS.cfg is used for all
the passwords but the profile can overwrite to have stronger or weaker
configuration.
- - - - -
72aaadfa by Marco Fargetta at 2025-02-10T21:46:16+01:00
Update script for plicy password contraint
The update add the policy password contraint to the registry but it does
not modify the current profiles policies.
- - - - -
eddc5301 by Marco Fargetta at 2025-02-10T21:46:16+01:00
Add test for CA password policy enforcement
- - - - -
11c92a86 by Marco Fargetta at 2025-02-10T21:55:58+01:00
Fix password check documentation
- - - - -
7a3fa494 by Christina Fu at 2025-02-10T16:18:56-08:00
[skip ci]
For doc convergence:
commenting out links that could lead to requirement of too many files imported
- - - - -
9fbbdb5f by Christina Fu at 2025-02-10T18:25:30-08:00
[skip ci]
Moved the generic Prerequisites into others/Installation_Prerequisites.adoc
and replace all Prerequisites section.
- - - - -
38ac6fc5 by Endi S. Dewata at 2025-02-10T20:28:06-06:00
Refactor ClientCertRequestCLI (part 1)
The generateRSAKeyPair() and generateECCKeyPair() in
ClientCertRequestCLI have been moved into NSSDatabase.
- - - - -
70d86d39 by Endi S. Dewata at 2025-02-10T20:28:06-06:00
Refactor ClientCertRequestCLI (part 2)
The ClientCertRequestCLI.createCRMFRequest() has been moved
into NSSDatabase.
- - - - -
4fd502e5 by Endi S. Dewata at 2025-02-10T20:28:06-06:00
Refactor ClientCertRequestCLI (part 3)
The ClientCertRequestCLI.createPKCS10Request() has been moved
into NSSDatabase.
- - - - -
9f361e72 by Endi S. Dewata at 2025-02-10T20:28:06-06:00
Refactor NSSCertRequestCLI
The code in NSSCertRequestCLI that constructs key usages has
been moved into NSSDatabase.
- - - - -
ce175d3a by Endi S. Dewata at 2025-02-11T11:45:42-06:00
Add test for PKCS10Client
A new test has been added to generate cert requests with RSA
and EC keys using PKCS10Client.
- - - - -
28cdc45b by Endi S. Dewata at 2025-02-11T19:35:21-06:00
Replace deprecated params in examples
The sample config files have been updated to use pki_ds_url
instead of pki_ds_ldap_port and pki_ds_ldaps_port since those
params have been deprecated since PKI 11.5 and will generate
deprecation warnings if used.
- - - - -
a0704b7e by Endi S. Dewata at 2025-02-11T19:36:55-06:00
Refactor PKCS10Client (part 1)
The PKCS10Client has been updated to create the key pair
using NSSDatabase.
- - - - -
cd202510 by Endi S. Dewata at 2025-02-11T19:36:55-06:00
Refactor PKCS10Client (part 2)
The PKCS10Client has been modified to create the PKCS #10
request using NSSDatabase.
- - - - -
c79d242d by Endi S. Dewata at 2025-02-12T15:01:26-06:00
Update version number to 11.6.0
- - - - -
6f36bf93 by Christina Fu at 2025-02-12T16:48:11-08:00
[skip ci]
adopted content from 6.3. Setting the FQDN of [RHCS 10cc] for doc convergence.
- - - - -
150f1607 by Endi S. Dewata at 2025-02-13T08:19:22-06:00
Add test for ACME container with CA
A new test has been added to create a CA container and an
ACME container using the CA, then run ACME tests using
certbot.
The pki-acme-run script has been modified to create the
/conf/acme folder to store imported config files if it
doesn't exist already.
The pki-server-run script has been modified to create an
NSS database and the /conf/certs folder to store imported
certs if they don't exist already.
The pki-server run command has been modified to provide
options to skip config upgrade and migration. The
pki-server-run script has also been modified to use these
options since in general containers should not alter the
config files automatically (including creating backup files).
For now containers should assume that the config files are
already upgraded/migrated by the admin.
The tests for basic ACME container and PKI server container
have been updated to no longer expect a backup folder to be
created in the /logs folder.
- - - - -
df2b41ae by Marco Fargetta at 2025-02-13T15:23:41+01:00
Fix SSL alert in CI
Jss has fixed ssl alert for non blocking socket and the messages are
updated in CI tests.
See: https://github.com/dogtagpki/jss/commit/2f516c6e1f04c1dd4333d257e71007786e2ae5c5
- - - - -
25b01d4c by Marco Fargetta at 2025-02-13T20:33:56+01:00
Update spec for compiler flags
C and C++ flags are now retrieved from 'optflags' macro. In Fedora this is:
CFLAGS='-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-U_FORTIFY_SOURCE,-D_FORTIFY_SOURCE=3 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -march=x86-64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protection -mtls-dialect=gnu2 -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer '
- - - - -
83d6a75b by Marco Fargetta at 2025-02-13T20:33:56+01:00
Using systemd for pkiuser in fedora
- - - - -
cb2c49b4 by Endi S. Dewata at 2025-02-13T20:25:35+00:00
Update pki.spec
- - - - -
77cceb30 by Endi S. Dewata at 2025-02-14T14:10:22-06:00
Use Maven with OpenJDK 17 on RHEL 9
- - - - -
ae1fe9cd by Christina Fu at 2025-02-14T16:45:25-08:00
[skip ci]
- point DS setup link to ../others/Installation_Prerequisites.adoc
- - - - -
2f4320b0 by Endi S. Dewata at 2025-02-14T20:04:19-06:00
Reduce failures in container tests
- - - - -
3a234e16 by Christina Fu at 2025-02-17T16:36:17-08:00
[skip ci]
remove closing ='s from headers in adoc files under pki/docs/installation
- - - - -
c72478ba by Endi S. Dewata at 2025-02-18T13:07:44-06:00
Fix home directory owner in containers
- - - - -
cb61a0b6 by Endi S. Dewata at 2025-02-18T15:59:35-06:00
Update ACME docs [skip ci]
- - - - -
83b1065b by Christina Fu at 2025-02-18T16:27:46-08:00
replace md quote style (“```”) with adoc style ("....") [skip ci]
- - - - -
1b95eb41 by Christina Fu at 2025-02-18T16:58:39-08:00
adding [literal,subs="+quotes,verbatim"] line above code "...." blocks [skip ci]
- - - - -
a6e1ef9b by Endi S. Dewata at 2025-02-19T17:41:33-06:00
Update PKIServer.create_logs_dir()
The PKIServer.create_logs_dir() has been updated to always create
the backup folder since the CI expects the folder to exist even if
there are no upgrade scripts for the current version.
- - - - -
a8f4af13 by Endi S. Dewata at 2025-02-19T17:41:33-06:00
Update version number to 11.7.0-alpha1
- - - - -
77e237fe by Christina Fu at 2025-02-19T16:42:35-08:00
Removed "Overview" per downstream convergence. [skip ci]
- - - - -
6af7cb59 by Christina Fu at 2025-02-19T16:42:35-08:00
Replace "This page describes the process" with "Follow this process"
per downstream convergence. [skip ci]
- - - - -
aa3690f5 by Christina Fu at 2025-02-19T16:42:35-08:00
avoid reference to the word "page" for downstream convergence. [skip ci]
- - - - -
bfb2aad9 by Endi S. Dewata at 2025-02-19T22:41:21-06:00
Fix expected backup folder permissions in CI
The expected permissions of backup folder have been updated
due to recent changes in PKIServer.create_logs_dir().
- - - - -
8d88ffd4 by Pritam Singh at 2025-02-20T17:40:20+05:30
Added 'pki_cert_chain_path' configuration parameter
- - - - -
05204b89 by Pritam Singh at 2025-02-20T17:45:57+05:30
Added 'pki_cert_chain_path' configuration parameter
- - - - -
760a59af by Pritam Singh at 2025-02-20T18:26:52+05:30
Added 'token' parameters
- - - - -
0a211786 by Pritam Singh at 2025-02-20T18:31:01+05:30
Added 'token' parameters
- - - - -
5fb8ce4a by Pritam Singh at 2025-02-20T18:44:06+05:30
Added 'token' and 'pki_cert_chain_path' configuration parameters
- - - - -
31ede6d1 by Christina Fu at 2025-02-20T14:01:52-08:00
adding missing note to assume export of CA signing cert to ca_signing.crt prior to cloning kra and ocsp with HSM [skip ci]
- - - - -
12e4d5c6 by Endi S. Dewata at 2025-02-20T22:07:03+00:00
Use Tomcat 9 on RHEL 10
- - - - -
9ab499a7 by Endi S. Dewata at 2025-02-20T18:03:48-06:00
Fix product_id and theme params in pki.spec
- - - - -
e8f13e40 by Marco Fargetta at 2025-02-24T10:22:06+01:00
Add stale automation for issues and PRs
See https://github.com/actions/stale
- - - - -
bb13a91c by Endi S. Dewata at 2025-02-24T14:28:41-06:00
Clean up HTTPConnectorCLI.print_connector()
The HTTPConnectorCLI.print_connector() has been updated to no
longer print sslVersionRangeStream, sslVersionRangeDatagram,
and sslRangeCiphers params since they are no longer used since
PKI 10.10.
- - - - -
b2e1edf9 by Endi S. Dewata at 2025-02-24T14:40:31-06:00
Refactor CRMFPopClient (part 1)
The CRMFPopClient has been modified to generate the key pairs
using NSSDatabase.createRSAKeyPair() and createECKeyPair().
- - - - -
86ba72f6 by Endi S. Dewata at 2025-02-24T14:43:28-06:00
Refactor CRMFPopClient (part 2)
The CRMFPopClient has been updated to generate the CRMF request
using NSSDatabase.createCRMFRequest().
- - - - -
4d74199f by Christina Fu at 2025-02-25T14:07:55-08:00
replacing "e.g." with "for example" with some additional rules:
- if ')' is not followed by a punctuation, replace it with ','
- if ')' is followed by a punctuation, remove the ')'
- ignore "e.g." inside asciidoc code blocks, e.g. acme/Installing-ACME-Responder-using-PKI-Server-ACME-CLI.adoc
- adding a pair of backticks to surround the example
[skip ci]
- - - - -
753a0a60 by Christina Fu at 2025-02-25T14:07:55-08:00
- replace "will be deployed" with "is deployed" under pki/docs/installation
- remove backticks surrounding words (instead of names) under pki/docs/installation
- remove the extra ", for example" under pki/docs/installation
[skip ci]
- - - - -
8078953a by Christina Fu at 2025-02-25T15:05:11-08:00
replace "will be" with "is" (if singular) or "are" (if plural) under
pki/docs/installation [skip ci]
- - - - -
d3ef7e86 by Marco Fargetta at 2025-02-26T10:21:23+01:00
Enable stale action
- - - - -
b1cb2efc by Marco Fargetta at 2025-02-26T17:29:52+01:00
Enable certificate revocation check in NonBlockingSocketFactory
- - - - -
904bdac4 by Endi S. Dewata at 2025-02-27T09:52:48-06:00
Split tpsclient into libpki-tps.so
Most of the code in tpsclient has been moved into libpki-tps.so
(i.e. reverting commit 65d1a36e6dcddf8ab2bf24ad072bbd26753c4a4e)
such that it can be reused by other tools. The main() function
itself has been moved into tpsclient.cpp.
- - - - -
2bb936bd by Endi S. Dewata at 2025-02-27T09:52:48-06:00
Add pki tps-client
The pki tps-client has been added to replace tpsclient to make
it easier to maintain TPS client code and to troubleshoot TPS
issues. Currently it will simply reuse libpki-tps.so but in the
future the native code will gradually be converted to Java.
The tpsclient has been deprecated and will be removed in the
future.
The basic TPS test has been updated to test both pki tps-client
and tpsclient.
- - - - -
b377f652 by Marco Fargetta at 2025-02-27T17:32:56+01:00
Update to jquery v3.7.1
- - - - -
c818d3bf by Marco Fargetta at 2025-02-27T17:32:56+01:00
Update to underscore v1.13.7
- - - - -
e9e3f945 by Marco Fargetta at 2025-02-27T17:32:56+01:00
Update to backbone v1.6.0
- - - - -
6c476607 by Christina Fu at 2025-02-27T09:10:32-08:00
pki/docs/installation adoc files renamed according to new conventions.
- All lower case
- ‘-’ instead of “_”
- Adding “moved to” message to old files
- Changing link references from old to new names
- replaced "Secure-Connection" with "ldaps"
under pki/docs/installation
- renamed Set-Up-Realm-DB.adoc to configure-est-realm-db.adoc
- replaced pkispawn cfg content display block markers to use "----" instead of "...."
[skip ci]
- - - - -
f3fdd26e by Endi S. Dewata at 2025-02-27T11:39:08-06:00
Add support for subsystem logging.properties
The CMSEngine, ACMEEngine, and ESTEngine have been modified
to support subsystem logging.properties. If the file exists,
it can be used to configure the logging level in various
libraries (e.g. RESTEasy) to help troubleshooting.
The CA, ACME, and EST tests have been modified to create
the subsystem logging.properties then check the debug log.
https://github.com/dogtagpki/pki/wiki/Configuring-Subsystem-Debug-Log
- - - - -
1ba47847 by Christina Fu at 2025-02-27T14:21:12-08:00
The initial Dogtag pki documentation convention readme file.
- future contributors to pki/docs are expected to conform to the contentions listed in this file.
- reviewers are expected to give a comment pointing any future doc PR to this file before giving any detailed reviews.
[skip ci]
- - - - -
1b82d230 by Christina Fu at 2025-02-27T15:32:25-08:00
under pki/docs/installation
- adding the following three lines to the top of adoc files with all lower case file names:
-- :_mod-docs-content-type: PROCEDURE
-- \n
-- [id="xxx_{context}"] where 'xxx' is the file name minus the .adoc extention
[skip ci]
- - - - -
7b4cdc22 by Christina Fu at 2025-02-27T16:11:13-08:00
Update dogtagpki-docs-convention-readme.adoc
- - - - -
6d697d30 by Christina Fu at 2025-02-27T17:17:56-08:00
Update dogtagpki-docs-convention-readme.adoc
- - - - -
9434241d by Marco Fargetta at 2025-02-28T11:29:15+01:00
Update CI stale to v9.1.0
There is a cache problem in v9 which should be solved in v9.1.0.
- - - - -
aa3c316e by Endi S. Dewata at 2025-02-28T10:16:41-06:00
Remove hard-coded pkidbuser
The pkidbuser is mainly used by PKI in IPA to access DS using
client cert auth. Regular (non-IPA) PKI generally do not use
this user but currently the user is created by default during
installation and the username is hard-coded in PKI.
To simplify the installation the code that sets up the database
user has been consolidated into configuration.py and the default
pki_share_dbuser_dn has been removed so it will no longer create
the user by default. IPA defines the pki_share_dbuser_dn during
installation so it will not be affected by this change.
The non-IPA tests have been updated to no longer check pkidbuser.
There are still some references to pkidbuser in CertFixCLI (which
is mainly used by IPA). They will be cleaned up separately later.
- - - - -
e43227c0 by Endi S. Dewata at 2025-02-28T17:05:27-06:00
Refactor RA_Client::Execute()
The RA_Client::Execute() has been converted into Java code
in TPSClientCLI.execute(). The original C code has been moved
into tpsclient.cpp. The TPSClientCLI.invokeOperation() has
been added to call RA_Client::InvokeOperation().
- - - - -
d09271c6 by Marco Fargetta at 2025-03-03T10:55:19+01:00
Increase number for CI stale actions
- - - - -
8083eb3b by Endi S. Dewata at 2025-03-04T08:55:02-06:00
Fix Azure pipelines
Previously all JAR files were installed in /usr/share/java/pki,
but since now pki-tools.jar uses JNI Maven might install it in
/usr/lib/java/pki depending on the build environment (which
requires further investigation).
To maintain consistency the CMake script has been modified to
install pki-tools.jar in /usr/lib/java/pki then create a link
to it in /usr/share/java/pki.
The RPM spec has been modified to check where pki-tools.jar is
installed then create a link to it from the other location.
- - - - -
324c209d by Endi S. Dewata at 2025-03-05T12:18:17-06:00
Don't use pki_token_name as default token
Previously the pki_token_name was used as the default token for
all system certs, but due to a bug the fallback mechanism has not
been working properly in all cases, so currently the token name
for each system cert has to be specified in pki_<cert>_token if
it's needed, which is actually simpler.
Since the bug has existed for a long time and might require a lot
of effort to properly fix and test it, the code that provides the
fallback mechanism is no longer needed and has been dropped.
- - - - -
d6fea77a by Marco Fargetta at 2025-03-06T10:21:17+01:00
Add actionw write permission to stale CI
The permission is required for an issue with cache.
https://github.com/actions/stale/issues/1133
- - - - -
ddaddb57 by Endi S. Dewata at 2025-03-06T20:30:45+00:00
Update minimum CMake version
- - - - -
559b876a by Marco Fargetta at 2025-03-07T10:14:03+01:00
Fix typos for SSN messages
- - - - -
c05485ed by Marco Fargetta at 2025-03-07T10:14:03+01:00
Update CI for typo fixes
- - - - -
610c2fa2 by Endi S. Dewata at 2025-03-07T11:31:01-06:00
Don't create audit signing cert by default
Previously the audit signing cert was always created by default
during installation, but it's actually only used if log signing
is enabled.
To reduce redundancies the default pki_audit_signing_nickname
has been removed so that pkispawn will skip creating the audit
signing cert if the nickname is not specified.
The selftest and pki-healthcheck have been modified to skip
validating the audit signing cert if the nickname is not
available.
The pki-server cert-find and pki-server subsystem-cert-find
commands have also been modified to skip displaying the audit
signing cert if the nickname is not available.
The basic tests of each subsystem have been updated to install
the subsystem without the audit signing cert nickname so it will
not create the cert. For basic CA test, it will later create the
cert and enable log signing manually.
- - - - -
dfe40ab7 by Endi S. Dewata at 2025-03-07T20:36:54+00:00
Fix javac --release option
- - - - -
4dc3e8c8 by Christina Fu at 2025-03-10T10:37:38-07:00
defer moving these user tool pages from wiki.
[skip ci]
- - - - -
3b61d531 by Christina Fu at 2025-03-10T16:47:15-07:00
Cover two conditions:
- using ds temp bootstrap certs
- using certs issued by a real CA
These are meant to be used bo the files in pki/docs/installation
[skip ci]
- - - - -
a90c1f41 by Christina Fu at 2025-03-10T16:53:07-07:00
remove the "moved to" files under pki/docs/installation
[skip ci]
- - - - -
7f42e95c by Christina Fu at 2025-03-10T17:15:12-07:00
removed the "moved to" .md files
[skip ci]
- - - - -
0bc40c61 by Endi S. Dewata at 2025-03-11T10:26:14-05:00
Convert TPSClientCLI.invokeOperation() to Java
The TPSClientCLI.invokeOperation() has been converted into Java
which will use native methods to call RA_Client methods. The
RA_Client::InvokeOperation() has been moved to tpsclient.cpp.
The old_style variable has been moved into RA_Client class to
make it more accessible.
The basic TPS test has been updated to test basic operations
using pki tps-client and tpsclient.
- - - - -
c331ad19 by Endi S. Dewata at 2025-03-11T10:39:26-05:00
Add test for reinstalling IPA
A new test has been added to install IPA server with CA and
KRA, remove the server, reinstall the server, and verify that
everything is working properly with new certs.
The IPA KRA test has also been updated since IPA issue #9735
has been fixed.
- - - - -
b703a675 by Endi S. Dewata at 2025-03-11T13:43:40-05:00
Clean up TPSClientCLI.cpp
- - - - -
dbb520a0 by Endi S. Dewata at 2025-03-11T14:47:55-05:00
Update dependency to JSS 5.7
- - - - -
0facec6e by jmagne at 2025-03-11T16:22:30-07:00
Fix: RHCS-5675 (#4993)
Bug 2351094 - TPS subsystem cert unable to unwrap shared secret and TPS install fails with pki_import_shared_secret=True config.
This fix allows the auto imporation of the shared secret into TPS when using the HSM to succeed.
Change-Id: I0259e2dbe49c042598e018ec5a3a8e8834c3f9e8
- - - - -
f69a551f by Pritam Singh at 2025-03-12T21:42:22+05:30
Add SELinux workaround note for cracklibCheck (#4974)
* Add SELinux workaround note for cracklibCheck
When cracklibCheck=true is enabled, SELinux prevents its execution and in this case cracklib not function as expected, So adding workaround to trust and allow this module in SELinux policy.
* Update ServerSideKeygen.adoc
* Update ServerSideKeygen.adoc
- - - - -
22f2181a by Christina Fu at 2025-03-12T17:38:53-07:00
ldaps-related setup cleanup, including:
- copying the slightly adjusted installing-ca-clone-with-ldaps-connection.adoc to installing-ca-clone-with-temp-ldaps-connection.adoc for reference. Using the temporary bootstrap DS server cert shouldn't be a recommended case
- modified installing-ca-clone-with-temp-ldaps-connection.adoc so that it assumes that the existing PKI instance is running withr real DS server cert, and issues a real DS server cert for the DS of the clone
- modified all ldaps installation adoc files to reflect the changes
- some adjustments to the already updated ldaps-related sections under pki/docs/installation/others
- renamed enabling-temp-ssl-connection-in-ds.adoc to enabling-ssl-connection-in-ds-with-bootstrap-cert.adoc
- renamed installing-ca-clone-with-temp-ldaps-connection.adoc to installing-ca-clone-with-ldaps-using-bootstrap-ds-certs.adoc
[skip ci]
- - - - -
ec48fb5f by Endi S. Dewata at 2025-03-13T08:17:22-05:00
Fix JRE dependency for pki-console
The pki.spec has been updated to require java-<version>-openjdk
for pki-console which provides the AWT library needed by the
console.
The Azure pipeline has been updated to build the console with
rpmbuild, CMake, and Maven and compare the binaries.
The CMake script has been updated to include all resource files
such that it generates a pki-console.jar identical to the one
built by Maven.
The Console.java has been updated to work with the latest Apache
Commons CLI library.
- - - - -
d067ba3b by Marco Fargetta at 2025-03-13T16:53:54+01:00
Add option to match CSR subject and SAN with TLS cert
The new option "enrollMatchTLSSubjSAN" default to true so the check is
always performed.
If disabled, users can add their checks in the authorizer executable
since the information for the match (CSR and cleint cert chain) are
provided.
- - - - -
bfeebd14 by Marco Fargetta at 2025-03-13T16:53:54+01:00
Add enrollMatchTLSSubjSAN option in est installation doc
- - - - -
b0d7d33e by Marco Fargetta at 2025-03-13T16:53:54+01:00
Add EST test for enrollMatchTLSSubjSAN
- - - - -
f5d6a767 by Marco Fargetta at 2025-03-13T16:53:54+01:00
Add EST subject check to basic authentication
If EST client uses basic authentication the CSR subject common name and
SAN, if present, have to match with the user full name or the user uid.
The check can vi disabled using the option "enrollMatchTLSSubjSAN" set
to false in the authorizer.conf file.
- - - - -
7cab30cd by Marco Fargetta at 2025-03-13T16:53:54+01:00
Update EST doc for basic authentication subject check
- - - - -
e32003c9 by Marco Fargetta at 2025-03-13T16:53:54+01:00
Update EST test for CSR subject check
- - - - -
3f840c06 by Marco Fargetta at 2025-03-13T16:53:54+01:00
Fix CMake libraries for EST
- - - - -
a9598133 by Marco Fargetta at 2025-03-13T19:08:47+01:00
Fix erroneous opsFlag in nss-key-create operation
- - - - -
57ed704c by Christina Fu at 2025-03-13T14:28:31-07:00
testing xref link to subsection of an adoc
[skip ci]
- - - - -
35b61951 by Christina Fu at 2025-03-13T15:19:41-07:00
desolving doc with simple command: exporting-ds-certificates.adoc
- merge the command line into referencing docs
[skip ci]
- - - - -
8f2e3807 by Christina Fu at 2025-03-13T15:26:30-07:00
xref ref test into subsection using downstream style of
- [id=xyz]
[skip ci]
- - - - -
98f54712 by Christina Fu at 2025-03-13T17:23:39-07:00
doc convergence: This is a test for asciidoc include
[skip ci]
- - - - -
6652b230 by Christina Fu at 2025-03-13T17:30:11-07:00
continue the test
remove the file name between []
[skip ci]
- - - - -
76897044 by Christina Fu at 2025-03-14T08:42:45-07:00
replacing "link:" with 'xref:" for links not begin with "http"
- to allow asciidoc processor to do intelligent substitution (supposedly).
[skip ci]
- - - - -
f3a04dfc by Christina Fu at 2025-03-14T09:27:01-07:00
removed test file
[skip ci]
- - - - -
a29de7fc by Endi S. Dewata at 2025-03-14T12:14:46-05:00
Convert TPSClientCLI.formatToken() to Java
The TPSClientCLI.formatToken() has been converted into Java.
The old style method will use Java threads to call the native
code that performs the actual operation. The new style method
is still implemented in C++ and might be converted into Java
in the future. The RA_Client::OpConnUpdate() has been moved
into tpsclient.cpp.
- - - - -
8aa58a72 by Jack Magne at 2025-03-14T15:02:46-07:00
Fix RHCS-5701:
Fix Bug 2352409 - Default signing algorithm dropdown is empty in pkiconsole and java NullPointerException error is thrown.
Fixed by removing the unneeded serial number management panel.
Change-Id: Ie3536d30c5feade350b4ccd25f55ce05bb77655e
- - - - -
84ab3d43 by Endi S. Dewata at 2025-03-17T10:28:40-05:00
Convert TPSClientCLI.resetPIN() to Java
The TPSClientCLI.resetPIN() has been converted into Java. The
old style method will use Java threads to call the native code
that performs the actual operation. The new style method is
still implemented in C++ and might be converted into Java in
the future. The RA_Client::OpConnResetPin() has been moved
into tpsclient.cpp.
The basic TPS test has been updated to perform PIN reset.
- - - - -
af53298c by Christina Fu at 2025-03-17T18:00:44-07:00
Renaming enabling-ssl-connection-in-ds.adoc to getting-ds-cert-issued-by-actual-ca.adoc so that it fits in the downstream post-install section more nicely.
[skip ci]
- - - - -
353f16a2 by Christina Fu at 2025-03-18T09:44:03-05:00
squashing pki-ldap-tree.adoc into creating-ds-instance.adoc
[skip ci]
- - - - -
42d61a94 by Endi S. Dewata at 2025-03-18T10:26:09-05:00
Convert TPSClientCLI.enrollToken() to Java
The TPSClientCLI.enrollToken() has been converted into Java.
The old style method will use Java threads to call the native
code that performs the actual operation. The new style method
is still implemented in C++ and might be converted into Java
in the future. The RA_Client::OpConnEnroll() has been moved
into tpsclient.cpp.
- - - - -
d6e696fa by Christina Fu at 2025-03-18T16:53:08-07:00
misc adjustments in pki/docs/installation, including:
- removing the word "temporary" for the DS bootstrap certs
- adding dc=est to pki ldap tree
[skip ci]
- - - - -
e681a786 by Endi S. Dewata at 2025-03-18T20:14:37-05:00
Update pki nss-cert-request
The pki nss-cert-request has been updated to provide options
to create a temporary, sensitive, or extractable key.
- - - - -
bcce1af1 by Marco Fargetta at 2025-03-19T09:43:58+01:00
Fix EST csr match condition
- - - - -
7d4f27e7 by Marco Fargetta at 2025-03-19T09:43:58+01:00
Add EST reenroll test with different CSR
- - - - -
d97e1cb0 by Christina Fu at 2025-03-19T14:25:33-07:00
under pki/docs/installation, replace calls to
pki client-cert-import ...
with
pki nss-cert-import ...
[skip ci]
more
- - - - -
9d3a4ab7 by Christina Fu at 2025-03-19T15:33:53-07:00
under pki/docs/installation
- remove all pki client-init calls
[skip ci]
- - - - -
5e676faa by Christina Fu at 2025-03-19T15:51:04-07:00
under pki/docs/installation,
- replace the "To use the admin certificate ..." line
[skip ci]
- - - - -
a0fed431 by Christina Fu at 2025-03-19T15:59:43-07:00
under pki/docs/installation,
- replace the import admin cert and key intro line
[skip ci]
- - - - -
c4f94669 by Christina Fu at 2025-03-19T16:13:14-07:00
under pki/docs/installation
- remove more pki client-init calls
[skip ci]
- - - - -
f2a83d54 by Christina Fu at 2025-03-19T16:18:27-07:00
under pki/docs/installation, replace
- Import admin key and certificate:
- with
- Import admin certificate and key into the client NSS database (by default ~/.dogtag/nssdb) with the following command:
[skip ci]
- - - - -
1a2b26b6 by Endi S. Dewata at 2025-03-19T21:20:42-05:00
Rename CertUtil.unwrapPKCS10() into unwrapCSR()
- - - - -
b6e4a298 by Endi S. Dewata at 2025-03-19T21:20:42-05:00
Add CertUtil.encodeCRMF()
The code that converts CRMF request into PEM format in
CRMFPopClient has been moved into CertUtil.encodeCRMF().
- - - - -
84a6d014 by Endi S. Dewata at 2025-03-19T21:28:07-05:00
Update CACertClient.submitRequest()
The CACertClient.submitRequest() has been updated to mimic
CRMFPopClient.submitRequest().
- - - - -
7bc402c1 by Endi S. Dewata at 2025-03-20T11:23:12-05:00
Fix deprecation warning in pki ca-cert-request-submit
- - - - -
5978683e by Endi S. Dewata at 2025-03-21T10:59:23-05:00
Update pki nss-cert-request to support CRMF
The pki nss-cert-request has been updated to support creating
a CRMF request and storing it into a file. In the future this
command might replace pki client-cert-request which submits
the request immediately to the CA.
- - - - -
9f3418ce by Endi S. Dewata at 2025-03-21T10:59:23-05:00
Update pki ca-cert-request-submit to support CRMF
The pki ca-cert-request-submit has been updated to support
submitting an existing CRMF request in PEM or DER format.
- - - - -
0e1c0255 by Endi S. Dewata at 2025-03-21T10:59:23-05:00
Update KRA tests
Some KRA tests have been updated to create the CRMF request
using pki nss-cert-request so that the request can be stored
into a file for further inspection, then submit the request
using pki ca-cert-request-submit.
- - - - -
26d5bf79 by Endi S. Dewata at 2025-03-21T14:11:21-05:00
Update pki ca-cert-issue to support CRMF
The pki ca-cert-issue has been modified to support submitting
an existing CRMF request, approving the request, and retrieving
the issued cert in one step.
Some KRA tests have been simplified using this command.
- - - - -
5d4af88b by Christina Fu at 2025-03-21T13:46:18-07:00
Remmove "_{context}" in adoc id under pki/docs/installation/
- based on the latest changes in upstream rhcs-docs, "_{context}"
needs to be removed from the file id
[sip ci]
- - - - -
811d9bbe by Endi S. Dewata at 2025-03-21T22:14:26-05:00
Update IPA tests to check pkispawn and pkidestroy logs
- - - - -
d8e468e8 by Endi S. Dewata at 2025-03-24T09:04:52-05:00
Update KeyClient.list_requests() and list_keys() to support REST API v2
The KeyClient.list_requests() and list_keys() have been modified
to use the PKIClient object to determine the proper path of the
REST API.
The KeyClient.__init__() has also been modified so that it can
be called without the crypto object and transport cert nickname.
These parameters are only needed for key archival/retrieval.
The Python test for KRA has been modified to test these methods
with REST API v1 and v2.
- - - - -
1d752a87 by Christina Fu at 2025-03-24T17:27:48-07:00
fixed xref from old md files to new adoc files
[skip ci]
- - - - -
983e7a76 by MichalTravnicek at 2025-03-25T14:03:54+01:00
Update pki.spec
- - - - -
291791c8 by Endi S. Dewata at 2025-03-25T11:10:20-05:00
Fix missing error messages
Previously when a failure happened in the Python code in some
cases the error message was missing which made it difficult to
troubleshoot the problem.
To simplify troubleshooting some of the Python code has been
updated to capture only the stdout and let the stderr appear
on the console so that it can be seen by the user.
The PKISubsystem.run() has been modified to provide stdout and
stderr params so they can be configured separately.
- - - - -
a242c13b by Christina Fu at 2025-03-25T15:21:43-07:00
Misc update to make it compatible with downstream docs once imported
[skip ci]
- - - - -
8e27e968 by Christina Fu at 2025-03-25T16:39:13-07:00
downstream import processing:
one small change for single line for script processing
[skip ci]
- - - - -
d1d4be64 by Michal Travnicek at 2025-03-26T15:58:24+01:00
CASigningUnit hexstring serial number
- - - - -
04fe7ef1 by Endi S. Dewata at 2025-03-26T16:36:02-05:00
Do not set up VLV by default
A new pki_ds_setup_vlv param has been added for pkispawn to add
and rebuild VLV indexes during installation. The default is set
to False and the CI tests have also been updated to no longer
set up the VLV indexes. So far there seems to be no issues in
the CI.
Disabling VLV will help identify any remaining VLV dependencies
so they can be removed. If this turns out to be causing many
issues for QE or IPA the default can be changed temporarily, but
eventually VLV should be disabled by default.
The PKIDeployer.setup_database() has been modified to set up the
regular search indexes in all cases, but set up the VLV indexes
only if pki_ds_setup_vlv is set to True.
The pki_clone_reindex_data param is no longer used so it has
been removed.
- - - - -
6edb63b3 by Endi S. Dewata at 2025-03-26T16:47:18-05:00
Update log messages in PKIServlet
- - - - -
c48a536d by Endi S. Dewata at 2025-03-26T16:47:18-05:00
Update log messages in AgentCertRequestServlet
- - - - -
60371172 by Endi S. Dewata at 2025-03-26T16:47:18-05:00
Update log messages in DBSearchResults
- - - - -
a9ce9a72 by Endi S. Dewata at 2025-03-26T17:57:31-05:00
Update pki *-find commands
The pki *-find commands have been updated to show the total
number of matching entries only if it's provided by the
server.
- - - - -
472fe4bb by Endi S. Dewata at 2025-03-27T09:00:49-05:00
Add test for paging parameters
The test for CA with SSNv2 has been updated to find cert requests
and certs using paging parameters. For cert requests the --start
param is used differently depending on the REST API version so
there is a separate test for each version. For certs the --start
param is used more consistently so there is only one test.
The pki ca-cert-request-find command has been modified to send
the --start param to the server as is so that it can be parsed
according to the REST API version.
- - - - -
593c8013 by Endi S. Dewata at 2025-03-27T09:39:24-05:00
Clean up pki pkcs12-export output
- - - - -
a79d5b88 by Endi S. Dewata at 2025-03-27T09:49:12-05:00
Clean up log messages in pki ca-cert-create
- - - - -
77b8c50a by Christina Fu at 2025-03-27T14:41:44-07:00
Fixed issue where comment lines were between the 'id' line and the subject header line that it's supposed to anchor. Solution was to move the comments to after the subjet header.
[skip ci]
- - - - -
ab43c5e9 by Christina Fu at 2025-03-28T10:48:52-07:00
Renamed ServerSideKeygen-related files for upstream->downstream convergence:
- ServerSideKeygen.adoc -> configuration-for-server-side-keygen.adoc
- Server-SideKeygenEnroll_approval.png -> server-side_keygen_enroll_approval.png
- Server-SideKeygenEnroll_manual.png -> server-side_keygen_enroll_manual.png
- Server-SideKeygen_LDAP_auth.png -> server-side_keygen_ldap_auth.png
[skip ci]
- - - - -
743cf876 by Endi S. Dewata at 2025-03-28T14:05:37-05:00
Update KeyClient.modify_key_status() to support REST API v2
A new test has been added to modify the status of a key using
KeyClient.modify_key_status(). The basic KRA test has also
been modified to perform the same test using pki kra-key-mod.
The pki kra-key-find and pki kra-key-mod have been modified
to no longer show the public key data. The pki kra-key-show
will continue to show the public key data.
- - - - -
ee30e47d by Christina Fu at 2025-03-28T14:06:04-07:00
getting installing-ca-with-external-ca-signing-certificate.adoc ready to replace the section: 7.5. Setting up subsystems with an external CA in downstream install guide
[skip ci]
- - - - -
ae6e1a26 by Christina Fu at 2025-03-28T21:14:54-07:00
As it turns out, standalone KRA and OCSP are described in the downstream Installation guide secton 7.6. Setting up a standalone KRA or OCSP.
This patch is to update the upstream docs so that they can be officially included in the Upstream->downstream doc convergence include list and processed properly for import to replace that section.
[skip ci]
- - - - -
c5396404 by Louise McGarry at 2025-03-31T11:57:12-07:00
Updates to align with docs standards
- - - - -
50c0ce03 by Louise McGarry at 2025-03-31T11:57:12-07:00
Reviewed est files to align with doc requirements
- - - - -
b0f444e4 by Louise McGarry at 2025-03-31T11:57:12-07:00
Fixes in line with feedback
- - - - -
6b968f5b by Louise McGarry at 2025-03-31T11:57:12-07:00
Fixed formatting for consistency
- - - - -
7ed53c1e by Christina Fu at 2025-03-31T13:51:22-07:00
fixed issue introduced by the comment between id line and the header line by moving it below the header
[skip ci]
- - - - -
f4db8290 by Christina Fu at 2025-03-31T15:19:57-07:00
fixed unpaird blocks ---
[skip ci]
- - - - -
e95213df by Endi S. Dewata at 2025-04-01T09:17:59-05:00
Update KeyClient to support archieval/retrieval with REST API v2
The KeyClient.submit_request() and retrieve_key_data() have been
updated to use the proper URL for the REST API version.
The CryptographyCryptoProvider's constructor has been updated
such that the transport cert nickname is optional.
The KeyRequestProcessor.archiveKey() has been updated to use the
same condition as in KeyRequestService.archiveKey() to validate
the key algorithm for symmetric key.
The basic KRA test has been updated to archive a secret then
retrieve it using pki CLI.
The KRA Python API test has been updated to archive a secret
then retrieve it using the updated Python API.
- - - - -
e6f29a63 by Endi S. Dewata at 2025-04-01T14:01:42-05:00
Rename Authority to AuthorityRepository
- - - - -
42b8d8e3 by Endi S. Dewata at 2025-04-01T14:24:10-05:00
Move AuthorityRepository instance to CAEngine
- - - - -
2e247d85 by Christina Fu at 2025-04-01T16:41:55-07:00
Revert "defer moving these user tool pages from wiki."
This reverts commit 4dc3e8c8f103a665a2b04e5ed93f12987b07fac6.
- - - - -
5440adaf by Endi S. Dewata at 2025-04-01T21:21:37-05:00
Move CAEngine.getAuthorityRecord() to AuthorityRepository
- - - - -
13ac667c by Endi S. Dewata at 2025-04-01T21:21:37-05:00
Move CAEngine.addAuthorityRecord() to AuthorityRepository
- - - - -
9bd2cd47 by Endi S. Dewata at 2025-04-01T21:21:37-05:00
Move CAEngine.modifyAuthorityEntry() to AuthorityRepository
- - - - -
3a83b40b by Endi S. Dewata at 2025-04-01T21:21:37-05:00
Add AuthorityRepository.deleteAuthorityRecord()
- - - - -
2e128be1 by Christina Fu at 2025-04-02T08:45:25-07:00
replace past tense with present tense to conform to downstream conventions.
[skip ci]
- - - - -
923194ae by Marco Fargetta at 2025-04-02T17:59:50+02:00
Fix doc typos
- - - - -
76552846 by Endi S. Dewata at 2025-04-02T11:06:04-05:00
Move CAEngine.haveAuthorityContainer() to AuthorityRepository
- - - - -
ce751a16 by Endi S. Dewata at 2025-04-02T11:06:04-05:00
Disable access log buffer in IPA tests
- - - - -
40fbe826 by Endi S. Dewata at 2025-04-02T11:06:04-05:00
Drop KeyClient.key_url and key_requests_url
The remaining methods in KeyClient have been updated to use the
proper URL for the REST API version.
The key_url and key_requests_url attributes are no longer used
so they have been removed.
- - - - -
84058d5b by Endi S. Dewata at 2025-04-02T16:58:51-05:00
Move CAEngine.updateAuthoritySerialNumber() to AuthorityRepository
- - - - -
49698850 by Endi S. Dewata at 2025-04-02T18:42:38-05:00
Update LWCA tests
The LWCA tests have been updated to check the host CA's LDAP
entry before running pki ca-authority-find.
- - - - -
4e33832e by Christina Fu at 2025-04-03T08:57:17-07:00
fixed downstream build issue on formatting reported by writer
[skip ci]
- - - - -
b0ed9f25 by Marco Fargetta at 2025-04-03T19:53:46+02:00
Modify default CA OCSP response to use Key hash instead of name
Default CA OCSP responder provide subject names in the reponse to
identify the reponder ID but this has some problems when the setup
include SubCA with their own OCSP have certificate with the same
subject. Moving to the ID should solve the problem.
- - - - -
c79076b1 by Marco Fargetta at 2025-04-03T19:53:46+02:00
Fix KeyHash for CA OCSP Responder ID
OCSP specification [1] requires the Key hash computed from the public
key without additional tags. It was computed from the encoded key which
include extra information and cannot be identified.
This commit fix how the key hash is generated.
1. https://datatracker.ietf.org/doc/html/rfc6960#section-4.2.1
- - - - -
2170cfad by Marco Fargetta at 2025-04-03T19:53:46+02:00
Add CI test for RootOCSP in SubCA scenario
- - - - -
b0ec8cca by Marco Fargetta at 2025-04-03T19:53:46+02:00
Upgrade script for internal OCSP ResponderID configuration
Default value for ResponderID has been update from Subject Name to Key
hash but running systems will keep their configuration making it
explicit.
- - - - -
908e1591 by Marco Fargetta at 2025-04-03T19:53:46+02:00
Update doc change for CA internal OCSP
- - - - -
16b6f8d4 by Marco Fargetta at 2025-04-03T19:53:46+02:00
Modify default ResponderID in OCSP
The OCSP responses from OCSP responder changes the default from
ResponderID from Subject name to Key hash.
This change has been already done in the CA internal OCSP to limit
problems with repeated name in some complex scenarios.
- - - - -
f53bcc4c by Marco Fargetta at 2025-04-03T19:53:46+02:00
Update doc for OCSP ResponderID default change
- - - - -
ba6d54a0 by Endi S. Dewata at 2025-04-03T14:49:58-05:00
Refactor AuthorityRepository.findCAs()
Currently the AuthorityRepository.findCAs() gets the authority
data from the CA objects in the CA engine. The AuthorityMonitor
creates a CA object for each authority record in LDAP, so it
might not scale well with large database and might be expensive
to run in cloud.
To address the issue, the AuthorityRepository.findCAs() has been
modified to get the data from the authority records directly. For
now it still uses the CA object to get some additional info, but
in the future it might be possible to store those info in LDAP as
well.
The AuthorityService.findCAs() has been modified to use the
AuthorityRepository.findCAs().
The AuthorityServlet.findCAs() has been modified to no longer
catch the exception and throw a BadRequestException since the
exception might not necessarily be a client issue.
- - - - -
1d927c39 by Endi S. Dewata at 2025-04-04T10:48:52-05:00
Refactor AuthorityRepository.getCA()
The AuthorityRepository.getCA() has been modified to get the
authority data from the authority record directly. For now it
still uses the CA object to get some additional info, but in
the future it might be possible to store those info in LDAP as
well.
The AuthorityRepository.readAuthorityData() has been modified
to get the issuer DN from the CA cert to match the original
behavior of the code.
The AuthorityService.getCA() has been modified to use the
AuthorityRepository.getCA().
- - - - -
8bc2de43 by Christina Fu at 2025-04-04T09:12:49-07:00
Comment out lines imcompatible with downstream doc build
[skip ci]
- - - - -
9a477004 by Marco Fargetta at 2025-04-07T10:01:02+02:00
Make PKIConnection default to non blocking
The PKIConnection is now using NonBlocckingSocketFactory as default to
create a socket. The non bloking socket is built in JSSSocket.
- - - - -
1f499cfa by Marco Fargetta at 2025-04-07T10:01:02+02:00
Installation steps has to ignore revoked certificate
During pkispawn some client command could fails because the revocation
cannot be verified since the server is down. These cases have to be
ignored.
- - - - -
25f09bf9 by Marco Fargetta at 2025-04-07T10:01:02+02:00
Make client OCSP check optional
With JSSSocket in the client it is possible to enable OCSP check for the
certificate. If not specified it is enabled for all clients operation
but it is disabled for all the client commands executed by the server.
There are several scenarios where the check are failing because of the
presence of other OCSP certificates. This is the case of SubCAs. For
this reason it is disabled at the moment but can be disabled.
An option could be to enable and making OCSP using KeyHash using the
param ca.byName.
To disable revocation check from pki cli it has been introduced the
option `--skip-revocation-check`.
- - - - -
979364ed by Marco Fargetta at 2025-04-07T10:01:02+02:00
Make optional OCSP check in CA running as client
When CA is running client operation there is no revocation check on
certificates. This can be enabled with the option in CS.cfg:
ca.clientRevocationCheck=true
The opetion can be enabled with pkispawn using the CA configuration:
pki_client_verify_cert=True
The default value is false
- - - - -
3d79d8ac by Marco Fargetta at 2025-04-07T10:01:02+02:00
Update v11.7 for OCSP in client commands
Since clients are moving to JSS which perform OCSP check by default
there are situation where these need to be disabled.
New option in pkispan and pki command have been added and here documented.
- - - - -
5829e041 by Marco Fargetta at 2025-04-07T10:01:02+02:00
Update CI for JSSSocket in pki CLI
- - - - -
99ac7de6 by Marco Fargetta at 2025-04-07T10:01:02+02:00
Fix network alias for IPA CI
IPA assign AIA to a dedicated host, named "ipa-ca", as described in
https://pagure.io/freeipa/issue/8595.
The host ipa-ca has to be an alias for the hostname to allow AIA to work
properly.
- - - - -
80cca90a by Marco Fargetta at 2025-04-07T10:01:02+02:00
Move clientRevocationCheck to KRA connector
The clientRevocationCheck is used only with KRA connector so it has been
moved to the connector configuration and renamed as "ca.connector.KRA.certRevocationCheck".
Additionally, the pkispawn parameter "pki_client_verify_cert" has been
renamed as "pki_kra_connector_verify_cert".
- - - - -
896cebce by Marco Fargetta at 2025-04-07T10:01:02+02:00
Update doc for name change in clientRevocationCheck
- - - - -
b760ed92 by Endi S. Dewata at 2025-04-07T12:00:59-05:00
Refactor AuthorityRepository.findAuthorityRecords()
The AuthorityRepository.findAuthorityRecords() has been updated
to construct an LDAP search filter from authority ID, authority
DN, parent ID, and parent DN if provided.
The AuthorityRepository.findCAs() has been updated to provide the
search params to findAuthorityRecords() instead of filtering out
the search results afterwards.
The CAEngine.getCA() has been updated to get the authority record
using the findAuthorityRecords() then call another getCA() with
the authority ID to get the CertificateAuthority object.
The CAEngine.deleteAuthority() has been updated to determine
whether the authority to be deleted has any descendant using the
findAuthorityRecords().
- - - - -
35506113 by Marco Fargetta at 2025-04-08T10:27:09+02:00
Replace httpclient deprecated code
PKI client connection are based on "DefaultHttpClient" and
"SchemeLayeredSocketFactory" but these classes have been deprecated and will
be removed so the code is updated to use their replacement.
- - - - -
d1afecff by Endi S. Dewata at 2025-04-08T09:22:22-05:00
Refactor CAEngine.validate()
The CAEngine.validate() has been updated to get the cert record
using the cert serial number from the OCSP request, then find the
authority records that might have issued the cert using the cert
issuer name, then finally validate the request against the CA
object that matches the hash value from the request.
The CAEngine.getCAs() is no longer used so it has been removed.
- - - - -
6457aa6f by Endi S. Dewata at 2025-04-08T12:38:47-05:00
Update test for CA clone with HSM
The test for CA clone with HSM has been updated to use a shared
HSM container connected to all CA replicas using p11-kit module
over SSH connection. Certs/keys created in HSM will be available
to all CA replicas immediately, so they don't need to be exported
from the HSM and transferred into other replicas (which might not
be possible in real deployments).
Currently the SSH client needs to be set up for both the root
user and pkiuser since pkispawn is executing HSM operations as
both users. Ideally everything should be done by pkiuser. This
will be addressed separately later.
https://p11-glue.github.io/p11-glue/p11-kit/manual/pkcs11-conf.html
- - - - -
0739167a by Christina Fu at 2025-04-08T17:20:24-07:00
moved dogtagpki-docs-convention-readme.adoc and update with more clarification. Also pushing the current "include" lists.
- - - - -
32e71d7f by Marco Fargetta at 2025-04-09T10:39:23+02:00
Using apache http basic authentication
The basic authentication is moved from resteasy filter to http
connection property.
- - - - -
0ad39b9e by Endi S. Dewata at 2025-04-09T10:02:08-05:00
Add test for LWCA clone with HSM
A new test has been added to create two CA replicas with a
shared HSM, create an LWCA in one, enroll certs in both, then
remove the LWCA from the other one. Since the HSM is shared
the LWCA can be used immediately on any replica without having
to transfer the signing key.
- - - - -
32e0f4db by Endi S. Dewata at 2025-04-09T14:34:34-05:00
Refactor RequestInQListener (part 1)
The CA-specific code in RequestInQListener has been moved into
CARequestInQListener.
- - - - -
e681dd26 by Endi S. Dewata at 2025-04-09T14:34:41-05:00
Refactor RequestInQListener (part 2)
The RequestInQListener has been moved into pki-server.jar so
that it can be used by KRA.
- - - - -
5008005a by Endi S. Dewata at 2025-04-09T14:51:21-05:00
Refactor CMSEngine.loadSubsystems()
The code in CMSEngine.loadSubsystems() that creates the subsystem
object has been moved into CMSEngine.createSubsystem().
- - - - -
1198568c by Rob Crittenden at 2025-04-10T09:47:23+02:00
Add issuer_dn to the CertDataInfo
This is needed by IPA for its cert-find command for backwards
compatibility.
Signed-off-by: Rob Crittenden <rcritten at redhat.com>
- - - - -
95a0672c by Endi S. Dewata at 2025-04-10T13:01:20-05:00
Remove redundant type casts
- - - - -
ad6cd755 by Endi S. Dewata at 2025-04-10T13:01:20-05:00
Move PinRemovalListener to pki-ca.jar
- - - - -
4ad2e4b2 by Endi S. Dewata at 2025-04-10T13:01:20-05:00
Add RequestListener.init()
A new RequestListener.init() without a Subsystem param has been
added since in most cases the param is not used.
- - - - -
bc941f61 by Endi S. Dewata at 2025-04-10T13:01:20-05:00
Add KRARequestInQListener
The KRARequestInQListener has been added to provide KRA-specific
RequestInQListener.
- - - - -
b27dc523 by Christina Fu at 2025-04-10T13:59:32-07:00
update docs relating to serial number mechanism change
- - - - -
be1a59f0 by Endi S. Dewata at 2025-04-10T18:04:18-05:00
Update CRLPublisher.init()
The CRLPublisher.init() has been updated to no longer take a
Subsystem param. If necessary, the Subsystem can be obtained
from the CAEngine.
- - - - -
8965e8b4 by Michal Travnicek at 2025-04-11T17:03:52+02:00
Fix empty parameter in CLI
- - - - -
6185addf by Michal Travnicek at 2025-04-11T17:03:52+02:00
Revert removing blank arguments in nssdb.py
Block blank nicknames in adding subsystem_certs
- - - - -
cbd7c22b by Marco Fargetta at 2025-04-11T18:03:05+02:00
Fix CLI debug
With the update in httpclient the response object is not a
BasicHttpResponse instance so the output was not printed when executed
in debug mode.
Since the entity operation are provided in the HttpResponse interface
there is no need to identify the real instance class.
- - - - -
233a282d by Marco Fargetta at 2025-04-11T18:03:05+02:00
Converting a CLI HTTP GET to httpclient
PKIClient implement several GET operations. One of these operation is
converted from RESTEasy client to apache httpcomponent-client to verify
the implementation.
- - - - -
dbe4ee47 by Marco Fargetta at 2025-04-11T18:03:05+02:00
Fix error handling for httpcomponent client connections
The reported exception is the exception associated with the problem and
it contains the error reason only if provided by the server.
The previous code was using a generic PKIException with error code
provided by resteasy which will have a default message.
- - - - -
92e18909 by Marco Fargetta at 2025-04-11T18:03:05+02:00
Update exception message in CI for the httpclient connections
- - - - -
f6cc5d8b by Marco Fargetta at 2025-04-11T18:03:05+02:00
Add dedicated exception for client connection problem
The new ClientConnectionException replace the ProcessingException
provided by RESTeasy library.
- - - - -
0a752706 by Endi S. Dewata at 2025-04-11T11:05:11-05:00
Refactor CAEngine.createCA()
The CAEngine.createCA() has been modified such that it calla
createAuthorityRecord() to create the AuthorityRecord with the
signing cert then calls another createCA() to create the CA
object.
- - - - -
51293959 by Endi S. Dewata at 2025-04-11T18:40:41-05:00
Update log messages in CAEngine
- - - - -
da22ae0a by Endi S. Dewata at 2025-04-11T18:40:41-05:00
Update log messages in SigningUnit
- - - - -
e9b011b6 by Endi S. Dewata at 2025-04-11T18:40:41-05:00
Update log messages in OCSPServlet
- - - - -
d49e7fbb by Marco Fargetta at 2025-04-14T18:26:02+02:00
Implement client GET collections with httpclient
Collections have no explicit mapping so they require additional steps
for their serialisation.
Note: XML message are not generated from the server for a bug so the
client to handle them has not been implemented.
- - - - -
a3d6e3ac by Endi S. Dewata at 2025-04-14T15:49:04-05:00
Update AuthorityRepository.createCA()
The AuthorityRepository.createCA() has been modified to create
just the authority record and the signing cert, but the CA object
will only be created later by the AuthorityMonitor when it detects
the new authority record in DS.
The AuthorityService.createCA() has been updated to call
AuthorityRepository.createCA() as well.
The CAEngine.createCA() is no longer used so it has been removed.
- - - - -
24730f9f by Marco Fargetta at 2025-04-15T09:47:13+02:00
Implement client DELETE with httpclient
- - - - -
7755f5e5 by Marco Fargetta at 2025-04-15T09:47:13+02:00
Implement client POST,PUT and PATCH with httpclient
- - - - -
fbf64d60 by Marco Fargetta at 2025-04-15T10:41:51+02:00
Replace erroneous resteasy MediaType from v2 servlet
- - - - -
efe8cf4a by Marco Fargetta at 2025-04-15T10:47:40+02:00
Replace erroneous resteasy exception from v2 servlet
- - - - -
1cd6d36e by Endi S. Dewata at 2025-04-15T09:50:57-05:00
Update CertClient.list_requests() to support REST API v2
The CertClient.list_requests() has been updated to use the proper
URL for the REST API version.
The CA Python API tests have been updated to list cert requests
using the updated Python API.
- - - - -
465edf1e by Endi S. Dewata at 2025-04-15T14:19:06-05:00
Move AuthorityMonitor.authorities into CAEngine
The authorities map in AuthorityMonitor has been moved into
CAEngine and can only be accessed through synchronized methods
to avoid race conditions. Later there might be additional fields
that will be moved from AuthorityMonitor to CAEngine as well.
The CAEngine.getCA() has been modified to look for the requested
CA object in the map. If the CA object doesn't exist it will be
loaded from the database and stored in the map.
The code in AuthorityMonitor.addCA() and remove() that updates
the authorities map has been moved into CAEngine as well.
- - - - -
d3144444 by Endi S. Dewata at 2025-04-15T14:42:26-05:00
Add AuthorityMonitor.init()
The code that initializes the AuthorityMonitor in CAEngine has
been moved into AuthorityMonitor.init().
- - - - -
ae26d934 by Endi S. Dewata at 2025-04-16T09:22:13-05:00
Move CryptoUtil.parseCRMFMsgs() to CRMFUtil
- - - - -
2c7413e4 by Endi S. Dewata at 2025-04-16T09:35:27-05:00
Move CertUtil.parseCRMF() to CRMFUtil
- - - - -
08c8d87e by Endi S. Dewata at 2025-04-16T09:35:27-05:00
Move CertUtil.encodeCRMF() to CRMFUtil
- - - - -
1a739bc5 by Endi S. Dewata at 2025-04-16T09:35:27-05:00
Move CryptoUtil.getX509KeyFromCRMFMsg() to CRMFUtil
- - - - -
9cf32f78 by Endi S. Dewata at 2025-04-16T09:35:27-05:00
Move CryptoUtil.getX509KeyFromCRMFMsgs() to CRMFUtil
- - - - -
b6cd7c75 by Endi S. Dewata at 2025-04-16T09:35:27-05:00
Move CryptoUtil.getSubjectName() to CRMFUtil
- - - - -
0729dd7a by Endi S. Dewata at 2025-04-16T09:40:29-05:00
Move CryptoUtil.getExtensionFromCertTemplate() to CRMFUtil
- - - - -
311edc81 by Endi S. Dewata at 2025-04-16T09:40:29-05:00
Move CryptoUtil.createCertTemplate() to CRMFUtil
- - - - -
ff4e55fc by Endi S. Dewata at 2025-04-16T09:44:52-05:00
Move CryptoUtil.createCertRequest() to CRMFUtil
- - - - -
b0f67bbf by Endi S. Dewata at 2025-04-16T09:49:37-05:00
Move CryptoUtil.createPop() to CRMFUtil
- - - - -
8b521951 by Endi S. Dewata at 2025-04-16T09:51:28-05:00
Move CryptoUtil.createCRMFRequest() to CRMFUtil
- - - - -
850a5bec by Marco Fargetta at 2025-04-16T10:54:20-05:00
Remove resteasy MediaType from PKIClient
The MediaType class in PKI has been renamed to MimeType since it
contains only MimeTypes.
- - - - -
a836ff5e by Endi S. Dewata at 2025-04-16T18:10:11-05:00
Clean up CRMFUtil.getExtensionFromCertTemplate()
- - - - -
4282b97b by Endi S. Dewata at 2025-04-17T10:29:50-05:00
Refactor CRMFUtil.encodeCRMF()
The CRMFUtil.encodeCRMF() has been updated to take a sequence
of CRMF messages.
- - - - -
01d3c841 by Endi S. Dewata at 2025-04-17T10:29:51-05:00
Refactor CRMFUtil.createCRMFRequest()
The CRMFUtil.createCRMFRequest() has been updated to return a
sequence of CRMF messages.
- - - - -
7be3c544 by Endi S. Dewata at 2025-04-17T10:29:51-05:00
Refactor CRMFUtil.createCertRequest()
The CRMFUtil.createCertRequest() has been updated to take a list
of extensions.
- - - - -
1d669d73 by Endi S. Dewata at 2025-04-17T10:29:53-05:00
Refactor NSSDatabase.createCRMFRequest()
The NSSDatabase.createCRMFRequest() has been updated to take
a list of extensions.
- - - - -
367e3271 by Endi S. Dewata at 2025-04-17T12:18:58-05:00
Refactor NSSDatabase.createCertificate()
The NSSDatabase.createCertificate() has been updated to take
a public key and a subject name.
- - - - -
bdfa9d68 by Endi S. Dewata at 2025-04-17T12:21:36-05:00
Add CRMFUtil.getSANExtension()
The CRMFUtil.getSANExtension() has been added to find a SAN
extension from a CRMF request.
- - - - -
86dbd473 by Endi S. Dewata at 2025-04-17T12:21:36-05:00
Update KRA container test
The test for KRA container has been updated to enroll a server
cert.
- - - - -
391d420a by Endi S. Dewata at 2025-04-17T16:49:32-05:00
Convert RA_Client::OpConnStart() to Java
The formatToken(), resetPIN(), and enrollToken() in TPSClientCLI
have been updated to support running multiple operations using
multiple threads.
The original RA_Client::OpConnStart() has been moved into
tpsclient.cpp.
- - - - -
b62aaa0d by Endi S. Dewata at 2025-04-17T18:03:30-05:00
Refactor ThreadConnUpdate()
The code that formats the token has been moved into FormatToken().
The remaining code in ThreadConnUpdate() has been moved into
tpsclient.cpp.
- - - - -
f2f890f8 by Endi S. Dewata at 2025-04-17T18:03:30-05:00
Refactor ThreadConnResetPin()
The code that resets the PIN in ThreadConnResetPin() has been
moved into ResetPIN(). The remaining code in ThreadConnResetPin()
has been moved into tpsclient.cpp.
- - - - -
e6f18001 by Endi S. Dewata at 2025-04-17T18:03:30-05:00
Refactor ThreadConnEnroll()
The code that enrolls the token in ThreadConnEnroll() has been
moved into EnrollToken(). The remaining code in ThreadConnEnroll()
has been moved into tpsclient.cpp.
- - - - -
f564ea4d by Endi S. Dewata at 2025-04-17T18:15:58-05:00
Move CAEngine.initCertSigningUnit() into CertificateAuthority
- - - - -
d8ded49e by Endi S. Dewata at 2025-04-17T18:16:41-05:00
Move CAEngine.initCRLSigningUnit() into CertificateAuthority
- - - - -
ce296b54 by Endi S. Dewata at 2025-04-17T18:17:19-05:00
Move CAEngine.initOCSPSigningUnit() into CertificateAuthority
- - - - -
22bf885d by Endi S. Dewata at 2025-04-17T18:17:20-05:00
Move CAEngine.startKeyRetriever() into CertificateAuthority
- - - - -
81ce5b42 by Endi S. Dewata at 2025-04-18T10:17:25-05:00
Add connection methods in TPSClientCLI
The code that manages the connection in TPSClientCLI has been
moved into separate methods.
- - - - -
72f7b11a by Endi S. Dewata at 2025-04-18T10:17:29-05:00
Add token methods in TPSClientCLI
The code that manages the token in TPSClientCLI has been
moved into separate methods.
- - - - -
451cc4d0 by Endi S. Dewata at 2025-04-18T10:17:34-05:00
Use synchronous LWCA KeyRetriever
The CertificateAuthority.startKeyRetriever() has been modified
to use a synchronous KeyRetriever to ensure that the LWCA has
the signing key before it can be used.
https://github.com/dogtagpki/pki/issues/4677
- - - - -
02ddc399 by Endi S. Dewata at 2025-04-18T12:58:18-05:00
Move CAEngine.initCA() into CertificateAuthority
- - - - -
6fc69d9f by Endi S. Dewata at 2025-04-18T12:58:21-05:00
Move CAEngine.checkForNewerCert() into CertificateAuthority
- - - - -
83d5a7a2 by Endi S. Dewata at 2025-04-18T15:02:04-05:00
Rename KeyRetrieverRunner.certificateAuthority
- - - - -
d46acd40 by Endi S. Dewata at 2025-04-21T09:02:37-05:00
Update FormatToken(), ResetPIN(), EnrollToken()
The FormatToken(), ResetPIN(), and EnrollToken() have been
updated to take a collection of extensions.
- - - - -
1b125b98 by Endi S. Dewata at 2025-04-21T11:17:29-05:00
Convert TPSClientCLI.performFormatToken() to Java
The TPSClientCLI.performFormatToken() has been replaced with
performOperation() which is written in Java and calls native
methods.
The original FormatToken() has been moved to tpsclient.cpp.
- - - - -
915fdc7c by Endi S. Dewata at 2025-04-21T11:17:29-05:00
Convert TPSClientCLI.performResetPIN() to Java
The TPSClientCLI.performResetPIN() has been replaced with
performOperation() which is written in Java and calls native
methods.
The original ResetPIN() has been moved to tpsclient.cpp.
- - - - -
3606a8ec by Endi S. Dewata at 2025-04-21T11:17:29-05:00
Convert TPSClientCLI.performEnrollToken() to Java
The TPSClientCLI.performEnrollToken() has been replaced with
performOperation() which is written in Java and calls native
methods.
The original EnrollToken() has been moved to tpsclient.cpp.
- - - - -
91214960 by Endi S. Dewata at 2025-04-21T12:13:43-05:00
Merge formatToken(), resetPIN(), enrollToken()
The formatToken(), resetPIN(), enrollToken() in TPSClientCLI
have been merged into performOperations().
- - - - -
07055839 by Endi S. Dewata at 2025-04-21T12:22:53-05:00
Refactor HandleLoginRequest()
The HandleLoginRequest() has been merged into TPSClientCLI.
The original code has been moved into tpsclient.cpp.
- - - - -
6209025f by Endi S. Dewata at 2025-04-21T12:22:53-05:00
Refactor HandleExtendedLoginRequest()
The HandleExtendedLoginRequest() has been merged into TPSClientCLI.
The original code has been moved into tpsclient.cpp.
- - - - -
690711fb by Endi S. Dewata at 2025-04-21T12:22:53-05:00
Refactor HandleStatusUpdateRequest()
The HandleStatusUpdateRequest() has been merged into TPSClientCLI.
The original code has been moved into tpsclient.cpp.
- - - - -
93c7fc6c by Endi S. Dewata at 2025-04-21T12:22:53-05:00
Refactor HandleSecureIdRequest()
The HandleSecureIdRequest() has been merged into TPSClientCLI.
The original code has been moved into tpsclient.cpp.
- - - - -
5edd857c by Endi S. Dewata at 2025-04-21T12:22:53-05:00
Refactor HandleASQRequest()
The HandleASQRequest() has been merged into TPSClientCLI.
The original code has been moved into tpsclient.cpp.
- - - - -
34e21809 by Endi S. Dewata at 2025-04-21T12:22:53-05:00
Refactor HandleTokenPDURequest()
The HandleTokenPDURequest() has been merged into TPSClientCLI.
The original code has been moved into tpsclient.cpp.
- - - - -
b76f2cde by Endi S. Dewata at 2025-04-21T12:22:53-05:00
Refactor HandleNewPinRequest()
The HandleNewPinRequest() has been merged into TPSClientCLI.
The original code has been moved into tpsclient.cpp.
- - - - -
0ccb674b by Endi S. Dewata at 2025-04-22T11:27:06-05:00
Add Python SubsystemClient
- - - - -
fc201f2c by Endi S. Dewata at 2025-04-22T11:27:06-05:00
Update CertClient to support REST API v2
The remaining methods in CertClient have been updated to use
the proper URL for the REST API version.
- - - - -
503a1158 by Endi S. Dewata at 2025-04-22T11:27:06-05:00
Update AuthorityClient to support REST API v2
The AuthorityClient has been updated to use the proper URL for
the REST API version.
- - - - -
dff5f493 by Endi S. Dewata at 2025-04-22T11:27:06-05:00
Update ProfileClient to support REST API v2
The ProfileClient has been updated to use the proper URL for
the REST API version.
- - - - -
d5026fa7 by Endi S. Dewata at 2025-04-22T11:27:06-05:00
Update SystemCertClient to support REST API v2
The SystemCertClient has been updated to use the proper URL for
the REST API version.
- - - - -
bc4170c5 by Endi S. Dewata at 2025-04-22T11:27:06-05:00
Update FeatureClient to support REST API v2
The FeatureClient has been updated to use the proper URL for
the REST API version.
- - - - -
390b13fc by Endi S. Dewata at 2025-04-22T11:27:06-05:00
Update SecurityDomainClient to support REST API v2
The SecurityDomainClient has been updated to use the proper URL
for the REST API version.
- - - - -
850c00b1 by Endi S. Dewata at 2025-04-22T11:27:06-05:00
Update SystemConfigClient to support REST API v2
The SystemConfigClient has been updated to use the proper URL
for the REST API version.
- - - - -
79aa44f1 by Marco Fargetta at 2025-04-23T21:24:54+02:00
Replace WebTarget with URIBuilder in PKI client
PKI client URL are built from the initial URI using the
httpcomponent-client URIBuilder.
- - - - -
2bf1184b by Rob Crittenden at 2025-04-24T11:36:03+02:00
Allow searching for certs by the issuerDN of the cert
This was possible to do by directly using the REST API
but the client library did not have a provision for it.
Signed-off-by: Rob Crittenden <rcritten at redhat.com>
- - - - -
43a527ae by Marco Fargetta at 2025-04-24T11:51:02+02:00
Fix postgres library for CI tests
- - - - -
34823e48 by Marco Fargetta at 2025-04-24T11:51:32+02:00
Fix postgres library path in EST doc installation
- - - - -
f382d87d by Endi S. Dewata at 2025-04-24T10:57:22-05:00
Fix pki-server <subsystem>-clone-prepare
The pki-server <subsystem>-clone-prepare has been updated to
support optional audit signing cert.
The PKISubsystem.export_system_cert() has been modified to
generate a more user-friendly error message.
The basic clone tests have been updated to no longer use audit
signing certs.
Resolves: https://github.com/dogtagpki/pki/issues/5053
- - - - -
74a64d6f by Marco Fargetta at 2025-04-25T00:41:34+02:00
Disable password console callback if file provided
When a password file is provided to the CLI then all password are read
from that file and no requests are done to the user if a token misses
password.
Missing password tokens are reported in verbose or debug mode.
The console password callback is still used if the user provides
password for individual tokens.
Fix issue #5045.
- - - - -
b33b5b8e by Marco Fargetta at 2025-04-30T20:42:41+02:00
Remove RESTeasy from EST subsystem
EST implementation has been converted from RESTEasy to PKIServlet in
order to work with a similar approach of rest APIs v2.
It is important to notice that EST subsystem does not fully implement
the CMSEngine and it does not use the subsystem authentication plugins
handled by the PKIRealm so the ACL and AuthMethod filters cannot work.
The authentication and authorisation is managed with the tomcat realm
and several specific controls implemented in EST subsystem. As a result
the migration to PKIServlet has not modified how EST is configured and
used.
- - - - -
9c5e4884 by Marco Fargetta at 2025-04-30T20:42:41+02:00
Upedate EST CI to read JSON error message
With migration to PKIServlet error messages are in JSON while
they where in XML.
- - - - -
f75662f0 by Endi S. Dewata at 2025-05-02T13:51:02-05:00
Update clone tests to check replica ID ranges
The CA and KRA clone tests have been modified to check the
changes to replica ID ranges throughout the cloning process
to prevent regressions.
Some scripts have been added to check replica ID ranges in
CS.cfg and DS.
- - - - -
26bb025a by Endi S. Dewata at 2025-05-02T13:59:25-05:00
Clean up pki pkcs12-cert-del output
- - - - -
6efb2328 by Endi S. Dewata at 2025-05-02T13:59:25-05:00
Clean up pki pkcs12-key-del output
- - - - -
1cd483ba by Endi S. Dewata at 2025-05-02T19:44:31-05:00
Clean up pki pkcs12-cert-import output
- - - - -
e8cc9930 by Endi S. Dewata at 2025-05-02T19:54:45-05:00
Update log messages in CertRequestService
- - - - -
c76c1467 by Endi S. Dewata at 2025-05-02T19:54:45-05:00
Update log messages in CertRequestServlet
- - - - -
a1d42ecb by Endi S. Dewata at 2025-05-02T19:54:45-05:00
Update log messages in AgentCertRequestServlet
- - - - -
f0f6e7a5 by Endi S. Dewata at 2025-05-05T10:51:23-05:00
Add KRA clone failover test
A new test has been added to install a CA with multiple KRAs
and perform cert enrollments with key archival to verify the
KRA failover functionality.
The test is currently failing as reported in this bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2363834
- - - - -
cac5a686 by Marco Fargetta at 2025-05-06T10:24:58+02:00
Fix client redirect strategy
Redirect during CLI operations are followed without user interaction
even the HTTP specification for 302 status recommend to follow only GET
operations without user interaction.
The correct solution should be to have tomcat returning status 307 but this
cannot be configured for moving from unsecure to secure connections.
Fix the #5054
- - - - -
cc1241d1 by Endi S. Dewata at 2025-05-06T09:16:32-05:00
Update standalone KRA test
The test for standalone KRA has been updated to install the
KRA without a security domain while the CA is down. The KRA
connector in CA and the CA subsystem user in KRA will be set
up after installation by the admin user from a separate
client container.
In the future all KRA installations might be done this way
to reduce the complexity of the installation code and to
make it more reliable (i.e. less dependent on a running CA).
The pki-server status has also been updated to support KRA
that does not have any security domain params.
- - - - -
24b31c76 by Marco Fargetta at 2025-05-06T17:25:34+02:00
Fix EST id when running in different context
- - - - -
5fe4e2c8 by Marco Fargetta at 2025-05-06T17:26:56+02:00
Removed not used RESTeasy dependencies
RESTeasy client has been replaced from all CLI and EST subsystem has
moved to plain servlet approach so library dependencies are updated
accordingly.
- - - - -
4009a4f4 by Endi S. Dewata at 2025-05-06T15:11:50-05:00
Update standalone OCSP test
The test for standalone OCSP has been updated to install the
OCSP without a security domain while the CA is down. The CRL
publishing will be set up after installation.
In the future all OCSP installations might be done this way
to reduce the complexity of the installation code and to
make it more reliable (i.e. less dependent on a running CA).
The pki-server status has also been updated to support OCSP
that does not have any security domain params.
- - - - -
af396a9b by Marco Fargetta at 2025-05-08T11:32:12+02:00
Remove resteasy client jar link
- - - - -
a0f227a7 by Endi S. Dewata at 2025-05-08T09:13:26-05:00
Add pki-server tps-connector-find
The pki-server tps-connector-find has been added to list the
connectors in TPS.
- - - - -
cee1e102 by vzlamal at 2025-05-08T08:38:03-07:00
remove substitutions that broke the code block
- - - - -
68637579 by vzlamal at 2025-05-08T08:38:03-07:00
remove substitutions that broke the code block
- - - - -
cf82ddd8 by vzlamal at 2025-05-08T08:38:03-07:00
changing commands to use pki export csr instead of parsing it with sed
- - - - -
8904738d by vzlamal at 2025-05-08T08:38:03-07:00
fix broken formating in installing-ca-with-existing-keys-in-hsm.adoc
- - - - -
41d966dd by Marco Fargetta at 2025-05-09T09:38:58+02:00
Implement ACME service with PKIServlet
ACME implementation has been converted from RESTEasy to PKIServlet in
order to work with a similar approach of rest APIs v2.
It is important to notice that ACME subsystem does not fully implement
the CMSEngine and it does not use the subsystem authentication plugins
handled by the PKIRealm so the ACL and AuthMethod filters cannot work.
The authentication and authorisation is managed with the tomcat realm
and several specific controls implemented in ACME subsystem. As a result
the migration to PKIServlet has not modified how ACME is configured and
used.
- - - - -
df22b136 by Marco Fargetta at 2025-05-09T09:38:58+02:00
Remove RESTEasy based services from ACME
- - - - -
fbf822d9 by Endi S. Dewata at 2025-05-09T09:59:33-07:00
Update TPS container test
The TPS container test has been updated to import KRA transport
cert into TKS which will be needed later by TPS.
The pki-server cert-import and PKIInstance.cert_import() have
been modified such that the cert ID param is optional to allow
the command to be used to import non-system certs into the
server's NSS database.
The PKIDeployer.create_cs_cfg() has been updated to merge the
template CS.cfg from /usr/share/pki into the existing CS.cfg
in the instance without overwriting existing params.
- - - - -
67e6e22b by Marco Fargetta at 2025-05-12T17:45:22+02:00
Fix pki CLI help commands list
A list of java commands is included in the python code to be included in
the help.
The pki help command, or when no command is provided, returns a list of
commands based on the initialised python CLI modules ignoring the commands
implemented by the java CLI. The new list include these and it is
printed in the help so all possible commands are shown.
Fixes: #5061
- - - - -
63e7c593 by Endi S. Dewata at 2025-05-13T07:26:45-07:00
Add pki-server tps-connector-add
The pki-server tps-connector-add has been added to create CA,
KRA, and TKS connectors in TPS.
The TPS container test has been updated to create TPS subsystem
users in CA, KRA, and TKS and the corresponding connectors in
TPS.
The code that creates the connectors in PKIDeployment has been
moved into TPSSubsystem.add_connector().
The TPSSubsystem.get_connector() has been modified to return
None if the connector doesn't exist.
- - - - -
2be5a6d2 by Endi S. Dewata at 2025-05-13T13:14:10-05:00
Consolidate CryptoUtil.generateKey()
- - - - -
75a8aecc by Endi S. Dewata at 2025-05-13T19:01:17-05:00
Add pki nss-key-export --session-key-size
- - - - -
f576c319 by Endi S. Dewata at 2025-05-13T19:01:17-05:00
Add pki nss-key-export --wrapper-cert
- - - - -
3576dbc6 by Marco Fargetta at 2025-05-14T13:04:19+02:00
Remove redundant code from EST spawn
- - - - -
8db49e17 by Endi S. Dewata at 2025-05-14T09:37:30-05:00
Add pki-server tks-connector-* commands
The pki-server tks-connector-find and tks-connector-add commands
have been added to manage connectors in TKS.
The TPS container test has been updated to add a TPS connector
in TKS and create a shared secret for TKS and TPS.
- - - - -
741a749d by Endi S. Dewata at 2025-05-15T08:32:22-05:00
Update TPS container test
The TPS container test has been updated to set up the user
auth database, add a token, format the token, enroll the
token, and reset the PIN.
The pki-tps-run script has been updated to require the base
DN of the user auth database.
- - - - -
114c7de0 by Pritam Singh at 2025-05-16T15:45:08+05:30
Update creating-ds-instance.adoc (#5076)
Added sed regexp fix for "Customize the DS configuration file"
- - - - -
71f00686 by Marco Fargetta at 2025-05-19T12:50:14+02:00
Fix P12 constraint configuration key
The key for cracklib check has been fixed. It was not loaded if the
other constraints were not present.
- - - - -
e481ef27 by Marco Fargetta at 2025-05-20T09:20:16+02:00
Add a new profile input for client information
Implement a new profile input `RAClientAuthInfoInput` for information
about client authentication.
When a RA send an enrollment request to the CA the new input allows to
provide information about the client originating the request in order to
implement ad-hoc policy. This could be relevant for some enrollment
such as EST.
- - - - -
5d0238c7 by Marco Fargetta at 2025-05-20T09:20:16+02:00
Modify EST to send client information
The CA could implement specific policy about the certificates to return
during EST enrollment. Client authentication information are provided to
the CA in order to implement such policies.
- - - - -
45142b5e by Endi S. Dewata at 2025-05-20T10:07:07-05:00
Add MCP server prototype
A prototype of MCP server has been added to demonstrate
accessing PKI services using LLM.
A new test has been added to install CA with MCP server,
install Ollama with Llama 3.2, then run MCP CLI to find
CA users.
https://github.com/dogtagpki/pki/wiki/Model-Context-Protocol
- - - - -
c8a9e68c by Endi S. Dewata at 2025-05-20T17:27:26-05:00
Add TPSSubsystem.update_profiles()
The code that configures TPS profiles has been moved into
TPSSubsystem.update_profiles().
- - - - -
2ff28cd3 by Endi S. Dewata at 2025-05-21T09:32:41-05:00
Add MCP_TESTS_ENABLED variable
The MCP server test has been modified to run only if the
MCP_TESTS_ENABLED variable is set to 'true'.
The test has also been updated to use a regex that will
work with bulleted and numbered list.
- - - - -
94d3edb6 by Endi S. Dewata at 2025-05-21T09:39:38-05:00
Add pki-server ca-connector-* commands
The pki-server ca-connector-find and ca-connector-add commands
have been added to manage connectors in CA. Some tests have been
updated to use these commands.
- - - - -
43444dc8 by Endi S. Dewata at 2025-05-21T13:07:21-05:00
Replace PKIDeployer.authdb_init() with get_authdb_url()
To improve reusability the PKIDeployer.authdb_init() has been
replaced with get_authdb_url() that returns the URL object of
the authentication database instead of storing it as an
instance attribute.
- - - - -
be348668 by Endi S. Dewata at 2025-05-21T14:51:01-05:00
Fix IPA clone test
- - - - -
817b9829 by Endi S. Dewata at 2025-05-21T21:21:27-05:00
Clean up PKIDeployer.import_ds_ca_cert()
The PKIDeployer.import_ds_ca_cert() has been modified to
return if the cert file to be imported does not exist.
- - - - -
5e063361 by Endi S. Dewata at 2025-05-22T12:26:56-05:00
Update TPS container
The pki-tps-run script has been modified to no longer require
the authorization database URL and base DN params. Instead,
these params can be configured directly in the CS.cfg. This
will reduce the number of params required to start the TPS
container.
The PKIDeployer.init_subsystem() has been modified to set
up the connection to the authentication database only if
the base DN is specified.
The default minimum connection param in TPS's CS.cfg has been
changed to 0 such that the TPS container can start without
creating a connection to the authentication database.
- - - - -
7de63d6d by Endi S. Dewata at 2025-05-22T13:45:00-05:00
Update PKIDeployer.ds_connect()
To improve reusability the PKIDeployer.ds_connect() has been
modified to take a URL object and return the DS connection
object of instead of storing it in PKIDeployer instance.
- - - - -
3015f366 by Endi S. Dewata at 2025-05-22T16:57:59-05:00
Clean up log messages in PKIInstance.load_external_certs_conf()
- - - - -
80816753 by Endi S. Dewata at 2025-05-22T17:52:42-05:00
Convert PKIDeployer.ds_init() into get_ds_url()
To improve reusability the PKIDeployer.ds_init() has been
converted into get_ds_url() that returns the URL object of the
internal database instead of storing it in PKIDeployer instance.
- - - - -
d8c32dba by Endi S. Dewata at 2025-05-27T09:31:02-05:00
Fix NPE in pki ca-kraconnector-add
The CAClient.addKRAConnector() has been updated to get the
Error field from the Response node.
- - - - -
8ed1bb07 by Rob Crittenden at 2025-05-27T19:22:35-05:00
Add python API for ACME enable/disable
These two new methods return True/False whether the ACME enable
or disable was successful.
This API is needed by IPA to avoid making direct REST calls.
Signed-off-by: Rob Crittenden <rcritten at redhat.com>
- - - - -
4f8bcdca by Fraser Tweedale at 2025-05-27T19:32:11-05:00
Update python API to support raw profiles
Fixes: https://github.com/dogtagpki/pki/issues/1928
- - - - -
ecfc9517 by Rob Crittenden at 2025-05-27T19:32:11-05:00
Update python API to support raw profiles (modify)
Part of: https://github.com/dogtagpki/pki/issues/1928
- - - - -
9eedd7a5 by Fraser Tweedale at 2025-05-27T19:38:32-05:00
python api: add SecurityDomainClient.remove_host()
- - - - -
cb657c08 by Rob Crittenden at 2025-05-27T19:40:50-05:00
Handle a missing request_url in the cert request REST output
In the class request_url defaults to None. If it isn't present in
in the json attributes the request_id can't be determined and ends
up as the string 'None'.
If request_url isn't present then use requestID instead.
Signed-off-by: Rob Crittenden <rcritten at redhat.com>
- - - - -
894eadb4 by Endi S. Dewata at 2025-05-28T10:03:09-05:00
Update TPS container test
The TPS container test has been modified to no longer specify
the PKI_DS_URL and PKI_DS_PASSWORD params for each container
which will make it easier to start and set up the containers.
Instead, the internal database hostnames, port numbers, and
passwords will be configured in the CS.cfg directly, then all
containers will be restarted before running the test.
The PKIDeployer.get_ds_url() has been modified to return None
if the internal database URL is blank.
The PKIDeployer.configure_internal_database() has been updated
to configure the internal database params in CS.cfg only if the
corresponding pkispawn params exist.
- - - - -
17a44731 by Endi S. Dewata at 2025-05-28T10:27:40-05:00
Add upgrade script to enable URL rewrite
An upgrade script has been added to add a RewriteValve and
create a link to rewrite.config that are missing in instances
created prior to PKI 11.3.
See also:
https://github.com/dogtagpki/pki/commit/f95df455c5f062ef024b91f5bfc95d919c91cfb7
https://github.com/dogtagpki/pki/commit/994d932100c7d335752fe817a7d8757f62439b08
- - - - -
f2757d58 by Endi S. Dewata at 2025-05-29T12:27:26-05:00
Update TPS container test to use generic subsystem users
Normally pkispawn would create subsystem users with a username
that contains the hostname and the port number of the subsystem
(e.g. CA-ca.example.com-8443). However, if the subsystem is
migrated to a different server the username will no longer be
correct and there's no official process to fix it. Also, in a
cloud environment the hostnames of the containers may be random
and not permanent.
To avoid issues or confusions it's recommended to use generic
subsystem users without the hostname or port number in the
username (e.g. CA). The TPS container test has been updated to
use generic subsystem users to demonstrate that it's already
supported by the current code.
In the future pkispawn might be modified to provide params to
change the usernames of the subsystem users.
- - - - -
4074a13e by Marco Fargetta at 2025-05-30T09:32:46+02:00
Add a new profile constraint for subject name
Implement a new profile constraint, named `RAClientAuthSubjectNameContraint`,
to limit the subject name of enrolled certificate when submitted from a diffierent
subsystem
The new constraint get the information for RAClientAuthInput and try to
match the client certificate subject with the one in the CSR or, if the
client was not using TLS authentication, match the client name.
The new constraint implement similar EST policy on the CA.
- - - - -
324e10c2 by Marco Fargetta at 2025-05-30T09:32:46+02:00
Add a pattern params to RAClientAuthSubjectNameContraint
The new params allows to define subject with additional information.
The pattern param has to match with the new subject after replacing the
2 possible values with the actual values:
- $ra_client_name$
- $ra_client_uid$
It is not handled like a regular expression.
The pattern is only used when client certificate is not available.
Finally, the estServiceCert.cfg has been modified to include the new
constraint (enabled) as well as the SubjectNameContraint so the user can
easily modify the policy to apply.
- - - - -
ab5a98c3 by Marco Fargetta at 2025-05-30T09:32:46+02:00
Modify pkispawn to request server certificate when not provided
EST was requesting a certificate using EST profile during pkispawn
instance creation. This is modified to use a server certificate profile.
It requires the right authorisation for the EST user.
- - - - -
e20e49e0 by Marco Fargetta at 2025-05-30T09:32:46+02:00
Update EST CI to the new profile subject contraint
- - - - -
301ae5bb by Marco Fargetta at 2025-05-30T09:32:46+02:00
Verify client group before enforce subject name with RAClientAuthSubjectNameContraint
When RAClientAuthSubjectNameContraint the subject is enforced to match
the client user id or the subject of the client provided certificate.
If the certificate is owned by a CA agent the subject is not enforced.
- - - - -
fc53e971 by Marco Fargetta at 2025-05-30T09:32:46+02:00
Update CI test to verify subject bypass with agent authentication
- - - - -
02c29d97 by Endi S. Dewata at 2025-06-03T11:13:02-05:00
Update pki-server cert-fix
The pki-server cert-fix CLI was originally written for IPA so it
had IPA-specific requirements. The CLI has been updated such that
it's easier to use in non-IPA environments.
The CLI will now provide an optional param to specify a database
user for connecting to the database with basic authentication. By
default it will use the bind DN configured in CS.cfg, but for IPA
it will continue to use uid=pkidbuser,ou=people,o=ipaca.
The CLI will also use ldapmodify instead of ldappasswd (which
requires LDAPI or LDAPS connection) to update the password of the
database user. This way the CLI can be used with a plain LDAP
connection. The CLI will also use the port number from the LDAP
URL, but for IPA it will continue to use 389.
The Offline System Certificate Renewal page has been converted
into AsciiDoc.
Some new tests have been added to renew CA system certs using
pki-server cert-fix CLI without IPA, one with LDAP connection
and another one with LDAPS connection.
- - - - -
d5a86383 by Marco Fargetta at 2025-06-03T20:38:27+02:00
Fix nuxwdog instances
Nuxwdog enabled instances are not working with latest release of systemd
for permission problems.
With the release of systemd version 257 the command
`systemd-ask-password` when executed as user in systemd servive cannot invoke agent for
password request because it is missing privileged. At the same time
cannot execute as system because pkiuser is not authorised.
The TTY agent alternative is not working properly because it is not
linked to the root shell executing the start command.
As a solution the `pki-server-nuxwdog` script is executed with privileged
user but it operates on user keyring. This required a new option with
user name and the possibility for keyring object to operate for a
specific user.
Fix #5085
- - - - -
dbefad46 by Marco Fargetta at 2025-06-03T20:38:27+02:00
Remove acl installation from workflow
Nuxwdog does not use setacl to startup, it has moved to a different
approach.
- - - - -
6040bca4 by Endi S. Dewata at 2025-06-03T14:18:49-05:00
Clean up log messages in NSSDatabase
- - - - -
430a09eb by Endi S. Dewata at 2025-06-03T14:20:05-05:00
Clean up log messages in CAService
- - - - -
50ab03db by Endi S. Dewata at 2025-06-03T14:20:49-05:00
Clean up log messages in ProcessCertReq
- - - - -
5c4097bc by Endi S. Dewata at 2025-06-03T14:21:08-05:00
Clean up log messages in RenewalServlet
- - - - -
ccbeca4c by Endi S. Dewata at 2025-06-03T19:56:01-05:00
Clean up log messages in Profile
- - - - -
56ee456f by Marco Fargetta at 2025-06-04T09:33:49+02:00
Make keyring clear operation on user id
- - - - -
f6068a8b by Endi S. Dewata at 2025-06-04T09:28:58-05:00
Fix pki-server db-schema-upgrade
The PKISubsystem.import_ldif() has been modified to call
ldapmodify with -H <URL> option instead of the obsolete
-h <hostname> option.
The server upgrade test has been updated to test pki-server
db-schema-upgrade which is currently just re-importing the
DS schema.
Resolves: https://github.com/dogtagpki/pki/issues/5086
- - - - -
e0c74aa8 by Christina Fu at 2025-06-04T15:01:00-07:00
trust option needs to be preceded by two '--' instead of '-'.
- - - - -
9e46d03e by Endi S. Dewata at 2025-06-04T18:16:17-05:00
Reorganize server port and user tests
- - - - -
87a9f22b by Marco Fargetta at 2025-06-05T15:53:16+02:00
Update EST CI pkcs12 command to newer option
The CI was using a deprecated option for the password and has been
replaced.
- - - - -
ed0bb297 by Christina Fu at 2025-06-05T09:17:13-07:00
Update README-doc-convention.adoc
Added convention for presentation of replaceable values.
- - - - -
80153feb by Endi S. Dewata at 2025-06-11T10:40:59-05:00
Add internationalization test
The PKIClient.entity() and unmarshall() has been updated
to create the request object and to parse the response
object with UTF-8 encoding.
The SimpleProperties.load() and store() has been updated
to load and to store the profile config file with UTF-8
encoding.
The ConfigStore.store() has been updated to export the
profile config into a raw format with UTF-8 encoding.
The pki <subsystem>-user-add has been modified to accept
a --full-name option for consistency with the pki-server
<subsystem>-user-add command.
The UserShowCLI has been modified to retrieve the correct
fields from the JSON object.
A new test has been added to create a cert profile, enroll
a cert, create a user, then perform client cert auth with
wide characters.
- - - - -
766b34e2 by Endi S. Dewata at 2025-06-11T15:37:54-05:00
Update KRAConnector.deregister() and TPSConnector.deregister()
The KRAConnector.deregister() and TPSConnector.deregister()
have been updated to use password.conf instead of the actual
password and to show the error message if the command fails.
- - - - -
ede420a3 by Endi S. Dewata at 2025-06-13T09:28:21-05:00
Add test for CA cert request templates
The test for CA Python API has been updated to check listing
and retrieving cert request templates with REST API v1 and v2.
- - - - -
2d255b6a by Christina Fu at 2025-06-13T10:05:01-07:00
RHCS-5994 Changes from Test Day CY25Q2
This patch covers some of the Doc change requests from taherrin that require upstream changes from the CY25Q2 Test Day.
https://issues.redhat.com/browse/RHCS-5994
- - - - -
0d63e486 by Christina Fu at 2025-06-16T15:37:08-07:00
RHCS-5927 [DOC] Asciidoc code block rendering issue with [literal,subs="+quotes,verbatim"]
This patch was re-created after https://github.com/dogtagpki/pki/pull/5077 that was provided by community member vzlamal to address the issue where bold and italic in some cases are mis-interpreted where '*' and '_' are intended to be literally part of the code.
Note that there is still a desire to bold the actual commands. This patch is to be considered a temporary fix.
https://issues.redhat.com/browse/RHCS-5927
- - - - -
9f944cd4 by Endi S. Dewata at 2025-06-17T08:36:06-05:00
Add basic test for pki-server CLI
The mandatory positional arguments for pki-server subcommands
have been changed to become optional such that the --help
option can be parsed properly.
A new test has been added to check pki-server help messages.
- - - - -
61f47121 by Endi S. Dewata at 2025-06-20T09:55:17-05:00
Add pki ocsp-cert-verify
The pki ocsp-cert-verify has been added to check the status
of a cert in an OCSP responder. The command can be used by
providing the serial number of the cert or by providing a
file containing DER-encoded OCSP request. In the future this
command might replace OCSPClient.
The basic OCSP test has been updated to check the cert status
using pki ocsp-cert-verify, OCSPClient, and OpenSSL.
- - - - -
be8cc53a by Christina Fu at 2025-06-20T09:45:48-07:00
RHCS-6004-[DOC-dev] Upstream->downstream import for Test Day changes involving upstream
This patch addresses comments from lmcgarry on the patch imported downstream.
https://issues.redhat.com/browse/RHCS-6004
- - - - -
a29205da by Endi S. Dewata at 2025-06-20T19:07:52-05:00
Clean up log messages in DefStore
- - - - -
4e475eff by Endi S. Dewata at 2025-06-23T08:21:36-05:00
Update OCSP clone test
The OCSP clone test has been updated to use a replicated
CRL database in LDAP instead of the default OCSP publishing
in order to provide properly replicated OCSP responders. In
the future OCSP clone installation might be required to use
this mechanism.
https://github.com/dogtagpki/pki/wiki/Setting-up-CRL-Database
https://github.com/dogtagpki/pki/wiki/Publishing-CA-Certificate-to-LDAP-Server
https://github.com/dogtagpki/pki/wiki/Publishing-CRL-to-LDAP-Server
https://github.com/dogtagpki/pki/wiki/Configuring-OCSP-Revocation-Info-Store
- - - - -
6fae9df3 by Endi S. Dewata at 2025-06-23T13:02:24-05:00
Add pki ca-crl-update
The pki ca-crl-update has been added to simplify manual CRL
update.
The deprecation of XMLObject has been removed since the class is
still used in multiple places and generates deprecation warnings.
Once the migration to REST API v2 is complete the class might be
deprecated again.
https://github.com/dogtagpki/pki/wiki/PKI-CA-CRL-CLI
https://github.com/dogtagpki/pki/wiki/UpdateCRL-Service
- - - - -
5ed1f72b by Endi S. Dewata at 2025-06-23T13:06:41-05:00
Refactor CertStatus
The CertStatus interface has been converted into a base class
which stores the label of the cert status. The code that uses
CertStatus has been updated to use the labels.
- - - - -
9a4c3e1c by Endi S. Dewata at 2025-06-24T09:39:48-05:00
Add test for built-in OCSP in CA clone
The test for CA clone has been updated to validate the
built-in OCSP responder.
- - - - -
2f3efaf3 by Endi S. Dewata at 2025-06-24T18:47:23-05:00
Add CRLAutoUpdateTask
The code in CRLIssuingPoint for updating the CRL automatically
has been moved into CRLAutoUpdateTask.
- - - - -
e7b4eb8d by Endi S. Dewata at 2025-06-24T19:00:06-05:00
Clean up log messages in LogFile.setupSigningFailure()
- - - - -
1d57ec76 by Endi S. Dewata at 2025-06-24T19:10:15-05:00
Update ElementProcessor to use generics
- - - - -
c4711bf7 by Christina Fu at 2025-06-27T10:34:42-07:00
pkidoc-find-unique-ext-links.py finds external linkns in adoc files. (#5143)
This script recursively searches all AsciiDoc (.adoc) files in a given directory.
- - - - -
162e56c5 by Endi S. Dewata at 2025-06-27T16:20:45-04:00
Add pki-server ca-crl-record-show
The pki-server ca-crl-record-show has been added to show
the CRL record in CA database.
- - - - -
74fed842 by Endi S. Dewata at 2025-06-27T16:20:45-04:00
Add pki-server ca-crl-record-cert-find
The pki-server ca-crl-record-cert-find has been added to
list the revoked certs in the CRL record in CA database.
- - - - -
590f28a4 by Endi S. Dewata at 2025-06-27T16:20:45-04:00
Update CRL test to use pki-server ca-crl-record
The CRL test has been updated to use pki-server ca-crl-record
commands to validate the CRL record in CA database.
- - - - -
4178934f by Christina Fu at 2025-06-27T15:13:10-07:00
pkidoc-find-unique-ext-links.py: print file names only instead of full paths and add result output file (#5144)
- print filenames only. Full paths output clutter the display and makes it difficult to read.
- optionally write result to an output file
- delete the accidental checkin of pkidoc-find-unique-ext-links0.py
- - - - -
6bf67f00 by Christina Fu at 2025-06-30T09:29:59-07:00
removing an experimental file used for an exercise with Github Copilot.
- - - - -
6dfc2d90 by Endi S. Dewata at 2025-06-30T15:23:30-04:00
Update server tests to get version number from pom.xml
- - - - -
18936d8f by Endi S. Dewata at 2025-06-30T15:23:30-04:00
Update version number to 11.7.0-beta1
- - - - -
543a88da by Endi S. Dewata at 2025-06-30T16:05:54-04:00
Fix doc links
- - - - -
db2e7fc3 by Endi S. Dewata at 2025-06-30T17:14:08-04:00
Update version number to 11.8.0-beta1
- - - - -
b5c6263d by Super User at 2025-07-01T18:29:49-04:00
Update RESTEasy dependency
- - - - -
5f27ecb7 by Endi S. Dewata at 2025-07-01T18:32:30-04:00
Update NSS dependency
- - - - -
fac32b67 by Endi S. Dewata at 2025-07-01T21:21:23-04:00
Update JSS dependency
- - - - -
4059b4b8 by Endi S. Dewata at 2025-07-09T09:22:40-05:00
Update version number to 11.9.0-alpha1
The build scripts have been modified to generate RPM version
numbers more compliant with Fedora Packaging Guidelines.
https://docs.fedoraproject.org/en-US/packaging-guidelines/Versioning
- - - - -
5379088b by Marco Fargetta at 2025-07-09T20:46:38+02:00
Add ACME support to ES256
Introduce ACME support to ES256 signature algorithm as requested in RFC
8555 section 6.2.
Fix #4638
- - - - -
f8ea9217 by Marco Fargetta at 2025-07-09T20:46:38+02:00
Include ACME test with Caddy web server
Caddy implement its ACME client and it uses ES256 as default signature.
- - - - -
b24f8736 by Fraser Tweedale at 2025-07-17T14:24:23-05:00
Handle some cases of uninitialised SigningUnit
The `CertificateAuthority.mSigningUnit` may be `null` in some cases.
In particular, when a clone does not yet have the keys for some
lightweight CA, its signing unit can be null. Update a handful of
locations to handle this scenario without triggering NPE or similar.
Related: https://issues.redhat.com/browse/RHCS-6003
- - - - -
69067ed6 by Fraser Tweedale at 2025-07-17T19:21:17-05:00
RHCS-6003: Revert "Use synchronous LWCA KeyRetriever"
This reverts commit 451cc4d0202f807ea6c1005744c9adb15435143d.
Making LWCA key retrieval causes hangs on servers to which
lightweight CA keys have not yet been successfully retrieved (e.g.
due to transient issue). The problem arises as follows:
1. AuthorityMonitor thread observes creation of new CA via LDAP
replication.
2. AuthorityMonitor initialises the CertificateAuthority object.
3. At SigningUnit initialisation, observes absence of keys and
initiates key retrieval (synchronously)
4. Key retrieval fails; enters exponential backoff loop
5. CertificateAuthority initialisation is stuck in key retrieval
backoff loop; it does not get added to the CA registry.
6. Separately, `AuthorityService` / `AuthorityServlet` receives a
request related to the CA (e.g. retrieve authority info or cert
chain).
7. Lookup via `AuthorityRepository` locates the data, but no
`CertificateAuthority` object exists for it. Starts the
initialisation process afresh (and hangs).
8. Rinse, repeat. Eventually even unrelated functions can be
impacted due to resource starvation (e.g. no available HTTP
worker threads).
The fix is to revert to asynchronous key retrieval. Happily, the
earlier patch reverted cleanly. The change to synchronous retrieval
was intended to resolve an [issue] with nondeterministic failures
when creating many LWCAs in rapid succession. Further investigation
of that issue hints that the issue may be resource limit related
because LDAP connection failures affect both LWCA creation and key
retrieval. We may need to do further investigation and
experimentation to solve that issue in a different way.
[issue]: https://github.com/dogtagpki/pki/issues/4677.
Fixes: https://issues.redhat.com/browse/RHCS-6003
- - - - -
a3e93c5d by Endi S. Dewata at 2025-07-17T21:29:52-05:00
Update CMake scripts
The PKI_TOMCAT_9_0_JAR variable have been renamed into
PKI_TOMCAT_IMPL_JAR to make it easier to support multiple
Tomcat versions.
- - - - -
11292e8a by Endi S. Dewata at 2025-07-18T14:15:04-05:00
Update dependency to JSS 5.9
- - - - -
00d2e49d by Endi S. Dewata at 2025-08-06T20:10:10-05:00
Update tests for KRA connector
Some tests have been updated to verify the config params for
KRA connector in CA's CS.cfg.
- - - - -
8502e1cb by Marco Fargetta at 2025-08-07T16:58:58+02:00
Replace java_devel dependency in pki-server
pki-server currently requires java_devel but it is not necessary for the
server to work properly.
Since this requirement has many dependencies to desktop related packages it
is replaced with the java_headless dependency which is enough to work.
The only tool used from java_devel is the command jar which has been
replaced by unzip since they support the same format.
- - - - -
6502a25d by Endi S. Dewata at 2025-08-07T12:10:12-05:00
Convert password enforcement test into SSKG test
The password enforcement test has been converted into a server-side
key generation test since it's using the caServerKeygen_UserCert
profile. It has also been updated to reproduce issue #5037 by
approving the pending requests. The issue itself will be fixed
separately later.
https://github.com/dogtagpki/pki/issues/5037
- - - - -
21b17ed5 by Endi S. Dewata at 2025-08-18T21:39:23-05:00
Disable Java Security Manager
- - - - -
14719535 by Endi S. Dewata at 2025-08-18T21:39:23-05:00
Disable RPATH
https://docs.fedoraproject.org/en-US/packaging-guidelines/#_beware_of_rpath
- - - - -
4bae017e by Endi S. Dewata at 2025-08-20T22:45:44-05:00
Update NSSDatabase.addCertificate()
The NSSDatabase.addCertificate() has been updated to return
the new cert added into NSS database.
- - - - -
c04e5ae7 by Endi S. Dewata at 2025-08-20T22:45:54-05:00
Add NSSDatabase.getCertificate()
The NSSDatabase.getCertificate() has been added to get a cert
from NSS database.
- - - - -
01aa3be4 by Endi S. Dewata at 2025-08-20T22:45:54-05:00
Add NSSDatabase.deleteCertificate()
The NSSDatabase.deleteCertificate() has been added to remove
a cert from NSS database.
- - - - -
87bebbf5 by Endi S. Dewata at 2025-08-20T22:45:54-05:00
Update NSSDatabase.add_cert()
The NSSDatabase.add_cert() has been updated to support runas
param.
- - - - -
7f03e1e2 by Endi S. Dewata at 2025-08-20T22:45:54-05:00
Update PKISubsystem.export_system_cert()
The PKISubsystem.export_system_cert() has been updated to use
NSSDatabase.export_pkcs12().
- - - - -
a15cbabb by Marco Fargetta at 2025-08-25T10:28:23+02:00
Revert CertificateAuthority update in KeyRetrieverRunner
During execution of KeyRetrieverRunner the CertificateAuthority could be
updated and the signing unit will not get properly initialised.
This is the case in IPA setup where an external key retriever is
configured as default.
Problem described in https://issues.redhat.com/browse/RHEL-108293
- - - - -
102ca61b by Marco Fargetta at 2025-08-25T10:28:23+02:00
Add IPA LWCA certificate generation in the tests
- - - - -
d824f9ce by Endi S. Dewata at 2025-08-25T13:58:43-05:00
Add reindex step for setting up ACME database
As described in issue #5160 with LMDB backend newly added DS
indexes always need to be rebuilt. For ACME and other subsystems
installed without pkispawn this additional step needs to be done
manually. In the future this step can be integrated into pkispawn
for ACME.
Some ACME tests have been modified to create DS instances with
LMDB backend to demonstrate the additional reindex step. The ACME
docs have been updated as well.
https://github.com/dogtagpki/pki/issues/5160
- - - - -
17319b8a by Marco Fargetta at 2025-08-26T09:39:03+02:00
Add new pki-server <subsystem>-group-add command
Add the CLI to add a new group from the administrator. The command
accept the option `--description` to include a group description and
requres the `group_id`.
- - - - -
6babf254 by Endi S. Dewata at 2025-08-26T21:17:01-05:00
Update basic server test
The basic server test has been updated to check Tomcat and
PKI shared libraries.
- - - - -
8339cb11 by Endi S. Dewata at 2025-08-27T11:58:59-05:00
Add pki-server acme-database-init
The pki-server acme-database-init has been added to simplify
ACME database initialization which includes importing the schema,
creating indexes, rebuilding indexes, and creating the subtree.
The command can only be used after the database is configured,
so some ACME tests have been changed to initialize the database
after the ACME subsystem is created.
- - - - -
c36489f8 by Endi S. Dewata at 2025-08-27T16:30:37-05:00
Update ACME tests to check pki-server acme-<object>-show
- - - - -
719d55d6 by Endi S. Dewata at 2025-08-28T09:32:58-05:00
Add pki-server acme-realm-init
The pki-server acme-realm-init has been added to simplify ACME
realm initialization which includes creating the DS subtrees
for the realm.
The RealmCommon.initRealm() has been added to initialize the
realm. The LDAPRealm has been updated to implement this method
for initializing ACME realm.
The PKISubsystem.run() has been modified to include the entire
Tomcat library which defines the realm classes.
Some ACME tests have been changed to initialize the realm using
this command.
- - - - -
42319d74 by Marco Fargetta at 2025-08-29T13:02:05+02:00
Add new pki-server <subsystem>-acl command group
Add the CLI to allow the administrator to modify the ACL. The command
includes the operation to find, add and delete ACL.
The operation are:
pki-server <subsystem>-acl-find
pki-server <subsystem>-acl-add <acl>
pki-server <subsystem>-acl-del <acl>
To remove the acl it has to exactly match the one in use.
- - - - -
0248c2fe by Endi S. Dewata at 2025-08-29T08:52:04-05:00
Add pki-server acme-database-index-rebuild
The pki-server acme-database-index-rebuild has been added to
simplify rebuilding ACME database indexes. This command can
be used to repair existing instances that are experiencing
issue #5160.
The pki-server acme-database-init has been updated to provide
a --skip-reindex option to demonstrate the issue.
https://github.com/dogtagpki/pki/issues/5160
- - - - -
4d2c4fde by Marco Fargetta at 2025-08-29T18:15:18+02:00
Add pki-server sd-type-add CLI
The new CLI allows to create a new entry in the security domain object
for a new subsystem type. This is neeeded when a new type of subsystem
is introduced.
The new CLI is:
pki-server sd-type-add <subsystem_type>
- - - - -
a74c8adf by Marco Fargetta at 2025-09-01T17:27:01+02:00
Fix update with nuxwdog
Upgrade/migrate script trying to read certificate information from
NSSDB read all the passwords from the related file but if it is not present
then only the password for the current token is read from keyctl. As a
result, the token has to be specified when DB is open or the operation
will fail.
An example of upgrade script accessing certificate information is in
base/server/upgrade/11.5.0/04-RemoveCertCSRfromConfig.py
Fix #4895
- - - - -
fba940ca by Marco Fargetta at 2025-09-23T20:41:43+02:00
Add doc changes for the new commands:
- pki-server sd-type-add
- pki-server <subsystem>-group-add
- pki-server <subsystem>-acl-find
- pki-server <subsystem>-acl-add
- pki-server <subsystem>-acl-del
- - - - -
5d66a109 by Marco Fargetta at 2025-09-24T11:53:28+02:00
Fix CMake build of acme module
- - - - -
da256cb1 by Marco Fargetta at 2025-09-25T09:17:55+02:00
Fix HSM connection and container in actions
Modify the actions to install the p11-kit-client package. It is needed
to connect with remote HSM.
Update owner of podman container generated files when running in the
action. They are owned by the _runner_ user.
- - - - -
8805e85a by Endi S. Dewata at 2025-09-29T17:52:05-05:00
Update IPA tests to check DS server after installation
- - - - -
b118ce47 by Endi S. Dewata at 2025-09-30T17:00:40-05:00
Update CMSEngine.shutdown() to show remaining threads
- - - - -
fd2f0035 by Endi S. Dewata at 2025-09-30T20:00:37-05:00
Add PKIDeployer.system_certs
The PKIDeployer.setup_system_certs() has been modified to
store the results in PKIDeployer.system_certs.
The PKIDeployer.deployer.setup_subsystem_user() has been
modified to use PKIDeployer.system_certs.
- - - - -
aa0612ac by Endi S. Dewata at 2025-10-01T16:20:10-05:00
Update initialization.py
The code that removes the subsystem from the security domain
in initialization.py has been moved into configuration.py.
The code that stops PKI server in initialization.py has been
moved into subsystem_layout.py.
- - - - -
6e0a310f by Endi S. Dewata at 2025-10-01T16:20:10-05:00
Update finalization.py
The code that manages PKI server in finalization.py has been
moved into instance_layout.py and configuration.py.
- - - - -
35c62881 by Endi S. Dewata at 2025-10-02T13:14:55-05:00
Update configuration.py
The code that enables/disables the instance in configuration.py
has been moved into instance_layout.py.
- - - - -
558c613c by Endi S. Dewata at 2025-10-02T17:34:48-05:00
Update instance_layout.py
The code that removes the instance in instance_layout.py has
been modified to use PKIServer.remove().
- - - - -
de198d6e by Marco Fargetta at 2025-10-06T09:31:32+02:00
Fix GET authority APIs
When the authority id cannot be found a 404 error message has to be
sent. It was reporting internal server error to the user.
- - - - -
29208e10 by Endi S. Dewata at 2025-10-06T09:55:50-05:00
Add ACME clone test
A new test has been added to install CA, ACME, and ACME replica,
then perform ACME registration and enrollment.
https://github.com/dogtagpki/pki/wiki/Installing-ACME-Responder-Clone
- - - - -
58305220 by Endi S. Dewata at 2025-10-06T14:22:15-05:00
Update rpminspect test to check RPM content
- - - - -
d3b0094c by Marco Fargetta at 2025-10-07T10:25:10+02:00
Make REST API exception return default to JSON
REST APIs v1 default format for entity is JSON as defined in [1] but in case an
exception is raised the default format is XML.
The PKIException default format is modified to JSON in order to be
consistent.
1. https://github.com/dogtagpki/pki/blob/master/base/server/src/main/java/com/netscape/cms/servlet/base/PKIService.java#L155
- - - - -
424f58d5 by gkimetto at 2025-10-09T08:49:18-04:00
Fix pki-server ca-audit-event-update-update fails with object has no attribute 'event_filter'
Added a fix to resolve a simple argparse issue causing failure in Issue# 5135.
The AuditEventUpdateCLI class parser.add_argument defines the "filter" argument
but the execute method was trying to access "args.event_filter"
Fix: 5135
- - - - -
57dc48af by Endi S. Dewata at 2025-10-09T09:48:21-05:00
Add CLI option to specify DS backend
The pki-server acme-database-init and acme-database-index-rebuild
have been modified to provide an option to specify the DS backend
for creating/rebuilding indexes.
The test for ACME with separate instance has been modified to use
a non-default DS backend.
Note that pkispawn will not be modified to initialize the database
(which is the current behavior when installing ACME with pkispawn).
Instead, for installing the first ACME instance the admin will need
to initialize the database using the above commands after running
pkispawn, and for installing an ACME replica the admin will need to
configure the DS replication separately.
https://github.com/dogtagpki/pki/wiki/PKI-Server-ACME-Database-CLI
https://github.com/dogtagpki/pki/wiki/PKI-Server-ACME-Realm-CLI
- - - - -
e98eae2f by Endi S. Dewata at 2025-10-10T11:14:51-05:00
Change nsPagedSizeLimit default value
The default value for nsPagedSizeLimit in pkidbuser has been
changed to -1 to avoid issues when cloning CA or KRA that uses
Sequential Serial Numbers as reported in PKI Issue #5133.
The pki-server <subsystem>-user-show and <subsystem>-user-mod
have been updated to provide options to inspect and modify the
user's operational attributes including nsPagedSizeLimit and
nsPagedLookThroughLimit.
The basic IPA test has been updated to verify that these
attributes can be inspected and modified using these tools
after installation.
For existing CA or KRA instances, the attribute needs to be
updated manually since the current upgrade mechanism cannot
reliably update the database (e.g. the database might not be
running when the automated upgrade runs which happens when PKI
server is started).
https://github.com/dogtagpki/pki/wiki/PKI-Server-Subsystem-User-CLI
Resolves: https://github.com/dogtagpki/pki/issues/5133
- - - - -
601a6c84 by Endi S. Dewata at 2025-10-13T10:01:40-05:00
Add support for pki-server ca-user-show --attr +
The pki-server ca-user-show has been modified to provide a way
to display all operational attributes in the user's LDAP entry.
https://github.com/dogtagpki/pki/wiki/PKI-Server-Subsystem-User-CLI
- - - - -
d9b4e8e9 by Endi S. Dewata at 2025-10-14T12:37:56-05:00
Move default instance name constant into pki.server
- - - - -
82c71dd1 by Endi S. Dewata at 2025-10-14T12:37:56-05:00
Move Tomcat port constants into pki.server
- - - - -
d532e80e by Endi S. Dewata at 2025-10-14T12:37:56-05:00
Move SELinux labels into pki.server
- - - - -
20bc64c6 by Endi S. Dewata at 2025-10-14T12:37:56-05:00
Convert pki_selinux_config_ports into local variable
- - - - -
80d6ecdd by Endi S. Dewata at 2025-10-14T12:38:44-05:00
Move SELinux methods into PKIServer
- - - - -
6e429cc4 by jmagne at 2025-10-14T16:58:22-07:00
IDM-3425 (#5190)
Complete CI and merge for dogtag-pki changes for f43 to master upstream branch.
This fix allows pki to build and run on either a tomcat 9 or tomcat 10 system.
If pki is built on a tomcat 9 system, it will run on a tomcat 9 platform.
If pki is built on a tomat 10 system, it will run on a tomcat 10 system.
Tomcat 10 is used for platforms >= f43 and >= rhel10.
Fix build.sh to determine the APP_SERVER variable without obtaining it from the spec file.
Account for jdk versions for rhel, different from fedora.
Address review comments.
- - - - -
1333c53b by Endi S. Dewata at 2025-10-14T20:22:59-05:00
Move verify_sensitive_data() into PKIDeployer
- - - - -
a0ef2534 by Endi S. Dewata at 2025-10-14T20:22:59-05:00
Merge initialization.py into PKIDeployer
- - - - -
505191c6 by Endi S. Dewata at 2025-10-14T20:22:59-05:00
Merge infrastructure_layout.py into PKIDeployer
- - - - -
39058397 by Endi S. Dewata at 2025-10-14T20:22:59-05:00
Merge security_databases.py into PKIDeployer
- - - - -
9f215669 by Endi S. Dewata at 2025-10-14T20:22:59-05:00
Merge selinux_setup.py into PKIDeployer
- - - - -
62c200b0 by Endi S. Dewata at 2025-10-14T20:22:59-05:00
Merge keygen.py into PKIDeployer
- - - - -
5488ae14 by Endi S. Dewata at 2025-10-14T20:22:59-05:00
Merge fapolicy_setup.py into PKIServer
- - - - -
c9061cec by Endi S. Dewata at 2025-10-14T20:22:59-05:00
Merge finalization.py into PKIDeployer
- - - - -
46e74390 by Marco Fargetta at 2025-10-15T13:58:42+02:00
Modify EST deployment to match other subsystems
EST subsystem has been modified to use the security domain during the
deployment and this is the default behaviour.
Installing with SD the EST subsystem will use the subsystem certificate
to communicate with the CA. An additional subsystem user is created when
deployed in a separate instance.
Alternatively, standalone 2 step installation is provided and in this
case the sslserver and subsystem certificate have to be generated during
installation.
EST cannot create its own SD since the related APIs are not present.
- - - - -
2704ee4b by Marco Fargetta at 2025-10-15T13:58:42+02:00
Update EST tests to use the new deployment approach
- - - - -
2d7a0d8e by Marco Fargetta at 2025-10-15T13:58:42+02:00
Add EST upgrade script
- - - - -
73106141 by Marco Fargetta at 2025-10-15T13:58:42+02:00
Update EST installation documentation
The EST installation has been modified to work with Security Domain or
in standalone mode like the other subsystem. The documentation has been
updated to match the changes.
Additionally, the new policies for subject matching are included.
- - - - -
9c24f06e by Marco Fargetta at 2025-10-15T13:58:42+02:00
Add EST document for manual upgrade
The upgrade script should perform the update process to allow EST
joining SD but there are conditions where these cannot be updated and
the administrator has to manually update the configuration.
A document describing these steps is included.
- - - - -
dc6fc231 by Marco Fargetta at 2025-10-15T13:58:42+02:00
Fix pylint executable miss in workflow
- - - - -
743df758 by gkimetto at 2025-10-22T08:30:49-04:00
Add helpful error message for missing NSS database password #5163
Updated useful message when "pki client cert request" fails with unfriendly error when NSS password is not provided
Updated message to: "NSS database password required. Use -c <password> to provide NSSDB password."
Fix: #5163
- - - - -
47355e40 by Marco Fargetta at 2025-10-22T17:40:57+02:00
Fix export sslserver CA in case of multiple certificates
- - - - -
d0c4bfe4 by Endi S. Dewata at 2025-10-24T10:54:29-05:00
Add key ID file option
The pki nss-key-create, nss-key-show, and nss-cert-request
commands have been modified to provide an option to specify
a file to store the ID of a new key or to load the ID of an
existing key.
The test for PKI CLI with ECC has been updated to use the
new option.
https://github.com/dogtagpki/pki/wiki/PKI-NSS-Key-CLI
https://github.com/dogtagpki/pki/wiki/Generating-Certificate-Request-with-PKI-NSS
- - - - -
9f3084fa by Endi S. Dewata at 2025-10-27T11:59:55-05:00
Move basic EST test into separate file
- - - - -
3de2e95c by Endi S. Dewata at 2025-10-27T11:59:55-05:00
Update log messages for external commands
- - - - -
2bda65ad by Endi S. Dewata at 2025-10-28T10:26:22-05:00
Add shell/batch mode for PKI CLI
The PKI CLI has been modified to provide a shell/batch mode
to run multiple commands in a single Java process which can
minimize the number of authentications to external resources
(e.g. NSS, HSM, SSL) since it will maintain a single session
across multiple commands.
Some tests have been updated to use PKI CLI in shell/batch
mode.
https://github.com/dogtagpki/pki/wiki/PKI-CLI
Resolves: https://github.com/dogtagpki/pki/issues/2701
- - - - -
8a2c1311 by Endi S. Dewata at 2025-10-29T18:13:56-05:00
Fix incorrect pki-tomcat JAR filename
- - - - -
f6128496 by Marco Fargetta at 2025-10-30T10:17:09+01:00
Add support to ML-DSA
New profiles and installation example are included to deploy a CA using
ML-DSA algorithms in all certificates.
The provided installation example is for ML-DSA-44.
- - - - -
fa92763e by Marco Fargetta at 2025-10-30T12:30:06+01:00
Fix python indent format error
- - - - -
e6f1e91d by Marco Fargetta at 2025-10-31T16:50:24+01:00
Fix keyring exception for missing id
When a password is searched in keyring but it is not present the
following log message fails with a TypeError because the key id is null.
This error is not handled and the startup fails with a message which
make not clear what is generating the problem.
The behaviour is modified to raise a value error which is handled and if
the password cannot be retrieved the final error will be something like:
Exception: No available password to access the token "internal"
- - - - -
1a967eca by Marco Fargetta at 2025-10-31T18:43:25+01:00
Remove log for host-manager and manager
The host-manager and manager web application are not deployed with
dogtag and following the tomcat recommendation [1] the logger should be
removed if the application are not configured.
1. https://tomcat.apache.org/tomcat-10.0-doc/logging.html#Considerations_for_production_usage
- - - - -
55560e0f by Marco Fargetta at 2025-10-31T18:43:25+01:00
Fix missing JAVA_OPTS
In tomcat 10 the JAVA_OPTS is not present in default configuration.
- - - - -
c4c60b44 by Marco Fargetta at 2025-10-31T18:43:25+01:00
Temporary fix for healthcheck
- - - - -
fe07ddb4 by Marco Fargetta at 2025-11-03T17:36:45+01:00
Fix python lint problem with log message
- - - - -
5656f3df by Endi S. Dewata at 2025-11-04T17:36:44-06:00
Update chown commands to use colons
- - - - -
738d7e1b by Endi S. Dewata at 2025-11-05T17:27:26-06:00
Move MainCLI.executeCommands() into CLI
- - - - -
b2dc1999 by Endi S. Dewata at 2025-11-05T19:13:05-06:00
Clean up log messages in PKISubsystem.run()
- - - - -
c2a7d667 by Fraser Tweedale at 2025-11-06T17:31:49+01:00
Use a single worker thread for LWCA key retrieval
Lightweight CA key retrieval is failing in an IPA test scenario
where many sub-CAs are created in rapid succession. The test output
suggests resource exhaustion (e.g. LDAP server connections). The
current implementation spawns a separate, concurrent key retriever
thread for each new LWCA. This behaviour is suspected to be the
cause of the failure.
Modify LWCA key retrieval to use a single retriever thread per
replica. Retrievals are processed sequentially. The exponential
backoff on failure is retained.
The queue behaviour lives in the new `KeyRetrieverWorker` class,
which uses `java.util.Timer` under the hood. `CAEngine`
instantiates a single instance of `KeyRetrieverWorker`, which in
turn starts the single timer thread and manages the queue.
Fixes: https://issues.redhat.com/browse/RHEL-27181
Fixes: https://github.com/dogtagpki/pki/issues/4677
- - - - -
f1ccb46c by Zachary Sherman-Burke at 2025-11-06T16:42:13-05:00
Added upgrade script to add latest version of java to JAVA_HOME in tomcat.conf file
- - - - -
31f59190 by Endi S. Dewata at 2025-11-07T09:03:33-06:00
Update NSSDatabase.get_cert() to use pki nss-cert-export
The NSSDatabase.get_cert() has been updated to use
pki nss-cert-export instead of certutil.
The tools tests have been updated to verify the behavior
of pki nss-cert-show and nss-cert-export commands.
- - - - -
27c25780 by Endi S. Dewata at 2025-11-07T09:05:37-06:00
Update NSSDatabase.get_trust() to use pki nss-cert-show
The NSSDatabase.get_trust() has been updated to use
pki nss-cert-show instead of certutil.
- - - - -
325851d0 by Endi S. Dewata at 2025-11-07T15:16:58-06:00
Update NSSDatabase.create_key()
The NSSDatabase.create_key() has been modified to call
pki nss-key-create with password.conf.
- - - - -
16f6e7fb by Endi S. Dewata at 2025-11-10T18:38:44-06:00
Update NSSDatabase.modify_cert() to use pki nss-cert-mod
The pki nss-cert-mod has been added to modify the trust
flags of an existing cert in NSS database.
The NSSDatabase.modify_cert() has been updated to use
pki nss-cert-mod instead of certutil.
The pki client-cert-mod has also been deprecated since
it uses certutil.
- - - - -
df4c7a41 by jmagne at 2025-11-10T17:27:59-08:00
Fix the SSH config on F43 for certain CI tests. (#5210)
This fix is part of getting old Tomcat 10.1 working under the new CI test changes, which now assumes f43.
- - - - -
d90f13c4 by Marco Fargetta at 2025-11-11T11:25:59+01:00
Add ML-DSA support for certificate request
The `pki client-cert-request` `--algorithm` option can specify the value
"mldsa" and the `--length`` can be 44, 65 (default) or 87.
Similarly, the command `pki nss-cert-request` `--key-type` option can specify the value
"ML-DSA" and the `--key-size` can be 44, 65 (default) or 87.
Finally, the command `pki client-cert-request` has been deprecated.
- - - - -
438655d9 by Endi S. Dewata at 2025-11-11T09:21:57-06:00
Update PKISubsystem.validate_system_cert()
The pki nss-cert-verify has been updated to provide an option
to validate the cert usage.
The PKISubsystem.validate_system_cert() has been updated to use
the new option.
The pki client-cert-validate --certusage option has been
deprecated.
- - - - -
dc960836 by Endi S. Dewata at 2025-11-12T17:17:31-06:00
Update test for pki pkcs12 CLI
The test for pki pkcs12 CLI has been updated to perform more
comprehensive validations.
The pki pkcs12-key-del has been updated to remove references
from the cert to the key being removed to avoid dangling
links.
The pki pkcs12-import has been updated to no longer assign
the default trust flags for CA certs if the --no-trust-flags
option is specified.
- - - - -
da045da8 by Marco Fargetta at 2025-11-13T12:00:55+01:00
Fix update script for EST
Fix type for group operation requireing a set instead of a list.
- - - - -
4055651a by Endi S. Dewata at 2025-11-13T10:27:43-06:00
Convert pki pkcs12-import to Java
Previously pki pkcs12-import was implemented both in Python
to import CA certs using certutil and in Java to import the
remaining certs using JSS. This was needed since JSS was not
able to preserve the nicknames when importing CA certs into
NSS database.
Since the latest JSS does not have that problem anymore, the
pki pkcs12-import has now been fully converted to Java. It
also has been modified to support the --no-ca-certs and
--no-user-certs options for backward compatibility. Some
options have also been deprecated to match the Python code.
The Python pki.cli.pkcs12 module has been removed since it's
no longer used.
The test for CA clone with secure DS has been updated since
certs are returned in a different order due to this change.
- - - - -
fff82b9f by Endi S. Dewata at 2025-11-13T20:11:05-06:00
Update tools tests to check help messages
- - - - -
599930aa by Endi S. Dewata at 2025-11-14T11:30:39-06:00
Update SecurityDomainCLI
The SecurityDomainCLI has been updated to point to the security
domain running on the CA. The ProxyCLI is no longer used so it
has been removed.
- - - - -
4daec6b0 by Endi S. Dewata at 2025-11-14T13:13:00-06:00
Update tests to check pki CLI help messages
- - - - -
d749d8ae by Endi S. Dewata at 2025-11-17T10:36:47-06:00
Update tests to check external commands used in installation
- - - - -
0252a891 by Endi S. Dewata at 2025-11-17T14:55:22-06:00
Drop AuthorityCLI.getAuthorityClient()
- - - - -
3dc4d29c by Endi S. Dewata at 2025-11-17T15:18:10-06:00
Drop CACertCLI.getCertClient()
- - - - -
57355027 by Endi S. Dewata at 2025-11-17T15:18:52-06:00
Drop CA ProfileCLI.getProfileClient()
- - - - -
52298339 by Endi S. Dewata at 2025-11-17T15:25:52-06:00
Drop FeatureCLI.getFeatureClient()
- - - - -
f19c1d61 by Endi S. Dewata at 2025-11-17T15:33:38-06:00
Drop GroupCLI.getGroupClient()
- - - - -
3841fa88 by Endi S. Dewata at 2025-11-17T15:44:03-06:00
Drop SelfTestCLI.getSelfTestClient()
- - - - -
eb45a0d2 by Endi S. Dewata at 2025-11-17T15:54:21-06:00
Drop UserCLI.getUserClient()
- - - - -
b8d3f1a6 by Taylor Herring at 2025-11-18T12:25:07-05:00
Improve maven tomcat dependency section in pki.spec and removed requirement for pki-resteasy to fix CentOS Copr (#5226)
Added >= RHEL10 to conditional in maven tomcat dependency section in pki.spec to cover Centos10 & RHEL 10 distributions
Also removed BuildRequires line for obsolete pki-resteasy package (#5226)
Added a trim function for getting the version ID and ID from /etc/os-release file, since quotes are newly added to this file in centos 10.
- - - - -
6022466d by Endi S. Dewata at 2025-11-18T13:00:18-06:00
Drop unused KRAClient.init()
- - - - -
13cce8dc by Endi S. Dewata at 2025-11-18T13:00:18-06:00
Drop TKSKeyCLI.getTPSConnectorClient()
- - - - -
0f9fa634 by Endi S. Dewata at 2025-11-18T13:00:18-06:00
Drop TPSConnectorCLI.getTPSConnectorClient()
- - - - -
4ee1fe61 by Endi S. Dewata at 2025-11-18T13:00:18-06:00
Drop ActivityCLI.getActivityClient()
- - - - -
5d746613 by Endi S. Dewata at 2025-11-18T13:00:18-06:00
Drop AuthenticatorCLI.getAuthenticatorClient()
- - - - -
d383eb01 by Endi S. Dewata at 2025-11-18T13:00:18-06:00
Drop TPSCertCLI.getTPSCertClient()
- - - - -
5637a800 by Endi S. Dewata at 2025-11-18T13:00:19-06:00
Drop ConnectorCLI.getConnectorClient()
- - - - -
f30f5ee8 by Endi S. Dewata at 2025-11-18T13:00:19-06:00
Drop TPS ProfileCLI.getProfileClient()
- - - - -
03f219d2 by Endi S. Dewata at 2025-11-18T13:00:19-06:00
Drop ProfileMappingCLI.getProfileMappingClient()
- - - - -
ac42b60c by Endi S. Dewata at 2025-11-18T13:00:19-06:00
Drop TokenCLI.getTokenClient()
- - - - -
1ea76f04 by Endi S. Dewata at 2025-11-18T17:58:22-06:00
Update SubsystemCLI.getSubsystemClient() to take PKIClient
- - - - -
723ebc78 by Endi S. Dewata at 2025-11-19T10:25:27-06:00
Update basic KRA test to validate key generation
- - - - -
62e11594 by Endi S. Dewata at 2025-11-19T10:25:52-06:00
Drop SubsystemCLI.login() and logout()
- - - - -
68631e6d by Endi S. Dewata at 2025-11-19T10:25:52-06:00
Drop SubsystemClient.login() and logout()
- - - - -
498bce80 by Endi S. Dewata at 2025-11-19T10:25:52-06:00
Drop unused Client.clients
- - - - -
a4f1f975 by Endi S. Dewata at 2025-11-19T10:25:52-06:00
Update CACertRequestCLI.getCertClient() to take PKIClient
- - - - -
bf0c3060 by Endi S. Dewata at 2025-11-19T10:25:53-06:00
Update ConfigCLI.getConfigClient() to take PKIClient
- - - - -
fb357431 by Endi S. Dewata at 2025-11-19T10:25:53-06:00
Update JobCLI.getJobClient() to take PKIClient
- - - - -
b9f7ace3 by Endi S. Dewata at 2025-11-19T13:28:34-06:00
Update KRAKeyCLI.getKeyClient() to take PKIClient
- - - - -
00f0ec23 by Endi S. Dewata at 2025-11-19T13:28:34-06:00
Update AuditCLI.getAuditClient() to take PKIClient
- - - - -
d8354076 by Endi S. Dewata at 2025-11-19T13:28:34-06:00
Update KRAConnectorCLI.getKRAConnectorClient() to take PKIClient
- - - - -
f4f51f9f by Endi S. Dewata at 2025-11-19T13:28:34-06:00
Update SecurityDomainCLI.getSecurityDomainClient() to take PKIClient
- - - - -
d39388d6 by Endi S. Dewata at 2025-11-19T13:28:34-06:00
Drop CLI.getClient()
- - - - -
65864d82 by Endi S. Dewata at 2025-11-20T10:37:19-06:00
Add SubsystemCommandCLI
The SubsystemCommandCLI has been added to be the super class
of CLI commands that will access a PKI subsystem.
- - - - -
d2fe3b4d by Endi S. Dewata at 2025-11-20T10:41:48-06:00
Add SubsystemCommandCLI.subsystemCLI
The SubsystemCommandCLI.subsystemCLI has been added to point
to the subsystem CLI object so it can be used directly by
subsystem commands.
- - - - -
baa2e60d by Endi S. Dewata at 2025-11-20T17:20:29-06:00
Move SubsystemCLI.execute() into SubsystemCommandCLI
The code that performs subsystem authentication has been
moved from SubsystemCLI.execute() into SubsystemCommandCLI.
- - - - -
14b57aa9 by Marco Fargetta at 2025-11-21T10:34:36+01:00
Rename keytype to MLDSA
Profiles and configuration use key type MLDSA so the command has been
modified to replace the key type from ML-DSA to MLDSA.
- - - - -
b7caa379 by Endi S. Dewata at 2025-11-21T10:29:23-06:00
Update CLIs to use SubsystemCommandCLI.subsystemCLI
- - - - -
d39d576c by Endi S. Dewata at 2025-11-21T23:04:01-06:00
Refactor CommandCLI.createOptions()
The CommandCLI.createOptions() has been modified to define the
default options to improve consistency and reduce duplicates.
- - - - -
21653142 by Marco Fargetta at 2025-11-24T20:30:04+01:00
Fix typo in class RAClientAuthSubjectNameContraint
- - - - -
cb250438 by Marco Fargetta at 2025-11-25T12:27:59+01:00
Add ML-DSA support in key default and constraint
Modify the `keyConstraintImpl` class_id in CA profiles to support the
`keyType` value MLDSA and `keyParameters` 44,65,87 for the ML-DSA
algorithms.
- - - - -
dc33fed6 by Marco Fargetta at 2025-11-25T12:27:59+01:00
Update profile for ML-DSA
All profiles are now accepting ML-DSA signatures and the ML-DSA specific
profiles have been updates to work with key constraints.
- - - - -
c8e127a0 by Marco Fargetta at 2025-11-25T12:27:59+01:00
Update script to add ML-DSA support in profiles
- - - - -
a4512ba7 by Marco Fargetta at 2025-11-26T15:56:50+01:00
Fix all profiles to support ML-DSA after upgrade
The upgrade script has been modified to update all the profiles
available in the instance to include ML-DSA signatures, including the
profile which are not in use by the CA.
- - - - -
b3e33300 by Christina Fu at 2025-11-26T09:30:51-08:00
Implements EST rfc7030 & rfc8951 fullcmc support (#5224)
* Implements EST fullcmc support: rfc7030 & rfc8951
Forwards CMC requests from EST to CA's ProfileSubmitCMCFull endpoint.
Preliminary implementation uses single profile configured in backend.conf.
Reflects fullcmc response status in HTTP response header.
Returns:
- success response in base64 of simple PKI Response
- failure response in base64 of full CMC response
Assisted-by: Claude
IDM-3993
* Add support of cert constraint-based authorization for EST /fullcmc
- Adds CMCAuthForEST authenticator to handle EST-forwarded CMC requests.
* Validate EST subsystem TLS cert using AgentCertAuth
* Validate RA-authenticated client cert via CMC
- Add RAHeaderClientCertSubjectNameConstraint for EST fullcmc
* Reads client cert from HTTP header (via SessionContext)
* Allows agents to request any subject name
* Restricts non-agents to their own certificate subject
- Extract isAgentCert() to EnrollConstraint base class for reuse
- Update RAClientAuthSubjectNameConstraint to use inherited method
- Updates CMCOutputTemplate to set pki-cmc-status header for EST requests
- Adds estFullcmcDeviceCert profile to use new constraint
- Register new constraint in registry.cfg
- Updates CS.cfg to register new authenticator and profile.
Assisted-by: Claude
IDM-4021
- - - - -
3a892a46 by Marco Fargetta at 2025-11-26T20:40:11+01:00
Fix issue with ML-DSA key type
In a previous commit the key type for ML-DSA family algorithm has been
modified from ML-DSA to MLDSA but there were several missed changes
creating problem in some cases.
- - - - -
412a296c by Endi S. Dewata at 2025-11-27T12:00:52+07:00
Remove unused code in CLI.execute()
The code that traverses the CLI hierarchy in CLI.execute()
is no longer used since the MainCLI.executeCommand() and
PKIServerCLI.executeCommand() are using CLI.findModule() to
find the command module to execute directly.
- - - - -
ac756417 by Endi S. Dewata at 2025-11-27T14:21:45+07:00
Add CLI.createOptions()
The CLI.createOptions() has been added to create CLI options
more consistently.
- - - - -
89c5db5c by Endi S. Dewata at 2025-11-27T15:18:14+07:00
Add CLI.parseOptions()
The CLI.parseOptions() has been added to parse CLI options
more consistently.
- - - - -
bd85b32e by Endi S. Dewata at 2025-11-28T07:29:54+07:00
Add SubsystemCommandCLI.getSubsystemClient()
The SubsystemCommandCLI.getSubsystemClient() has been added
to simplify obtaining the client object for a subsystem.
- - - - -
6007947b by Endi S. Dewata at 2025-11-28T07:29:55+07:00
Add SubsystemCommandCLI.getPKIClient()
- - - - -
1eef9cce by Endi S. Dewata at 2025-11-28T07:29:56+07:00
Rename MainCLI.getClient() to getPKIClient()
- - - - -
72109735 by Endi S. Dewata at 2025-11-28T07:29:58+07:00
Update tests to check for warnings during installation
- - - - -
d7dc9d7f by Endi S. Dewata at 2025-12-02T13:02:49-06:00
Add connection params for pki <subsystem>-* commands
Previously the connection params (e.g. server URL, username,
password, nickname) for PKI CLI had to be specified globally
(i.e. pki <connection> <command>) and they would be used by all
commands running in shell/batch mode.
To support connections to multiple servers in shell/batch mode,
the subsystem commands have been modified to provide command-
specific connection params (i.e. pki <subsystem>-* <connection>).
The SubsystemCommandCLI has been modified to define the connection
options for all subsystem commands and also parse the specified
params. If the server URL is specified the command will use the
specified connection params, otherwise it will use the global
connection params.
The pki --http-output option has been added to replace the
--output option to avoid conflicts with existing command
options with the same name.
The Python code used by pkispawn/pkidestroy has been modified
to use the command-specific connection params such that later
it will be able to use the shell/batch mode.
- - - - -
99be58e2 by Marco Fargetta at 2025-12-03T10:50:01+01:00
Add CI for ML-DSA
- - - - -
7039ec82 by Marco Fargetta at 2025-12-03T10:50:01+01:00
Add installation doc for ML-DSA CA
Documentation for CA with ML-DSA key based on the equivalent for ECC
- - - - -
936c4044 by Endi S. Dewata at 2025-12-03T21:56:34+07:00
Add pki ca-sd-join/leave
The pki securitydomain-join/leave commands actually only work
with a security domain running inside the CA, so the commands
have been replaced with pki ca-sd-join/leave commands which
also support command-specific connection params.
In the future all remaining pki securitydomain-* commands will
be replaced with pki ca-sd-* commands.
The Python code used by pkispawn/pkidestroy has been modified
to use the new commands.
- - - - -
ed4f2cd5 by Endi S. Dewata at 2025-12-03T22:38:56+07:00
Fix typo
- - - - -
396dfc1f by Marco Fargetta at 2025-12-03T18:38:59+01:00
Fix wrong parameter value in documentation
- - - - -
f53863fd by Marco Fargetta at 2025-12-04T17:59:36+01:00
Remove check for pki log folder
Remove the check to pki logs folder because it is not always present.
Tomcat 10.1 [1] has modified the logging system introducing a lazy creation
so log folder and file are created only if there is something to write.
Therefore, the pki folder for pki webapps logs is not created since at
default logging level there should be no logs.
1. https://fedoraproject.org/wiki/Changes/Tomcat10ChangeProposal#Detailed_Description
- - - - -
993ce30a by dependabot[bot] at 2025-12-09T10:04:38+01:00
Bump ansible from 8.5.0 to 12.2.0 in /tests/dogtag/pytest-ansible
Bumps [ansible](https://github.com/ansible-community/ansible-build-data) from 8.5.0 to 12.2.0.
- [Changelog](https://github.com/ansible-community/ansible-build-data/blob/main/docs/release-process.md)
- [Commits](https://github.com/ansible-community/ansible-build-data/compare/8.5.0...12.2.0)
---
updated-dependencies:
- dependency-name: ansible
dependency-version: 12.2.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support at github.com>
- - - - -
d4bdc159 by Endi S. Dewata at 2025-12-10T12:25:51+07:00
Update tests to check external commands used by pkidestroy
- - - - -
43d574b0 by Endi S. Dewata at 2025-12-10T15:32:46+07:00
Rename server's SubsystemCLI into ServerCommandCLI
- - - - -
d1fa6394 by Endi S. Dewata at 2025-12-10T15:34:02+07:00
Add default options for ServerCommandCLI
- - - - -
24d05d71 by Endi S. Dewata at 2025-12-12T00:03:24+07:00
Convert pki-server <subsystem>-db-* commands to Java
The pki-server commands are mainly implemented in Python which
will use PKI Python API, but if the API needs to use NSS, LDAP,
or PKI Java API it will call an external Java code and each
call will require a separate NSS authentication.
To avoid this problem some of the pki-server <subsystem>-db-*
commands used by pkispawn/pkidestroy have been converted to run
the corresponding Java code directly so later they can be
executed in shell/batch mode which only requires a single NSS
authentication.
The methods in PKISubsystem that call these commands have
been modified to call pki-server so later these calls can
be converted into shell/batch mode.
A new global -i option has been added to pki-server CLI to
specify the instance name. This later can be used to specify
the instance name for all commands executed in shell/batch
mode.
- - - - -
d26b7347 by Endi S. Dewata at 2025-12-13T08:31:40+07:00
Convert pki-server <subsystem>-user-* to Java
In order to minimize the number of NSS authentications the
pki-server <subsystem>-user-* commands used during installation
have been converted to run the corresponding Java code directly
so later they can be executed in shell/batch mode.
The SubsystemUserAddCLI Java class has been modified to provide
options to import the user certificate which were provided by
the corresponding Python class.
- - - - -
f17ddabe by Endi S. Dewata at 2025-12-13T08:31:40+07:00
Convert pki-server <subsystem>-group-* to Java
In order to minimize the number of NSS authentications the
pki-server <subsystem>-group-* commands used during installation
have been converted to run the corresponding Java code directly
so later they can be executed in shell/batch mode.
- - - - -
27c8959d by Endi S. Dewata at 2025-12-15T23:06:25+07:00
Convert pki-server ca-profile-* to Java
In order to minimize the number of NSS authentications the
pki-server <subsystem>-profile-* commands used during installation
have been converted to run the corresponding Java code directly
so later they can be executed in shell/batch mode.
- - - - -
717e0b27 by Endi S. Dewata at 2025-12-15T23:06:25+07:00
Convert pki-server ca-cert-* to Java
In order to minimize the number of NSS authentications the
pki-server <subsystem>-cert-* commands used during installation
have been converted to run the corresponding Java code directly
so later they can be executed in shell/batch mode.
The CACertCreateCLI and CACertImportCLI Java classes have been
modified to provide the options to specify the CSR and whether
to import the newly created cert which were provided by the
corresponding Python classes.
- - - - -
1784d642 by Christina Fu at 2025-12-15T08:37:22-08:00
Add EST /fullcmc upgrade script (#5249)
- Add device.conf with appropriate extensions for device certificates
(keyUsage: digitalSignature, keyEncipherment; extendedKeyUsage: clientAuth)
- Update estFullcmcDeviceCert.cfg to remove inappropriate extensions:
- Remove nonRepudiation from keyUsage (not appropriate for devices)
- Remove emailProtection from extendedKeyUsage (not needed for devices)
These changes ensure device certificates have appropriate key usage for
IoT/device authentication rather than user-oriented extensions."
- 01-EnableEST.py: updated to update changes needed in the CA
- 02-EnableESTFullCMC.py: added to update changes needed in the EST
Assisted-by Claude
IDM-4226
- - - - -
c0f7f10b by Christina Fu at 2025-12-15T17:09:50-08:00
fix pylint issue
/usr/share/pki/server/upgrade/11.9.0/01-EnableEST.py:172:32: E128 continuation line under-indented for visual indent
'com.netscape.cms.authentication.CMCAuthForEST')
- - - - -
41237feb by Endi S. Dewata at 2025-12-16T14:55:08+07:00
Update HSM tests to check external commands
- - - - -
d59043ff by Christina Fu at 2025-12-16T08:42:44-08:00
Fix CMCAuthForEST to support non-agent users (#5250)
- Skip CA database authentication for EST fullcmc enrollment in CMCAuth:
Extract CA user database authentication from verifySignerInfo() into
a separate protected authenticateCAUser() method that can be cleanly
overridden by subclasses.
Changes to CMCAuthForEST.java:
- Add authenticateCAUser() override that skips CA database authentication
- Let profile constraint handle agent vs non-agent checks.
- Add ML-DSA signature algorithm support to CMC authentication
Note: Comprehensive testing with ML-DSA certificates will be handled in a separate ticket to ensure thorough validation.
- - - - -
a6cab315 by Christina Fu at 2025-12-16T08:55:26-08:00
Create EST fllcmc example install/setup/test doc (#5251)
Assisted-by Claude
idm-4310
- - - - -
c3909f56 by Endi S. Dewata at 2025-12-17T11:28:54+07:00
Convert pki-server sd-* to Java
Currently the pki-server sd-* commands are hard-coded to work
only with CA. Since a security domain can also run on standalone
KRA and OCSP these commands have been replaced with pki-server
<subsystem>-sd-* commands.
In order to minimize the number of NSS authentications the
pki-server <subsystem>-sd-* commands used during installation
have been converted to run the corresponding Java code directly
so later they can be executed in shell/batch mode.
- - - - -
edc0b711 by Endi S. Dewata at 2025-12-17T11:28:54+07:00
Convert pki-server <subsystem>-range-* to Java
In order to minimize the number of NSS authentications the
pki-server <subsystem>-range-* commands used during installation
have been converted to run the corresponding Java code directly
so later they can be executed in shell/batch mode.
- - - - -
d166a0cb by Endi S. Dewata at 2025-12-19T01:39:26+07:00
Convert pki-server <subsystem>-db-repl-* to Java
In order to minimize the number of NSS authentications the
pki-server <subsystem>-db-repl-* commands used during installation
have been converted to run the corresponding Java code directly
so later they can be executed in shell/batch mode.
The Java code has been modified to provide DS connection params
as in the original Python code.
- - - - -
ded27328 by Endi S. Dewata at 2025-12-19T01:39:26+07:00
Convert pki-server <subsystem>-db-vlv-* to Java
In order to minimize the number of NSS authentications the
pki-server <subsystem>-db-vlv-* commands used during installation
have been converted to run the corresponding Java code directly
so later they can be executed in shell/batch mode.
- - - - -
205623db by Endi S. Dewata at 2025-12-24T05:58:37+07:00
Convert pki-server <subsystem>-acl-* to Java
In order to minimize the number of NSS authentications the
pki-server <subsystem>-acl-* commands used during installation
have been converted to run the corresponding Java code directly
so later they can be executed in shell/batch mode.
- - - - -
b954f2eb by Endi S. Dewata at 2025-12-24T05:58:37+07:00
Convert pki-server <subsystem>-crl-* to Java
In order to minimize the number of NSS authentications the
pki-server <subsystem>-crl-* commands used during installation
have been converted to run the corresponding Java code directly
so later they can be executed in shell/batch mode.
- - - - -
dafb5f01 by Endi S. Dewata at 2025-12-24T07:19:49+08:00
Convert pki-server <subsystem>-id-generator-update to Java
In order to minimize the number of NSS authentications the
pki-server <subsystem>-id-generator-* commands used during
installation have been converted to run the corresponding
Java code directly so later they can be executed in
shell/batch mode.
- - - - -
b868d7ba by Endi S. Dewata at 2026-01-03T09:35:55+07:00
Update return code in pki nss-cert-export
The pki nss-cert-export has been modified to return an error
code 1 if the cert does not exist in order to distinguish it
from other errors.
- - - - -
e95530cf by Endi S. Dewata at 2026-01-03T10:43:44+07:00
Add pki nss-key-create --token option
The pki nss-key-create has been modified to provide an option
to specify the token to generate the key.
- - - - -
8f1b8cd9 by Endi S. Dewata at 2026-01-03T10:43:44+07:00
Add pki nss-cert-request --token option
The pki nss-cert-request has been modified to provide an option
to specify the token to generate the key to load the key from.
- - - - -
557d02e4 by Endi S. Dewata at 2026-01-03T12:07:02+07:00
Add pki nss-key-create --output-file option
The pki nss-key-create has been modified to provide an option
to store the output into a file.
- - - - -
8dbfad35 by Endi S. Dewata at 2026-01-03T12:07:02+07:00
Add pki nss-cert-show --output-file option
The pki nss-cert-show has been modified to provide an option
to store the output into a file.
- - - - -
17caeabd by Endi S. Dewata at 2026-01-05T13:32:51+07:00
Update NSSDatabase.verify_cert()
The NSSDatabase.verify_cert() has been updated to take an
optional cert usage param.
- - - - -
2342d4ca by Endi S. Dewata at 2026-01-10T07:23:32+07:00
Update CI to support Fedora 42
Currently the CI only works with Fedora 43 which uses Tomcat 10.
Sometimes it's necessary to run the CI with a different Fedora
version using the BASE_IMAGE variable. In order to support Fedora
42 which uses Tomcat 9, the CI has been updated to get the Fedora
version from the running container then use it to perform the
proper validation.
- - - - -
43d21879 by Marco Fargetta at 2026-01-12T16:44:07+01:00
Update FIPS option for JDK>25
When running in FIPS mode the provider SunJSSE+SunPKCS11 conflict with
JSS. To avoid problems the JVM has to start in non FIPS mode, JSS will
take care to use the correct policy.
>From Java 8 to 24 the fips was disabled with the option `-Dcom.redhat.fips=false`
(see [1]). In Java 25 the option has been changed and it is
`-Dredhat.crypto-policies=false` (see [2]).
To avoid problems both options are included so fips is disabled with all
JVM versions.
Fixes #5256
1. https://docs.redhat.com/en/documentation/red_hat_build_of_openjdk/8/html/release_notes_for_red_hat_build_of_openjdk_8.0.472/rn-openjdk-disabling-fips-on-rhel82
2. https://docs.redhat.com/en/documentation/red_hat_build_of_openjdk/25/html/release_notes_for_red_hat_build_of_openjdk_25.0.1/crypto_fips
- - - - -
87a91f8a by Endi S. Dewata at 2026-01-13T02:46:32+07:00
Fix KRA container test
- - - - -
df78f076 by Endi S. Dewata at 2026-01-13T02:46:32+07:00
Update NSSDatabase.export_cert_from_db()
The NSSDatabase.export_cert_from_db() has been converted into
export_cert_bundle() to improve reusability.
- - - - -
3e041f90 by Endi S. Dewata at 2026-01-13T02:46:32+07:00
Add pki --exit-on-error option
The pki CLI has been modified an option to exit immediately
if there's an error in shell/batch mode.
- - - - -
45831837 by Marco Fargetta at 2026-01-15T11:31:13+01:00
Fix file permission when random serial is in use
Permission for the file `CS.cfg` is different if deployment use
sequential serial number (0o0660) or random serial number (0o0664).
The permission has been modified to always be 0o0660.
Fixes #4906.
- - - - -
117135c5 by Marco Fargetta at 2026-01-15T11:31:13+01:00
Add update script for configuration file permission
All configuration files should be 0o0660 but with random serial number
they could have different permission. It has been fixed and the script
will update current instances.
- - - - -
28385685 by Marco Fargetta at 2026-01-15T18:26:33+01:00
Update version to 11.10.0-alpha1
- - - - -
444dc7d3 by Endi S. Dewata at 2026-01-16T02:51:23+07:00
Convert pki password-generate to Java
The pki password-generate CLI has been converted to Java
so that later it can be used in shell/batch mode.
A new test has been added to verify pki password-generate
with default and non-default charsets.
- - - - -
d530a2c7 by Marco Fargetta at 2026-01-16T12:26:26+01:00
Update jss requirements to 5.10
- - - - -
156096ec by Marco Fargetta at 2026-01-16T16:53:28+01:00
Fix permission in container configuration
- - - - -
af48a58c by Marco Fargetta at 2026-01-21T10:41:43+01:00
Fix python pylint error in EST upgrade script
- - - - -
8e8da636 by Endi S. Dewata at 2026-01-22T18:02:28-06:00
Clean up RPM spec
- - - - -
487a56cd by Marco Fargetta at 2026-01-23T10:13:37+01:00
Fix CMake build with tomcat10
CMake build had tomcat-9 library hard-coded and has been removed to get
it from the `build.sh`.
The `build.sh` test to identify the tomcat version to use was not
working with dotted version (e.g. 10.2) and it has been fixed.
- - - - -
cb9b0f60 by gkimetto at 2026-01-26T09:08:46-05:00
[DEV] [FIX] OCSP response provides a SHA1 signature in the header packet #DOGTAG-4129
Add support for detecting and optionally rejecting OCSP requests that
use deprecated digest algorithms (MD2, MD5, SHA-1), and allow
configuration of the OCSP response signing algorithm.
Doc update:
Add this CS.cfg Configuration for CA's built in responder in pki-tomcat:
# /var/lib/pki/{instance}/conf/ca/CS.cfg
# Reject deprecated algorithms (default: false)
ca.ocspRejectDeprecatedAlgorithms=true
# Configure response signing algorithm (default: use signing unit default)
ca.ocspResponseSigningAlgorithm=SHA256withRSA
Alternatively for Standalone OCSP Responder
Edit /var/lib/pki/<instance>/ocsp/CS.cfg and add:
ocsp.rejectDeprecatedAlgorithms=true
ocsp.responseSigningAlgorithm=SHA256withRSA
Supported Signing Algorithms:
- SHA256withRSA
- SHA384withRSA
- SHA512withRSA
- SHA256withEC
- SHA384withEC
- SHA512withEC
After making changes, restart the PKI instance:
systemctl restart pki-tomcatd@<instance>.service
Fix: DOGTAG-4129
- - - - -
753f1702 by Marco Fargetta at 2026-01-27T16:12:37+01:00
Add ML-DSA key option to caInternalAuthAuditSigningCert profile
- - - - -
9d3de1bf by Marco Fargetta at 2026-01-28T12:28:00+01:00
Move client to APIs v2
CLI default APIs is moved to v2. v1 APIs can still be used only if
specified in the CLI.
Additionally, certrequest operation has been fixed because the v2 does
not provide the requestURL with id in decimal format..
- - - - -
4a29f097 by Marco Fargetta at 2026-01-28T12:28:00+01:00
Update action for v2 APIs
Since CLI is now using the v2 APIs as default the command the test have been update to verify default and v1 APIs. Additionally, checks on server logs have been fixed since they are different because of different API paths.
- - - - -
c4779567 by Marco Fargetta at 2026-01-28T12:28:00+01:00
Fix EST action with postgresql
The `tomcat-digest` command does not work in Fedora 43 with tomcat10 out-of-the-box but because of library problem. The problem is solved providing a custom CLASSPATH to a proper tomcat library.
- - - - -
5f64d786 by Endi S. Dewata at 2026-01-28T14:27:24-06:00
Fix upgrade script indexes
- - - - -
47cef968 by Marco Fargetta at 2026-01-29T11:33:42+01:00
Add check for audit signature with ML-DSA
Enable audit signature in ML-DSA tests to verify the logger recognise
the keys and signature algorithms.
- - - - -
ee912a66 by Marco Fargetta at 2026-01-29T11:33:42+01:00
Fix audit signing with ML-DSA
When a certificate key is ML-DSA-* audit has to be signed with the
corresponding signature algorithm (the names of algorithm key and
signature are the same).
- - - - -
7c7c8c7f by Marco Fargetta at 2026-01-29T12:10:33+01:00
Add ML-DSA key option to caInstallCACert profile
- - - - -
fcdfef33 by Marco Fargetta at 2026-01-30T15:45:07+01:00
Fix ca test regular expression
Command `ca-cert-find` output has slightly changed the format and the
regular expression in test has been updated to get the right fields.
- - - - -
a64237d2 by Alessandro Garagnani at 2026-01-30T15:47:52+01:00
Fix pki ca-cert-hold/release-hold/revoke showing Java exception
This patch fixes hold, release and revoke CLI Java implementations to handle errors in the same way as main CLI
This patch extend the handle error common behaviour to all childen of java.lang.Exception. Prior to this any uncaught exception more specific would have raised stacktrace logs to the standard output.
- - - - -
eb548dd8 by Endi S. Dewata at 2026-01-30T23:46:10+07:00
Disable ML-DSA test on Fedora 42
The ML-DSA test has been disabled on Fedora 42 since it's
failing with SSLV3_ALERT_HANDSHAKE_FAILURE. The test works
fine on Fedora 43 or later.
- - - - -
89c8c000 by Christina Fu at 2026-02-02T14:02:34-08:00
Add VLV index for CRL generation by issuer + CI test (#5268)
This fixes unindexed LDAP searches during CRL generation by adding
the allRevokedCertsByIssuer VLV index.
The fix addresses two bugs found in the original DOGTAG_10_5_BRANCH
implementation (commit e587f95576):
- Bug 1: VLV index parent DN must match VLV search name
- Bug 2: nsindexVLVAttribute must reference the index, not search
Changes:
- Add allRevokedCertsByIssuer VLV search and index to vlv.ldif
- Add allRevokedCertsByIssuer-{instanceId}Index to vlvtasks.ldif
- Move VLV creation to after certificate installation in configuration.py
so that CA signing certificate DN is available for VLV filter
- Update SubsystemDBVLVAddCLI to read CA DN from NSS certificate and
set {caIssuerDN} template variable with enhanced logging
- Add setParam() method to LDAPConfigurator for dynamic templates
- Add note about LWCA limitation in configuration.py
CI Test:
- Added verification step to ca-crl-test.yml workflow
- Checks DS access log after CRL generation to confirm VLV usage
- Displays LDAP queries for revoked certificates showing index usage
Server Change doc:
- Added Server change doc for v11.10 and added entry for this fix
Tested on fresh installations and upgrades without restart.
Assisted-by: Claude
Fixes: DOGTAG-4244
- - - - -
38d63085 by Endi S. Dewata at 2026-02-02T18:58:58-06:00
Drop KRAConnector.get_ca_list_from_security_domain()
The KRAConnector.deregister() has been modified to reuse
PKIDeployer.get_domain_info().
- - - - -
f9c8e36b by Endi S. Dewata at 2026-02-02T18:58:58-06:00
Add PKIDeployer.remove_kra_connector()
The code that removes a KRA connector from a CA subsystem has
been moved into PKIDeployer.remove_kra_connector().
- - - - -
d2ae7615 by Endi S. Dewata at 2026-02-02T18:58:58-06:00
Add PKIDeployer.remove_kra_connectors()
The code that removes a KRA connector from all CA subsystems
has been moved from PKIDeployer.remove_kra_connectors().
- - - - -
d8de4baf by Endi S. Dewata at 2026-02-02T18:58:58-06:00
Add PKIDeployer.remove_tps_connector()
The code that removes a TPS connector from a TKS subsystem
has been moved into PKIDeployer.remove_tps_connector().
- - - - -
18f58c87 by Marco Fargetta at 2026-02-04T14:51:28+01:00
Fix certificate verification with multiple CA
If multiple CA root certificates are present in the NSSDB the CLI
`nss-cert-verify` will cycle among the CAs to verify the
signature. However, if CA certificate are configured with different
key algorithms the `PKITrustManager.checkCert()` method raises an
exception when the certificate key algorithm does not match the one for
the CA so the check will not move to the next CA certificate.
The `InvalidKeyCertificate` is handled to allow moving to the next
certificate.
Fixes: #5242
- - - - -
da542c37 by Marco Fargetta at 2026-02-04T14:51:28+01:00
Fix nss-cert-verify option dependency
The CLI nss-cert-verify `--cert-usage` option works only if the nickname is provided
but if a certificate file is provided there is no output indicating that
the check is skipped.
A `CLIException` is thrown to make evident the usage cannot be verified
if the certificate nickname is not provided.
Fixes: #5246
- - - - -
f01cf683 by Endi S. Dewata at 2026-02-04T22:37:31+07:00
Fix CA container tests
The CA container tests have been updated to support Tomcat 9
on Fedora 42 in addition to Tomcat 10 on Fedora 43 or later.
- - - - -
b04b4267 by Marco Fargetta at 2026-02-04T16:41:48+01:00
Fix MLDSA configuration example
- - - - -
5edab9fe by Marco Fargetta at 2026-02-05T14:36:24+01:00
Fix ML-DSA CA cloning
During cloning sslserver and subsystem certificate are created using a
dedicated certificate. The deployment script has been modified to
include the correct profile for ML-DSA and dedicated profiles have been
created.
- - - - -
4fba4585 by Endi S. Dewata at 2026-02-05T23:07:48+07:00
Update basic installation tests
The basic installation tests have been updated to
check the content of <instance>/conf/alias and
<instance>/conf/Catalina/localhost directories.
- - - - -
a59bfa01 by Marco Fargetta at 2026-02-05T17:39:31+01:00
Fix error in algorithm name for audit signing
- - - - -
8208a982 by Marco Fargetta at 2026-02-05T19:12:28+01:00
Fix admin profile for ML-DSA key certificate
If the subsystem is not a CA the admin certificate request should use
the profile `caMLDSAAdminCert` when the ML-DSA key is used but it was
using the default `caAdminCert` profile.
- - - - -
fa922f29 by Marco Fargetta at 2026-02-06T09:42:13+01:00
Fix typo in profile name for ML-DSA admin certificates
- - - - -
89f7176d by Marco Fargetta at 2026-02-06T10:22:07+01:00
Update upgrade script for MLDSA
The profiles `caMLDSAInternalAuthSubsystemCert` and `caMLDSAInternalAuthServerCert` are included in the upgrade script for ML-DSA.
These profiles are used by other subsystem during spawn to generate
server and subsystem certificates through security domain.
- - - - -
0c12fb51 by Michael L. Young at 2026-02-07T00:41:56+07:00
Add Rocky Linux support to get_tomcat_app_server
The get_tomcat_app_server function in build.sh only recognizes rhel,
centos, and fedora as valid distribution IDs. Rocky Linux uses ID="rocky"
in /etc/os-release, which caused the function to fall through to the
default case and return tomcat-9.0 instead of checking the version and
selecting tomcat-10.1 for Rocky Linux 10+.
This patch adds "rocky" to the case statement so Rocky Linux is treated
the same as RHEL/CentOS for Tomcat version selection.
Signed-off-by: Michael L. Young <elgueromexicano at gmail.com>
- - - - -
ea6fbae9 by Endi S. Dewata at 2026-02-09T22:39:51+07:00
Fix localhost log file permission
Previously pki-server ran Java commands as the current user
(e.g. root), so files generated by the commands (e.g. localhost
log file) would be owned by the current user instead of PKI user
(e.g. pkiuser) which might cause issues later.
The PKIServerCLI.execute_java() has been modified to run the
command as PKI user by default unless the current user wants to
run it as itself.
The pki-server CLI has been modified to provide an option to
run the command as the current user which could be useful for
containers.
The methods in PKISubsystem that use pki-server CLI have been
modified to change the ownership of the temporary directory to
PKI user so that the files in it can be accessed by the CLI.
The CASubsystem.create_cert() has been modified to no longer
create a temporary directory since it's not actually needed.
The tests have been updated to verify that the localhost log
file is owned by pkiuser instead of root. The container tests
have been modified to store files in /tmp since the current
directory cannot be accessed by pkiuser.
- - - - -
5d43b840 by Endi S. Dewata at 2026-02-09T15:38:05-06:00
Add test-init.sh
The test-init.sh has been added to initialize the default
values of some environment variables in several branches.
This way the same code can be used in multiple branches
which simplifies the branching process.
- - - - -
bc60dd88 by Endi S. Dewata at 2026-02-09T16:53:43-06:00
Update healthcheck tests to show external commands
- - - - -
72137a59 by Endi S. Dewata at 2026-02-10T20:24:47+00:00
Clean up RPM spec
- - - - -
d7504725 by Endi S. Dewata at 2026-02-10T20:20:02-06:00
Fix default values in test-init.sh
The test-init.sh has been updated to set the default values
of environment variables properly for all branches.
- - - - -
c9e5a139 by Endi S. Dewata at 2026-02-13T04:45:32+07:00
Add support for bundling commons-logging.jar
The build scripts have been updated to optionally support
bundling commons-logging.jar in addition to other libraries
into the RPM package.
The server test has been updated to check the libraries
included in the RPM package.
- - - - -
4ff0bc83 by Marco Fargetta at 2026-02-13T10:01:39+01:00
Fix AKI and SKI in PKITrustManager checkCert
The AKI and SKI in `checkCert(...)` where logged as `null` because the
UniqueId where extracted from the certificate instead of the proper
AKI and SKI extension. As reported in the RFC#5280 [1] the unique identifier
should not be used unless of specific case where subject are reused.
Additionally, an additional condition is included to skip the test in
case certificate AKI does not match with SKI of trusted certificate
since this is a requirement for a valid signature.
1. https://www.rfc-editor.org/rfc/rfc5280#section-4.1.2.8
Fix: #5247
- - - - -
437b88d8 by Marco Fargetta at 2026-02-13T10:09:04+01:00
Fix registry update in EST upgrade script
The registry is not properly updated because the `save()` method
is called only if a condition is selected ignoring the others.
Additionally, the condition is not correct.
- - - - -
eee444dd by Endi S. Dewata at 2026-02-13T15:40:28-06:00
Clean up CA tests
- - - - -
65ae3d33 by Endi S. Dewata at 2026-02-17T09:53:12-06:00
Add support for bundling Apache Commons library
The build scripts have been updated to optionally support
bundling Apache Commons library in addition to other libraries
into the RPM package.
- - - - -
d06d376b by Endi S. Dewata at 2026-02-17T13:10:34-06:00
Add support for bundling HTTP Components library
The build scripts have been updated to optionally support
bundling HTTP Components library in addition to other
libraries into the RPM package.
- - - - -
cfe20246 by Endi S. Dewata at 2026-02-17T13:10:34-06:00
Add support for bundling SLF4J library
The build scripts have been updated to optionally support
bundling SLF4J library in addition to other libraries into
the RPM package.
- - - - -
f9fa051a by Alessandro Garagnani at 2026-02-18T13:30:41+01:00
Add new test for CA cloning with ML-DSA keys
- - - - -
2c381f82 by jmagne at 2026-02-18T08:44:37-08:00
New old tomcat 10 (#5265)
* First cut, new tomcat 10 support.
* Get dogtag working under old tomcat 10 or new tomcat 10.
New code to reconcile the proper systemd unit to use in old vs new tomcat 10 scenario, assisted by coding assitant.
The fix to the unit files uses a script that detects if we have upgraded tomcat from old tomcat 10 to new tomcat10.
If that is the case it replaces the current unit file with a newer copy of the unit file that supports new tomcat10.
This solution was deemed the most simple after several alternate attempts to get this working. Also this supports both
fresh installs under old or new tomcat 10 and also supports an independent upgrade from old to new tomcat 10.
At the next restart the unit file will be updated.
Based upon further feedback, I"ve implemented a solution based using one single file but having it call abstracted
scripts to start and stop the server, which determines which tomcat 10 is present and calls the correct start script.
- - - - -
49f244bc by Christina Fu at 2026-02-18T15:35:50-08:00
Add new feature entries for VLV Index for CRL Generation and EST /fullcmc to Server-Changes.adoc (#5288)
- - - - -
48eb8ea2 by Christina Fu at 2026-02-18T15:46:28-08:00
adding missing [] for link in Server-Changes.adoc
- - - - -
f62cc0fb by Endi S. Dewata at 2026-02-19T09:52:01-06:00
Disable test for CA clone with ML-DSA on Fedora 42
Similar to eb548dd8c006fa4bf4e20d7dacf1262fcace5308, the CA
clone test with ML-DSA has been disabled on Fedora 42 since
it's failing with SSLV3_ALERT_HANDSHAKE_FAILURE. The test
works fine on Fedora 43 or later.
- - - - -
47a7ae4e by Taylor Herring at 2026-02-23T10:14:19-05:00
Fix nuxwdog password handling for HSM environments
This commit fixes password handling issues that prevented PKI instances
from starting when using nuxwdog password store with HSM tokens.
Changes:
1. password.conf existence check - Check if password.conf exists in
NSSDatabase constructor rather than at each usage point. This ensures
self.password_conf is only set when the file actually exists, preventing
errors when the file is missing. Also guarded remaining unconditional
uses of self.password_conf in modify_cert() and verify_cert().
2. get_all_passwords() fixes - Changed delimiter from ':' to '=' to match
password.conf format expected by NSS tools. Also kept the 'hardware-'
prefix when writing HSM token passwords to the multi-token password
file. The PKI CLI expects the 'hardware-' prefix to identify HSM tokens
(e.g. 'hardware-NHSM-CONN-XC=password'), but the code was stripping it,
causing the CLI to skip HSM token authentication.
3. Multi-token password support for HSM - Added need_all_tokens logic to
get_trust(), get_cert(), and export_cert_bundle() methods. When accessing
certificates on HSM tokens, both internal token and HSM token passwords
are required. The all_tokens=True parameter creates a multi-token password
file using password.conf format ('-f' flag) instead of single-password
format ('-C' flag).
4. Keyring.getKeyID() NumberFormatException fix - When a key doesn't exist
in the keyring, keyctl returns the error message "keyctl_search: Required
key not available" instead of a numeric key ID. The code now catches
NumberFormatException and logs the non-numeric output for troubleshooting,
rather than letting the exception propagate. This was the original bug
encountered during fresh install with nuxwdog and HSM (DOGTAG-4272).
5. export_ca_cert() HSM token password pre-population - Pre-populate the
HSM token password from keyring before opening the NSS database. In
nuxwdog mode, password.conf does not exist and passwords are stored in
the kernel keyring. Without this, open_nssdb() only fetches the internal
token password, leaving the HSM token password missing from the password
file passed to the PKI CLI.
6. pki-server-nuxwdog sleep timer - Increased background sleep from 10 to
600 seconds to ensure the keyring file descriptor remains open longer
during the ExecStartPre sequence (systemd bug #1668954).
Assisted by: Claude Sonnet 4.5
- - - - -
6ef5ca02 by Endi S. Dewata at 2026-02-23T10:07:37-06:00
Add encrypt_alg_oid and wrap_name for KeyClient.retrieve_key()
The KeyClient.retrieve_key() has been modified to provide
params to override encrypt_alg_oid and wrap_name attributes
in KeyClient.
- - - - -
5e72a1f9 by Endi S. Dewata at 2026-02-23T18:41:13-06:00
Clean up KRA tests
- - - - -
c062e122 by Marco Fargetta at 2026-02-24T10:49:21+01:00
Add test for ML-DSA-87
The ML-DSA-87 requires a bigger buffer for TLS handshake otherwise the
deployment will fail.
The ML-DSA test is extended to verify the installation using ML-DSA-87
with default buffer and bigger buffer.
- - - - -
72c03848 by Endi S. Dewata at 2026-02-24T09:07:05-06:00
Drop KeyClient.archive_key()
The KeyClient.archive_key() was supposed to provide a convenient
way to archive data, but it's using a CryptoProvider to generate
an initialization vector and a session key, then wrap the key and
encrypt the data for archival. It's also using a transport cert
stored in memory without an update mechanism so it could become
obsolete. The caller had no control over this process.
To reduce dependency on CryptoProvider and to allow more control
over the archival process the archive_key() has been dropped and
replaced with the existing archive_encrypted_data().
The drmtest.py is obsolete but it has been updated accordingly.
The pki-kra-key-archive.py script and IPA are already using
archive_encrypted_data() so they are not affected by this change.
- - - - -
fe83a3d3 by Endi S. Dewata at 2026-02-25T10:16:04-06:00
Update KeyClient.retrieve_key()
Previously the KeyClient.retrieve_key() could be called without
the trans_wrapped_session_key param for convenience. In that case
it would use a CryptoProvider to generate a session key, wrap the
key, then decipher or unwrap the retrieved data/key. It's also
using a transport cert stored in memory without update mechanism
so it could become obsolete. The caller had no control over this
process.
To reduce dependency on CryptoProvider and to allow more control
over retrieval operation the method has been modified such that
the caller needs to provide the trans_wrapped_session_key param
and also decrypt/unwrap the retrieved data/key.
The drmtest.py is obsolete but it has been updated accordingly.
The pki-kra-key-retrieve.py script and IPA are already calling
this method with the required param so they are not affected by
this change.
- - - - -
9921f332 by Endi S. Dewata at 2026-02-26T09:09:32-06:00
Drop KeyClient.get_transport_cert()/set_transport_cert()
The KeyClient.get_transport_cert()/set_transport_cert() and the
corresponding attributes have been removed since the archival/
retrieval code in KeyClient that uses them has been removed.
The KeyClient and KRAClient constructors will generate a warning
if the transport cert nickname is specified.
The drmtest.py is obsolete but it has been updated accordingly.
The pki-kra-key-archieve/retrieve.py scripts and IPA do not use
these methods/attributes so they are not affected by this change.
- - - - -
1a5ad762 by Endi S. Dewata at 2026-02-27T10:13:43-06:00
Update test for KRA with ECC
The test for KRA with ECC has been updated to use pki
ca-cert-issue since the pki client-cert-request will be
deprecated in the future. It's also been updated to
check the CLI outputs and LDAP records in more details.
- - - - -
c8295e31 by Endi S. Dewata at 2026-02-27T11:05:52-06:00
Drop CryptoProvider.get_cert()
The CryptoProvider.get_cert() has been removed since it's no
longer used and it doesn't provide any mechanism to update
the certs stored in memory.
The KRAClient and KeyClient constructors have been modified
to no longer take transport cert params.
The CryptographyCryptoProvider constructor will still take
transport cert nickname and data params but the values will
no longer be used (i.e. deprecated).
The pki-kra-key-archieve/retrieve.py and drmtest.py have
been updated to no longer create CryptographyCryptoProvider
with transport cert params.
IPA will continue to create CryptographyCryptoProvider with
transport cert params, but it should not be affected by the
deprecation.
- - - - -
7450737c by Endi S. Dewata at 2026-03-03T07:27:34-08:00
Update IPA KRA test to check crypto params
The IPA KRA test has been updated to check the crypto params
stored in key records in order to prevent regressions.
- - - - -
0a66e84b by Endi S. Dewata at 2026-03-03T07:31:17-08:00
Drop CryptoProvider.symmetric_wrap()
The CryptoProvider.symmetric_wrap() has been dropped in order
to reduce dependency on Python Cryptography. The caller will
be responsible to perform the encryption operation.
- - - - -
95a17b33 by jmagne at 2026-03-03T17:50:13-08:00
Add support for old and new Tomcat 10.1 - Upgrade and branch porting (#5301)
This fix introduces an upgrade script for pki 10.11.0 which fixes the
permissions of instance directory "webapps". This is the only directory
so far detected to be different in the following two scenarios:
1. Install a fresh pki 11.9.0 instance on old tomcat 10.
2. Install a fresh pki 11.10.0 instance on old tomcat 10.
When starting with scenario #1 above and upgrading pki to 11.10.0,
the upgrade script will change the perms of the webapps directory to
770 instead of the previous 755.
Note this code used the code assistant to make the script extensible
should we discover that we need to take care of additional directories.
- - - - -
2d9e14b4 by Endi S. Dewata at 2026-03-04T07:53:22-08:00
Drop CryptoProvider.asymmetric_wrap()
The CryptoProvider.asymmetric_wrap() has been dropped in order
to reduce dependency on Python Cryptography. The caller will
be responsible to perform the key wrapping operation.
- - - - -
53a5d61b by Endi S. Dewata at 2026-03-05T07:45:06-08:00
Add support for Tomcat 10 with bundled build dependencies
Previously the code in pki.spec would only perform javax2jakarta
migration on bundled runtime dependencies imported from external
RPM packages, but it wouldn't migrate bundled build dependencies
provided as dist-git sources.
The code has been reorganized such that it would perform the
migration on both bundled build and runtime dependencies which
are needed to support Tomcat 10 on certain platforms.
- - - - -
2bc1e917 by Endi S. Dewata at 2026-03-06T09:32:38-08:00
Drop CryptoProvider.key_unwrap()
The CryptoProvider.key_unwrap() has been dropped in order to
reduce dependency on Python Cryptography. The caller will be
responsible to perform the key unwrap operation.
- - - - -
74b3f85e by Endi S. Dewata at 2026-03-06T09:32:38-08:00
Drop CryptoProvider.symmetric_unwrap()
The CryptoProvider.symmetric_unwrap() has been dropped in order
to reduce dependency on Python Cryptography. The caller will be
responsible to perform the decrypt operation.
- - - - -
5ff2f58b by Marco Fargetta at 2026-03-07T00:40:38+01:00
Remove references to v1 classes
References to classes and interfaces implementing v1 REST API, outside of the API itself, are replaced in order to have a total separation of the API implementations.
The total separation will make easier to remove v1 REST APIs in future releases.
- - - - -
562f5f43 by Marco Fargetta at 2026-03-09T16:18:38+01:00
Fix default tomcat for non RHEL dirivative distro
- - - - -
acf268c0 by Lukáš Lipinský at 2026-03-10T10:39:14+01:00
build: add Oracle Linux ID to get_tomcat_app_server
Treat /etc/os-release ID="ol" the same as RHEL when selecting the Tomcat app server version.
Signed-off-by: Lukáš Lipinský <lukas.lipinsky at oracle.com>
- - - - -
786eebce by Endi S. Dewata at 2026-03-10T09:50:31-07:00
Drop crypto methods and params from CryptoProvider
The crypto-related methods and params in CryptoProvider have been
dropped in order to reduce dependency on Python Cryptography. The
caller will be responsible to provide the nonce, the session key,
and the crypto params.
- - - - -
e0737e2e by Marco Fargetta at 2026-03-11T11:54:22+01:00
Replace FormParam with a custom Param annotation
FormParam is an annotation defined in javaee [1] for binding form
parameter in request entity to method parameter but since all the APIs
moved to XML first and json later the FormParam was not used for its
original goal. It is used to identify some fields inside Json mapped
objects.
Since the annotation is present in classes used by both v1 and v2 APIs
preventing to remove the resteasy dependency it has been replaced with a
custom annotation named "Param".
1. https://docs.oracle.com/javaee/7/api/javax/ws/rs/FormParam.html
- - - - -
ba629ff4 by Marco Fargetta at 2026-03-11T16:16:16+01:00
Remove the PKIRESTProvider
The PKIRESTProvider was used in the PKIconnection to stream the
message body in resteasy client. The commit
79aa44f1c7870799206ec22d319b354e527524d0 has replaced the resteasy
client with httpcomponent-client library so the PKIRESTProvider is not
needed.
- - - - -
28e8fbf7 by Endi S. Dewata at 2026-03-12T14:28:51-07:00
Update tests to check for core dumps
The tests that sometimes crash due to SIGSEGV have been
updated to check for core dumps to help the investigation.
- - - - -
883c979c by Marco Fargetta at 2026-03-13T09:58:28+01:00
Move key parameters in KeyParameters class
Static KeyParameter where defined in the Key*Resource classes. Since
the resource classes are associated to v1 APIs and can be removed in
future releases the parameters have been moved to a class defined only
for them.
- - - - -
7278acf4 by Alessandro Garagnani at 2026-03-13T19:44:05+01:00
Dropping dependency on python-six
Removes all six imports
Removes all six dependencies
Tracked by issue IDM-4697
- - - - -
8187cb79 by Endi S. Dewata at 2026-03-16T07:41:54-07:00
Reorganize CA API test
The API test in CA basic test has been moved into a separate
workflow to make it easier to investigate the SIGSEGV issue.
- - - - -
a536d8ca by Endi S. Dewata at 2026-03-17T15:04:09-05:00
Update tests to check for core dumps (part 2)
The tests that sometimes crash due to SIGSEGV have been
updated to check for core dumps to help the investigation.
- - - - -
50c3958e by Endi S. Dewata at 2026-03-19T12:18:28-05:00
Use Java 21 on Fedora 43
- - - - -
8d096fed by Endi S. Dewata at 2026-03-19T18:03:28-05:00
Replace PKIDeployer.client with pki_client
- - - - -
b014c5a7 by Endi S. Dewata at 2026-03-19T19:36:34-05:00
Replace PKIDeployer.sd_connection with sd_client
- - - - -
227bbeb5 by Marco Fargetta at 2026-03-24T12:02:45+01:00
Move KRA KeyRequestDAO to v1 packages
KeyRequestDAO was used by both v1 and v2 APIs but it has dependency on resteasy package creating problem in case of dropping v1 APIs and related dependency.
The class has been moved to v1 packages and the few methods in use by v2 APIs have been duplicated in the KeyProcessor class so they are totally independent.
- - - - -
510893a7 by Marco Fargetta at 2026-03-24T12:02:45+01:00
Move KRA CMSRequestDAO to v1 packages
CMSRequestDAO was used only by v1 APIs so it is moved to v1 package to make easier to drop it with the other v1 APIs.
- - - - -
b714c47a by Marco Fargetta at 2026-03-24T12:02:45+01:00
Remove MultivaluedMap from RESTMessage
RESTMessage is a base class for REST request/response messages used in
several APIs. The message can accept MultivaluedMap which is provided
by resteasy and used only in APIs v1. The constructor using
MultivaluedMap has been removed and v1 APIs extend RESTMessage to add
this specific constructor.
- - - - -
df56fbc5 by Marco Fargetta at 2026-03-24T12:02:45+01:00
Remove unused constructors using MultivaluedMap
These constructors were not used in the current code but will maintain
a dependency with resteasy so they are removed.
- - - - -
87d4d5e9 by Endi S. Dewata at 2026-03-24T14:43:32-07:00
Drop ESC dependency
The pki.spec has been modified to no longer depend on ESC,
so ESC will need to be installed separately, possibly on an
older system that still has it.
The theme files related to ESC have also been removed.
- - - - -
e3d81382 by Endi S. Dewata at 2026-03-25T09:41:44-05:00
Clean up OCSP tests
- - - - -
808384b1 by Endi S. Dewata at 2026-03-25T11:10:22-05:00
Update tests to check for core dumps (part 3)
The tests that sometimes crash due to SIGSEGV have been
updated to check for core dumps to help the investigation.
- - - - -
13a31b4c by Endi S. Dewata at 2026-03-25T15:22:55-05:00
Clean up sub CA tests
- - - - -
acfa83f1 by Endi S. Dewata at 2026-03-25T15:22:55-05:00
Clean up TKS tests
- - - - -
1bd5508c by Endi S. Dewata at 2026-03-25T15:22:55-05:00
Clean up TPS tests
- - - - -
02747cdf by Endi S. Dewata at 2026-03-25T16:20:11-05:00
Clean up server tests
- - - - -
f415088b by Endi S. Dewata at 2026-03-25T17:36:00-05:00
Clean up tools tests
- - - - -
12c39669 by Endi S. Dewata at 2026-03-25T18:29:16-05:00
Update tests to check for core dumps (part 4)
The tests that sometimes crash due to SIGSEGV have been
updated to check for core dumps to help the investigation.
- - - - -
bca84994 by Marco Fargetta at 2026-03-26T11:25:00+01:00
Move or delete resteasy dependency
Remove the use of MultivaluedMap and UriInfo because they were not actually used outside of v1 APIs. Replace Response status with HttpStatus in the check and resteasy MediaType with internal MimeType. Finally some static values have been duplicated outside of Resource classes.
- - - - -
6782ba93 by Christina Fu at 2026-03-27T14:05:23-07:00
Standalone Build Mechanism for KRATool (pki-kratool rpm): (#5319)
Added build-kratool.sh script and associated spec/pom.xml files to generate
a standalone kratool RPM package. This allows administrators to install or
update KRATool independently without overwriting existing PKI RPMs that may
contain critical hotfixes.
Build: ./base/tools/build-kratool.sh rpm
Output: ~/build/kratool/
Assisted-by: Claude
IDM-5245
- - - - -
a375b8c8 by Christina Fu at 2026-03-30T09:24:17-07:00
Add cross-scheme migration support to KRATool (#5320)
This commit adds comprehensive cross-scheme migration capabilities to KRATool,
enabling secure migration of archived keys between KRA instances using different
cryptographic schemes (e.g., from RSA+AES/CBC to RSA-OAEP+AES-KWP for FIPS-mode HSMs).
Key Features:
- Secure rewrap flow: Private keys remain wrapped throughout migration; only
session keys are temporarily exposed during token transfer
- Entry-based LDIF processing: Order-independent parsing extracts privateKeyData
and publicKeyData regardless of their position in LDIF records
- Algorithm auto-detection: Automatically regenerates session keys when source
and target algorithms or key sizes differ, with user confirmation
- HSM compatibility: Supports payload processing in NSS DB (software token) via
-use_nss_for_payload_processing flag when HSM lacks algorithm support
- Pure Java implementation: JSS_KeyExchange mechanism with automatic fallback
to temporary RSA keypair approach for key transfer between tokens
- Performance optimizations: reuse SecureRandom, cloneKey capability caching, IV reuquirements caching, and -verbose flag to
minimize logging for large datasets
Supported Algorithms:
- Session key wrap: RSA, RSA-OAEP
- Payload wrap: AES KeyWrap/Wrapped etc. (CKM_AES_KEY_WRAP_KWP, recommended),
New Command-Line Options:
-use_cross_scheme
-source_rsa_wrap_algorithm <RSA|RSA-OAEP>
Source session key wrap algorithm (default: RSA)
-target_rsa_wrap_algorithm <RSA|RSA-OAEP>
Target session key wrap algorithm (default: RSA-OAEP)
-source_payload_wrap_algorithm <algorithm>
Source payload wrap algorithm
-target_payload_wrap_algorithm <algorithm>
Target payload wrap algorithm
-source_payload_wrap_keysize <128|192|256>
Source payload wrapping key size in bits (default: 128)
-target_payload_wrap_keysize <128|192|256>
Target payload wrapping key size in bits (default: 128)
-use_nss_for_payload_processing
Perform payload unwrap/rewrap in NSS DB when HSM lacks algorithm support
-regenerate_session_key
Force session key regeneration even when algorithms match
-split_target_ldif_per_records <N>
Split output into multiple LDIF files, each containing N records
-verbose
Enable detailed per-record logging for debugging
TEST-ONLY (hidden) options:
-skip_rewrap
-force_rsa_keypair_transfer
Assisted-by: Claude
IDM-5245
- - - - -
b3278522 by Endi S. Dewata at 2026-04-06T11:20:57-05:00
Add compatibility tests for OpenDNSSEC
Some tests with SoftHSM have been updated to install OpenDNSSEC
to prevent regression on PKI Issue #5045.
https://github.com/dogtagpki/pki/issues/5045
- - - - -
ea89f8d4 by Zachary Sherman-Burke at 2026-04-10T08:07:43-04:00
Fix EST fullcmc documentation errors
- - - - -
06ee605d by Endi S. Dewata at 2026-04-20T10:00:23-05:00
Update pki nss-cert-request
The pki nss-cert-request has been updated to store the ID of
the newly created key into the key ID file if specified.
- - - - -
7f5163ce by Endi S. Dewata at 2026-04-20T10:00:24-05:00
Update pki nss-key-show
The pki nss-key-show has been updated to throw a CLIException
if the key ID or the nickname does not exist in NSS database.
- - - - -
f808a793 by Endi S. Dewata at 2026-04-20T10:00:26-05:00
Rename pki-nss-hsm-test.yml to pki-nss-softhsm-test.yml
- - - - -
f7d85053 by Endi S. Dewata at 2026-04-21T11:36:27-05:00
Update MainCLI.promptForPassword()
The MainCLI.promptForPassword() has been updated similar to the
Password.readPasswordFromConsole() in JSS to read the password from
the standard input in case the system console is not available.
- - - - -
a5852f93 by Endi S. Dewata at 2026-04-21T14:16:38-05:00
Add pki nss-key-del
The pki nss-key-del has been added to provide a way to remove a key
pair. The CryptoUtil.deletePrivateKey() has been replaced with
deleteKeyPair() to remove the private key and the public key too if
exists, similar to JSSKeyStoreSpi.engineDeleteEntry() in JSS.
- - - - -
578def46 by Christina Fu at 2026-04-21T14:41:58-07:00
Add PKI HSM compatibility verification tools (#5330)
This commit introduces tools for verifying HSM/PKCS#11 compatibility
with Dogtag PKI KRA key archival and recovery operations:
- hsmCompatVerifyServ: Server-side verification tool that creates
mock CA/KRA certificates on HSM, verifies complete KRA workflow
including transport unwrap, storage wrap/unwrap, and PKCS#12 export.
Supports LDIF file operations for archival and recovery.
- hsmCompatVerifyClnt: Client-side tool that generates test keys,
wraps them using session key and KRA transport certificate.
- CryptoToolsUtil: Utility class for PKIArchiveOptions creation
and key wrapping operations.
Key features:
- Supports RSA and RSA-OAEP for asymmetric key wrapping (default: RSA-OAEP)
- Supports multiple symmetric key wrap algorithms: AES KeyWrap/Wrapped
(default, recommended for HSM/FIPS), AES KeyWrap/Padding,
AES KeyWrap/NoPadding, AES/CBC/PKCS5Padding
- LDIF file support for archival and recovery operations with three modes:
* Full workflow (default): archive to LDIF + recover + create PKCS#12
* Archive-only mode (--archive-only): create LDIF and stop
* Recovery-only mode (--recover-only): recover from existing LDIF
* Custom LDIF path (--ldif-file): default is <client-db-path>/kra-archived-key.ldif
- Password file options for better security (--*-passwd-file) to avoid
password visibility in process listings
- Clear option naming:
* --pkiserv-db-path for PKI server NSS database path
* --client-db-path for client NSS database path (base for all file defaults)
* --hsm-token for HSM token name
* --p12-output for PKCS#12 output file
- Automatic path resolution: relative p12 paths resolve to client-db-path,
full paths displayed in output and pk12util commands
- Standalone operation without requiring PKI server installation
- Verifies complete KRA workflow on HSM tokens
- Non-legacy PKCS#12 support with --legacyPKCS12 option:
* Non-legacy mode (default): AES-256-KWP, HSM compatible
* Legacy mode: PBE_SHA1_DES3_CBC (may fail on some HSM in FIPS 140-3)
* Matches KRA behavior: kra.legacyPKCS12=false, kra.nonLegacyAlg=AES-KWP
- HSM token fallback to internal token for P12 creation (matching KRA pattern)
- Fix HSM key iteration to handle keys without accessible public keys
Assisted-by: Claude
IDM-4768
- - - - -
aee9aa25 by Christina Fu at 2026-04-21T14:42:58-07:00
Standalone build mechanism for PKI HSM compatibility tools (pki-hsm-compat-verify rpm) (#5331)
Add standalone build infrastructure to create a standalone pki-hsm-compat-verify
RPM package independent of main PKI build. This allows administrators to install
or update the tool independently without overwriting existing PKI RPMs that may
contain critical hotfixes.
- build-hsm-compat-verify.sh: Standalone build script
- pki-hsm-compat-verify.spec: RPM spec file
- hsm-compat-verify-pom.xml: Maven configuration
The package provides two command-line tools:
- hsmCompatVerifyServ: Server-side HSM verification
- hsmCompatVerifyClnt: Client-side key generation
Assisted-by: Claude
IDM-4768
- - - - -
45d5d708 by Endi S. Dewata at 2026-04-22T14:04:27-04:00
Fix password prompt in pki CLI
The pki CLI has been modified to disable the password callback only
if the password config is specified (e.g. during installation) to
prevent OpenDNSSEC from triggering a password prompt but still allow
password prompts in other cases.
The tests for pki CLI with RSA, ECC, and SoftHSM has been updated
to create CA signing cert, SSL server cert, and audit signing cert
to validate the password prompts.
- - - - -
7a017229 by Endi S. Dewata at 2026-04-27T10:28:14-05:00
Reorganize CA profile tests
- - - - -
25b410ca by Endi S. Dewata at 2026-04-27T18:30:41-05:00
Update PKIDeployer.get_domain_info()
The PKIDeployer.get_domain_info() has been updated such that the
caller is required to call sd_connect() first.
- - - - -
67dc6147 by Endi S. Dewata at 2026-04-27T18:30:46-05:00
Merge PKIDeployer.join_security_domain() into get_install_token()
- - - - -
be7e3df6 by Endi S. Dewata at 2026-04-27T19:10:30-05:00
Update pki nss-cert-request
The pki nss-cert-request has been updated to allow optional
transport nickname such that it can generate a CRMF request
without PKIArchiveOptions.
- - - - -
ff83616a by Endi S. Dewata at 2026-04-27T22:25:03-05:00
Fix PKICertImport test by adding basicConstraints to intermediate CA
The ca_sub_signing.conf was missing the basicConstraints extension
which is required for NSS to recognize a certificate as a valid CA.
This caused test_chain_import to fail with "Certificate type not
approved for application" when verifying intermediate CA certificates.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
19496a36 by Endi S. Dewata at 2026-04-29T10:08:39-05:00
Update exception message in pki nss-cert-del
- - - - -
791cf549 by Endi S. Dewata at 2026-04-29T14:52:32-05:00
Update RPM spec to use %autochangelog
- - - - -
52d4be99 by Endi S. Dewata at 2026-04-30T21:32:46-05:00
Clean up log messages in EnrollmentService.serviceRequest()
- - - - -
c789a47c by Endi S. Dewata at 2026-04-30T21:32:46-05:00
Clean up log messages in RecoveryService.serviceRequest()
- - - - -
3c84fdfa by Endi S. Dewata at 2026-05-01T12:49:24-05:00
Clean up log messages in NSSDatabase
- - - - -
a9e91eb9 by Endi S. Dewata at 2026-05-01T18:20:41-05:00
Add tests for pki nss-cert-verify
- - - - -
0b52ac28 by Alexander Bokovoy at 2026-05-05T14:56:44+02:00
dbs: throw DBRecordNotFoundException from LDAPSession.read() when entry is not found
LDAPSearchResults.next() can return null when the LDAP search yields
no results instead of throwing LDAPException(NO_SUCH_OBJECT). The
code dereferences entry.getAttributeSet() without a null check,
causing a NullPointerException.
Throw DBRecordNotFoundException to be consistent with the existing
LDAPException(NO_SUCH_OBJECT) path already handled by
LDAPExceptionConverter.
Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>
- - - - -
9d8d6d26 by Alexander Bokovoy at 2026-05-05T14:56:44+02:00
deployment: set packetSize on AJP connectors
Add pki_ajp_packet_size to default.cfg (default: 65536, the AJP
maximum) and use it when creating AJP connectors in enable_proxy().
The upstream httpd proxy must be configured with a matching
ProxyIOBufferSize to allow the larger packets through.
Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>
- - - - -
3007edaf by Alexander Bokovoy at 2026-05-05T14:56:44+02:00
upgrade: add packetSize=65536 to existing AJP connectors
Upgrade script for existing instances that sets packetSize on all
AJP/1.3 connectors in server.xml. Skips connectors that already
carry a packetSize attribute. Reads the default value from
pki_ajp_packet_size in default.cfg.
Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>
- - - - -
8e667b2b by Alexander Bokovoy at 2026-05-05T14:56:44+02:00
docs: document AJP packet size and LDAPSession NPE fix in v11.10.0 changes
Signed-off-by: Alexander Bokovoy <abokovoy at redhat.com>
- - - - -
5eaaad16 by Endi S. Dewata at 2026-05-05T09:40:36-05:00
Add test for caStorageCert profile
A new test has been added to enroll a storage cert with RSA key
using PKCS #10 request and CRMF request with/without POP.
- - - - -
a8f335d4 by Endi S. Dewata at 2026-05-05T09:40:36-05:00
Add test for caTransportCert profile
A new test has been added to enroll a transport cert with RSA key
using PKCS #10 request and CRMF request with/without POP.
- - - - -
d35069ea by Endi S. Dewata at 2026-05-05T09:50:57-05:00
Consolidate system cert healthchecks into single module
Merge expiration.py and trustflags.py into systemcerts.py to combine
trust flag validation and expiration checks into unified classes for
each subsystem (CA, KRA, OCSP, TKS, TPS) to reduce pki-healthcheck
execution time.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
91cccca7 by Endi S. Dewata at 2026-05-05T21:27:43-05:00
Update PKISubsystem.validate_system_cert()
The PKISubsystem.validate_system_cert() has been modified
to validate the system cert using NSSDatabase.verify_cert().
- - - - -
4b979037 by Endi S. Dewata at 2026-05-07T13:32:47-05:00
Add test for PKI CLI with Kryoptic
A new test has been added to check PKI CLI against Kryoptic.
The test is similar to the existing test for SoftHSM, but
there are some differences in how the trust flags are handled
in Kryoptic.
- - - - -
666e243c by Endi S. Dewata at 2026-05-07T13:33:11-05:00
Rename code-analysis.yml to java-tests.yml
- - - - -
376006aa by Endi S. Dewata at 2026-05-07T13:33:11-05:00
Rename ca-tests2.yml to ca-extra-tests.yml
- - - - -
8129f9a8 by Endi S. Dewata at 2026-05-11T15:17:39-05:00
Update NSSDatabase.createCertificate()
The NSSDatabase.createCertificate() has been updated to require
the caller to provide the hash function.
- - - - -
a5a7b7fa by Endi S. Dewata at 2026-05-11T15:17:40-05:00
Clean up NSSExtensionGenerator.createExtensions()
The NSSExtensionGenerator.createExtensions() that takes an
issuer and a PKCS #10 object has been merged into another
method.
- - - - -
cab88984 by Endi S. Dewata at 2026-05-11T15:24:23-05:00
Clean up log messages during installation
- - - - -
8719aa4d by Endi S. Dewata at 2026-05-11T17:02:53-05:00
Clean up log messages during token auth
- - - - -
3bdde006 by Christina Fu at 2026-05-12T14:32:06-07:00
Fix KeyException handling in PKCS11KeyCLI.printKeyInfo() (#5348)
Add "throws java.security.KeyException" to printKeyInfo() method signature
to properly handle potential KeyException from PrivateKey.getType() calls.
While the current JSS master getType() does not throw KeyException, this
change prepares PKI for future JSS API enhancements that may add exception
handling for key type detection (e.g., reading CKA_PARAMETER_SET for ML-KEM
and ML-DSA keys can fail on some PKCS#11 tokens).
Impact:
- Callers (PKCS11KeyFindCLI, PKCS11KeyShowCLI) already declare "throws Exception"
so they automatically propagate this exception
- No functional change to current behavior
- Improves API consistency
Assisted-by: Claude
- - - - -
c277d955 by Endi S. Dewata at 2026-05-13T15:37:23-05:00
Update PKI CLI to support PQC
The pki nss-key-create and pki nss-cert-request have been updated
to support ML-KEM.
The pki nss-cert-request and pki nss-cert-issue have been updated
to use SHA256 only for RSA and EC. ML-DSA and ML-KEM do not use a
hash function.
The pki nss-cert-issue has been updated to support CRMF request.
The NSSDatabase.createCertificate() has been updated to allow
optional hash function.
A new test has been added to issue ML-DSA and ML-KEM certs using
PKI CLI.
- - - - -
91c4bd54 by Endi S. Dewata at 2026-05-13T16:08:45-05:00
Update CRMFPopClient to support PQC
The CRMFPopClient has been updated to support creating a CRMF
request with ML-DSA or ML-KEM key.
The KeyConstraint has been updated to support ML-KEM.
New tests have been added to install CA with ML-DSA then enroll
storage and transport certs with ML-KEM which can be used for KRA
installation later. The enrollment is done using a CRMF request
without POP created with CRMFPopClient and PKI CLI. The enrollment
is also done using profiles that use security domain session (i.e.
install token) for authentication.
- - - - -
dd68d591 by jmagne at 2026-05-13T14:54:07-07:00
IDM-5781 Add support to PBMAC1 in pkcs 12 [PKI] (#5346)
* IDM-5781 Add support to PBMAC1 in pkcs 12 [PKI] - Java
- Add configurePFXMac() to RecoveryService for CS.cfg-driven MAC selection
- Add --mac-type and --mac-digest to pki pkcs12-export CLI
- Add PKCS#12 MAC configuration to KRA CS.cfg
- Optimize SecurityDataProcessor IV generation for client-provided IVs
- Add debug logging to TransportKeyUnit unwrap operations
- Bump JSS dependency to >= 5.10.0
Assisted-by: Claude Sonnet 4.5
* IDM-5781 Add support to PBMAC1 in pkcs 12 [PKI] - Python
- Add --mac-type and --mac-digest to pki-server instance-cert-export
- Add --mac-type and --mac-digest to pki-server subsystem-cert-export
- Add mac_type/mac_digest params to nssdb.export_pkcs12()
- Add pki_pkcs12_mac_type/mac_digest to default.cfg
- Write KRA CS.cfg MAC settings during pkispawn deployment
- Hardcode legacy defaults for subsystem cert export
Assisted-by: Claude Sonnet 4.5
- - - - -
af558a0a by Endi S. Dewata at 2026-05-14T10:22:28-05:00
Rename PKISubsystem.get_cert_info() to get_system_cert_config()
- - - - -
dea3514f by Endi S. Dewata at 2026-05-14T10:22:32-05:00
Rename PKISubsystem.get_nssdb_cert_info() to get_system_cert_info()
- - - - -
a636463d by jmagne at 2026-05-14T14:18:06-07:00
Fix a couple of python violations intruduced by pbmac1 feature. (#5352)
- - - - -
fbc5a9fd by Endi S. Dewata at 2026-05-15T11:50:05-05:00
Update PKISubsystem.export_cert_chain()
The PKISubsystem.export_cert_chain() has been updated to provide
pkcs12_password param.
- - - - -
a96cb1ed by Endi S. Dewata at 2026-05-15T11:50:31-05:00
Update PKISubsystem.export_system_cert()
The PKISubsystem.export_system_cert() has been updated to provide
pkcs12_password param.
- - - - -
e503a76c by Endi S. Dewata at 2026-05-15T13:50:08-05:00
Update PKIInstance.export_external_certs()
The PKIInstance.export_external_certs() has been updated to
provide pkcs12_password param.
- - - - -
9918b8d9 by Endi S. Dewata at 2026-05-15T14:53:42-05:00
Update NSSDatabase.create_key()
The NSSDatabase.create_key() has been updated to provide
key_strength param.
- - - - -
24dbdf43 by Endi S. Dewata at 2026-05-15T15:00:14-05:00
Update NSSDatabase.create_request()
The NSSDatabase.create_request() has been updated to provide
request_type param.
- - - - -
976a96bf by Endi S. Dewata at 2026-05-15T16:22:20-05:00
Clean up log messages
- - - - -
b52c97b5 by Endi S. Dewata at 2026-05-18T15:22:00-05:00
Update pki-server <subsystem>-clone-prepare
The pki-server <subsystem>-clone-prepare commands have been
modified to create a PKCS #12 file in a temporary directory
accessible by pkiuser first, then move the file to the final
location and update the ownership after everything is done.
- - - - -
cd497ca0 by Endi S. Dewata at 2026-05-18T15:22:11-05:00
Clean up log messages in LogFile
- - - - -
c110a795 by jmagne at 2026-05-18T14:49:35-07:00
Fix: [Dev] Enable end to end KWP Support for KRA Key Archival and Recovery. (#5349)
Change distilled down to a simple resolution of any confusion on whether to use AES KEY WRAP PAD or KWP in a kra WrapingParams situation. This fix takes steps to make sure KWP is used if the token supports that mechanism.
Also added a fallback to AES KEY WRAP PAD in case the client call explicitly wanted this algorithm.
Assisted by: Claude Sonnet 4..
- - - - -
b273c619 by Endi S. Dewata at 2026-05-19T10:42:44-05:00
Fix failure in CA test with ML-DSA
The PK11PrivKey.getAlgorithm() in JSS was updated recently to
return the algorithm family name (e.g. ML-DSA) instead of the
full algorithm name (e.g. ML-DSA-<strength>) which have caused
the CA test with ML-DSA to fail due to NoSuchAlgorithmException
in LogFile.setupSigning().
The code has been modified to handle the algorithm family name
properly so that the test will complete successfully.
The PKI CLI test with PQC has been updated to validate the key
algorithm.
- - - - -
edefb1f5 by Endi S. Dewata at 2026-05-19T11:07:10-05:00
Update pkispawn to support KRA with PQC
pkispawn has been modified to support installing KRA with ML-KEM
for storage and transport certs and ML-DSA for other certs. It
will use CRMF without POP to request ML-KEM certs from the CA.
A new test has been added to install CA and KRA with ML-DSA and
ML-KEM certs. The test needs to modify the profiles used to issue
the storage and transport certs since they don't support ML-KEM
by default. In the future the profiles can be updated to support
ML-KEM so this step will not be needed. Also in the future the
test can be improved to validate key archival and recovery.
- - - - -
98ef735d by Endi S. Dewata at 2026-05-19T11:07:43-05:00
Clean up KRA clone tests
- - - - -
cdce94bc by Christina Fu at 2026-05-19T14:13:49-07:00
Add PQC algorithm mapping and ML-KEM key wrap/unwrap helpers (#5354)
Adds helper methods to CryptoUtil for PQC operations:
Algorithm name mapping:
- getMLDSAStrength(): Maps ML-DSA algorithm names to strength parameters
- getMLDSASignatureAlgorithm(): Maps ML-DSA names to SignatureAlgorithm
- getMLKEMStrength(): Maps ML-KEM algorithm names to strength parameters
ML-KEM encapsulation/decapsulation:
- encapsulateMLKEM(): Generates shared secret and ciphertext
- decapsulateMLKEM(): Recovers shared secret from ciphertext
- KEMEncapsulation: Result class containing shared secret and ciphertext
(compatible with existing non-PQC LDAP storage format)
These helpers consolidate PQC algorithm handling and will be used by
KRA key archival/recovery and hsmCompatVerify test tools.
IDM-6295
Assisted-by: Claude
- - - - -
275572f3 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix Javadoc warnings on unknown tag
- - - - -
d981255b by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix remaining Javadoc warnings
- Fix @exception tags with incorrect class names:
- CertUserDBAuthentication: Replace EAuthsException with actual exception types
- NullAuthentication: Replace fully qualified names with actual exception types
- PasswdUserDBAuthentication: Replace fully qualified names with actual exception types
- LdapConnFactory: Fix EldapException to ELdapException
- LogEventListener: Replace generic text with EBaseException
- CRMFParser: Fix malformed @exception tag to specify IOException
- Fix @param tags with incorrect parameter names:
- DBSSession: Change sortKey to sortKeys to match actual parameter
- Fix broken @link references:
- LDAPDatabase: Replace broken findPagedCertRecords reference with description
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
dc9bba94 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix unused variable warning in tkstool delete.c
Remove unused 'count' variable that was causing -Wunused-but-set-variable
build warning. The variable was incremented but never used in the logic.
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
5bdaccdd by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix unused parameter warnings in tkstool file.c
Mark wrappedKeyName parameter as unused in TKS_ReadInputFileIntoSECItem
and TKS_WriteSECItemIntoOutputFile functions. These parameters are part
of the API interface but not used in the current implementation.
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
4dad4111 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix unused parameter warning in tkstool help.c
Mark progName parameter as unused in TKS_PrintHelp function.
The parameter is part of the API interface but not used in
the current implementation.
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
50694352 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix build warnings in tkstool key.c
- Fix signed/unsigned comparison warnings by changing int variables
to PRUint32 in InputHexSessionKey and TKS_GenerateSessionKeyShare
- Fix variable shadowing by renaming pwdata parameter to pwdataParam
in TKS_ImportSymmetricKey
- Remove unused origin variable from TKS_ImportSymmetricKey
- Mark unused parameters as intentionally unused in TKS_ImportSymmetricKey
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
11dba8bc by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix unused parameter warnings in tkstool list.c
Mark index and dopriv parameters as unused in TKS_ListKeys function.
These parameters are part of the API interface but not used in
the current implementation.
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
7d794512 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix build warnings in tkstool pppolicy.c
- Add missing field initializers for SEC_ASN1Template structures
(explicit NULL and 0 values for 'sub' and 'size' fields)
- Mark unused 'msg' parameters as intentionally unused in
secu_PrintUserNoticeQualifier and secu_PrintPolicyInfo functions
- Add explicit fallthrough comment to fix implicit fallthrough warning
in secu_PrintPolicyQualifier switch statement
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
91487fd3 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix missing prototype warning in tkstool secerror.c
Add missing include for secutil.h which contains the prototype
for SECU_Strerror function, fixing the -Wmissing-prototypes warning.
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
40e3bb35 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix unused result warning in tkstool secpwd.c
Check return value of QUIET_FGETS (fgets) to fix -Wunused-result
warning. Handle error/EOF cases properly by restoring echo and
returning NULL. Also add safety check before removing newline
character to prevent accessing invalid memory.
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
b6eba393 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix initial build warnings in tkstool secutil.c (part 1)
- Make internal functions static: SECU_GetString, SECU_PrintErrMsg, secu_InitSlotPassword
- Add format attribute to SECU_PrintErrMsg to fix format warning
- Mark unused parameters: SECU_GetPasswordString (arg), SECU_FilePasswd (slot)
- Fix missing field initializer in SECU_ReadDERFromFile filedata struct
- Fix unused variable warning in SECU_ChangePW by using rv to check PK11_InitPin result
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
7f61b983 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix more build warnings in tkstool secutil.c (part 2)
Make more internal functions static to fix missing prototype warnings:
- secu_StdinToItem
- SECU_StripTagAndLength
- SECU_PrintSet
- SECU_PrintEncodedBoolean
- SECU_PrintEncodedInteger
- SECU_PrintEncodedObjectID
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
16d38b79 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix additional build warnings in tkstool secutil.c (part 3)
- Make more internal functions static: SECU_DecodeAndPrintExtensions,
SECU_PrintSetOfExtensions, SECU_PrintSetOfAny, SECU_PrintCertAttribute,
SECU_PrintCertAttributes, printFlags
- Add format attributes to SECU_PrintError and SECU_PrintSystemError
- Mark unused parameters: SECU_GetClientAuthData (fd, caNames),
secu_PrintSubjectPublicKeyInfo (arena), SECU_ParseCommandLine (progName),
SECU_PrintCertAttribute (m)
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
cc9e7502 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix unused parameter warnings in tkstool secutil.c (part 4)
Mark unused 'msg' parameters in extension printing functions:
- secu_PrintX509KeyUsage
- secu_PrintAuthKeyIDExtension
- secu_PrintCRLDistPtsExtension
- secu_PrintNameConstraintsExtension
- secu_PrintAuthorityInfoAcess
Mark unused 'authorityKeyID' parameter in SECU_FindCrlIssuer
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
41ebd66e by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix implicit fallthrough and const qualifier warnings in tkstool secutil.c (part 5)
- Add missing break statements in SECU_printCertProblems switch cases
to fix implicit fallthrough warnings
- Fix const qualifier warnings by changing variable declarations:
- SECU_ConfigDirectory: home -> const char *
- SECU_PrintName: str -> const char *
- SECU_PrintCertNickname: name -> const char *
- Fix const qualifier warning in SECU_GetModulePassword by casting "external"
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
c9f91e36 by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix remaining build warnings in tkstool secutil.c (part 6)
- Fix const qualifier warnings: change errstr to const char * in SECU_printCertProblems
- Fix sign comparison warnings: cast sizeof to PRInt32 in SECU_PrintPRandOSError
- Fix pointer-to-int cast warnings: use uintptr_t intermediate cast in SECU_printCertProblems
- Fix deprecated declaration warnings: replace CERTDB_VALID_PEER with CERTDB_TERMINAL_RECORD
- Fix sign comparison in SECU_StoreCRL: cast PR_Write result to unsigned int
- Add stdint.h include for uintptr_t support
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
76451a9e by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix compiler warnings in tkstool.c
- Fix const qualifier warnings by declaring DBPrefix and slotname as const char*
- Fix sign comparison warnings by casting sizeof to PRInt32 when comparing with errLen
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
a16956fa by Endi S. Dewata at 2026-05-20T01:28:30+00:00
Fix compiler warnings in tkstool util.c
- Fix unterminated string initialization by using {0} instead of explicit null characters
- Fix unused-but-set variables by adding proper terminal settings restoration
- Fix unused result warning for system() calls by storing and marking result as unused
- Add terminal restoration code to properly restore original terminal settings
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
c083ca67 by Endi S. Dewata at 2026-05-20T16:00:28-05:00
Update PQC tests, docs, and config files
A new doc and config file have been added for installing
KRA with PQC. The test for KRA with PQC has been updated to
use the new config file.
The installing-ca-with-mldsa.adoc has been renamed into
installing-ca-with-pqc.adoc for consistency.
The ca-mldsa.cfg and ca-clone-mldsa.cfg have been renamed into
ca-pqc.cfg and ca-clone-pqc.cfg for consistency. The files have
also been updated to use ML-DSA-65 to reflect the default
strength for ML-DSA.
The ca-mldsa-test.yml and ca-clone-mldsa-test.yml have been
renamed into ca-pqc-test.yml and ca-clone-pqc-test.yml for
consistency and also updated to use ML-DSA-65.
- - - - -
7092e06c by Endi S. Dewata at 2026-05-20T16:47:05-05:00
Update NSSDatabase.run()
The NSSDatabase.run() has been updated to switch user only
if the current user is not the owner of the NSS database.
- - - - -
02a1d82f by Endi S. Dewata at 2026-05-21T17:22:33-05:00
Drop PKIDeployer.self.system_certs
- - - - -
aece5f64 by Endi S. Dewata at 2026-05-21T17:22:33-05:00
Rename PKIServer.store_cert_request() into store_csr()
- - - - -
708941c3 by Endi S. Dewata at 2026-05-21T17:22:33-05:00
Refactor PKIDeployer.setup_sytstem_certs()
Some of the code in PKIDeployer.setup_sytstem_certs() has been
simplified and moved into setup_system_cert().
- - - - -
4be4f7e8 by Endi S. Dewata at 2026-05-21T17:22:33-05:00
Add PKIDeployer.setup_local_system_cert()
The code that creates a system cert locally has been moved
into PKIDeployer.setup_local_system_cert().
- - - - -
8c0e4ba0 by Endi S. Dewata at 2026-05-21T17:22:33-05:00
Add PKIDeployer.setup_remote_system_cert()
The code that creates a system cert remotely has been moved
into PKIDeployer.setup_remote_system_cert().
- - - - -
bd2e3f55 by Endi S. Dewata at 2026-05-21T17:22:33-05:00
Add PKIDeployer.setup_system_csr()
The code that generates a CSR for a system cert has been moved
into PKIDeployer.setup_system_csr().
- - - - -
2f52f93e by Christina Fu at 2026-05-21T18:34:04-07:00
Fix CryptoUtil ML-KEM methods to accept key size in bits (#5363)
Change encapsulateMLKEM() and decapsulateMLKEM() to accept key
size in bits instead of bytes, consistent with PKI convention and
other CryptoUtil methods like generateKey().
The methods now convert bits to bytes internally when calling the
Java KEM API, making them compatible with params.getSkLength()
which returns key size in bits.
IDM-6295
- - - - -
8b3796ae by Endi S. Dewata at 2026-05-26T14:09:30-05:00
Add support for installing CA with Kryoptic
The code in NSSDatabase, PKIInstance, PKISubsystem, and PKIDeployer
has been modified to run external commands as pkiuser so that they
can access Kryoptic token in pkiuser's home directory.
The PKIDeployer.setup_system_cert() has been modified to set the
trust attributes while importing the certs due to an issue in
Kryoptic, but it will continue to update the trust attributes
after import for cloning with certain HSMs (e.g. SoftHSM) where
trust attributes are stored in the internal token.
- - - - -
0060dddb by Endi S. Dewata at 2026-05-26T14:09:30-05:00
Add test for installing CA with Kryoptic
A new test has been added to create a Kryoptic token in pkiuser's
home directory then install CA with the token. The existing test
for PKI CLI with Kryoptic has been updated to set the trust
attributes while importing the certs due to an issue in Kryoptic.
- - - - -
348eb021 by Endi S. Dewata at 2026-05-26T18:09:51-05:00
Drop PKISubsystem.find_system_certs()
The PKISubsystem.find_system_certs() has been replaced with
get_subsystem_certs() and the get_subsystem_cert() will only
be called if needed.
- - - - -
e0c86aff by Endi S. Dewata at 2026-05-26T18:10:32-05:00
Replace PKISubsystem.get_subsystem_cert() in pki-healthcheck
The pki-healthcheck has been updated to call PKISubsystem.
get_system_cert_config() instead of get_subsystem_cert() and
it will only call get_system_cert_info() if needed.
- - - - -
1ae6193a by Endi S. Dewata at 2026-05-26T20:36:22-05:00
Replace PKISubsystem.get_subsystem_cert() in pki-server CLI
The pki-server CLI has been updated to call PKISubsystem.
get_system_cert_config() instead of get_subsystem_cert() and
it will only call get_system_cert_info() if needed.
- - - - -
077c0f9d by Marco Fargetta at 2026-05-27T12:04:59+02:00
Fix ML-DSA signing algorithm name extraction
Extract the specific ML-DSA variant name from NamedParameterSpec when
determining the signing algorithm. This ensures ML-DSA keys use the
correct variant identifier (e.g., ML-DSA-44, ML-DSA-65, ML-DSA-87)
rather than the generic KeyPairAlgorithm name when signing
certificates.
This fix is necessary because ML-DSA has multiple variants defined by
NIST FIPS 204, and the signing operation requires the specific variant
name to select the correct algorithm parameters.
- - - - -
83fcb97c by Marco Fargetta at 2026-05-27T15:02:17+02:00
Add ML-DSA support to PKCS10Client
PKCS10Client now supports generating ML-DSA key pairs in addition to
RSA and EC. The -a parameter accepts "mldsa" and the -l parameter
specifies the ML-DSA strength (44, 65, or 87, default 65).
Updated documentation to reflect ML-DSA support. Renamed rsa_keylen
variable to keyStrength for clarity.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
205f30e0 by Endi S. Dewata at 2026-05-27T20:17:05-05:00
Replace PKISubsystem.get_subsystem_cert() in PKIDeployer
The PKIDeployer has been updated to call PKISubsystem.
get_system_cert_config() or get_system_cert_info() directly
instead of get_subsystem_cert().
- - - - -
c4f02e17 by Endi S. Dewata at 2026-05-28T09:15:03-05:00
Add test for installing KRA with Kryoptic
A new test has been added to create a Kryoptic token in pkiuser's
home directory then install CA and KRA with the token using PQC
certs.
The existing test for installing CA with Kryoptic has also been
updated to use PQC certs.
- - - - -
351e3201 by Endi S. Dewata at 2026-05-28T13:08:57-05:00
Drop PKISubsystem.get_subsystem_cert()
The remaining references to PKISubsystem.get_subsystem_cert()
have been replaced with get_system_cert_config() and
get_system_cert_info().
- - - - -
5d4cc46b by Endi S. Dewata at 2026-05-28T18:18:52+00:00
Fix build warnings in pistool delete.c
Replace deprecated key.h include with keyhi.h and remove unused count variable in TKS_DeleteKeys().
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
73268b71 by Endi S. Dewata at 2026-05-28T18:30:33+00:00
Fix build warnings in pistool file.c
Mark wrappedKeyName parameters as intentionally unused in TKS_ReadInputFileIntoSECItem() and TKS_WriteSECItemIntoOutputFile().
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
00ed2d3f by Endi S. Dewata at 2026-05-28T18:30:55+00:00
Fix build warnings in pistool help.c
Mark progName parameter as intentionally unused in TKS_PrintHelp().
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
18b8e0ff by Endi S. Dewata at 2026-05-28T18:30:58+00:00
Fix build warnings in pistool key.c
Fix sign comparison warnings by casting PL_strlen() results to appropriate
integer types (int or PRIntn).
Fix const-qualifier warnings by updating function signatures to accept
const char * for string parameters:
- InputHexSessionKey: sessionKeyShareName parameter
- InputHexKCV: sessionKeyShareName parameter
- TKS_ComputeAndDisplayKCV: keyName parameter (in both key.c and pistool.h)
- Make keyType parameter const in TKS_ComputeAndDisplayKCV
Fix declaration-after-statement by moving variable declarations to comply
with ISO C90.
Fix uninitialized variable warning by explicitly initializing
hexSessionKeyShare field-by-field to avoid false positive with LTO.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
75c15949 by Endi S. Dewata at 2026-05-28T18:31:37+00:00
Fix build warnings in pistool list.c
Mark index and dopriv parameters as intentionally unused in TKS_ListKeys().
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
d4864872 by Endi S. Dewata at 2026-05-28T20:24:42+00:00
Fix build warnings in pistool secerror.c
Add include for secutil.h to provide the SECU_Strerror prototype.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
0ead8e91 by Endi S. Dewata at 2026-05-28T20:24:42+00:00
Fix build warnings in pistool secpwd.c
Check the return value of fgets and handle NULL properly to avoid
undefined behavior when fgets fails.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
ede5482f by Endi S. Dewata at 2026-05-28T20:24:42+00:00
Fix build warnings in pistool util.c
- Fix unterminated string initialization by using {0}
- Remove unused variables: rv, orig_lflag, orig_cc_min, orig_cc_time
- Capture and explicitly ignore system() return value
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
7214549f by Endi S. Dewata at 2026-05-28T22:06:41+00:00
Fix build warnings in pistool pppolicy.c
Add explicit NULL/0 initializers to SEC_ASN1Template structures to fix
-Wmissing-field-initializers warnings:
- secu_PolicyQualifierTemplate: qualifierID and qualifierValue entries
- secu_PolicyInfoTemplate: policyID and policyQualifiers entries
SEC_ASN1Template has four fields: kind, offset, sub, and size. When sub
is NULL and size is 0, both must be explicitly specified to avoid compiler
warnings about missing field initializers.
Make msg parameters const char * in pppolicy.c functions:
- secu_PrintUserNoticeQualifier
- secu_PrintPolicyQualifier
- secu_PrintPolicyInfo
Also update const char * for msg parameters in secutil.c and secutil.h:
- SECU_PrintString
- SECU_PrintGeneralizedTime
- SECU_PrintAny
- SECU_PrintObjectID
Mark unused msg parameters with (void) casts in:
- secu_PrintUserNoticeQualifier
- secu_PrintPolicyInfo
Add FALLTHROUGH comment for intentional switch case fall-through in
secu_PrintPolicyQualifier.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
9c7f7807 by Marco Fargetta at 2026-05-29T10:05:21+02:00
Add ML-DSA signature support for CMC enrollment
Implement RFC 9882 algorithm requirements for Certificate Management
over CMS (CMC) [1] by adding support for ML-DSA post-quantum signature
algorithms.
Changes:
- Update CMCRequest to detect ML-DSA key types and select appropriate
signature algorithms based on parameter specs
- Configure SHA-512 as the digest algorithm for ML-DSA signatures in
both CMCRequest and CMCOutputTemplate
This enables CMC-based enrollment and issuance of certificates using
post-quantum ML-DSA signature algorithms as specified in RFC 9882.
Additionally, add a new `caCMCMLDSAserverCert` profile for server
certificates with ML-DSA keys (ML-DSA-44, ML-DSA-65, ML-DSA-87) and
register the new profile in CS.cfg profile list.
1. RFC 9882 - Using ML-DSA in the Cryptographic Message Syntax (CMS)
(https://www.rfc-editor.org/rfc/rfc9882)
- - - - -
9de01b55 by Marco Fargetta at 2026-05-29T10:05:21+02:00
Extend CA PQC tests with a CMC certificate request
- - - - -
00a9aa9d by jmagne at 2026-05-29T16:28:25-07:00
Fix [Dev] ML-KEM (with Archival) support for CRMFPopClient (and/or cli) (#5364)
Add code in KRA to extract the ML-KEM session key if encapsulated.
Added a new user profile caMLKEMUserCert.cfg
Fixed UserKeyDefault.java to recognize ML-KEM, it already checks for ML-DSA.
Assisted-by: Claude Sonnet 4.5
- - - - -
60dc2ac8 by Christina Fu at 2026-05-29T18:57:39-07:00
Add ML-KEM storage support to KRA key archival (#5358)
* Add ML-KEM support to KRA key archival
This change adds ML-KEM key archival support to KRA when using an ML-KEM
storage certificate:
- When an ML-KEM storage certificate is detected, the archival process uses
ML-KEM encapsulation to derive a shared secret (instead of generating and
wrapping a session key with RSA/EC as in traditional archival).
- The user's private key is wrapped with the shared secret using AES-KWP,
producing a backward-compatible privateKeyData structure:
SEQUENCE { kemCiphertext, wrappedPrivateKey }
- Runtime enforcement ensures that ML-KEM storage certificates cannot be
used with the allowEncDecrypt_archival mode, as ML-KEM does not support
this alternative encryption path.
- The privateKeyData structure remains compatible with existing code:
RSA/EC storage: SEQUENCE { wrappedSessionKey, wrappedPrivateKey }
ML-KEM storage: SEQUENCE { kemCiphertext, wrappedPrivateKey }
Recovery (unwrap) support will be added in a separate PR.
Assisted-by: Claude
IDM-5472
IDM-6363
* Improve ML-KEM keyRecord metadata and upgrade to AES-256
Skip non-applicable metadata fields for ML-KEM key archival:
- sessionKeyWrapAlgorithm and sessionKeyKeyGenAlgorithm are not
applicable to ML-KEM (uses encapsulation, not wrapping/generation)
- payloadEncryptionOID and payloadEncryptionIV are only used when
kra.allowEncDecrypt.archival=true (which ML-KEM does not support)
Add storageKeyAlgorithm field to keyRecord metadata to clearly
indicate the storage certificate algorithm (e.g., "ML-KEM-1024",
"RSA", "EC") for better visibility and debugging.
Upgrade default session key size from AES-128 to AES-256 for
improved security (applies to RSA, EC, and ML-KEM storage certs).
Add recommended security settings to KRA CS.cfg:
- keyWrap.useOAEP=true for RSA session key wrapping
- kra.legacyPKCS12=false with AES-256-KWP for PKCS#12 encryption
- Add explanatory comments for configuration clarity
Before (ML-KEM keyRecord metadata):
metaInfo: sessionKeyWrapAlgorithm:RSA
metaInfo: payloadEncrypted:false
metaInfo: sessionKeyKeyGenAlgorithm:AES
metaInfo: sessionKeyType:AES
metaInfo: sessionKeyLength:128
metaInfo: payloadEncryptionOID:2.16.840.1.101.3.4.1.2
metaInfo: payloadEncryptionIV:N5Dpy30TAonmtwgnCdFpKg==
metaInfo: payloadWrapAlgorithm:AES KeyWrap/Padding
algorithm: 2.16.840.1.101.3.4.4.2
After (ML-KEM keyRecord metadata):
metaInfo: storageKeyAlgorithm:ML-KEM
metaInfo: payloadEncrypted:false
metaInfo: sessionKeyType:AES
metaInfo: sessionKeyLength:256
metaInfo: payloadWrapAlgorithm:AES KeyWrap/Padding
algorithm: 2.16.840.1.101.3.4.4.2
Assisted-by: Claude
IDM-5472 IDM-6363
- - - - -
7d865942 by Zachary Sherman-Burke at 2026-06-01T10:47:47-04:00
Adding test to verify LDAPS works with ML-DSA
- - - - -
47d959ed by Taylor Herring at 2026-06-01T14:54:52-04:00
Fix Tomcat paths for RHEL compatibility (DOGTAG-4399)
Update Tomcat executable and systemd wrapper script paths for pki-tomcat-start/stop from /usr/bin to /usr/sbin for compatibility in RHEL. Additionally removed an in-line systemd service file comment causing a systemd parsing warning, which also resulted in pkispawn failure
- - - - -
ecab4dd3 by Taylor Herring at 2026-06-01T17:29:31-04:00
Add upstream test for internal OCSP with ML-DSA (DOGTAG-4381)
- - - - -
216614ab by Taylor Herring at 2026-06-01T19:31:13-04:00
fix: enable caMLDSAUserCert profile for internal OCSP test
- - - - -
6bbe41cb by Endi S. Dewata at 2026-06-01T22:00:35-05:00
Fix build warnings in pistool.c and related files
This commit addresses multiple ISO C90 compliance and build warnings:
- Move variable declarations to the beginning of code blocks to comply
with ISO C90 (all declarations must appear before executable statements)
- Make string literal initializations use const char *
- Fix sign comparison warnings by casting sizeof to PRInt32
- Fix const qualifier warnings by updating function signatures
- Add KEY_ALG_UNKNOWN cases to switch statements
- Mark unused DBDir variable
- Initialize detectedAlgString to NULL
The changes ensure pistool.c compiles cleanly with strict C90 compliance
flags and eliminates declaration-after-statement, sign-compare, and
const-qualifier warnings.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
7febec1d by Endi S. Dewata at 2026-06-01T22:03:44-05:00
Clean up log messages in CI
- - - - -
f0b3d0b5 by Christina Fu at 2026-06-01T20:44:21-07:00
Minimize impact on non-PQC deployments for KRA archival (#5373)
Changes to reduce impact on existing RSA/EC KRA deployments:
1. CS.cfg: Restore sessionKeyLength=128 (from 256) and keep
keyWrap.useOAEP commented out (false by default) to maintain
backward compatibility with existing configurations.
2. KeyRecord.java: Only store storageKeyAlgorithm metadata for
ML-KEM keys. RSA/EC keys don't need this field since the
algorithm can be determined from the key itself.
Note: TransportKeyUnit.java already has the correct RSA unwrap
logic from the parent commit, so no changes needed.
- - - - -
34b2d8a0 by Zachary Sherman-Burke at 2026-06-02T06:51:03-04:00
Add HTTPS connector test with ML-DSA certs (DOGTAG-4372)
- - - - -
b1758ecd by Christina Fu at 2026-06-02T14:46:15-07:00
Add ML-KEM-specific enrollment profiles for KRA storage and transport certificates (#5361)
Creates dedicated enrollment profiles for issuing ML-KEM certificates to KRA
subsystems, ensuring RFC 9935 compliance.
Changes:
- Add caMLKEMInternalAuthDRMstorageCert profile
* Supports ML-KEM-512, ML-KEM-768, ML-KEM-1024
* Sets keyEncipherment as only key usage bit (per RFC 9935 §5)
* No clientAuth EKU (ML-KEM certs don't perform SSL client auth)
* Uses ML-DSA-65 for signing
- Add caMLKEMInternalAuthTransportCert profile
* Same ML-KEM parameter set support
* RFC 9935 compliant key usage
* No clientAuth EKU
- Update pkispawn to use ML-KEM profiles when KRA certs use MLKEM key type
* Automatically selects caMLKEMInternalAuthDRMstorageCert for ML-KEM storage certs
* Automatically selects caMLKEMInternalAuthTransportCert for ML-KEM transport certs
* Falls back to RSA profiles (caInternalAuthDRMstorageCert/caInternalAuthTransportCert) for non-ML-KEM
* For ML-KEM: sets keyEncipherment only, no clientAuth
* For RSA/EC: preserves existing key usage and clientAuth
- Add ML-KEM exemption to certificate validation
* CertUtil.verifyCertificateUsage() skips SSLClient validation for ML-KEM certs
* ML-KEM transport/storage certs have only keyEncipherment, not SSLClient usage
* Allows ML-KEM KRA instances to start without validation errors
* Existing RSA/EC KRA instances unaffected (still validate with SSLClient)
* Errors in ML-KEM detection propagate to caller rather than being silently caught
- Add ML-KEM profile tests
* New workflow files for testing ML-KEM-specific profiles
* Tests CRMFPopClient enrollment without POP for both ML-KEM variants
* Tests PKI CLI CRMF enrollment without POP
* Verifies cert issuance and key matching
* Existing RSA/EC profile tests remain unchanged
RFC 9935 compliance: ML-KEM certificates must have keyEncipherment as the
only key usage bit when the keyUsage extension is present.
Assisted-by: Claude
IDM-6363
- - - - -
39414a48 by Christina Fu at 2026-06-02T20:45:05-07:00
Add ML-KEM support for KRA key recovery (#5362)
This commit implements complete ML-KEM support for KRA key recovery
workflow, enabling recovery of keys that were archived using ML-KEM
storage certificates or retrieval using ML-KEM transport certificates.
Server-side recovery changes (storage key):
- StorageKeyUnit.java:
* Updated unwrap() methods for both PrivateKey and SymmetricKey
recovery to detect ML-KEM storage certificate
* Added ML-KEM decapsulation to recover shared secret from KEM
ciphertext instead of traditional session key unwrapping
* Maintains backward compatibility with RSA/EC storage certificates
* Added comments documenting SEQUENCE structure semantics for
RSA/EC (wrapped session key) vs ML-KEM (KEM ciphertext)
- RecoveryService.java:
* Added note that allowEncDecrypt_recovery is not supported for
ML-KEM storage at this time
Server-side recovery changes (transport key):
- EncryptionUnit.java:
* Updated unwrap_session_key() to detect ML-KEM transport
certificate and use decapsulation instead of unwrapping
* Added clarifying comments explaining KEM ciphertext vs wrapped key
Client-side recovery changes (transport key handling):
- CryptoUtil.java:
* Added defensive checks in wrapSymmetricKey() and wrapUsingPublicKey()
* Throws clear exception if ML-KEM transport key is detected
Client-side recovery changes (passphrase-based recovery):
- CryptoProvider.java:
* Added abstract encapsulateMLKEM() method for ML-KEM encapsulation
- NSSCryptoProvider.java:
* Implemented encapsulateMLKEM() with token.importPublicKey() to
fix SIGSEGV crash during ML-KEM public key operations
* Added defensive NSS token login logic with helpful error messages
for uninitialized NSS databases
- KeyClient.java:
* Updated retrieveKeyByPassphrase() and retrieveKeyByRequestWithPassphrase()
to detect ML-KEM transport certificate and use encapsulateMLKEM()
* For ML-KEM: generates shared secret directly via encapsulation
* For RSA/EC: generates session key and wraps it (existing behavior)
* Encrypts passphrase with session key/shared secret in both cases
Key insight: ML-KEM encapsulation produces both the shared secret and
ciphertext together, unlike RSA/EC where the session key is generated
separately and then wrapped.
Recovery workflow:
1. Read privateKeyData SEQUENCE from KeyRecord
2. Extract ciphertext (first OCTET STRING) and wrapped key (second)
3. If storage/transport cert is ML-KEM: decapsulate to get shared secret
4. If storage/transport cert is RSA/EC: unwrap session key (existing path)
5. Unwrap user's private key with shared secret/session key
6. Create PKCS#12 with recovered key (works for PQC keys)
The PKCS#12 creation code requires no changes as it already works
with PQC keys (verified by hsmCompatVerifyServ tool).
Assisted-by: Claude
IDM-5473 IDM-6363
- - - - -
a7b3b731 by Endi S. Dewata at 2026-06-03T14:40:48+00:00
Add function prototypes and const qualifiers to secutil.h and secutil.c
Header file (secutil.h):
- Add missing function prototypes to prevent -Wmissing-prototypes warnings
- Update function parameters to const char* for string literals to fix const qualifier warnings
- Add format attributes for printf-style functions to enable static analysis
- Update function signatures: SECU_PrintError, SECU_PrintSystemError, SECU_PrintErrMsg
- Fix SECU_StripTagAndLength return type to SECStatus (matches implementation usage)
- Add const qualifiers to message parameters in print functions
Implementation file (secutil.c):
- Update function signatures to match header with const char* qualifiers
- Fix return types (int to SECStatus) for SECU_DecodeAndPrintExtensions,
SECU_PrintSetOfExtensions, SECU_PrintSetOfAny, SECU_PrintCertAttribute,
and SECU_PrintCertAttributes
This aligns the function definitions with their prototypes and eliminates
missing prototypes and const qualifier warnings while maintaining API compatibility.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
b3d8c258 by Endi S. Dewata at 2026-06-03T14:40:48+00:00
Fix build warnings in secutil.c
- Mark unused parameters with __attribute__((unused)) to suppress -Wunused-parameter warnings
- Fix implicit enum conversion warning by returning SECFailure instead of SEC_ERROR_NO_MEMORY
- Add missing break statement to fix -Wimplicit-fallthrough warning in SECU_printCertProblems
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
25cd080e by Endi S. Dewata at 2026-06-03T14:40:48+00:00
Fix build warnings in pistool secutil files
Add const qualifiers to function parameters accepting string literals
and update all function definitions to match updated declarations.
Changes include:
- secutil.h: Update function declarations to use const char * for
message/prompt parameters (SEC_GetPassword, SECU_PrintPolicy,
SECU_PrintCRLInfo, SECU_PrintName, SECU_PrintExtensions,
SECU_PrintFingerprints)
- secutil.c: Update ~35 function definitions to match declarations,
mark unused parameters with __attribute__((unused)), and fix
implicit fall-through in switch statement by adding missing break
- pppolicy.c: Update SECU_PrintPolicy definition to use const char *
- secpwd.c: Update SEC_GetPassword definition to use const char *
This resolves all const-discard warnings, unused-parameter warnings,
and conflicting type errors in the pistool native code.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
ed51092a by Endi S. Dewata at 2026-06-03T20:14:37+00:00
Fix build warnings in pistool secutil.c
- Replace deprecated CERTDB_VALID_PEER with CERTDB_TERMINAL_RECORD
- Add const qualifier to SECU_PPFunc msg parameter
- Cast PRInt32 to size_t for sizeof comparisons
- Use uintptr_t for pointer-to-int conversions
- Cast PR_Write return value for unsigned comparison
- Fix sizeof(sd) to sizeof(*sd) in memset
- Fix incompatible pointer type errors in SECU_PrintCertificate function
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
6e0a0df3 by Endi S. Dewata at 2026-06-03T20:15:15+00:00
Fix build warnings in setpin b64.c
- Remove unused variable 'len' in ldif_base64_encode_internal
- Add function prototype for ldif_base64_encode
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
fba365da by Endi S. Dewata at 2026-06-03T20:15:15+00:00
Fix build warnings in setpin options.c
Updated function signatures and declarations in setpin options
files to resolve compiler warnings.
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
49f3938e by Endi S. Dewata at 2026-06-03T20:15:15+00:00
Fix build warnings in setpin.c
- Add static qualifiers and function prototypes for internal functions
- Cast string literals to char* for LDAPMod structure assignments
- Cast pwd parameter to unsigned char* for PK11_HashBuf
- Move struct berval declaration before code to comply with C90
- Cast pointer to uintptr_t before converting to unsigned int
- Remove unused 'change' variable
- Fix strcpy source/destination issue by using pointer assignment
- Add stdint.h for uintptr_t
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
0a81d9b9 by Endi S. Dewata at 2026-06-04T00:33:07+00:00
Fix XP_UNIX redefinition warning in config.h
Add ifndef guard around XP_UNIX definition to prevent redefinition
warnings when NSPR headers (which already define XP_UNIX) are included.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
c5e28b2b by Endi S. Dewata at 2026-06-04T00:33:07+00:00
Fix build warning in Util.cpp
Remove unused status variable in DiversifyKey function.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
59ad7c01 by Endi S. Dewata at 2026-06-04T00:33:07+00:00
Fix build warnings in RA_Client.cpp
Replace unsafe sprintf pattern that used output buffer as both source
and destination with pointer arithmetic to safely append hex bytes.
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
05e1be32 by Endi S. Dewata at 2026-06-04T00:33:07+00:00
Fix build warnings in RA_Conn.cpp
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
46b5435b by Endi S. Dewata at 2026-06-04T00:33:07+00:00
Fix build warnings in RA_Token.cpp
- Change char* to const char* for curveName in curveNameTagPair struct
- Change char* to const char* for keycurve variable in ProcessGenerateKeyECC
- Fix const char* to char* conversion in SetMSN function using const_cast
- Add missing variable declarations: input buffer in CreateSessionKey, algtag in ProcessGenerateKey
- Remove unused variables and code: input buffer loops, attrFlags, n variable assignment
- Add void cast to suppress algtag unused variable warning in ProcessGenerateKey
- Move pkeyb and pkeyb_len declarations inside VERIFY_PROOF ifdef block
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
03a1b221 by Endi S. Dewata at 2026-06-04T00:33:07+00:00
Fix build warning in TPSClientCLI.cpp
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
e9c19b49 by Endi S. Dewata at 2026-06-04T00:33:07+00:00
Fix build warning in tpsclient.cpp
Co-Authored-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
a3257d40 by Marco Fargetta at 2026-06-05T09:44:23+02:00
Update kryoptic configuration for trust attributes
To be compatible with NSS, Kryoptic has introduced the new
configuration option `objects_dedup = "TrustOnly"` which prevent the
creation of multiple overlapping trust objects.
The Kryoptic workflow has been updated to use the new configuration.
- - - - -
daa308e2 by Zachary Sherman-Burke at 2026-06-05T13:48:56-04:00
Fix duplicate error messages in LDAPExceptionConverter
- - - - -
7d896dc4 by parrishjd at 2026-06-05T20:53:02+02:00
Update 04-UpdateMLDSAProfiles.py
Allow for highly modified profiles with the same name.
Update 04-UpdateMLDSAProfiles.py
Fixed line length by linter
- - - - -
60558cda by Endi S. Dewata at 2026-06-05T14:29:36-05:00
Clean up test messages
- - - - -
03b94b80 by Endi S. Dewata at 2026-06-05T14:29:36-05:00
Clean up build messages
- - - - -
b4dc2455 by Endi S. Dewata at 2026-06-05T14:29:36-05:00
Update version number to 11.10.0-beta2
- - - - -
ee33dee3 by Endi S. Dewata at 2026-06-08T16:07:39-05:00
Fix publish job
The pom.xml has been updated to use org.jboss.spec.javax.ws.rs
so that it can be used to publish Maven artifacts. The pki-local
will now be created dynamically in pki.spec. The publish job has
also been updated to use Java 21.
- - - - -
02b3d7f1 by Endi S. Dewata at 2026-06-09T15:27:20-05:00
Add build.sh --product-version option
The build.sh has been updated to provide an option to specify
a product version in case it's different from the PKI version.
- - - - -
1c1c6141 by Zachary Sherman-Burke at 2026-06-10T11:42:31-04:00
Add HTTPS connector test with ML-DSA certs and Kryoptic HSM
- - - - -
a1bca89c by jmagne at 2026-06-10T15:11:24-07:00
Address sporadic CI crashes by having the CLI cmds clean up the connection at the end. (#5376)
Assisted by Claude Sonnet 4.5.
- - - - -
079f8284 by Christina Fu at 2026-06-10T17:29:58-07:00
Add ML-KEM archival/recovery tests (#5381)
* Register and enable caMLKEMUserCert profile
- Add caMLKEMUserCert to profile list in CS.cfg
- Add caMLKEMUserCert.class_id mapping
- Enable caMLKEMUserCert profile by default (enable=true)
- Keep visible=false for API/programmatic use
IDM-4328
* Enhance kra-pqc-test with ML-KEM archival/recovery tests
Enhanced the KRA PQC test workflow to include comprehensive ML-KEM key
archival and recovery testing:
- Configure KRA CS.cfg for ML-KEM archival with AES KeyWrap/Padding
- Use CRMFPopClient with -t false to keep ML-KEM-768 key in client NSS DB
- Generate cert request with key archival to KRA
- Test cert import into original client NSS DB (verify trust flags u,u,u)
- Test ML-KEM key retrieval and PKCS#12 export
- Import PKCS#12 with p12tool into new NSS DB (verify trust flags u,u,u)
- Verify ML-DSA-65 for system certs, ML-KEM-768 for transport/storage
The test validates both recovery scenarios:
1. Client retains private key: import cert into original NSS DB
2. Client lost private key: recover from KRA PKCS#12 into new NSS DB
The test focuses on PQC-specific functionality and removes redundant
file permission checks already covered in kra-basic-test.yml.
Assisted-by: Claude
IDM-4328
- - - - -
5ce2f9e6 by Marco Fargetta at 2026-06-11T18:36:15+02:00
Update CA PQC test with new dynamic buffer size
- - - - -
3c00b348 by Christina Fu at 2026-06-11T09:40:27-07:00
Fix crmf pop client mldsa temp (#5382)
* Set PQC keys as non-temporary by default in CRMFPopClient
ML-DSA and ML-KEM private keys need to be permanent (not temporary) for
NSS to properly link them with imported certificates. This matches the
existing behavior for RSA keys.
Without this fix, certificates imported via client-cert-import show
trust flags ,, instead of u,u,u because NSS cannot find the matching
private key, even though CRMFPopClient generated and stored it.
The fix simplifies the logic: only EC keys are temporary by default,
all other algorithms (RSA, ML-DSA, ML-KEM) are permanent.
DOGTAG-4435
* Add CI test for ML-DSA CRMFPopClient enrollment
This test verifies that ML-DSA keys generated by CRMFPopClient are
properly linked to their certificates after import (trust flags u,u,u).
The test validates the fix in CRMFPopClient.java that makes ML-DSA
keys non-temporary by default, eliminating the need for users to
manually specify -t false.
Test procedure:
- Enable caMLDSAUserCert profile
- Generate ML-DSA-65 key with CRMFPopClient using POP_NONE
- Issue certificate and import it
- Verify trust flags are u,u,u (proving key is linked)
DOGTAG-4435
- - - - -
e6e2c3e6 by Marco Fargetta at 2026-06-11T18:58:18+02:00
Fix PQC test for multiple deployment
Clean the home folder to allow the server to be re-installed with different options.
- - - - -
cc839e6e by Endi S. Dewata at 2026-06-12T11:22:29-05:00
Update dependencies in .classpath
- - - - -
da016d52 by Endi S. Dewata at 2026-06-12T14:00:54-05:00
Clean up log messages in PKIDeployer
- - - - -
49e4f1cb by Endi S. Dewata at 2026-06-12T14:00:54-05:00
Refactor PKIDeployer.create_cert_request()
The PKIDeployer.create_cert_request() has been modified to
simply call NSSDatabase.create_request() and return the CSR
as a string. The caller is responsible to provide the params
including hash alg and extensions.
- - - - -
47971d09 by Endi S. Dewata at 2026-06-15T14:00:03-05:00
Fix KRA installation with external certs on Kryoptic
The NSSDatabase.add_ca_cert() has been updated to run pki
nss-cert-import as pkiuser so it can access Kryoptic token.
The PKIDeployer.generate_csr() has been updated use
create_cert_request() to create the cert request as a string
to avoid file permission when used with Kryoptic.
The PKIDeployer.setup_system_cert() has been updated to use
PKISubsystem.get_system_cert_info() so it can get the CA
signing cert info from Kryoptic.
A new test has been updated to install KRA with external
certs on Kryoptic.
- - - - -
751eae03 by Endi S. Dewata at 2026-06-15T20:17:17-05:00
Remove redundant code in systemcerts.py
The calls to NSSDatabase.get_trust() are no longer needed since
the trust attributes are already available from the cert info.
The nssdb_connection() is no longer used so it has been removed
as well.
- - - - -
ae062d90 by Endi S. Dewata at 2026-06-15T20:18:29-05:00
Fix warnings due to deprecated --key-size option
- - - - -
eede50ab by Endi S. Dewata at 2026-06-15T20:18:29-05:00
Fix warnings due to deprecated --fullName option
- - - - -
60144d21 by Endi S. Dewata at 2026-06-15T20:18:29-05:00
Fix warnings due to unused params in TPS CS.cfg
- - - - -
f6f7edae by Endi S. Dewata at 2026-06-15T20:18:29-05:00
Fix warnings due to missing ca.crt
- - - - -
41bac9b7 by Endi S. Dewata at 2026-06-15T20:18:29-05:00
Update tests to disallow warnings
- - - - -
0e8956d8 by jmagne at 2026-06-15T19:23:12-07:00
For Server Side KeyGen, both CA and TPS, allow the key usages to be configured. (#5383)
For the CA, we can configure these in the SSKG CA cert enrollment profiles.
For TPS we can confugire these both in the token profile for each key type or the keyset mapping resolver configuration.
Exs:
CA SSKG profile (e.g., caServerKeygen_UserCert):
policyset.userCertSet.3.default.params.keyGenUsages=sign,verify,sign_recover,verify_recover,encrypt,decrypt,wrap,unwrap
TPS static profile config:
op.enroll.externalRegISEtoken.keyGen.encryption.serverKeygen.enable=True
op.enroll.externalRegISEtoken.keyGen.encryption.serverKeygen.archive=true
op.enroll.externalRegISEtoken.keyGen.encryption.serverKeygen.drm.conn=kra1
op.enroll.externalRegISEtoken.keyGen.encryption.serverKeygen.keyGenUsages=sign,verify,sign_recover,verify_recover,wrap,unwrap
TPS keySetMappingResolver:
tps.mapping.resolver.keySetMappingResolver.0.filter.tokenCUID.start=40906145B1960000
tps.mapping.resolver.keySetMappingResolver.0.filter.tokenCUID.end=40906145B19600FF
tps.mapping.resolver.keySetMappingResolver.0.target.keySet=defKeySet
tps.mapping.resolver.keySetMappingResolver.0.target.keyWrapAlg=KWP
tps.mapping.resolver.keySetMappingResolver.0.target.keyGenUsages=sign,verify,sign_recover,verify_recover,wrap,unwrap
Assisted-by : claude Sonnet 4.5.
- - - - -
9507e67c by Yaakov Selkowitz at 2026-06-16T12:22:24+02:00
Add Fedora ELN support to get_tomcat_app_server
Fedora ELN, the basis for the next RHEL major version, now uses ID="eln"
and VERSION_ID=11 in /etc/os-release to avoid confusion with Fedora Linux.
This fixes the build script so that tomcat-10.1 is properly selected for ELN.
Signed-off-by: Yaakov Selkowitz <yselkowi at redhat.com>
- - - - -
5d46b046 by Endi S. Dewata at 2026-06-16T09:38:10-05:00
Update OCSPServlet response on internal error
The OCSPServlet has been updated to return a proper response
status if there is an internal error (e.g. missing CRL data)
as defined in RFC 6960:
https://datatracker.ietf.org/doc/html/rfc6960#section-2.3
> The response "internalError" indicates that the OCSP responder
> reached an inconsistent internal state. The query should be
> retried, potentially with another responder.
The OCSP clients have been updated to check for error status
before processing the response bytes and generate a more
intelligible error message.
The OCSP tests have been updated to expect the new error
message.
- - - - -
15e9c416 by Endi S. Dewata at 2026-06-16T12:34:52-05:00
Update tests to use actions/cache at v5
- - - - -
6bce3e6b by Christina Fu at 2026-06-16T15:56:51-07:00
Auto-configure key wrapping based on storage cert type (#5386)
This change automatically selects the appropriate key wrapping profile
based on the storage certificate type during KRA installation.
Changes:
- Add wrapping.2 defaults to CS.cfg for ML-KEM storage certs
- Auto-select wrapping profile in configure_kra() based on storage_key_type:
- wrapping.1 for RSA/ECC storage certs (existing default)
- wrapping.2 for ML-KEM storage certs
- Users can override individual wrapping parameters via pkispawn config
- ML-KEM installations get secure PKCS#12 settings by default
- Update kra-pqc-test.yml to verify auto-configuration
- Add comprehensive LDAP validation for ML-KEM archived keys
This makes the code more maintainable and easier to extend for future
key types without requiring ML-KEM-specific logic.
Assisted-by: Claude
DOGTAG-4328 part 2
- - - - -
6dda7b3e by Endi S. Dewata at 2026-06-16T18:04:40-05:00
Update version number to 11.10.0
- - - - -
b86abaa9 by Marco Fargetta at 2026-06-17T11:47:46+02:00
Fix phase update error
The update script is expecting the phase to be removed by commenting
the option and not with the `%undefine'.
- - - - -
544da294 by Christina Fu at 2026-06-17T09:34:53-07:00
Add KRATool and hsmCompatVerify to v11.10.0 Tools Changes (#5391)
- KRATool: Document cross-scheme migration support
- hsmCompatVerify: Document new HSM compatibility verification tools
Assisted-by: Claude
- - - - -
0844e811 by Endi S. Dewata at 2026-06-18T15:06:19-05:00
Update tests to use actions/checkout at v7
- - - - -
a779ea6b by Endi S. Dewata at 2026-06-18T15:08:30-05:00
Update tests to use docker/setup-buildx-action at v4
- - - - -
36137ba8 by Endi S. Dewata at 2026-06-18T15:09:55-05:00
Update tests to use docker/build-push-action at v7
- - - - -
f9c6f47e by Endi S. Dewata at 2026-06-22T10:38:12-05:00
Update tests to use lewagon/wait-on-check-action at v1.8.0
- - - - -
f377ce57 by Marco Fargetta at 2026-06-24T11:06:07+02:00
Use parent CA key type for LWCA generation
Previously, lightweight CAs always generated RSA keys regardless of
the parent CA's key type. This change makes LWCA key generation
match the parent CA's algorithm and strength.
Changes:
- Detect parent CA key type (RSA, EC, ML-DSA) and generate matching
key pair for lightweight CA
- Use appropriate signature algorithm in PKCS10 request based on
key type instead of hardcoded SHA256withRSA
- Add key parameter constraints to caCACert profile
- Maintain backward compatibility with fallback to RSA 3072
Assisted-by: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
6ee86b15 by Endi S. Dewata at 2026-06-24T09:13:32-05:00
Update tests to use actions/setup-java at v5
- - - - -
7c60de13 by Endi S. Dewata at 2026-06-24T09:13:32-05:00
Update tests to use docker/login-action at v4
- - - - -
f4312dcf by Endi S. Dewata at 2026-06-24T09:13:32-05:00
Update tests to use actions/upload-artifact at v7
- - - - -
fd93ad36 by Endi S. Dewata at 2026-06-25T15:55:05-05:00
Add variable to enable/disable test suites
A new GH Action variable has been added to configure the
list of test suites that will run in the CI.
https://github.com/dogtagpki/pki/wiki/Configuring-Test-Suites
- - - - -
8593d41c by Endi S. Dewata at 2026-06-26T19:08:24-05:00
Drop support for Fedora 42
- - - - -
b0369148 by Endi S. Dewata at 2026-06-26T19:10:57-05:00
Clean up log messages
- - - - -
00d5d272 by Endi S. Dewata at 2026-07-01T15:01:46-05:00
Add test for sub CA with PQC
A new test has been added to install root CA and sub CA
with PQC, then validate the cert requests, issued certs,
cert chains, cert statuses, and cert usages.
- - - - -
2cb3a819 by Endi S. Dewata at 2026-07-02T13:22:29-05:00
Move RSN and SSN tests to CA Extra
- - - - -
cf3040e0 by Endi S. Dewata at 2026-07-02T19:49:59-05:00
Rename DB_IMAGE to DS_IMAGE
- - - - -
01fd4ca8 by Endi S. Dewata at 2026-07-06T16:27:55-05:00
Replace FEDORA_VERSION >> with tee -a
Change all echo "FEDORA_VERSION=$FEDORA_VERSION" >> $GITHUB_ENV
to echo "FEDORA_VERSION=$FEDORA_VERSION" | tee -a $GITHUB_ENV.
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
dea6b5f6 by Endi S. Dewata at 2026-07-06T18:13:54-05:00
Simplify and standardize TOMCAT_FLAVOR tests
Streamline TOMCAT_FLAVOR conditional logic:
- Replace expected/expected_new_tomcat10 with expected_old/expected_new
- Replace if/else conditionals with direct diff expected_$TOMCAT_FLAVOR output
- Remove "Detected Tomcat flavor:" debug print statements
- Change echo >> $GITHUB_ENV to echo | tee -a $GITHUB_ENV
- Simplify computation into one-liner test command
This reduces code duplication, eliminates output noise, improves readability,
and simplifies test maintenance across all workflow files.
Co-Authored-By: Claude Sonnet 4 <noreply at anthropic.com>
- - - - -
d0ec8c0c by Endi S. Dewata at 2026-07-07T20:00:26-05:00
Clean up log messages in CAService.issueX509Cert()
- - - - -
83a08e18 by Endi S. Dewata at 2026-07-10T12:20:29-05:00
Fix python3-flake8 dependency
- - - - -
40d9178c by Taylor Herring at 2026-07-13T17:58:56-04:00
Fix ML-DSA profiles incorrectly setting keyUsageKeyAgreement=true
ML-DSA is a pure signature algorithm (FIPS 204) and does not support
key agreement or data encipherment. Fixes DOGTAG-4513.
- - - - -
400409f7 by Marco Fargetta at 2026-07-14T10:11:48+02:00
Add REST API v1 build-time control with runtime deprecation
Introduce build-time flag to exclude v1 REST API code and
dependencies, with optional runtime control for managing v1
deprecation when included.
Build-time Control:
- New --without-apiv1 flag in build.sh to exclude v1 code from build
- Default: v1 REST API included (backward compatible)
- When excluded: v1 source files not compiled, JAX-RS/RESTEasy
dependencies skipped, binary RPMs ~2-3MB smaller
- Maven property api.v1=true/false controls profile activation
- Profile api-v1-deps includes JAX-RS/RESTEasy/Jackson-JAX-RS dependencies
- Profile api-v1-dropped excludes v1 source files via maven-compiler-plugin
Runtime Control (when v1 built):
- Three runtime states: enabled, deprecated (default), disabled
- System property api.v1.status controls behavior at runtime
- Can be set per-instance via tomcat.conf or per-subsystem via CS.cfg
- ApiStatusHelper centralizes status checking across all subsystems
- Input validation: trims, lowercases, rejects invalid values
Runtime States:
1. enabled: v1 fully functional, no warnings
2. deprecated (default): v1 functional with startup warnings and
standard Deprecation headers (IETF draft-dalal-deprecation-header)
3. disabled: v1 returns HTTP 404 Not Found with clean JSON error response,
includes Deprecation
Implementation:
- base/pom.xml: api-v1-dropped profile for source exclusion
- base/common/pom.xml: api-v1-deps profile for conditional dependencies
- base/javadoc/CMakeLists.txt: Exclude v1 REST packages from javadoc
- pki.spec: Conditional BuildRequires/Requires, %post JAR cleanup
- build.sh: --without-apiv1 flag, passes to CMake and RPM
- ApiStatusHelper: Shared utility for status validation and handling
- ApiDisabledResource: JAX-RS catch-all returning HTTP 410 Gone
- ApiDeprecationFilter: JAX-RS response filter adding standard headers
- All Application classes updated to use ApiStatusHelper
HTTP Standards Compliance:
- Deprecation header for deprecated state
- Link header (RFC 8288) pointing to v2 API documentation
- Separate HTTP method handlers per JAX-RS specification
RPM Build:
- build.sh: ./build.sh --without-apiv1 rpm
- rpmbuild: rpmbuild --without apiv1 -ba pki.spec
- Spec validates bcond and sets build_api_v1 conditional
- Maven receives -Dapi.v1=true/false based on bcond
Migration Path:
- Default: v1 included at build, deprecated at runtime (warnings)
- Gradual: Configure runtime disabled to enforce v2 migration
- Final: Build with --without-apiv1 to remove v1 code permanently
Documentation: docs/changes/v11.10.0/Packaging-Changes.adoc and
Server-Changes.adoc
Assisted-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
c4bb4b57 by Endi S. Dewata at 2026-07-14T11:32:53-05:00
Update basic CA test
The basic CA test has been updated to validate the cert
requests, issued certs, cert chains, cert statuses, and
cert usages, similar to the test for sub CA with PQC.
The basic CA test has also been updated to create the
audit signing cert by default so that the default cert
can also be validated.
The sub CA test has also been updated to validate the
cert usages using pki nss-cert-verify in addition to
vfychain which is failing in some cases.
NOTE: There are some key usage inconsistencies between
the certs in basic (i.e. root) CA and the certs in sub
CA. This will require further investigation.
- - - - -
2ec00ebe by Christina Fu at 2026-07-15T08:42:27-07:00
Add PQC and multi-token support to hsmCompatVerify tools (#5392)
Key Features added:
**PQC Support:**
- ML-DSA (44/65/87) for CA signing certificates
- ML-KEM (512/768/1024) for KRA transport and storage certificates
- ML-KEM encapsulation for secure key archival (replaces RSA wrap)
- Support for archiving RSA/EC/ML-KEM user keys with ML-KEM transport
- PKCS#12 export modes: AES-KWP, AES-256-CBC, 3DES-CBC legacy
- Auto-enable PQC mode when ML-KEM user key type selected
**Multi-Token Deployment:**
- Separate token support for CA and KRA certificates via --ca-token and --kra-token
- Independent token authentication (password file or inline)
- Smart token reuse when CA and KRA share same token
- Backward compatible (defaults to single --hsm-token)
- Works with both traditional (RSA/EC) and PQC modes
**Additional Features:**
- CA-only setup mode (--ca-only) for faster testing
- Session key size derived programmatically from CryptoUtil.getWrappingParams()
- Backward-compatible --algorithm flag (alias for --user-key-type)
- Enhanced configuration output and validation
**Documentation and Usability:**
- Reorganized --help examples: Quick Start (Software Token, HSM Traditional, HSM PQC)
- Added PKCS#12 import guidance (p12tool from dogtag-jss-tools package)
- Enhanced help text with full workflow examples and advanced usage reference
Bug fixes:
- Fix IV file path derivation from wrapped-private filename
- Fix LDIF field name consistency (payloadWrapIV instead of payloadEncryptionIV)
Assisted-by: Claude
IDM-5817 IDM-6617 IDM-7034 DOGTAG-4484
- - - - -
6c1c16b6 by Christina Fu at 2026-07-16T17:01:35-07:00
Fix KRATool generating wrong session key size in cross-scheme migration (#5400)
* Fix KRATool generating wrong session key size in cross-scheme migration
Use mTargetPayloadWrapKeySize directly instead of getKeySizeFromAlgorithm()
to ensure correct target key size when source and target algorithms have
the same name.
Changes:
- Line 3244: Use mTargetPayloadWrapKeySize for session key generation
- Line 6913: Use mTargetPayloadWrapKeySize for LDIF sessionKeyLength update
- Remove redundant 'if (targetKeySize == 0)' checks (can never be 0)
- Delete unused getKeySizeFromAlgorithm() method
- Update pki-kratool.spec: Replace java-17-openjdk-* with java-* >= 1:17
to allow any Java 17+ implementation
- Remove printUsage() calls after error messages to prevent dumping full
usage text (~250 lines) on every error
Assisted-by: Claude
DOGTAG-4517 DOGTAG-4495 DOGTAG-4498
* Fix KRATool cross-scheme DES3 source key migration
KRATool cross-scheme mode failed when migrating keys archived with DES3
session key wrapping. The error was "Key is not the right type for this
algorithm" due to hardcoded SymmetricKey.AES and 128-bit strength in
session key unwrap operations.
Changes:
- Add getSymmetricKeyType() helper to map algorithm name to SymmetricKey.Type
(DES3/DESede → SymmetricKey.DES3, AES → SymmetricKey.AES)
- Add getKeyStrength() helper to determine key strength in bits
(DES3 always returns 168 bits, AES uses user-specified size)
- Fix session key unwrap to use derived sourceKeyType and sourceKeyStrength
instead of hardcoded SymmetricKey.AES/128 (rewrap_wrapped_key_data line 3128)
- Fix importSessionKeyToToken() to accept and use keyType parameter instead
of hardcoded SymmetricKey.AES (line 2881)
- Fix needNewSessionKey() to use getKeyStrength() for accurate source key
size in user prompts (shows "168-bit DES3" not "128-bit DES3")
- Update validation to accept 168-bit keysize for source (DES3)
- Update help text to document 168-bit option for DES3 sources
- Restrict target to AES only (no DES3 target - legacy/deprecated)
- Add validation to reject DES3 as target algorithm
The tool now correctly handles migration FROM legacy DES3 TO modern AES:
-source_payload_wrap_algorithm "DES3/CBC/Padding" \
-source_payload_wrap_keysize 168 \
-target_payload_wrap_algorithm "AES KeyWrap/Padding" \
-target_payload_wrap_keysize 128
Assisted-by: Claude
DOGTAG-4496 DOGTAG-4508
Fix exit codes for cross-scheme validation errors
- - - - -
63188fa5 by Marco Fargetta at 2026-07-17T10:14:39+02:00
Fix bundled jackson version mismatch
New versions of jackson (>2.20) uses a major.minor version for the
jackson-annotations package but it keep the same major.minor.update
for the other modules. Since the cmake script will retrieve the
version from the jackson-annotations the compilation is failing when
2.21.4 is bundled.
This change will consider the jackson-annotation separately from the
other modules.
- - - - -
9622ae31 by Christina Fu at 2026-07-21T14:26:53-07:00
KRATool: Fix DES3 key size for PKCS#11 unwrap operations (#5402)
The previous fix used 168 bits for DES3 key strength, which caused
PKCS#11 C_UnwrapKey to fail with error -8152 "The key does not
support the requested operation."
Root cause: DES3 has an effective security strength of 168 bits
(3 × 56-bit keys), but the actual PKCS#11 key length must be
192 bits (24 bytes: 3 × 64-bit keys including parity bits).
When getKeyStrength() returned 168, CryptoUtil.unwrap() divided
by 8 to get 21 bytes, but NSS pk11mech.c:PK11_GetKeyType()
expects exactly 24 bytes for DES3 (or 16 bytes for DES2).
Changes:
- Update getKeyStrength() to return 192 for DES3 (was 168)
- Add detailed comment explaining the 168 vs 192 distinction
- Update inline comments to reflect 192-bit PKCS#11 requirement
Users can still specify -source_payload_wrap_keysize 168 (the
commonly cited effective strength), but internally we now use
192 for all PKCS#11 operations.
Fixes: DES3 to AES-KWP migration in cross-scheme mode
Reported-by: QE
Assisted-by: Claude
DOGTAG-4496 DOGTAG-4508
- - - - -
38c10070 by Endi S. Dewata at 2026-07-22T02:26:31-05:00
Fix basic server test
The basic server test has been updated to work with Fedora 45 and
and the new-style of Tomcat 10.
- - - - -
b7c6afac by Endi S. Dewata at 2026-07-23T13:44:21-05:00
Fix container startup scripts
The container startup scripts have been updated to no longer
update the file and folder permissions to avoid conflicts with
upgrade scripts that update the permissions.
- - - - -
ec5c1b3c by Christina Fu at 2026-07-23T18:00:01-07:00
KRATool: Update DES3 key size documentation to recommend 192 bits (#5404)
The previous documentation recommended users specify 168 for DES3,
but the code internally uses 192 bits for PKCS#11 operations. This
caused confusion when users saw "192-bit DES3" in logs after
specifying 168.
Changes:
- Update help text to recommend 192 for DES3 (was 168)
- Remove 168 from documented options (still accepted for backward compatibility)
- Update error message to list only documented options (128, 192, 256)
- Add missing javadoc @param keyType in importSessionKeyToToken()
Users can still specify 168 if needed (it works the same), but 192
is now the recommended and documented value.
Assisted-by: Claude
Related to: IDM-4508
- - - - -
9168f301 by Endi S. Dewata at 2026-07-24T02:06:50-05:00
Fix update_version.sh to handle phase properly
- - - - -
1de2daac by Marco Fargetta at 2026-07-24T09:50:37+02:00
Fix LDAPSession.countEntries() warning with page results
The method LDAPSession.countEntries() is updated to use raw paged
search. It was counting the object associated with the retrieved ldap
query but the query in this case retrieve only objectClass so the
object mapping was failing.
The count was correct but there were additional logs for the mapping
error and it requires extra time for object mapping.
Assisted-By: Claude Sonnet 4.5 <noreply at anthropic.com>
- - - - -
452be375 by Marco Fargetta at 2026-07-28T17:41:37+02:00
Fix authorisation bypass in ACME enable/disable
Fix #5405
- - - - -
da07c70d by Marco Fargetta at 2026-07-28T18:37:15+02:00
Update version number to 11.10.1
- - - - -
3152 changed files:
- .classpath
- .github/workflows/pki-nss-hsm-test.yml → .github/workflows/PKCS10Client-test.yml
- .github/workflows/PKICertImport-test.yml
- .github/workflows/acme-certbot-test.yml → .github/workflows/acme-basic-test.yml
- + .github/workflows/acme-clone-test.yml
- + .github/workflows/acme-container-basic-test.yml
- + .github/workflows/acme-container-ca-test.yml
- − .github/workflows/acme-container-test.yml
- + .github/workflows/acme-existing-nssdb-test.yml
- .github/workflows/acme-postgresql-test.yml
- + .github/workflows/acme-separate-test.yml
- .github/workflows/acme-switchover-test.yml
- .github/workflows/acme-tests.yml
- .github/workflows/build.yml
- + .github/workflows/ca-admin-user-test.yml
- + .github/workflows/ca-api-test.yml
- .github/workflows/ca-basic-test.yml
- + .github/workflows/ca-cert-revocation-test.yml
- .github/workflows/ca-clone-hsm-test.yml
- + .github/workflows/ca-clone-pqc-test.yml
- + .github/workflows/ca-clone-replicated-ds-test.yml
- .github/workflows/ca-clone-secure-ds-test.yml
- + .github/workflows/ca-clone-shared-ds-test.yml
- + .github/workflows/ca-clone-ssnv1-test.yml
- + .github/workflows/ca-clone-ssnv2-test.yml
- .github/workflows/ca-clone-test.yml
- + .github/workflows/ca-clone-tests.yml
- .github/workflows/ca-shared-token-test.yml → .github/workflows/ca-cmc-shared-token-test.yml
- + .github/workflows/ca-container-basic-test.yml
- + .github/workflows/ca-container-existing-certs-test.yml
- + .github/workflows/ca-container-existing-config-test.yml
- + .github/workflows/ca-container-migration-test.yml
- + .github/workflows/ca-container-system-service-test.yml
- + .github/workflows/ca-container-tests.yml
- + .github/workflows/ca-container-user-service-test.yml
- .github/workflows/ca-crl-test.yml
- .github/workflows/ca-ds-connection-test.yml
- .github/workflows/ca-ecc-test.yml
- .github/workflows/ca-existing-certs-test.yml
- + .github/workflows/ca-existing-config-test.yml
- .github/workflows/ca-existing-ds-test.yml
- .github/workflows/ca-existing-hsm-test.yml
- .github/workflows/ca-existing-nssdb-test.yml
- + .github/workflows/ca-extra-tests.yml
- + .github/workflows/ca-hsm-operation-test.yml
- + .github/workflows/ca-kryoptic-test.yml
- + .github/workflows/ca-mldsa-CRMFPopClient-test.yml
- .github/workflows/ca-notification-request-test.yml
- .github/workflows/ca-nuxwdog-test.yml
- + .github/workflows/ca-pqc-test.yml
- + .github/workflows/ca-profile-caDirPinUserCert-test.yml
- + .github/workflows/ca-profile-caDirUserCert-test.yml
- + .github/workflows/ca-profile-caInternalAuthDRMstorageCert-test.yml
- + .github/workflows/ca-profile-caInternalAuthTransportCert-test.yml
- + .github/workflows/ca-profile-caMLKEMInternalAuthDRMstorageCert-test.yml
- + .github/workflows/ca-profile-caMLKEMInternalAuthTransportCert-test.yml
- + .github/workflows/ca-profile-caServerCert-test.yml
- + .github/workflows/ca-profile-caStorageCert-test.yml
- + .github/workflows/ca-profile-caTransportCert-test.yml
- + .github/workflows/ca-profile-custom-test.yml
- + .github/workflows/ca-profile-tests.yml
- .github/workflows/ca-pruning-test.yml
- .github/workflows/ca-publishing-ca-cert-test.yml
- .github/workflows/ca-publishing-crl-file-test.yml
- .github/workflows/ca-publishing-crl-ldap-test.yml
- .github/workflows/ca-publishing-user-cert-test.yml
- + .github/workflows/ca-renewal-automated-ldaps-test.yml
- + .github/workflows/ca-renewal-automated-test.yml
- + .github/workflows/ca-renewal-manual-hsm-test.yml
- + .github/workflows/ca-renewal-manual-test.yml
- .github/workflows/ca-rsa-pss-test.yml
- + .github/workflows/ca-rsa-test.yml
- .github/workflows/ca-rsnv1-test.yml
- + .github/workflows/ca-secure-ds-pqc-test.yml
- .github/workflows/ca-secure-ds-test.yml
- − .github/workflows/ca-sequential-test.yml
- .github/workflows/ca-hsm-test.yml → .github/workflows/ca-softhsm-test.yml
- + .github/workflows/ca-ssnv1-test.yml
- + .github/workflows/ca-ssnv2-test.yml
- .github/workflows/ca-tests.yml
- − .github/workflows/ca-tests2.yml
- .github/workflows/qe-tests.yml → .github/workflows/disabled/qe-tests.yml
- .github/workflows/est-basic-test.yml
- + .github/workflows/est-ds-realm-separate-test.yml
- + .github/workflows/est-ds-realm-test.yml
- + .github/workflows/est-postgresql-realm-test.yml
- + .github/workflows/est-standalone-test.yml
- .github/workflows/est-tests.yml
- − .github/workflows/init.yml
- .github/workflows/ipa-acme-test.yml
- .github/workflows/ipa-basic-test.yml
- .github/workflows/ipa-clone-test.yml
- + .github/workflows/ipa-kra-test.yml
- + .github/workflows/ipa-reinstall-test.yml
- + .github/workflows/ipa-renewal-test.yml
- + .github/workflows/ipa-subca-test.yml
- .github/workflows/ipa-tests.yml
- .github/workflows/code-analysis.yml → .github/workflows/java-tests.yml
- .github/workflows/kra-basic-test.yml
- + .github/workflows/kra-clone-failover-test.yml
- + .github/workflows/kra-clone-hsm-test.yml
- + .github/workflows/kra-clone-replicated-ds-test.yml
- + .github/workflows/kra-clone-shared-ds-test.yml
- .github/workflows/kra-clone-test.yml
- + .github/workflows/kra-clone-tests.yml
- .github/workflows/kra-cmc-test.yml
- + .github/workflows/kra-container-test.yml
- + .github/workflows/kra-ecc-test.yml
- + .github/workflows/kra-existing-certs-test.yml
- + .github/workflows/kra-existing-config-test.yml
- + .github/workflows/kra-existing-ds-test.yml
- + .github/workflows/kra-existing-hsm-test.yml
- + .github/workflows/kra-existing-nssdb-test.yml
- + .github/workflows/kra-external-certs-kryoptic-test.yml
- .github/workflows/kra-external-certs-test.yml
- + .github/workflows/kra-kryoptic-test.yml
- + .github/workflows/kra-migration-test.yml
- .github/workflows/kra-oaep-test.yml
- + .github/workflows/kra-pqc-test.yml
- .github/workflows/kra-separate-test.yml
- .github/workflows/kra-sequential-test.yml
- .github/workflows/kra-hsm-test.yml → .github/workflows/kra-softhsm-test.yml
- + .github/workflows/kra-sskg-test.yml
- .github/workflows/kra-standalone-test.yml
- .github/workflows/kra-tests.yml
- .github/workflows/ca-lightweight-test.yml → .github/workflows/lwca-basic-test.yml
- + .github/workflows/lwca-clone-hsm-test.yml
- .github/workflows/ca-lightweight-hsm-test.yml → .github/workflows/lwca-hsm-test.yml
- .github/workflows/ocsp-basic-test.yml
- .github/workflows/ocsp-clone-test.yml
- .github/workflows/ocsp-cmc-test.yml
- + .github/workflows/ocsp-container-test.yml
- .github/workflows/ocsp-crl-direct-test.yml
- .github/workflows/ocsp-crl-ldap-test.yml
- + .github/workflows/ocsp-existing-config-test.yml
- .github/workflows/ocsp-external-certs-test.yml
- .github/workflows/ocsp-hsm-test.yml
- .github/workflows/ocsp-separate-test.yml
- .github/workflows/ocsp-standalone-test.yml
- .github/workflows/ocsp-tests.yml
- + .github/workflows/pki-basic-test.yml
- .github/workflows/pki-nss-aes-test.yml
- .github/workflows/pki-nss-ecc-test.yml
- .github/workflows/pki-nss-exts-test.yml
- + .github/workflows/pki-nss-kryoptic-test.yml
- + .github/workflows/pki-nss-pqc-test.yml
- .github/workflows/pki-nss-rsa-test.yml
- + .github/workflows/pki-nss-softhsm-test.yml
- + .github/workflows/pki-password-test.yml
- .github/workflows/pki-pkcs11-test.yml
- .github/workflows/pki-pkcs12-test.yml
- .github/workflows/pki-pkcs7-test.yml
- + .github/workflows/pki-server-basic-test.yml
- .github/workflows/publish.yml
- .github/workflows/ca-container-test.yml → .github/workflows/python-ca-rest-api-v1-test.yml
- + .github/workflows/python-ca-test.yml
- + .github/workflows/python-kra-test.yml
- .github/workflows/python-lint-test.yml
- .github/workflows/python-tests.yml
- .github/workflows/rpminspect-test.yml
- .github/workflows/scep-test.yml
- .github/workflows/server-backup-test.yml
- .github/workflows/server-basic-test.yml
- .github/workflows/server-container-test.yml
- .github/workflows/server-https-jks-test.yml
- + .github/workflows/server-https-kryoptic-pqc-test.yml
- + .github/workflows/server-https-nss-pqc-test.yml
- .github/workflows/server-https-nss-test.yml
- .github/workflows/server-https-pem-test.yml
- .github/workflows/server-https-pkcs12-test.yml
- + .github/workflows/server-mcp-test.yml
- + .github/workflows/server-port-test.yml
- .github/workflows/server-tests.yml
- .github/workflows/server-upgrade-test.yml
- .github/workflows/ca-non-default-user-test.yml → .github/workflows/server-user-test.yml
- .github/workflows/sonarcloud-pull.yml → .github/workflows/sonarcloud-pr-test.yml
- + .github/workflows/stale.yml
- .github/workflows/subca-basic-test.yml
- + .github/workflows/subca-clone-hsm-test.yml
- + .github/workflows/subca-clone-test.yml
- .github/workflows/subca-cmc-test.yml
- .github/workflows/subca-external-test.yml
- .github/workflows/subca-hsm-test.yml
- + .github/workflows/subca-pqc-test.yml
- + .github/workflows/subca-tests.yml
- .github/workflows/tks-basic-test.yml
- .github/workflows/tks-clone-test.yml
- + .github/workflows/tks-container-test.yml
- + .github/workflows/tks-existing-config-test.yml
- .github/workflows/tks-external-certs-test.yml
- .github/workflows/tks-hsm-test.yml
- .github/workflows/tks-separate-test.yml
- .github/workflows/tks-tests.yml
- .github/workflows/tools-tests.yml
- .github/workflows/tps-basic-test.yml
- .github/workflows/tps-clone-test.yml
- + .github/workflows/tps-container-test.yml
- + .github/workflows/tps-existing-config-test.yml
- .github/workflows/tps-external-certs-test.yml
- .github/workflows/tps-hsm-test.yml
- .github/workflows/tps-separate-test.yml
- .github/workflows/tps-tests.yml
- .github/workflows/update-version-test.yml
- + .github/workflows/wait-for-build.yml
- .gitignore
- + .packit.yaml
- CMakeLists.txt
- Dockerfile
- README.md
- azure-pipelines.yml
- base/CMakeLists.txt
- base/acme/CMakeLists.txt
- base/acme/Dockerfile
- base/acme/bin/pki-acme-run
- base/acme/conf/configsources.conf
- base/acme/database/ds/database.conf
- base/acme/database/ldap/database.conf
- base/acme/database/openldap/database.conf
- base/acme/database/postgresql/database.conf
- base/acme/issuer/pki/issuer.conf
- base/acme/openshift/pki-acme-database.yaml
- base/acme/openshift/pki-acme-deployment.yaml
- base/acme/openshift/pki-acme-issuer.yaml
- base/acme/openshift/pki-acme-realm.yaml
- base/acme/pom.xml
- base/acme/realm/ds/create.ldif
- base/acme/realm/ds/realm.conf
- base/acme/realm/in-memory/realm.conf
- base/acme/realm/postgresql/realm.conf
- base/acme/src/main/java/org/dogtagpki/acme/database/ACMEDatabase.java
- base/acme/src/main/java/org/dogtagpki/acme/database/LDAPDatabase.java
- base/acme/src/main/java/org/dogtagpki/acme/issuer/ACMEIssuer.java
- base/acme/src/main/java/org/dogtagpki/acme/issuer/NSSIssuer.java
- base/acme/src/main/java/org/dogtagpki/acme/issuer/PKIIssuer.java
- base/acme/src/main/java/org/dogtagpki/acme/realm/LDAPRealm.java
- − base/acme/src/main/java/org/dogtagpki/acme/server/ACMEAccountOrdersService.java
- − base/acme/src/main/java/org/dogtagpki/acme/server/ACMEAccountService.java
- + base/acme/src/main/java/org/dogtagpki/acme/server/ACMEAccountServlet.java
- − base/acme/src/main/java/org/dogtagpki/acme/server/ACMEApplication.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMEAuthorizationService.java → base/acme/src/main/java/org/dogtagpki/acme/server/ACMEAuthorizationServlet.java
- − base/acme/src/main/java/org/dogtagpki/acme/server/ACMECertificateService.java
- + base/acme/src/main/java/org/dogtagpki/acme/server/ACMECertificateServlet.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMEChallengeProcessor.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMEChallengeService.java → base/acme/src/main/java/org/dogtagpki/acme/server/ACMEChallengeServlet.java
- − base/acme/src/main/java/org/dogtagpki/acme/server/ACMEDirectoryService.java
- + base/acme/src/main/java/org/dogtagpki/acme/server/ACMEDirectoryServlet.java
- − base/acme/src/main/java/org/dogtagpki/acme/server/ACMEDisableService.java
- + base/acme/src/main/java/org/dogtagpki/acme/server/ACMEDisableServlet.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMERequestFilter.java → base/acme/src/main/java/org/dogtagpki/acme/server/ACMEEnableFilter.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMEEnableService.java → base/acme/src/main/java/org/dogtagpki/acme/server/ACMEEnableServlet.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMEEngine.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMEIdentifierValidator.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMELoginService.java → base/acme/src/main/java/org/dogtagpki/acme/server/ACMELoginServlet.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMELogoutService.java → base/acme/src/main/java/org/dogtagpki/acme/server/ACMELogoutServlet.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMENewAccountService.java → base/acme/src/main/java/org/dogtagpki/acme/server/ACMENewAccountServlet.java
- − base/acme/src/main/java/org/dogtagpki/acme/server/ACMENewNonceService.java
- + base/acme/src/main/java/org/dogtagpki/acme/server/ACMENewNonceServlet.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMENewOrderService.java → base/acme/src/main/java/org/dogtagpki/acme/server/ACMENewOrderServlet.java
- − base/acme/src/main/java/org/dogtagpki/acme/server/ACMEOrderService.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMEFinalizeOrderService.java → base/acme/src/main/java/org/dogtagpki/acme/server/ACMEOrderServlet.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMERevokeCertificateService.java → base/acme/src/main/java/org/dogtagpki/acme/server/ACMERevokeCertificateServlet.java
- − base/acme/src/main/java/org/dogtagpki/acme/server/ACMEService.java
- + base/acme/src/main/java/org/dogtagpki/acme/server/ACMEServlet.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMEWebListener.java
- + base/acme/src/main/java/org/dogtagpki/server/acme/cli/ACMECLI.java
- + base/acme/src/main/java/org/dogtagpki/server/acme/cli/ACMEDatabaseCLI.java
- + base/acme/src/main/java/org/dogtagpki/server/acme/cli/ACMEDatabaseIndexCLI.java
- + base/acme/src/main/java/org/dogtagpki/server/acme/cli/ACMEDatabaseIndexRebuildCLI.java
- + base/acme/src/main/java/org/dogtagpki/server/acme/cli/ACMEDatabaseInitCLI.java
- + base/acme/src/main/java/org/dogtagpki/server/acme/cli/ACMERealmCLI.java
- + base/acme/src/main/java/org/dogtagpki/server/acme/cli/ACMERealmInitCLI.java
- + base/acme/tomcat-10.1/conf/Catalina/localhost/acme.xml
- base/acme/webapps/acme/WEB-INF/web.xml
- base/acme/webapps/acme/index.jsp
- base/ca/CMakeLists.txt
- base/ca/Dockerfile
- base/ca/bin/pki-ca-run
- base/ca/database/ds/acl.ldif
- base/ca/database/ds/create.ldif
- base/ca/database/ds/vlv.ldif
- base/ca/database/ds/vlvtasks.ldif
- base/ca/pom.xml
- base/ca/shared/conf/CS.cfg
- base/ca/shared/conf/caCert.profile
- + base/ca/shared/conf/mldsaAdminCert.profile
- + base/ca/shared/conf/mldsaServerCert.profile
- + base/ca/shared/conf/mldsaSubsystemCert.profile
- base/ca/shared/conf/registry.cfg
- base/ca/shared/profiles/ca/AdminCert.cfg
- base/ca/shared/profiles/ca/ECAdminCert.cfg
- base/ca/shared/profiles/ca/acmeServerCert.cfg
- base/ca/shared/profiles/ca/caAdminCert.cfg
- base/ca/shared/profiles/ca/caAgentFileSigning.cfg
- base/ca/shared/profiles/ca/caAgentServerCert.cfg
- base/ca/shared/profiles/ca/caAuditSigningCert.cfg
- base/ca/shared/profiles/ca/caCACert.cfg
- base/ca/shared/profiles/ca/caCMCECUserCert.cfg
- base/ca/shared/profiles/ca/caCMCECserverCert.cfg
- + base/ca/shared/profiles/ca/caCMCECserverCertWithCRLDP.cfg
- base/ca/shared/profiles/ca/caCMCECsubsystemCert.cfg
- + base/ca/shared/profiles/ca/caCMCMLDSAserverCert.cfg
- base/ca/shared/profiles/ca/caCMCUserCert.cfg
- base/ca/shared/profiles/ca/caCMCauditSigningCert.cfg
- base/ca/shared/profiles/ca/caCMCcaCert.cfg
- base/ca/shared/profiles/ca/caCMCcaIssuanceProtectionCert.cfg
- base/ca/shared/profiles/ca/caCMCkraStorageCert.cfg
- base/ca/shared/profiles/ca/caCMCkraTransportCert.cfg
- base/ca/shared/profiles/ca/caCMCocspCert.cfg
- base/ca/shared/profiles/ca/caCMCserverCert.cfg
- + base/ca/shared/profiles/ca/caCMCserverCertWithCRLDP.cfg
- base/ca/shared/profiles/ca/caCMCsubsystemCert.cfg
- base/ca/shared/profiles/ca/caCrossSignedCACert.cfg
- base/ca/shared/profiles/ca/caDirBasedDualCert.cfg
- base/ca/shared/profiles/ca/caDirPinUserCert.cfg
- base/ca/shared/profiles/ca/caDirUserCert.cfg
- base/ca/shared/profiles/ca/caDualCert.cfg
- base/ca/shared/profiles/ca/caDualRAuserCert.cfg
- base/ca/shared/profiles/ca/caECAdminCert.cfg
- base/ca/shared/profiles/ca/caECAgentServerCert.cfg
- base/ca/shared/profiles/ca/caECDirPinUserCert.cfg
- base/ca/shared/profiles/ca/caECDirUserCert.cfg
- base/ca/shared/profiles/ca/caECDualCert.cfg
- base/ca/shared/profiles/ca/caECFullCMCSharedTokenCert.cfg
- base/ca/shared/profiles/ca/caECFullCMCUserCert.cfg
- base/ca/shared/profiles/ca/caECFullCMCUserSignedCert.cfg
- base/ca/shared/profiles/ca/caECInternalAuthServerCert.cfg
- base/ca/shared/profiles/ca/caECInternalAuthSubsystemCert.cfg
- base/ca/shared/profiles/ca/caECServerCert.cfg
- + base/ca/shared/profiles/ca/caECServerCertWithCRLDP.cfg
- base/ca/shared/profiles/ca/caECServerCertWithSCT.cfg
- base/ca/shared/profiles/ca/caECSimpleCMCUserCert.cfg
- base/ca/shared/profiles/ca/caECSubsystemCert.cfg
- base/ca/shared/profiles/ca/caECUserCert.cfg
- base/ca/shared/profiles/ca/caEncECUserCert.cfg
- base/ca/shared/profiles/ca/caEncUserCert.cfg
- base/ca/shared/profiles/ca/caFullCMCSharedTokenCert.cfg
- base/ca/shared/profiles/ca/caFullCMCUserCert.cfg
- base/ca/shared/profiles/ca/caFullCMCUserSignedCert.cfg
- base/ca/shared/profiles/ca/caIPAserviceCert.cfg
- base/ca/shared/profiles/ca/caInstallCACert.cfg
- base/ca/shared/profiles/ca/caInternalAuthAuditSigningCert.cfg
- base/ca/shared/profiles/ca/caInternalAuthDRMstorageCert.cfg
- base/ca/shared/profiles/ca/caInternalAuthOCSPCert.cfg
- base/ca/shared/profiles/ca/caInternalAuthServerCert.cfg
- base/ca/shared/profiles/ca/caInternalAuthSubsystemCert.cfg
- base/ca/shared/profiles/ca/caInternalAuthTransportCert.cfg
- base/ca/shared/profiles/ca/caJarSigningCert.cfg
- + base/ca/shared/profiles/ca/caMLDSAAdminCert.cfg
- + base/ca/shared/profiles/ca/caMLDSAInternalAuthServerCert.cfg
- + base/ca/shared/profiles/ca/caMLDSAInternalAuthSubsystemCert.cfg
- + base/ca/shared/profiles/ca/caMLDSAServerCert.cfg
- + base/ca/shared/profiles/ca/caMLDSASubsystemCert.cfg
- + base/ca/shared/profiles/ca/caMLDSAUserCert.cfg
- + base/ca/shared/profiles/ca/caMLKEMInternalAuthDRMstorageCert.cfg
- + base/ca/shared/profiles/ca/caMLKEMInternalAuthTransportCert.cfg
- + base/ca/shared/profiles/ca/caMLKEMUserCert.cfg
- base/ca/shared/profiles/ca/caOCSPCert.cfg
- base/ca/shared/profiles/ca/caOtherCert.cfg
- base/ca/shared/profiles/ca/caRACert.cfg
- base/ca/shared/profiles/ca/caRARouterCert.cfg
- base/ca/shared/profiles/ca/caRAagentCert.cfg
- base/ca/shared/profiles/ca/caRAserverCert.cfg
- base/ca/shared/profiles/ca/caRouterCert.cfg
- base/ca/shared/profiles/ca/caServerCert.cfg
- + base/ca/shared/profiles/ca/caServerCertWithCRLDP.cfg
- base/ca/shared/profiles/ca/caServerCertWithSCT.cfg
- base/ca/shared/profiles/ca/caServerKeygen_DirUserCert.cfg
- base/ca/shared/profiles/ca/caServerKeygen_UserCert.cfg
- base/ca/shared/profiles/ca/caSignedLogCert.cfg
- base/ca/shared/profiles/ca/caSigningECUserCert.cfg
- base/ca/shared/profiles/ca/caSigningUserCert.cfg
- base/ca/shared/profiles/ca/caSimpleCMCUserCert.cfg
- base/ca/shared/profiles/ca/caStorageCert.cfg
- base/ca/shared/profiles/ca/caSubsystemCert.cfg
- base/ca/shared/profiles/ca/caTPSCert.cfg
- base/ca/shared/profiles/ca/caTransportCert.cfg
- base/ca/shared/profiles/ca/caUUIDdeviceCert.cfg
- base/ca/shared/profiles/ca/caUserCert.cfg
- base/ca/shared/profiles/ca/caUserSMIMEcapCert.cfg
- + base/ca/shared/profiles/ca/estFullcmcDeviceCert.cfg
- base/ca/shared/profiles/ca/estServiceCert.cfg
- base/ca/shared/webapps/ca/WEB-INF/web.xml
- base/ca/shared/webapps/ca/agent/ca/queryBySerial.html
- base/ca/shared/webapps/ca/agent/ca/queryCert.template
- base/ca/shared/webapps/ca/ee/ca/queryBySerial.html
- base/ca/shared/webapps/ca/ee/ca/queryCert.template
- base/ca/src/main/java/com/netscape/ca/AuthorityMonitor.java
- base/ca/src/main/java/com/netscape/ca/CAService.java
- base/ca/src/main/java/com/netscape/ca/CASigningUnit.java
- + base/ca/src/main/java/com/netscape/ca/CRLAutoUpdateTask.java
- base/ca/src/main/java/com/netscape/ca/CRLConfig.java
- base/ca/src/main/java/com/netscape/ca/CRLIssuingPoint.java
- base/ca/src/main/java/com/netscape/ca/CRLIssuingPointConfig.java
- base/ca/src/main/java/com/netscape/ca/CertRecordProcessor.java
- base/ca/src/main/java/com/netscape/ca/CertificateAuthority.java
- base/ca/src/main/java/com/netscape/ca/GetCertStatus.java
- base/ca/src/main/java/com/netscape/ca/KeyRetrieverRunner.java
- + base/ca/src/main/java/com/netscape/ca/KeyRetrieverWorker.java
- base/ca/src/main/java/com/netscape/ca/ServiceCheckChallenge.java
- base/ca/src/main/java/com/netscape/ca/ServiceGetCAChain.java
- base/common/src/main/java/com/netscape/certsrv/notification/IEmailResolver.java → base/ca/src/main/java/com/netscape/certsrv/notification/EmailResolver.java
- base/ca/src/main/java/com/netscape/certsrv/publish/CRLPublisher.java
- − base/ca/src/main/java/com/netscape/certsrv/publish/IPublishRuleSet.java
- base/ca/src/main/java/com/netscape/cms/authentication/CAAuthSubsystem.java
- base/ca/src/main/java/com/netscape/cms/authentication/CMCAuth.java
- + base/ca/src/main/java/com/netscape/cms/authentication/CMCAuthForEST.java
- base/ca/src/main/java/com/netscape/cms/authentication/CMCUserSignedAuth.java
- base/ca/src/main/java/com/netscape/cms/authentication/FlatFileAuth.java
- base/ca/src/main/java/com/netscape/cms/authentication/SSLClientCertAuthentication.java → base/ca/src/main/java/com/netscape/cms/authentication/SSLClientCertAuthManager.java
- base/ca/src/main/java/com/netscape/cms/authentication/SharedSecret.java
- base/ca/src/main/java/com/netscape/cms/crl/CMSAuthorityKeyIdentifierExtension.java
- base/ca/src/main/java/com/netscape/cms/jobs/PublishCertsJob.java
- base/ca/src/main/java/com/netscape/cms/jobs/RenewalNotificationJob.java
- base/ca/src/main/java/com/netscape/cms/jobs/UnpublishExpiredJob.java
- base/server/src/main/java/com/netscape/cmscore/request/SearchEnumeration.java → base/ca/src/main/java/com/netscape/cms/listeners/CARequestInQListener.java
- base/ca/src/main/java/com/netscape/cms/listeners/CertificateIssuedListener.java
- base/ca/src/main/java/com/netscape/cms/listeners/CertificateRevokedListener.java
- base/server/src/main/java/com/netscape/cms/listeners/PinRemovalListener.java → base/ca/src/main/java/com/netscape/cms/listeners/PinRemovalListener.java
- base/ca/src/main/java/com/netscape/cms/profile/common/CACertCAEnrollProfile.java
- base/ca/src/main/java/com/netscape/cms/profile/common/CAEnrollProfile.java
- base/ca/src/main/java/com/netscape/cms/profile/common/EnrollProfile.java
- + base/ca/src/main/java/com/netscape/cms/profile/common/PolicyConstraintConfig.java
- + base/ca/src/main/java/com/netscape/cms/profile/common/PolicyDefaultConfig.java
- base/ca/src/main/java/com/netscape/cms/profile/common/Profile.java
- base/ca/src/main/java/com/netscape/cms/profile/common/ProfileConfig.java
- base/ca/src/main/java/com/netscape/cms/profile/common/ProfileInput.java
- base/ca/src/main/java/com/netscape/cms/profile/common/ProfileOutput.java
- + base/ca/src/main/java/com/netscape/cms/profile/common/ProfilePolicyConfig.java
- + base/ca/src/main/java/com/netscape/cms/profile/common/ProfilePolicySetConfig.java
- + base/ca/src/main/java/com/netscape/cms/profile/common/ProfilePolicySetsConfig.java
- base/ca/src/main/java/com/netscape/cms/profile/common/ServerCertCAEnrollProfile.java
- base/ca/src/main/java/com/netscape/cms/profile/common/UserCertCAEnrollProfile.java
- base/ca/src/main/java/com/netscape/cms/profile/constraint/CAValidityConstraint.java
- base/ca/src/main/java/com/netscape/cms/profile/constraint/CMCSharedTokenSubjectNameConstraint.java
- base/ca/src/main/java/com/netscape/cms/profile/constraint/CMCUserSignedSubjectNameConstraint.java
- base/ca/src/main/java/com/netscape/cms/profile/constraint/EnrollConstraint.java
- base/ca/src/main/java/com/netscape/cms/profile/constraint/ExternalProcessConstraint.java
- base/ca/src/main/java/com/netscape/cms/profile/constraint/KeyConstraint.java
- base/ca/src/main/java/com/netscape/cms/profile/constraint/NoConstraint.java
- + base/ca/src/main/java/com/netscape/cms/profile/constraint/P12ExportPasswordConstraint.java
- base/ca/src/main/java/com/netscape/cms/profile/constraint/PolicyConstraint.java
- + base/ca/src/main/java/com/netscape/cms/profile/constraint/RAClientAuthSubjectNameConstraint.java
- + base/ca/src/main/java/com/netscape/cms/profile/constraint/RAHeaderClientCertSubjectNameConstraint.java
- base/ca/src/main/java/com/netscape/cms/profile/constraint/SubjectNameConstraint.java
- base/ca/src/main/java/com/netscape/cms/profile/constraint/UniqueKeyConstraint.java
- base/ca/src/main/java/com/netscape/cms/profile/constraint/UniqueSubjectNameConstraint.java
- base/ca/src/main/java/com/netscape/cms/profile/def/AuthInfoAccessExtDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/CAEnrollDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/CAValidityDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/CRLDistributionPointsExtDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/CertificatePoliciesExtDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/EnrollDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/FreshestCRLExtDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/NameConstraintsExtDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/NoDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/PolicyDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/PolicyMappingsExtDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/ServerKeygenUserKeyDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/SubjectAltNameExtDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/SubjectDirAttributesExtDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/SubjectInfoAccessExtDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/UserKeyDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/UserSubjectNameDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/ValidityDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/nsNKeySubjectNameDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/def/nsTokenUserKeySubjectNameDefault.java
- base/ca/src/main/java/com/netscape/cms/profile/input/CMCCertReqInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/CertReqInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/DualKeyGenInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/EncryptionKeyGenInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/EnrollInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/FileSigningInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/GenericInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/ImageInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/KeyGenInput.java
- + base/ca/src/main/java/com/netscape/cms/profile/input/RAClientAuthInfoInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/SerialNumRenewInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/ServerKeygenInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/SigningKeyGenInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/SubjectAltNameExtInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/SubjectDNInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/SubjectNameInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/SubmitterInfoInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/nsHKeyCertReqInput.java
- base/ca/src/main/java/com/netscape/cms/profile/input/nsNKeyCertReqInput.java
- base/ca/src/main/java/com/netscape/cms/profile/output/CMMFOutput.java
- base/ca/src/main/java/com/netscape/cms/profile/output/CertOutput.java
- base/ca/src/main/java/com/netscape/cms/profile/output/EnrollOutput.java
- base/ca/src/main/java/com/netscape/cms/profile/output/PKCS7Output.java
- base/ca/src/main/java/com/netscape/cms/profile/output/nsNKeyOutput.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/AVAPattern.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/LdapCaSimpleMap.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/LdapCertCompsMap.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/LdapCertExactMap.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/LdapCertSubjMap.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/LdapCrlIssuerCompsMap.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/LdapDNCompsMap.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/LdapEnhancedMap.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/LdapSimpleMap.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/MapAVAPattern.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/MapDNPattern.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/MapRDNPattern.java
- base/ca/src/main/java/com/netscape/cms/publish/mappers/NoMap.java
- base/ca/src/main/java/com/netscape/cms/publish/publishers/FileBasedPublisher.java
- base/ca/src/main/java/com/netscape/cms/publish/publishers/LdapCaCertPublisher.java
- base/ca/src/main/java/com/netscape/cms/publish/publishers/LdapCertSubjPublisher.java
- base/ca/src/main/java/com/netscape/cms/publish/publishers/LdapCertificatePairPublisher.java
- base/ca/src/main/java/com/netscape/cms/publish/publishers/LdapCrlPublisher.java
- base/ca/src/main/java/com/netscape/cms/publish/publishers/LdapEncryptCertPublisher.java
- base/ca/src/main/java/com/netscape/cms/publish/publishers/LdapUserCertPublisher.java
- base/ca/src/main/java/com/netscape/cms/publish/publishers/OCSPPublisher.java
- base/ca/src/main/java/com/netscape/cms/selftests/ca/CAPresence.java
- base/ca/src/main/java/com/netscape/cms/selftests/ca/CAValidity.java
- base/ca/src/main/java/com/netscape/cms/servlet/admin/CAAdminServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/admin/CAPolicyAdminServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/admin/ProfileAdminServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/admin/PublisherAdminServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/base/CADynamicVariables.java
- + base/ca/src/main/java/com/netscape/cms/servlet/base/CADynamicVariablesAdmin.java
- + base/ca/src/main/java/com/netscape/cms/servlet/base/CADynamicVariablesAgent.java
- + base/ca/src/main/java/com/netscape/cms/servlet/base/CAListRequests.java
- + base/ca/src/main/java/com/netscape/cms/servlet/base/CAPortsServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/base/QueryBySerial.java
- + base/ca/src/main/java/com/netscape/cms/servlet/base/SearchCert.java
- + base/ca/src/main/java/com/netscape/cms/servlet/base/SearchRevokeCert.java
- + base/ca/src/main/java/com/netscape/cms/servlet/base/UpdateDirectory.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/DisplayBySerial.java → base/ca/src/main/java/com/netscape/cms/servlet/cert/CADisplayBySerial.java
- + base/ca/src/main/java/com/netscape/cms/servlet/cert/CADisplayBySerialAgent.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/CMCRevReqServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/CertRequestInfoFactory.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/CertReviewResponseFactory.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/ChallengeRevocationServlet1.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/DisplayCRL.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/DoRevoke.java
- + base/ca/src/main/java/com/netscape/cms/servlet/cert/DoRevokeAgent.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/EnrollServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/GetCAChain.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/GetCRL.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/GetInfo.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/HashEnrollServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/ImportCertsTemplateFiller.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/ListCerts.java
- + base/ca/src/main/java/com/netscape/cms/servlet/cert/MasterCAGetInfo.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/Monitor.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/RenewalServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/SrchCerts.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/UpdateCRL.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/UpdateDir.java
- base/ca/src/main/java/com/netscape/cms/servlet/cert/scep/CRSEnrollment.java
- + base/ca/src/main/java/com/netscape/cms/servlet/cert/scep/SCEPConfig.java
- base/ca/src/main/java/com/netscape/cms/servlet/common/CMCOutputTemplate.java
- base/ca/src/main/java/com/netscape/cms/servlet/connector/KRAConnectorServlet.java → base/ca/src/main/java/com/netscape/cms/servlet/connector/CAConnectorServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/csadmin/BootstrapProfile.java
- + base/ca/src/main/java/com/netscape/cms/servlet/csadmin/CAGetCookie.java
- base/server/src/main/java/com/netscape/cmscore/request/RequestList.java → base/ca/src/main/java/com/netscape/cms/servlet/ocsp/CAOCSPServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileListAgentServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileListServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileReviewServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitCMCFullAuditSigningServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitCMCFullCAServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitCMCFullKRAStorageServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitCMCFullKRATransportServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitCMCFullOCSPServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitCMCFullServerServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitCMCFullServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitCMCFullSubsystemServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitCMCServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitCMCSimpleServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitSelfSignedCMCFullServlet.java
- + base/ca/src/main/java/com/netscape/cms/servlet/profile/ProfileSubmitUserSignedCMCFullServlet.java
- base/ca/src/main/java/com/netscape/cms/servlet/request/CertReqParser.java
- base/ca/src/main/java/com/netscape/cms/servlet/request/ProcessCertReq.java
- base/ca/src/main/java/com/netscape/cmscore/cert/CrlCachePrettyPrint.java
- base/ca/src/main/java/com/netscape/cmscore/cert/CrossCertPairSubsystem.java
- base/ca/src/main/java/com/netscape/cmscore/connector/LocalConnector.java
- base/ca/src/main/java/com/netscape/cmscore/dbs/CRLRepository.java
- base/ca/src/main/java/com/netscape/cmscore/dbs/CertRecordMapper.java
- base/ca/src/main/java/com/netscape/cmscore/dbs/CertStatusUpdateTask.java
- base/ca/src/main/java/com/netscape/cmscore/dbs/CertificateRepository.java
- base/ca/src/main/java/com/netscape/cmscore/dbs/SerialNumberUpdateTask.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/CAPublisherProcessor.java
- + base/ca/src/main/java/com/netscape/cmscore/ldap/LDAPPublishingConfig.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/LdapAndExpression.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/LdapConnModule.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/LdapEnrollmentListener.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/LdapExpression.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/LdapOrExpression.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/LdapPredicateParser.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/LdapPublishModule.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/LdapRenewalListener.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/LdapRevocationListener.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/LdapSimpleExpression.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/LdapUnrevocationListener.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/PublisherProcessor.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/PublishingConfig.java
- base/ca/src/main/java/com/netscape/cmscore/ldap/PublishingPublisherConfig.java
- + base/ca/src/main/java/com/netscape/cmscore/ldap/PublishingPublisherInstancesConfig.java
- + base/ca/src/main/java/com/netscape/cmscore/ldap/PublishingPublisherPluginsConfig.java
- + base/ca/src/main/java/com/netscape/cmscore/ldap/PublishingQueueConfig.java
- base/server/src/main/java/com/netscape/cmscore/notification/ReqCertEmailResolver.java → base/ca/src/main/java/com/netscape/cmscore/notification/ReqCertEmailResolver.java
- base/ca/src/main/java/com/netscape/cmscore/notification/ReqCertSANameEmailResolver.java
- base/ca/src/main/java/com/netscape/cmscore/profile/LDAPProfileSubsystem.java
- base/ca/src/main/java/com/netscape/cmscore/request/CertRequestRepository.java
- base/ca/src/main/java/org/dogtagpki/ct/CTEngine.java
- base/ca/src/main/java/org/dogtagpki/legacy/ca/CAPolicy.java
- base/ca/src/main/java/com/netscape/cms/profile/common/ProfilePoliciesConfig.java → base/ca/src/main/java/org/dogtagpki/legacy/ca/CAPolicyConfig.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/AgentPolicy.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/AttributePresentConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/DSAKeyConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/IssuerConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/KeyAlgorithmConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/RSAKeyConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/RenewalConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/RenewalValidityConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/RevocationConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/SigningAlgorithmConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/SubCANameConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/UniqueSubjectNameConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/constraints/ValidityConstraints.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/AuthInfoAccessExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/AuthorityKeyIdentifierExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/BasicConstraintsExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/CRLDistributionPointsExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/CertificatePoliciesExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/CertificateRenewalWindowExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/CertificateScopeOfUseExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/ExtendedKeyUsageExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/GenericASN1Ext.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/IssuerAltNameExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/KeyUsageExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/NSCCommentExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/NSCertTypeExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/NameConstraintsExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/OCSPNoCheckExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/PolicyConstraintsExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/PolicyMappingsExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/PresenceExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/PrivateKeyUsagePeriodExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/RemoveBasicConstraintsExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/SubjAltNameExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/SubjectAltNameExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/SubjectDirectoryAttributesExt.java
- base/ca/src/main/java/org/dogtagpki/legacy/server/policy/extensions/SubjectKeyIdentifierExt.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/AuthorityRecord.java
- base/ca/src/main/java/org/dogtagpki/server/ca/CAConfig.java
- base/ca/src/main/java/org/dogtagpki/server/ca/CAEngine.java
- base/ca/src/main/java/org/dogtagpki/server/ca/CAWebListener.java
- base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACLI.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACRLCLI.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACRLRecordCLI.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACRLRecordCertCLI.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACRLRecordCertFindCLI.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACRLRecordShowCLI.java
- base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACertCLI.java
- base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACertCreateCLI.java
- base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACertFindCLI.java
- base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACertImportCLI.java
- base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACertRemoveCLI.java
- base/ca/src/main/java/org/dogtagpki/server/ca/cli/CACertRequestImportCLI.java
- base/ca/src/main/java/org/dogtagpki/server/ca/cli/CADBCLI.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/cli/CADBInitCLI.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/cli/CAIdCLI.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/cli/CAIdGeneratorCLI.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/cli/CAIdGeneratorUpdateCLI.java
- base/ca/src/main/java/org/dogtagpki/server/ca/cli/CAProfileImportCLI.java
- base/ca/src/main/java/org/dogtagpki/server/ca/cli/CARangeUpdateCLI.java
- base/ca/src/main/java/org/dogtagpki/server/ca/job/PruningJob.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/job/SerialNumberUpdateJob.java
- − base/ca/src/main/java/org/dogtagpki/server/ca/rest/CASecurityDomainService.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/base/AuthorityRepository.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/base/ProfileBase.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/AgentCertRequestService.java
- base/ca/src/main/java/org/dogtagpki/server/ca/rest/CertService.java → base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/AgentCertService.java
- base/ca/src/main/java/org/dogtagpki/server/ca/rest/AuthorityService.java → base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/AuthorityService.java
- base/ca/src/main/java/org/dogtagpki/server/ca/rest/CAApplication.java → base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/CAApplication.java
- base/server/src/main/java/org/dogtagpki/server/rest/InfoService.java → base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/CAInfoService.java
- base/ca/src/main/java/org/dogtagpki/server/ca/rest/CAInstallerService.java → base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/CAInstallerService.java
- base/ca/src/main/java/org/dogtagpki/server/ca/rest/CASystemCertService.java → base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/CASystemCertService.java
- base/ca/src/main/java/org/dogtagpki/server/ca/rest/CertRequestDAO.java → base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/CertRequestDAO.java
- base/ca/src/main/java/org/dogtagpki/server/ca/rest/CertRequestService.java → base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/CertRequestService.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/CertService.java
- base/ca/src/main/java/org/dogtagpki/server/ca/rest/KRAConnectorService.java → base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/KRAConnectorService.java
- base/ca/src/main/java/org/dogtagpki/server/ca/rest/ProfileService.java → base/ca/src/main/java/org/dogtagpki/server/ca/rest/v1/ProfileService.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/AgentCertRequestServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/AgentCertServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/AuthorityServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CAAccountServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CAAuditServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CAFeatureServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CAGroupServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CAInfoServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CAInstallerServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CAJobServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CASecurityDomainServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CASelfTestServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CAServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CASystemCertServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CAUserServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CertRequestServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/CertServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/KRAConnectorServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/ProfileServlet.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/AgentCertACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/AgentCertAuthMethod.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/AgentCertRequestACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/AgentCertRequestAuthMethod.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/AuthorityACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/AuthorityAuthMethod.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CAAccountACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CAAccountAuthMethod.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CAAuditACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CAAuditAuthMethod.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CAGroupACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CAGroupAuthMethod.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CASecurityDomainACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CASecurityDomainAuthMethod.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CASelfTestACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CASelfTestAuthMethod.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CAUserACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/CAUserAuthMethod.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/EmptyACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/EmptyAuthMethod.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/KRAConnectorACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/KRAConnectorAuthMethod.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/ProfileACL.java
- + base/ca/src/main/java/org/dogtagpki/server/ca/rest/v2/filters/ProfileAuthMethod.java
- − base/ca/src/main/java/org/dogtagpki/server/rest/CAInfoService.java
- base/ca/src/test/java/com/netscape/cms/servlet/test/CATest.java
- + base/ca/tomcat-10.1/CMakeLists.txt
- + base/ca/tomcat-10.1/conf/Catalina/localhost/ca.xml
- base/common/CMakeLists.txt
- base/common/THIRD_PARTY_LICENSES
- base/common/examples/CMakeLists.txt
- base/common/examples/java/CAClientExample.java
- base/common/pom.xml
- base/common/python/pki/__init__.py
- base/common/python/pki/account.py
- + base/common/python/pki/acme.py
- base/common/python/pki/authority.py
- + base/common/python/pki/ca.py
- base/common/python/pki/cert.py
- base/common/python/pki/cli/__init__.py
- base/common/python/pki/cli/main.py
- − base/common/python/pki/cli/password.py
- − base/common/python/pki/cli/pkcs12.py
- base/common/python/pki/cli/upgrade.py
- base/common/python/pki/client.py
- base/common/python/pki/crypto.py
- base/common/python/pki/encoder.py
- base/common/python/pki/feature.py
- base/common/python/pki/info.py
- base/common/python/pki/key.py
- base/common/python/pki/keyring.py
- base/common/python/pki/kra.py
- base/common/python/pki/nssdb.py
- base/common/python/pki/pkcs12.py
- base/common/python/pki/profile.py
- + base/common/python/pki/subsystem.py
- base/common/python/pki/system.py
- base/common/python/pki/systemcert.py
- base/common/python/pki/upgrade.py
- + base/common/python/pki/user.py
- base/common/python/pki/util.py
- base/common/python/setup.py
- base/common/sbin/pki-upgrade
- base/common/share/etc/pki.conf
- base/common/src/main/java/com/netscape/certsrv/account/AccountClient.java
- − base/common/src/main/java/com/netscape/certsrv/authentication/IPasswdUserDBAuthentication.java
- base/common/src/main/java/com/netscape/certsrv/authority/AuthorityClient.java
- base/common/src/main/java/com/netscape/certsrv/authority/AuthorityResource.java
- base/common/src/main/java/com/netscape/certsrv/base/BadRequestException.java
- base/common/src/main/java/com/netscape/certsrv/base/IExtPrettyPrint.java → base/common/src/main/java/com/netscape/certsrv/base/ClientConnectionException.java
- base/common/src/main/java/com/netscape/certsrv/base/ConflictingOperationException.java
- base/common/src/main/java/com/netscape/certsrv/base/DataCollection.java
- base/common/src/main/java/com/netscape/certsrv/base/ExtendedPluginInfo.java
- base/common/src/main/java/com/netscape/certsrv/base/ForbiddenException.java
- base/common/src/main/java/com/netscape/certsrv/base/HTTPGoneException.java
- base/common/src/main/java/com/netscape/certsrv/base/IExtendedPluginInfo.java
- − base/common/src/main/java/com/netscape/certsrv/base/IPrettyPrintFormat.java
- + base/common/src/main/java/com/netscape/certsrv/base/MimeType.java
- base/common/src/main/java/com/netscape/certsrv/base/PKIException.java
- base/common/src/main/java/com/netscape/certsrv/base/RESTMessage.java
- + base/common/src/main/java/com/netscape/certsrv/base/RequestNotAcceptable.java
- base/common/src/main/java/com/netscape/certsrv/base/ResourceNotFoundException.java
- base/common/src/main/java/com/netscape/certsrv/base/SecurityDomainSessionTable.java
- base/common/src/main/java/com/netscape/certsrv/base/ServiceUnavailableException.java
- base/common/src/main/java/com/netscape/certsrv/base/UnauthorizedException.java
- + base/common/src/main/java/com/netscape/certsrv/base/UnsupportedMediaType.java
- + base/common/src/main/java/com/netscape/certsrv/ca/CAAgentCertClient.java
- + base/common/src/main/java/com/netscape/certsrv/ca/CAAgentCertRequestClient.java
- + base/common/src/main/java/com/netscape/certsrv/ca/CACRLClient.java
- base/common/src/main/java/com/netscape/certsrv/ca/CACertClient.java
- + base/common/src/main/java/com/netscape/certsrv/ca/CACertRequestClient.java
- base/common/src/main/java/com/netscape/certsrv/ca/CAClient.java
- + base/common/src/main/java/com/netscape/certsrv/cert/AgentCertRequestResource.java
- + base/common/src/main/java/com/netscape/certsrv/cert/AgentCertResource.java
- base/common/src/main/java/com/netscape/certsrv/cert/CertDataInfos.java
- base/common/src/main/java/com/netscape/certsrv/cert/CertEnrollmentRequest.java
- base/common/src/main/java/com/netscape/certsrv/cert/CertRequestResource.java
- base/common/src/main/java/com/netscape/certsrv/cert/CertResource.java
- base/common/src/main/java/com/netscape/certsrv/cert/CertSearchRequest.java
- base/common/src/main/java/com/netscape/certsrv/client/Client.java
- base/common/src/main/java/com/netscape/certsrv/client/ClientConfig.java
- base/common/src/main/java/com/netscape/certsrv/client/PKICertificateApprovalCallback.java
- base/common/src/main/java/com/netscape/certsrv/client/PKIClient.java
- − base/common/src/main/java/com/netscape/certsrv/client/PKIClientAuthenticator.java
- base/common/src/main/java/com/netscape/certsrv/client/PKIConnection.java
- − base/common/src/main/java/com/netscape/certsrv/client/PKIRESTProvider.java
- base/common/src/main/java/com/netscape/certsrv/client/SubsystemClient.java
- base/common/src/main/java/com/netscape/certsrv/dbs/EDBException.java → base/common/src/main/java/com/netscape/certsrv/dbs/DBException.java
- base/common/src/main/java/com/netscape/certsrv/dbs/EDBNotAvailException.java → base/common/src/main/java/com/netscape/certsrv/dbs/DBNotAvailableException.java
- + base/common/src/main/java/com/netscape/certsrv/dbs/DBRecordAlreadyExistsException.java
- base/common/src/main/java/com/netscape/certsrv/dbs/EDBRecordNotFoundException.java → base/common/src/main/java/com/netscape/certsrv/dbs/DBRecordNotFoundException.java
- base/common/src/main/java/com/netscape/certsrv/dbs/certdb/CertId.java
- base/common/src/main/java/com/netscape/certsrv/group/GroupClient.java
- base/common/src/main/java/com/netscape/certsrv/group/GroupCollection.java
- base/common/src/main/java/com/netscape/certsrv/group/GroupData.java
- base/common/src/main/java/com/netscape/certsrv/group/GroupMemberData.java
- base/common/src/main/java/com/netscape/certsrv/key/AsymKeyGenerationRequest.java
- base/common/src/main/java/com/netscape/certsrv/key/KeyArchivalRequest.java
- base/common/src/main/java/com/netscape/certsrv/key/KeyClient.java
- + base/common/src/main/java/com/netscape/certsrv/key/KeyParameters.java
- base/common/src/main/java/com/netscape/certsrv/key/KeyRecoveryRequest.java
- + base/common/src/main/java/com/netscape/certsrv/key/KeyRequestClient.java
- base/common/src/main/java/com/netscape/certsrv/key/KeyRequestResource.java
- base/common/src/main/java/com/netscape/certsrv/key/KeyResource.java
- base/common/src/main/java/com/netscape/certsrv/key/SymKeyGenerationRequest.java
- base/common/src/main/java/com/netscape/certsrv/kra/KRAClient.java
- base/common/src/main/java/com/netscape/certsrv/ldap/ELdapException.java
- base/common/src/main/java/com/netscape/certsrv/ldap/LDAPExceptionConverter.java
- base/common/src/main/java/com/netscape/certsrv/logging/ActivityClient.java
- base/common/src/main/java/com/netscape/certsrv/logging/ActivityCollection.java
- base/common/src/main/java/com/netscape/certsrv/logging/AuditClient.java
- base/common/src/main/java/com/netscape/certsrv/logging/AuditFileCollection.java
- − base/common/src/main/java/com/netscape/certsrv/notification/IEmailFormProcessor.java
- base/common/src/main/java/com/netscape/certsrv/ocsp/OCSPClient.java
- base/common/src/main/java/com/netscape/certsrv/profile/ProfileClient.java
- base/common/src/main/java/com/netscape/certsrv/profile/ProfileDataInfo.java
- base/common/src/main/java/com/netscape/certsrv/profile/ProfileDataInfos.java
- base/common/src/main/java/com/netscape/certsrv/profile/ProfileResource.java
- base/common/src/main/java/com/netscape/certsrv/profile/ProfileRetrievalRequest.java
- base/common/src/main/java/com/netscape/certsrv/request/AgentApprovals.java
- base/common/src/main/java/com/netscape/certsrv/selftests/SelfTestClient.java
- base/common/src/main/java/com/netscape/certsrv/selftests/SelfTestCollection.java
- base/common/src/main/java/com/netscape/certsrv/selftests/SelfTestResults.java
- base/common/src/main/java/com/netscape/certsrv/system/FeatureClient.java
- base/common/src/main/java/com/netscape/certsrv/system/KRAConnectorClient.java
- base/common/src/main/java/com/netscape/certsrv/system/KRAConnectorInfo.java
- base/common/src/main/java/com/netscape/certsrv/system/SecurityDomainClient.java
- base/common/src/main/java/com/netscape/certsrv/system/TPSConnectorClient.java
- base/common/src/main/java/com/netscape/certsrv/system/TPSConnectorCollection.java
- base/common/src/main/java/com/netscape/certsrv/tks/TKSClient.java
- base/common/src/main/java/com/netscape/certsrv/tps/TPSClient.java
- base/common/src/main/java/com/netscape/certsrv/tps/authenticator/AuthenticatorClient.java
- base/common/src/main/java/com/netscape/certsrv/tps/authenticator/AuthenticatorCollection.java
- base/common/src/main/java/com/netscape/certsrv/tps/cert/TPSCertClient.java
- base/common/src/main/java/com/netscape/certsrv/tps/cert/TPSCertCollection.java
- base/common/src/main/java/com/netscape/certsrv/tps/connector/ConnectorClient.java
- base/common/src/main/java/com/netscape/certsrv/tps/connector/ConnectorCollection.java
- base/common/src/main/java/com/netscape/certsrv/tps/profile/ProfileClient.java
- base/common/src/main/java/com/netscape/certsrv/tps/profile/ProfileCollection.java
- base/common/src/main/java/com/netscape/certsrv/tps/profile/ProfileMappingClient.java
- base/common/src/main/java/com/netscape/certsrv/tps/token/TokenClient.java
- base/common/src/main/java/com/netscape/certsrv/tps/token/TokenCollection.java
- base/common/src/main/java/com/netscape/certsrv/user/UserCertCollection.java
- base/common/src/main/java/com/netscape/certsrv/user/UserCertData.java
- base/common/src/main/java/com/netscape/certsrv/user/UserClient.java
- base/common/src/main/java/com/netscape/certsrv/user/UserData.java
- base/common/src/main/java/com/netscape/certsrv/user/UserMembershipData.java
- base/common/src/main/java/com/netscape/certsrv/util/CryptoProvider.java
- base/common/src/main/java/com/netscape/certsrv/util/NSSCryptoProvider.java
- base/acme/src/main/java/org/dogtagpki/acme/server/ACMEManagedService.java → base/common/src/main/java/com/netscape/certsrv/util/Param.java
- base/server/src/main/java/com/netscape/cmscore/cert/CertDateCompare.java → base/common/src/main/java/com/netscape/cmscore/cert/CertDateCompare.java
- base/common/src/main/java/com/netscape/cmsutil/crypto/CryptoUtil.java
- base/common/src/main/java/com/netscape/cmsutil/ocsp/CertStatus.java
- base/common/src/main/java/com/netscape/cmsutil/ocsp/GoodInfo.java
- base/common/src/main/java/com/netscape/cmsutil/ocsp/OCSPProcessor.java
- base/common/src/main/java/com/netscape/cmsutil/ocsp/OCSPResponse.java
- base/common/src/main/java/com/netscape/cmsutil/ocsp/OCSPResponseStatus.java
- base/common/src/main/java/com/netscape/cmsutil/ocsp/RevokedInfo.java
- base/common/src/main/java/com/netscape/cmsutil/ocsp/UnknownInfo.java
- base/common/src/main/java/com/netscape/cmsutil/password/PasswordStore.java
- base/common/src/main/java/com/netscape/cmsutil/util/Keyring.java
- base/common/src/main/java/com/netscape/cmsutil/xml/XMLObject.java
- base/common/src/main/java/org/dogtagpki/acme/ACMEClient.java
- + base/common/src/main/java/org/dogtagpki/acme/ACMEException.java
- base/common/src/main/java/org/dogtagpki/acme/JWK.java
- base/common/src/main/java/org/dogtagpki/ca/CASystemCertClient.java
- base/tomcat/src/main/java/org/dogtagpki/tomcat/PKITrustManager.java → base/common/src/main/java/org/dogtagpki/cert/PKITrustManager.java
- base/common/src/main/java/org/dogtagpki/cli/CLI.java
- base/common/src/main/java/org/dogtagpki/cli/CLIException.java
- base/common/src/main/java/org/dogtagpki/cli/CommandCLI.java
- + base/common/src/main/java/org/dogtagpki/client/JSSSocketFactory.java
- + base/common/src/main/java/org/dogtagpki/client/SSLSocketFactory.java
- base/common/src/main/java/org/dogtagpki/common/CAInfoClient.java
- base/common/src/main/java/org/dogtagpki/common/ConfigClient.java
- base/common/src/main/java/org/dogtagpki/common/InfoClient.java
- base/common/src/main/java/org/dogtagpki/common/KRAInfoClient.java
- base/common/src/main/java/org/dogtagpki/common/LoginClient.java
- base/common/src/main/java/org/dogtagpki/job/JobClient.java
- base/common/src/main/java/org/dogtagpki/kra/KRASystemCertClient.java
- base/common/src/main/java/org/dogtagpki/nss/NSSDatabase.java
- base/common/src/main/java/org/dogtagpki/nss/NSSExtensionGenerator.java
- base/common/src/main/java/org/dogtagpki/tps/TPSConnection.java
- base/common/src/main/java/org/dogtagpki/tps/apdu/APDU.java
- + base/common/src/main/java/org/dogtagpki/tps/apdu/DeleteKeysAPDU.java
- base/common/src/main/java/org/dogtagpki/tps/apdu/SelectAPDU.java
- base/common/src/main/java/org/dogtagpki/tps/main/TPSBuffer.java
- base/common/src/main/java/org/dogtagpki/tps/msg/EndOpMsg.java
- base/common/src/main/java/org/dogtagpki/tps/msg/TPSMessage.java
- base/common/src/main/java/org/dogtagpki/tps/msg/TokenPDURequestMsg.java
- + base/common/src/main/java/org/dogtagpki/util/cert/CRMFUtil.java
- base/common/src/main/java/org/dogtag/util/cert/CertUtil.java → base/common/src/main/java/org/dogtagpki/util/cert/CertUtil.java
- base/common/src/main/java/org/dogtagpki/util/logging/PKILogger.java
- base/common/src/test/java/com/netscape/certsrv/account/AccountTest.java
- base/common/src/test/java/com/netscape/certsrv/authority/AuthorityDataTest.java
- base/common/src/test/java/com/netscape/certsrv/base/DataTest.java
- base/common/src/test/java/com/netscape/certsrv/base/RESTMessageTest.java
- base/common/src/test/java/com/netscape/certsrv/cert/CertDataInfoTest.java
- base/common/src/test/java/com/netscape/certsrv/cert/CertDataInfosTest.java
- base/common/src/test/java/com/netscape/certsrv/cert/CertDataTest.java
- base/common/src/test/java/com/netscape/certsrv/cert/CertEnrollmentRequestTest.java
- base/common/src/test/java/com/netscape/certsrv/cert/CertRequestInfoTest.java
- base/common/src/test/java/com/netscape/certsrv/cert/CertRequestInfosTest.java
- base/common/src/test/java/com/netscape/certsrv/cert/CertRetrievalRequestTest.java
- base/common/src/test/java/com/netscape/certsrv/cert/CertReviewResponseTest.java
- base/common/src/test/java/com/netscape/certsrv/cert/CertRevokeRequestTest.java
- base/common/src/test/java/com/netscape/certsrv/cert/CertSearchRequestTest.java
- base/common/src/test/java/com/netscape/certsrv/client/ClientConfigTest.java
- base/common/src/test/java/com/netscape/certsrv/dbs/keydb/KeyIdTest.java
- base/common/src/test/java/com/netscape/certsrv/group/GroupDataTest.java
- base/common/src/test/java/com/netscape/certsrv/group/GroupMemberCollectionTest.java
- base/common/src/test/java/com/netscape/certsrv/group/GroupMemberDataTest.java
- base/common/src/test/java/com/netscape/certsrv/key/AsymKeyGenerationRequestTest.java
- base/common/src/test/java/com/netscape/certsrv/key/KeyArchivalRequestTest.java
- base/common/src/test/java/com/netscape/certsrv/key/KeyDataTest.java
- base/common/src/test/java/com/netscape/certsrv/key/KeyInfoCollectionTest.java
- base/common/src/test/java/com/netscape/certsrv/key/KeyInfoTest.java
- base/common/src/test/java/com/netscape/certsrv/key/KeyRecoveryRequestTest.java
- base/common/src/test/java/com/netscape/certsrv/key/KeyRequestInfoCollectionTest.java
- base/common/src/test/java/com/netscape/certsrv/key/KeyRequestInfoTest.java
- base/common/src/test/java/com/netscape/certsrv/key/KeyRequestResponseTest.java
- base/common/src/test/java/com/netscape/certsrv/key/KeyTest.java
- base/common/src/test/java/com/netscape/certsrv/key/SymKeyGenerationRequestTest.java
- base/common/src/test/java/com/netscape/certsrv/logging/ActivityDataTest.java
- base/common/src/test/java/com/netscape/certsrv/logging/AuditConfigTest.java
- base/common/src/test/java/com/netscape/certsrv/logging/AuditFileTest.java
- base/common/src/test/java/com/netscape/certsrv/profile/PolicyConstraintTest.java
- base/common/src/test/java/com/netscape/certsrv/profile/PolicyConstraintValueTest.java
- base/common/src/test/java/com/netscape/certsrv/profile/PolicyDefaultTest.java
- base/common/src/test/java/com/netscape/certsrv/profile/ProfileAttributeTest.java
- base/common/src/test/java/com/netscape/certsrv/profile/ProfileDataInfoTest.java
- base/common/src/test/java/com/netscape/certsrv/profile/ProfileDataTest.java
- base/common/src/test/java/com/netscape/certsrv/profile/ProfileInputTest.java
- base/common/src/test/java/com/netscape/certsrv/profile/ProfileOutputTest.java
- base/common/src/test/java/com/netscape/certsrv/profile/ProfileParameterTest.java
- base/common/src/test/java/com/netscape/certsrv/profile/ProfilePolicyTest.java
- base/common/src/test/java/com/netscape/certsrv/property/DescriptorTest.java
- base/common/src/test/java/com/netscape/certsrv/request/CMSRequestInfoTest.java
- base/common/src/test/java/com/netscape/certsrv/request/RequestIdTest.java
- base/common/src/test/java/com/netscape/certsrv/selftests/SelfTestDataTest.java
- base/common/src/test/java/com/netscape/certsrv/selftests/SelfTestResultTest.java
- base/common/src/test/java/com/netscape/certsrv/system/CertificateSetupRequestTest.java
- base/common/src/test/java/com/netscape/certsrv/system/DomainInfoTest.java
- base/common/src/test/java/com/netscape/certsrv/system/FeatureTest.java
- base/common/src/test/java/com/netscape/certsrv/system/InstallTokenTest.java
- base/common/src/test/java/com/netscape/certsrv/system/KRAConnectorInfoTest.java
- base/common/src/test/java/com/netscape/certsrv/system/SecurityDomainHostTest.java
- base/common/src/test/java/com/netscape/certsrv/system/SecurityDomainSubsystemTest.java
- base/common/src/test/java/com/netscape/certsrv/system/SystemCertDataTest.java
- base/common/src/test/java/com/netscape/certsrv/system/TPSConnectorDataTest.java
- base/common/src/test/java/com/netscape/certsrv/tps/authenticator/AuthenticatorDataTest.java
- base/common/src/test/java/com/netscape/certsrv/tps/cert/TPSCertDataTest.java
- base/common/src/test/java/com/netscape/certsrv/tps/connector/ConnectorDataTest.java
- base/common/src/test/java/com/netscape/certsrv/tps/profile/ProfileDataTest.java
- base/common/src/test/java/com/netscape/certsrv/tps/profile/ProfileMappingDataTest.java
- base/common/src/test/java/com/netscape/certsrv/tps/token/TokenDataTest.java
- base/common/src/test/java/com/netscape/certsrv/user/UserCertDataTest.java
- base/common/src/test/java/com/netscape/certsrv/user/UserCollectionTest.java
- base/common/src/test/java/com/netscape/certsrv/user/UserDataTest.java
- base/common/src/test/java/com/netscape/certsrv/user/UserMembershipCollectionTest.java
- base/common/src/test/java/com/netscape/certsrv/user/UserMembershipDataTest.java
- base/common/src/test/java/com/netscape/cms/servlet/test/ConfigurationTest.java
- base/common/src/test/java/com/netscape/cmsutil/crypto/KeyIDCodecTest.java
- − base/common/src/test/java/com/netscape/test/TestListener.java
- base/common/src/test/java/com/netscape/test/TestRunner.java
- base/common/src/test/java/org/dogtagpki/common/CAInfoTest.java
- base/common/src/test/java/org/dogtagpki/common/ConfigDataTest.java
- base/common/src/test/java/org/dogtagpki/common/InfoTest.java
- base/common/src/test/java/org/dogtagpki/common/KRAInfoTest.java
- base/console/CMakeLists.txt
- base/console/bin/pkiconsole
- + base/console/pom.xml
- base/console/src/main/java/com/netscape/admin/certsrv/CMSAdmin.java
- base/console/src/main/java/com/netscape/admin/certsrv/CMSTaskModel.java
- base/console/src/main/java/com/netscape/admin/certsrv/Console.java
- base/console/src/main/java/com/netscape/admin/certsrv/UIMapperRegistry.java
- base/console/src/main/java/com/netscape/admin/certsrv/config/CMSCAGeneralPanel.java
- base/console/src/main/java/com/netscape/admin/certsrv/config/WBaseManualCertRequestPage.java
- base/console/src/main/java/com/netscape/admin/certsrv/config/install/WIGenKeyCertReqPage.java
- base/console/src/main/java/com/netscape/admin/certsrv/connection/JSSConnection.java
- base/console/src/main/java/com/netscape/admin/certsrv/security/Response.java
- base/console/src/main/java/com/netscape/admin/certsrv/task/CMSMigrateCreate.java
- base/console/src/main/java/com/netscape/admin/certsrv/task/CMSStartDaemon.java
- + base/console/src/main/java/com/netscape/management/client/AboutDialog.java
- + base/console/src/main/java/com/netscape/management/client/CloseVetoException.java
- + base/console/src/main/java/com/netscape/management/client/FeedbackIndicator.java
- + base/console/src/main/java/com/netscape/management/client/FontPreferencesTab.java
- + base/console/src/main/java/com/netscape/management/client/Framework.java
- + base/console/src/main/java/com/netscape/management/client/FrameworkInitializer.java
- + base/console/src/main/java/com/netscape/management/client/IFramework.java
- + base/console/src/main/java/com/netscape/management/client/IFrameworkInitializer.java
- + base/console/src/main/java/com/netscape/management/client/IMenuInfo.java
- + base/console/src/main/java/com/netscape/management/client/IMenuItem.java
- + base/console/src/main/java/com/netscape/management/client/IMenuItemCategory.java
- + base/console/src/main/java/com/netscape/management/client/IMenuItemCheckBox.java
- + base/console/src/main/java/com/netscape/management/client/IMenuItemSeparator.java
- + base/console/src/main/java/com/netscape/management/client/IMenuItemText.java
- + base/console/src/main/java/com/netscape/management/client/IPage.java
- + base/console/src/main/java/com/netscape/management/client/IResourceModel.java
- + base/console/src/main/java/com/netscape/management/client/IResourceModelListener.java
- + base/console/src/main/java/com/netscape/management/client/IResourceObject.java
- + base/console/src/main/java/com/netscape/management/client/IStatusItem.java
- + base/console/src/main/java/com/netscape/management/client/ITaskModel.java
- + base/console/src/main/java/com/netscape/management/client/ITaskModelListener.java
- + base/console/src/main/java/com/netscape/management/client/ITaskObject.java
- + base/console/src/main/java/com/netscape/management/client/LDAPTaskModel.java
- + base/console/src/main/java/com/netscape/management/client/MenuData.java
- + base/console/src/main/java/com/netscape/management/client/MenuItemCategory.java
- + base/console/src/main/java/com/netscape/management/client/MenuItemCheckBox.java
- + base/console/src/main/java/com/netscape/management/client/MenuItemSeparator.java
- + base/console/src/main/java/com/netscape/management/client/MenuItemText.java
- + base/console/src/main/java/com/netscape/management/client/ResourceCellRenderer.java
- + base/console/src/main/java/com/netscape/management/client/ResourceModel.java
- + base/console/src/main/java/com/netscape/management/client/ResourceModelEvent.java
- + base/console/src/main/java/com/netscape/management/client/ResourceObject.java
- + base/console/src/main/java/com/netscape/management/client/ResourcePage.java
- + base/console/src/main/java/com/netscape/management/client/SettingsPreferencesTab.java
- + base/console/src/main/java/com/netscape/management/client/StatusItemIcon.java
- + base/console/src/main/java/com/netscape/management/client/StatusItemProgress.java
- + base/console/src/main/java/com/netscape/management/client/StatusItemSecureMode.java
- + base/console/src/main/java/com/netscape/management/client/StatusItemSpacer.java
- + base/console/src/main/java/com/netscape/management/client/StatusItemText.java
- + base/console/src/main/java/com/netscape/management/client/TaskModel.java
- + base/console/src/main/java/com/netscape/management/client/TaskModelEvent.java
- + base/console/src/main/java/com/netscape/management/client/TaskObject.java
- + base/console/src/main/java/com/netscape/management/client/TaskPage.java
- + base/console/src/main/java/com/netscape/management/client/UIPermissions.java
- + base/console/src/main/java/com/netscape/management/client/UIPermissionsPreferencesTab.java
- + base/console/src/main/java/com/netscape/management/client/ace/ACIAttribute.java
- + base/console/src/main/java/com/netscape/management/client/ace/ACIEditor.java
- + base/console/src/main/java/com/netscape/management/client/ace/ACIManager.java
- + base/console/src/main/java/com/netscape/management/client/ace/ACIParser.java
- + base/console/src/main/java/com/netscape/management/client/ace/HostTab.java
- + base/console/src/main/java/com/netscape/management/client/ace/IACITab.java
- + base/console/src/main/java/com/netscape/management/client/ace/RightsTab.java
- + base/console/src/main/java/com/netscape/management/client/ace/TargetTab.java
- + base/console/src/main/java/com/netscape/management/client/ace/TimeTab.java
- + base/console/src/main/java/com/netscape/management/client/ace/UGChooserDialog.java
- + base/console/src/main/java/com/netscape/management/client/ace/UGTab.java
- + base/console/src/main/java/com/netscape/management/client/ace/UGTable.java
- + base/console/src/main/java/com/netscape/management/client/ace/UGTableModel.java
- + base/console/src/main/java/com/netscape/management/client/acl/ACL.java
- + base/console/src/main/java/com/netscape/management/client/acl/AttributeList.java
- + base/console/src/main/java/com/netscape/management/client/acl/FileACL.java
- + base/console/src/main/java/com/netscape/management/client/acl/HttpACL.java
- + base/console/src/main/java/com/netscape/management/client/acl/HttpWriter.java
- + base/console/src/main/java/com/netscape/management/client/acl/LdapACL.java
- + base/console/src/main/java/com/netscape/management/client/acl/LdapACLSelector.java
- + base/console/src/main/java/com/netscape/management/client/acl/LdapRule.java
- + base/console/src/main/java/com/netscape/management/client/acl/LdapWriter.java
- + base/console/src/main/java/com/netscape/management/client/acl/Rule.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/ACLEditor.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/ACLEditorConstants.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/ACLEditorWindow.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/ACLRuleTableWindow.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/ACLSelectorWindow.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/AttributesWindow.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/CallbackAction.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/CustomJTable.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/DataModelAdapter.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/DataModelFactory.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/DefaultDataModelFactory.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/DefaultWindowFactory.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/HorizontalLine.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/HostsDataModel.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/InheritedTableDataModel.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/PickerWindow.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/PopupErrorDialog.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/RightsDataModel.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/RightsWindow.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/SelectionListener.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/SyntaxWindow.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/Table.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/TableDataModel.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/TimeWindow.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/UserGroupDataModel.java
- + base/console/src/main/java/com/netscape/management/client/acleditor/WindowFactory.java
- + base/console/src/main/java/com/netscape/management/client/cmd/CommandLineParser.java
- + base/console/src/main/java/com/netscape/management/client/cmd/GetOpt.java
- + base/console/src/main/java/com/netscape/management/client/comm/AbstractCommClient.java
- + base/console/src/main/java/com/netscape/management/client/comm/AsyncByteArrayInputStream.java
- + base/console/src/main/java/com/netscape/management/client/comm/ClientThread.java
- + base/console/src/main/java/com/netscape/management/client/comm/CommChannel.java
- + base/console/src/main/java/com/netscape/management/client/comm/CommClient.java
- + base/console/src/main/java/com/netscape/management/client/comm/CommClient2.java
- + base/console/src/main/java/com/netscape/management/client/comm/CommManager.java
- + base/console/src/main/java/com/netscape/management/client/comm/CommRecord.java
- + base/console/src/main/java/com/netscape/management/client/comm/HttpChannel.java
- + base/console/src/main/java/com/netscape/management/client/comm/HttpException.java
- + base/console/src/main/java/com/netscape/management/client/comm/HttpManager.java
- + base/console/src/main/java/com/netscape/management/client/comm/HttpsChannel.java
- + base/console/src/main/java/com/netscape/management/client/comm/Response.java
- + base/console/src/main/java/com/netscape/management/client/components/ButtonFactory.java
- + base/console/src/main/java/com/netscape/management/client/components/ClickBorder.java
- + base/console/src/main/java/com/netscape/management/client/components/ComponentFactory.java
- + base/console/src/main/java/com/netscape/management/client/components/DetailTable.java
- + base/console/src/main/java/com/netscape/management/client/components/DirBrowserDialog.java
- + base/console/src/main/java/com/netscape/management/client/components/DirModel.java
- + base/console/src/main/java/com/netscape/management/client/components/DirNode.java
- + base/console/src/main/java/com/netscape/management/client/components/DirNodeEvent.java
- + base/console/src/main/java/com/netscape/management/client/components/DirTree.java
- + base/console/src/main/java/com/netscape/management/client/components/DotBorder.java
- + base/console/src/main/java/com/netscape/management/client/components/ErrorDialog.java
- + base/console/src/main/java/com/netscape/management/client/components/FlatBorder.java
- + base/console/src/main/java/com/netscape/management/client/components/FontChooserDialog.java
- + base/console/src/main/java/com/netscape/management/client/components/FontFactory.java
- + base/console/src/main/java/com/netscape/management/client/components/GenericDialog.java
- + base/console/src/main/java/com/netscape/management/client/components/IDataCollectionModel.java
- + base/console/src/main/java/com/netscape/management/client/components/IDirContentListener.java
- + base/console/src/main/java/com/netscape/management/client/components/IDirModel.java
- + base/console/src/main/java/com/netscape/management/client/components/IDirNode.java
- + base/console/src/main/java/com/netscape/management/client/components/IDirNodeListener.java
- + base/console/src/main/java/com/netscape/management/client/components/IPAddressField.java
- + base/console/src/main/java/com/netscape/management/client/components/IPByteField.java
- + base/console/src/main/java/com/netscape/management/client/components/ISortableTableModel.java
- + base/console/src/main/java/com/netscape/management/client/components/IWizardPageContent.java
- + base/console/src/main/java/com/netscape/management/client/components/IWizardPageValidator.java
- + base/console/src/main/java/com/netscape/management/client/components/IWizardSequenceManager.java
- + base/console/src/main/java/com/netscape/management/client/components/PopupMenuButton.java
- + base/console/src/main/java/com/netscape/management/client/components/RootDirNode.java
- + base/console/src/main/java/com/netscape/management/client/components/StatusDialog.java
- + base/console/src/main/java/com/netscape/management/client/components/Table.java
- + base/console/src/main/java/com/netscape/management/client/components/TableMap.java
- + base/console/src/main/java/com/netscape/management/client/components/TableSorter.java
- + base/console/src/main/java/com/netscape/management/client/components/TaskDetailArea.java
- + base/console/src/main/java/com/netscape/management/client/components/TextDetailArea.java
- + base/console/src/main/java/com/netscape/management/client/components/TimeDayPanel.java
- + base/console/src/main/java/com/netscape/management/client/components/TreePanelCellRenderer.java
- + base/console/src/main/java/com/netscape/management/client/components/UIConstants.java
- + base/console/src/main/java/com/netscape/management/client/components/Wizard.java
- + base/console/src/main/java/com/netscape/management/client/components/WizardDataCollectionModel.java
- + base/console/src/main/java/com/netscape/management/client/components/WizardNavigator.java
- + base/console/src/main/java/com/netscape/management/client/components/WizardPage.java
- + base/console/src/main/java/com/netscape/management/client/components/WizardSequenceManager.java
- + base/console/src/main/java/com/netscape/management/client/console/Console.java
- + base/console/src/main/java/com/netscape/management/client/console/ConsoleHelp.java
- + base/console/src/main/java/com/netscape/management/client/console/ConsoleInfo.java
- + base/console/src/main/java/com/netscape/management/client/console/LoginDialog.java
- + base/console/src/main/java/com/netscape/management/client/console/RestartDialog.java
- + base/console/src/main/java/com/netscape/management/client/console/SplashScreen.java
- + base/console/src/main/java/com/netscape/management/client/console/VersionInfo.java
- + base/console/src/main/java/com/netscape/management/client/console/genverinfo.sh
- + base/console/src/main/java/com/netscape/management/client/keycert/README.txt
- + base/console/src/main/java/com/netscape/management/client/logging/IFilterComponent.java
- + base/console/src/main/java/com/netscape/management/client/logging/ILogViewerModel.java
- + base/console/src/main/java/com/netscape/management/client/logging/LogLengthCommClient.java
- + base/console/src/main/java/com/netscape/management/client/logging/LogViewer.java
- + base/console/src/main/java/com/netscape/management/client/logging/LogViewerModel.java
- + base/console/src/main/java/com/netscape/management/client/preferences/AbstractPreferencesTab.java
- + base/console/src/main/java/com/netscape/management/client/preferences/FilePreferenceManager.java
- + base/console/src/main/java/com/netscape/management/client/preferences/FilePreferences.java
- + base/console/src/main/java/com/netscape/management/client/preferences/IPreferencesTab.java
- + base/console/src/main/java/com/netscape/management/client/preferences/LDAPPreferenceManager.java
- + base/console/src/main/java/com/netscape/management/client/preferences/LDAPPreferences.java
- + base/console/src/main/java/com/netscape/management/client/preferences/PreferenceManager.java
- + base/console/src/main/java/com/netscape/management/client/preferences/Preferences.java
- + base/console/src/main/java/com/netscape/management/client/preferences/PreferencesDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/CACertificatePane.java
- + base/console/src/main/java/com/netscape/management/client/security/CRLCertificatePane.java
- + base/console/src/main/java/com/netscape/management/client/security/CertInstallCertInfoPage.java
- + base/console/src/main/java/com/netscape/management/client/security/CertInstallCertNamePage.java
- + base/console/src/main/java/com/netscape/management/client/security/CertInstallCertPage.java
- + base/console/src/main/java/com/netscape/management/client/security/CertInstallSetTrustPage.java
- + base/console/src/main/java/com/netscape/management/client/security/CertInstallTypePage.java
- + base/console/src/main/java/com/netscape/management/client/security/CertInstallWizard.java
- + base/console/src/main/java/com/netscape/management/client/security/CertMigrateAliasSelectionPage.java
- + base/console/src/main/java/com/netscape/management/client/security/CertMigrateConfirmPage.java
- + base/console/src/main/java/com/netscape/management/client/security/CertMigrateSourcePage.java
- + base/console/src/main/java/com/netscape/management/client/security/CertMigrateWizard.java
- + base/console/src/main/java/com/netscape/management/client/security/CertRequestWizard.java
- + base/console/src/main/java/com/netscape/management/client/security/CertificateDetailDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/CertificateDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/CertificateInfoPanels.java
- + base/console/src/main/java/com/netscape/management/client/security/CertificateList.java
- + base/console/src/main/java/com/netscape/management/client/security/CertificateListPane.java
- + base/console/src/main/java/com/netscape/management/client/security/CipherPreferenceDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/ClientAuthPanel.java
- + base/console/src/main/java/com/netscape/management/client/security/EditTrustDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/EncryptionOptions.java
- + base/console/src/main/java/com/netscape/management/client/security/EncryptionPanel.java
- + base/console/src/main/java/com/netscape/management/client/security/EncryptionTokenDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/IClientAuthOptions.java
- + base/console/src/main/java/com/netscape/management/client/security/IEncryptionOptions.java
- + base/console/src/main/java/com/netscape/management/client/security/InstallCRLDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/InstallPKCSDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/KeyCertUtility.java
- + base/console/src/main/java/com/netscape/management/client/security/ListTableModel.java
- + base/console/src/main/java/com/netscape/management/client/security/PKCSConfigDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/Parser.java
- + base/console/src/main/java/com/netscape/management/client/security/PromptForTrustDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/PromptTokenPasswordDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/SecurityPreferences.java
- + base/console/src/main/java/com/netscape/management/client/security/SecurityUtil.java
- + base/console/src/main/java/com/netscape/management/client/security/ServerCertificatePane.java
- + base/console/src/main/java/com/netscape/management/client/security/SetTokenPwdDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/StatusPage.java
- + base/console/src/main/java/com/netscape/management/client/security/TokenPasswordPage.java
- + base/console/src/main/java/com/netscape/management/client/security/ViewCertificateDialog.java
- + base/console/src/main/java/com/netscape/management/client/security/csr/CertRequestInfoPage.java
- + base/console/src/main/java/com/netscape/management/client/security/csr/CertRequestKeyPage.java
- + base/console/src/main/java/com/netscape/management/client/security/csr/CertRequestSubmissionPage.java
- + base/console/src/main/java/com/netscape/management/client/security/csr/DefaultPlugin.java
- + base/console/src/main/java/com/netscape/management/client/security/csr/ICAPlugin.java
- + base/console/src/main/java/com/netscape/management/client/security/csr/ICAPluginUtil.java
- + base/console/src/main/java/com/netscape/management/client/security/csr/IContentPage.java
- + base/console/src/main/java/com/netscape/management/client/security/csr/ISecurityUtil.java
- + base/console/src/main/java/com/netscape/management/client/security/csr/IUIPage.java
- + base/console/src/main/java/com/netscape/management/client/security/csr/manifest.mf
- + base/console/src/main/java/com/netscape/management/client/topology/AbstractServerObject.java
- + base/console/src/main/java/com/netscape/management/client/topology/AdminGroupNode.java
- + base/console/src/main/java/com/netscape/management/client/topology/CancelOpenDialog.java
- + base/console/src/main/java/com/netscape/management/client/topology/DefaultTopologyPlugin.java
- + base/console/src/main/java/com/netscape/management/client/topology/DomainNode.java
- + base/console/src/main/java/com/netscape/management/client/topology/HostNode.java
- + base/console/src/main/java/com/netscape/management/client/topology/ICustomView.java
- + base/console/src/main/java/com/netscape/management/client/topology/INodeInfo.java
- + base/console/src/main/java/com/netscape/management/client/topology/IProductObject.java
- + base/console/src/main/java/com/netscape/management/client/topology/IRemovableServerObject.java
- + base/console/src/main/java/com/netscape/management/client/topology/IServerObject.java
- + base/console/src/main/java/com/netscape/management/client/topology/ITopologyPlugin.java
- + base/console/src/main/java/com/netscape/management/client/topology/KeyCertMigrationDialog.java
- + base/console/src/main/java/com/netscape/management/client/topology/NetworkNode.java
- + base/console/src/main/java/com/netscape/management/client/topology/NewDomainDialog.java
- + base/console/src/main/java/com/netscape/management/client/topology/NodeData.java
- + base/console/src/main/java/com/netscape/management/client/topology/NodeDataPanel.java
- + base/console/src/main/java/com/netscape/management/client/topology/PermissionDlg.java
- + base/console/src/main/java/com/netscape/management/client/topology/ProductSelectionDialog.java
- + base/console/src/main/java/com/netscape/management/client/topology/ServerLocModel.java
- + base/console/src/main/java/com/netscape/management/client/topology/ServerLocNode.java
- + base/console/src/main/java/com/netscape/management/client/topology/ServerNode.java
- + base/console/src/main/java/com/netscape/management/client/topology/ServerRootPromptDialog.java
- + base/console/src/main/java/com/netscape/management/client/topology/ServiceLocator.java
- + base/console/src/main/java/com/netscape/management/client/topology/TopTopologyNode.java
- + base/console/src/main/java/com/netscape/management/client/topology/TopologyInitializer.java
- + base/console/src/main/java/com/netscape/management/client/topology/TopologyModel.java
- + base/console/src/main/java/com/netscape/management/client/topology/TopologyResourcePage.java
- + base/console/src/main/java/com/netscape/management/client/topology/customview/CustomView.java
- + base/console/src/main/java/com/netscape/management/client/topology/customview/EditDialog.java
- + base/console/src/main/java/com/netscape/management/client/topology/customview/NewDialog.java
- + base/console/src/main/java/com/netscape/management/client/topology/customview/RenameDialog.java
- + base/console/src/main/java/com/netscape/management/client/topology/customview/ViewInfo.java
- + base/console/src/main/java/com/netscape/management/client/topology/customview/ViewObject.java
- + base/console/src/main/java/com/netscape/management/client/topology/customview/ViewSelectorComponent.java
- + base/console/src/main/java/com/netscape/management/client/topology/customview/ViewSelectorDialog.java
- + base/console/src/main/java/com/netscape/management/client/topology/ug/EditUserGroupPane.java
- + base/console/src/main/java/com/netscape/management/client/topology/ug/IUGToolPlugin.java
- + base/console/src/main/java/com/netscape/management/client/topology/ug/OUPickerDialog.java
- + base/console/src/main/java/com/netscape/management/client/topology/ug/UGPage.java
- + base/console/src/main/java/com/netscape/management/client/ug/ActionPanel.java
- + base/console/src/main/java/com/netscape/management/client/ug/AdvancePanel.java
- + base/console/src/main/java/com/netscape/management/client/ug/AttributeSearchFilter.java
- + base/console/src/main/java/com/netscape/management/client/ug/BasicPanel.java
- + base/console/src/main/java/com/netscape/management/client/ug/CancelSearchDialog.java
- + base/console/src/main/java/com/netscape/management/client/ug/ChangeDirectoryDialog.java
- + base/console/src/main/java/com/netscape/management/client/ug/DefaultResEditorPage.java
- + base/console/src/main/java/com/netscape/management/client/ug/DirectoryListItem.java
- + base/console/src/main/java/com/netscape/management/client/ug/DynamicQueryDlg.java
- + base/console/src/main/java/com/netscape/management/client/ug/GroupLanguageFactory.java
- + base/console/src/main/java/com/netscape/management/client/ug/IAdvancedResPickerPlugin.java
- + base/console/src/main/java/com/netscape/management/client/ug/ILanguageFactory.java
- + base/console/src/main/java/com/netscape/management/client/ug/ILocalize.java
- + base/console/src/main/java/com/netscape/management/client/ug/IRPCallBack.java
- + base/console/src/main/java/com/netscape/management/client/ug/IRPSearchDlg.java
- + base/console/src/main/java/com/netscape/management/client/ug/IResEditorAdvancedOpt.java
- + base/console/src/main/java/com/netscape/management/client/ug/IResourceDeleteCallBack.java
- + base/console/src/main/java/com/netscape/management/client/ug/IResourceEditorAccPage.java
- + base/console/src/main/java/com/netscape/management/client/ug/IResourceEditorPage.java
- + base/console/src/main/java/com/netscape/management/client/ug/IResourcePickerPlugin.java
- + base/console/src/main/java/com/netscape/management/client/ug/ISearchResultCallBack.java
- + base/console/src/main/java/com/netscape/management/client/ug/IStandardResPickerPlugin.java
- + base/console/src/main/java/com/netscape/management/client/ug/LanguagePage.java
- + base/console/src/main/java/com/netscape/management/client/ug/LdapQueryBuilderDialog.java
- + base/console/src/main/java/com/netscape/management/client/ug/OULanguageFactory.java
- + base/console/src/main/java/com/netscape/management/client/ug/OUPage.java
- + base/console/src/main/java/com/netscape/management/client/ug/PickerEditorResourceSet.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorAccountPage.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorCertGroupMembers.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorDynamicGpMembers.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorGroupInfo.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorGroupMembers.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorGroupTitlePage.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorNTUser.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorOUTitlePage.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorPasswordPage.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorPosixGpMembers.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorPosixGroup.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorPosixUser.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorStaticGpMembers.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorUserPage.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResEditorUserTitlePage.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResourceEditor.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResourceEditorActionPane.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResourcePageObservable.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResourcePickerDlg.java
- + base/console/src/main/java/com/netscape/management/client/ug/ResourcePickerDlgMenu.java
- + base/console/src/main/java/com/netscape/management/client/ug/SearchParameter.java
- + base/console/src/main/java/com/netscape/management/client/ug/SearchResultPanel.java
- + base/console/src/main/java/com/netscape/management/client/ug/TitlePanel.java
- + base/console/src/main/java/com/netscape/management/client/ug/UGTextArea.java
- + base/console/src/main/java/com/netscape/management/client/ug/UserLanguageFactory.java
- + base/console/src/main/java/com/netscape/management/client/ug/VLDirectoryTable.java
- + base/console/src/main/java/com/netscape/management/client/ug/VLDirectoryTableModel.java
- + base/console/src/main/java/com/netscape/management/client/util/ADUtil.java
- + base/console/src/main/java/com/netscape/management/client/util/About.java
- + base/console/src/main/java/com/netscape/management/client/util/AbstractDialog.java
- + base/console/src/main/java/com/netscape/management/client/util/AbstractModalDialog.java
- + base/console/src/main/java/com/netscape/management/client/util/AcceptLanguage.java
- + base/console/src/main/java/com/netscape/management/client/util/AcceptLanguageList.java
- + base/console/src/main/java/com/netscape/management/client/util/AdmTask.java
- + base/console/src/main/java/com/netscape/management/client/util/AdmTaskArg.java
- + base/console/src/main/java/com/netscape/management/client/util/ArrowIcon.java
- + base/console/src/main/java/com/netscape/management/client/util/Assert.java
- + base/console/src/main/java/com/netscape/management/client/util/AssertionError.java
- + base/console/src/main/java/com/netscape/management/client/util/AssertionException.java
- + base/console/src/main/java/com/netscape/management/client/util/BrowseHistoryListener.java
- + base/console/src/main/java/com/netscape/management/client/util/BrowseHtmlDialog.java
- + base/console/src/main/java/com/netscape/management/client/util/BrowseHtmlHistory.java
- + base/console/src/main/java/com/netscape/management/client/util/BrowseHtmlPane.java
- + base/console/src/main/java/com/netscape/management/client/util/Browser.java
- + base/console/src/main/java/com/netscape/management/client/util/ClassLoaderUtil.java
- + base/console/src/main/java/com/netscape/management/client/util/ClipBoard.java
- + base/console/src/main/java/com/netscape/management/client/util/CompleteAcceptLanguageList.java
- + base/console/src/main/java/com/netscape/management/client/util/DatePicker.java
- + base/console/src/main/java/com/netscape/management/client/util/DateTimePicker.java
- + base/console/src/main/java/com/netscape/management/client/util/DayPicker.java
- + base/console/src/main/java/com/netscape/management/client/util/Debug.java
- + base/console/src/main/java/com/netscape/management/client/util/DefaultCellRenderer.java
- + base/console/src/main/java/com/netscape/management/client/util/DirUtil.java
- + base/console/src/main/java/com/netscape/management/client/util/DottedBorder.java
- + base/console/src/main/java/com/netscape/management/client/util/ExtendedMouseAdapter.java
- + base/console/src/main/java/com/netscape/management/client/util/GridBagUtil.java
- + base/console/src/main/java/com/netscape/management/client/util/Help.java
- + base/console/src/main/java/com/netscape/management/client/util/HelpAdminURL.java
- + base/console/src/main/java/com/netscape/management/client/util/IProgressListener.java
- + base/console/src/main/java/com/netscape/management/client/util/ISpinListener.java
- + base/console/src/main/java/com/netscape/management/client/util/IWizardControl.java
- + base/console/src/main/java/com/netscape/management/client/util/IWizardPageControl.java
- + base/console/src/main/java/com/netscape/management/client/util/ImageInfo.java
- + base/console/src/main/java/com/netscape/management/client/util/IndexDialog.java
- + base/console/src/main/java/com/netscape/management/client/util/JButtonFactory.java
- + base/console/src/main/java/com/netscape/management/client/util/KingpinClassLoader.java
- + base/console/src/main/java/com/netscape/management/client/util/KingpinLDAPConnection.java
- + base/console/src/main/java/com/netscape/management/client/util/LDAPInputStream.java
- + base/console/src/main/java/com/netscape/management/client/util/LDAPOutputStream.java
- + base/console/src/main/java/com/netscape/management/client/util/LDAPUtil.java
- + base/console/src/main/java/com/netscape/management/client/util/LinkedList.java
- + base/console/src/main/java/com/netscape/management/client/util/LinkedListElement.java
- + base/console/src/main/java/com/netscape/management/client/util/LocalJarClassLoader.java
- + base/console/src/main/java/com/netscape/management/client/util/ModalDialogUtil.java
- + base/console/src/main/java/com/netscape/management/client/util/MultilineLabel.java
- + base/console/src/main/java/com/netscape/management/client/util/Permissions.java
- + base/console/src/main/java/com/netscape/management/client/util/RemoteImage.java
- + base/console/src/main/java/com/netscape/management/client/util/ResourceSet.java
- + base/console/src/main/java/com/netscape/management/client/util/SimpleReferral.java
- + base/console/src/main/java/com/netscape/management/client/util/SingleByteDocument.java
- + base/console/src/main/java/com/netscape/management/client/util/SingleBytePasswordField.java
- + base/console/src/main/java/com/netscape/management/client/util/SingleByteTextArea.java
- + base/console/src/main/java/com/netscape/management/client/util/SingleByteTextField.java
- + base/console/src/main/java/com/netscape/management/client/util/SpinControl.java
- + base/console/src/main/java/com/netscape/management/client/util/SpinEvent.java
- + base/console/src/main/java/com/netscape/management/client/util/SwingPackageNameConverter.java
- + base/console/src/main/java/com/netscape/management/client/util/TableHeaderEditor.java
- + base/console/src/main/java/com/netscape/management/client/util/TimePicker.java
- + base/console/src/main/java/com/netscape/management/client/util/UITools.java
- + base/console/src/main/java/com/netscape/management/client/util/URLByteEncoder.java
- + base/console/src/main/java/com/netscape/management/client/util/UtilConsoleGlobals.java
- + base/console/src/main/java/com/netscape/management/client/util/Wizard.java
- + base/console/src/main/java/com/netscape/management/nmclf/SecondaryTabbedPane.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiBoundedRangeModel.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiCheckCellEditor.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiCheckCellRenderer.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiComboBoxUI.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiConstants.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiIconText.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiListCellRenderer.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiLookAndFeel.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiOptionPane.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiOptionPaneUI.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiPasswordField.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiScrollPane.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiTable.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiTableCellRenderer.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiTableColumn.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiTableHeaderBorder.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiTableHeaderRenderer.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiTableUI.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiTitle.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiTreeCellRenderer.java
- + base/console/src/main/java/com/netscape/management/nmclf/SuiTreeUI.java
- base/console/src/main/java/com/netscape/admin/certsrv/images/CertificateServer.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/CertificateServer.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/CertificateServerL.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/CertificateServerL.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/LOGobjs.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/LOGobjs.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/UGobjs.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/UGobjs.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/acl.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/acl.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/aclobj.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/aclobj.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/aclplugin.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/aclplugin.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/alertl.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/alertl.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/allfolder16n.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/allfolder16n.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/allgroup16n.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/allgroup16n.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/alllogdoc16n.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/alllogdoc16n.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/alllogfolder16n.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/alllogfolder16n.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/alluser16n.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/alluser16n.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/alluserwithcert16n.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/alluserwithcert16n.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/auth.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/auth.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/authobj.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/authobj.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/authplugin.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/authplugin.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/cert24.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/cert24.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/cert41.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/cert41.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/cert42.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/cert42.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/cms-branding.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/cms-branding.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/error.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/error.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/genobject.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/genobject.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/jobobj.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/jobobj.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/jobplugin.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/jobplugin.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/jobs.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/jobs.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/ldapub.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/ldapub.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/messagel.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/messagel.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/notsecure.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/notsecure.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/plug.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/plug.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/plugin.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/plugin.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/pluginfolder.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/pluginfolder.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/red-ball-small.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/red-ball-small.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/rule-16.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/rule-16.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/ruleDisable-16.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/ruleDisable-16.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/ruleplugin-16.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/ruleplugin-16.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/rulesobj.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/rulesobj.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/secure.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/secure.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/servlet-16.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/servlet-16.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/servlet-plugin-16.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/servlet-plugin-16.gif
- base/console/src/main/java/com/netscape/admin/certsrv/images/servletobj.gif → base/console/src/main/resources/com/netscape/admin/certsrv/images/servletobj.gif
- + base/console/src/main/resources/com/netscape/management/client/ace/ace.properties
- + base/console/src/main/resources/com/netscape/management/client/acleditor/ACLResources.properties
- themes/dogtag/common-ui/shared/esc/images/HelpButton.gif → base/console/src/main/resources/com/netscape/management/client/acleditor/images/allgroup16n.gif
- themes/dogtag/common-ui/shared/esc/images/OKButton.gif → base/console/src/main/resources/com/netscape/management/client/acleditor/images/allhost16n.gif
- themes/dogtag/common-ui/shared/esc/images/CloseButton.gif → base/console/src/main/resources/com/netscape/management/client/acleditor/images/alluser16n.gif
- + base/console/src/main/resources/com/netscape/management/client/alias.properties
- + base/console/src/main/resources/com/netscape/management/client/comm/HttpsChannel.properties
- + base/console/src/main/resources/com/netscape/management/client/components/Wizard.properties
- + base/console/src/main/resources/com/netscape/management/client/components/components.properties
- + base/console/src/main/resources/com/netscape/management/client/components/dirtree.properties
- + base/console/src/main/resources/com/netscape/management/client/components/images/ascending.gif
- + base/console/src/main/resources/com/netscape/management/client/components/images/checkHeader.gif
- + base/console/src/main/resources/com/netscape/management/client/components/images/descending.gif
- + base/console/src/main/resources/com/netscape/management/client/components/images/downArrow.gif
- + base/console/src/main/resources/com/netscape/management/client/components/images/leftArrow.gif
- + base/console/src/main/resources/com/netscape/management/client/components/images/moon.gif
- + base/console/src/main/resources/com/netscape/management/client/components/images/rightArrow.gif
- + base/console/src/main/resources/com/netscape/management/client/components/images/sun.gif
- + base/console/src/main/resources/com/netscape/management/client/components/images/upArrow.gif
- + base/console/src/main/resources/com/netscape/management/client/console/console.properties
- + base/console/src/main/resources/com/netscape/management/client/default.properties
- + base/console/src/main/resources/com/netscape/management/client/defaultAbout.properties
- + base/console/src/main/resources/com/netscape/management/client/defaultLicense.properties
- + base/console/src/main/resources/com/netscape/management/client/images/ConsoleBanner.gif
- + base/console/src/main/resources/com/netscape/management/client/images/OldServer.gif
- + base/console/src/main/resources/com/netscape/management/client/images/admin.gif
- + base/console/src/main/resources/com/netscape/management/client/images/all.gif
- + base/console/src/main/resources/com/netscape/management/client/images/anyone.gif
- + base/console/src/main/resources/com/netscape/management/client/images/error16.gif
- + base/console/src/main/resources/com/netscape/management/client/images/folder.gif
- + base/console/src/main/resources/com/netscape/management/client/images/group.gif
- + base/console/src/main/resources/com/netscape/management/client/images/host.gif
- themes/dogtag/common-ui/shared/esc/images/CancelButton.gif → base/console/src/main/resources/com/netscape/management/client/images/log.gif
- + base/console/src/main/resources/com/netscape/management/client/images/logfolder.gif
- + base/console/src/main/resources/com/netscape/management/client/images/logo16.gif
- + base/console/src/main/resources/com/netscape/management/client/images/logo32.gif
- + base/console/src/main/resources/com/netscape/management/client/images/notsecure.gif
- + base/console/src/main/resources/com/netscape/management/client/images/ou.gif
- + base/console/src/main/resources/com/netscape/management/client/images/red-ball-small.gif
- + base/console/src/main/resources/com/netscape/management/client/images/red-ball.gif
- + base/console/src/main/resources/com/netscape/management/client/images/secure.gif
- + base/console/src/main/resources/com/netscape/management/client/images/self.gif
- + base/console/src/main/resources/com/netscape/management/client/images/task.gif
- + base/console/src/main/resources/com/netscape/management/client/images/user.gif
- + base/console/src/main/resources/com/netscape/management/client/images/warn16.gif
- + base/console/src/main/resources/com/netscape/management/client/keycert/CertManagementResource.properties
- + base/console/src/main/resources/com/netscape/management/client/keycert/ChangeKeyPasswordDialogResource.properties
- + base/console/src/main/resources/com/netscape/management/client/keycert/CipherResource.properties
- + base/console/src/main/resources/com/netscape/management/client/keycert/EncryptionPaneResource.properties
- + base/console/src/main/resources/com/netscape/management/client/keycert/KeyCertTaskInfoResource.properties
- + base/console/src/main/resources/com/netscape/management/client/keycert/KeyCertWizardResource.properties
- + base/console/src/main/resources/com/netscape/management/client/keycert/PKCS11ManagementResource.properties
- + base/console/src/main/resources/com/netscape/management/client/preferences/preferences.properties
- + base/console/src/main/resources/com/netscape/management/client/security/KeyCertWizardResource.properties
- + base/console/src/main/resources/com/netscape/management/client/security/ServerAuthResource.properties
- + base/console/src/main/resources/com/netscape/management/client/security/securityResource.properties
- + base/console/src/main/resources/com/netscape/management/client/topology/images/domain16.gif
- + base/console/src/main/resources/com/netscape/management/client/topology/images/failedLoad.gif
- + base/console/src/main/resources/com/netscape/management/client/topology/images/host.gif
- + base/console/src/main/resources/com/netscape/management/client/topology/images/host16.gif
- + base/console/src/main/resources/com/netscape/management/client/topology/images/load.gif
- + base/console/src/main/resources/com/netscape/management/client/topology/images/red-ball-small.gif
- + base/console/src/main/resources/com/netscape/management/client/topology/topology.properties
- + base/console/src/main/resources/com/netscape/management/client/ug/PickerEditorResource.properties
- + base/console/src/main/resources/com/netscape/management/client/util/default.properties
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/Computer.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/DetailsView.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/Directory.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/Error.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/File.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/FloppyDrive.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/Folder.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/HardDrive.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/HomeFolder.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/Inform.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/JavaCup.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/ListView.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/NewFolder.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/Question.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/TreeClosed.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/TreeCollapser.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/TreeExpander.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/TreeLeaf.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/TreeOpen.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/UpFolder.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/Warn.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/group.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/group24.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/ou.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/ou24.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/user.gif
- + base/console/src/main/resources/com/netscape/management/nmclf/icons/user24.gif
- base/est/CMakeLists.txt
- + base/est/bin/estauthz
- − base/est/conf/realm.conf
- + base/est/pom.xml
- + base/est/shared/CS.cfg
- + base/est/shared/authorizer.conf
- + base/est/shared/backend.conf
- + base/est/shared/realm/ds/create.ldif
- + base/est/shared/realm/ds/ds.conf
- + base/est/shared/realm/in-memory/in-memory.conf
- + base/est/shared/realm/postgresql/create.sql
- + base/est/shared/realm/postgresql/postgresql.conf
- + base/est/shared/realm/postgresql/statements.conf
- base/est/src/main/java/org/dogtagpki/est/DogtagRABackend.java
- − base/est/src/main/java/org/dogtagpki/est/ESTApplication.java
- base/est/src/main/java/org/dogtagpki/est/ESTBackend.java
- base/est/src/main/java/org/dogtagpki/est/ESTEngine.java
- base/est/src/main/java/org/dogtagpki/est/ESTRequestAuthorizer.java
- base/est/src/main/java/org/dogtagpki/est/ESTFrontend.java → base/est/src/main/java/org/dogtagpki/est/ESTServlet.java
- base/est/src/main/java/org/dogtagpki/est/ESTWebListener.java
- base/est/src/main/java/org/dogtagpki/est/ExternalProcessRequestAuthorizer.java
- − base/est/src/main/java/org/dogtagpki/est/HandleBadAcceptHeaderRequestFilter.java
- − base/est/src/main/java/org/dogtagpki/est/ReformatContentTypeResponseFilter.java
- + base/est/tomcat-10.1/conf/Catalina/localhost/est.xml
- base/est/webapps/est/WEB-INF/web.xml
- base/server/share/webapps/pki/admin/console/config/topmenu.vm → base/est/webapps/est/index.jsp
- base/javadoc/CMakeLists.txt
- base/kra/CMakeLists.txt
- + base/kra/bin/pki-kra-run
- base/kra/database/ds/create.ldif
- base/kra/pom.xml
- base/kra/shared/conf/CS.cfg
- base/kra/shared/webapps/kra/WEB-INF/web.xml
- base/server/src/main/java/com/netscape/cmscore/cert/CertPrettyPrint.java → base/kra/src/main/java/com/netscape/cms/listeners/KRARequestInQListener.java
- base/common/src/main/java/com/netscape/certsrv/notification/IEmailResolverKeys.java → base/kra/src/main/java/com/netscape/cms/servlet/admin/KRAACLAdminServlet.java
- base/kra/src/main/java/com/netscape/cms/servlet/admin/KRAAdminServlet.java
- + base/kra/src/main/java/com/netscape/cms/servlet/admin/KRAAuthAdminServlet.java
- base/kra/src/main/java/com/netscape/cms/servlet/admin/KRACMSAdminServlet.java
- + base/kra/src/main/java/com/netscape/cms/servlet/admin/KRAJobsAdminServlet.java
- + base/kra/src/main/java/com/netscape/cms/servlet/admin/KRALogAdminServlet.java
- base/kra/src/main/java/com/netscape/cms/servlet/admin/KRAPolicyAdminServlet.java
- + base/kra/src/main/java/com/netscape/cms/servlet/admin/KRAUsrGrpAdminServlet.java
- + base/kra/src/main/java/com/netscape/cms/servlet/base/KRADynamicVariables.java
- + base/kra/src/main/java/com/netscape/cms/servlet/base/KRAGrantRecovery.java
- + base/kra/src/main/java/com/netscape/cms/servlet/base/KRAHeaderServlet.java
- + base/kra/src/main/java/com/netscape/cms/servlet/base/KRAIndexServlet.java
- + base/kra/src/main/java/com/netscape/cms/servlet/base/KRAListRequests.java
- + base/kra/src/main/java/com/netscape/cms/servlet/base/KRAPortsServlet.java
- + base/kra/src/main/java/com/netscape/cms/servlet/base/KRASearchKey.java
- + base/kra/src/main/java/com/netscape/cms/servlet/base/KRASearchKeyForRecovery.java
- base/kra/src/main/java/com/netscape/cms/servlet/connector/GenerateKeyPairServlet.java
- + base/kra/src/main/java/com/netscape/cms/servlet/connector/KRAConnectorServlet.java
- base/kra/src/main/java/com/netscape/cms/servlet/connector/TokenKeyRecoveryServlet.java
- base/kra/src/main/java/com/netscape/cms/servlet/csadmin/GetTransportCert.java
- + base/kra/src/main/java/com/netscape/cms/servlet/csadmin/KRAAdminUpdateDomainXML.java
- + base/kra/src/main/java/com/netscape/cms/servlet/csadmin/KRADownloadPKCS12.java
- + base/kra/src/main/java/com/netscape/cms/servlet/csadmin/KRAGetConfigEntries.java
- + base/kra/src/main/java/com/netscape/cms/servlet/csadmin/KRAGetCookie.java
- + base/kra/src/main/java/com/netscape/cms/servlet/csadmin/KRAGetStatus.java
- + base/kra/src/main/java/com/netscape/cms/servlet/csadmin/KRAMainPageServlet.java
- + base/kra/src/main/java/com/netscape/cms/servlet/csadmin/KRARegisterUser.java
- + base/kra/src/main/java/com/netscape/cms/servlet/csadmin/KRATokenAuthenticate.java
- + base/kra/src/main/java/com/netscape/cms/servlet/csadmin/KRAUpdateDomainXML.java
- base/kra/src/main/java/com/netscape/cms/servlet/csadmin/KRAUpdateNumberRange.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/ConfirmRecoverBySerial.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/DisplayBySerial.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/DisplayBySerialForRecovery.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/DisplayTransport.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/ExamineRecovery.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/GetApprovalStatus.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/GetAsyncPk12.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/GetPk12.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/GrantAsyncRecovery.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/GrantRecovery.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/RecoverBySerial.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/SrchKey.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/SrchKeyForRecovery.java
- base/kra/src/main/java/com/netscape/cms/servlet/request/KeyProcessReq.java
- base/kra/src/main/java/com/netscape/cms/servlet/request/KeyQueryReq.java
- base/kra/src/main/java/com/netscape/cms/servlet/request/KeyReqParser.java
- base/kra/src/main/java/com/netscape/cmscore/dbs/KeyRecordMapper.java
- base/kra/src/main/java/com/netscape/cmscore/dbs/KeyRepository.java
- base/kra/src/main/java/com/netscape/kra/AsymKeyGenService.java
- base/kra/src/main/java/com/netscape/kra/EncryptionUnit.java
- base/kra/src/main/java/com/netscape/kra/EnrollmentService.java
- base/kra/src/main/java/com/netscape/kra/KRAService.java
- base/kra/src/main/java/com/netscape/kra/KeyRecoveryAuthority.java
- base/kra/src/main/java/com/netscape/kra/NetkeyKeygenService.java
- base/kra/src/main/java/com/netscape/kra/RecoveryService.java
- base/kra/src/main/java/com/netscape/kra/SecurityDataProcessor.java
- base/kra/src/main/java/com/netscape/kra/StorageKeyUnit.java
- base/kra/src/main/java/com/netscape/kra/SymKeyGenService.java
- base/kra/src/main/java/com/netscape/kra/TokenKeyRecoveryService.java
- base/kra/src/main/java/com/netscape/kra/TransportKeyUnit.java
- base/kra/src/main/java/org/dogtagpki/legacy/kra/KRAPolicy.java
- + base/kra/src/main/java/org/dogtagpki/legacy/kra/KRAPolicyConfig.java
- base/kra/src/main/java/org/dogtagpki/server/kra/KRAConfig.java
- base/kra/src/main/java/org/dogtagpki/server/kra/KRAEngine.java
- base/kra/src/main/java/org/dogtagpki/server/kra/KRAWebListener.java
- base/kra/src/main/java/org/dogtagpki/server/kra/ProofOfArchival.java
- base/kra/src/main/java/org/dogtagpki/server/kra/cli/KRACLI.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/cli/KRADBCLI.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/cli/KRADBInitCLI.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/cli/KRAIdCLI.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/cli/KRAIdGeneratorCLI.java
- base/kra/src/main/java/org/dogtagpki/server/kra/cli/KRARangeUpdateCLI.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/cli/kraIdGeneratorUpdateCLI.java
- − base/kra/src/main/java/org/dogtagpki/server/kra/rest/KRASecurityDomainService.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/base/KeyProcessor.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/base/KeyRequestProcessor.java
- base/kra/src/main/java/org/dogtagpki/server/kra/rest/KRAApplication.java → base/kra/src/main/java/org/dogtagpki/server/kra/rest/v1/KRAApplication.java
- base/kra/src/main/java/org/dogtagpki/server/rest/KRAInfoService.java → base/kra/src/main/java/org/dogtagpki/server/kra/rest/v1/KRAInfoService.java
- base/kra/src/main/java/org/dogtagpki/server/kra/rest/KRASystemCertService.java → base/kra/src/main/java/org/dogtagpki/server/kra/rest/v1/KRASystemCertService.java
- base/kra/src/main/java/com/netscape/cms/servlet/key/KeyRequestDAO.java → base/kra/src/main/java/org/dogtagpki/server/kra/rest/v1/KeyRequestDAO.java
- base/kra/src/main/java/org/dogtagpki/server/kra/rest/KeyRequestService.java → base/kra/src/main/java/org/dogtagpki/server/kra/rest/v1/KeyRequestService.java
- base/kra/src/main/java/org/dogtagpki/server/kra/rest/KeyService.java → base/kra/src/main/java/org/dogtagpki/server/kra/rest/v1/KeyService.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KRAAccountServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KRAAuditServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KRAGroupServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KRAInfoServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KRAJobServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KRASecurityDomainServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KRASelfTestServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KRAServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KRASystemCertServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KRAUserServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KeyRequestServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/KeyServlet.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/EmptyACL.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/EmptyAuthMethod.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRAAccountACL.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRAAccountAuthMethod.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRAAuditACL.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRAAuditAuthMethod.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRAGroupACL.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRAGroupAuthMethod.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRASecurityDomainACL.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRASecurityDomainAuthMethod.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRASelfTestACL.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRASelfTestAuthMethod.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRAUserACL.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KRAUserAuthMethod.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KeyACL.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KeyAuthMethod.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KeyRequestACL.java
- + base/kra/src/main/java/org/dogtagpki/server/kra/rest/v2/filters/KeyRequestAuthMethod.java
- base/kra/src/test/python/drmtest.py
- base/kra/src/test/python/drmtest.readme.txt
- + base/kra/tomcat-10.1/CMakeLists.txt
- + base/kra/tomcat-10.1/conf/Catalina/localhost/kra.xml
- base/ocsp/CMakeLists.txt
- + base/ocsp/bin/pki-ocsp-run
- base/ocsp/pom.xml
- base/ocsp/shared/conf/CS.cfg
- base/ocsp/shared/webapps/ocsp/WEB-INF/web.xml
- + base/ocsp/src/main/java/com/netscape/cms/ocsp/CRLLdapValidator.java
- base/ocsp/src/main/java/com/netscape/cms/ocsp/DefStore.java
- base/ocsp/src/main/java/com/netscape/cms/ocsp/LDAPStore.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/admin/OCSPACLAdminServlet.java
- base/ocsp/src/main/java/com/netscape/cms/servlet/admin/OCSPAdminServlet.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/admin/OCSPAuthAdminServlet.java
- base/ocsp/src/main/java/com/netscape/cms/servlet/admin/OCSPCMSAdminServlet.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/admin/OCSPJobsAdminServlet.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/admin/OCSPLogAdminServlet.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/admin/OCSPUsrGrpAdminServlet.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/base/OCSPHeaderServlet.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/base/OCSPIndexServlet.java
- base/common/src/main/java/com/netscape/certsrv/base/ICertPrettyPrint.java → base/ocsp/src/main/java/com/netscape/cms/servlet/base/OCSPPortsServlet.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/base/OCSPReadAddCAPage.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/base/OCSPReadAddCRLPage.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/base/OCSPReadCheckCertPage.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/csadmin/OCSPAdminUpdateDomainXML.java
- base/common/src/main/java/com/netscape/certsrv/base/ICRLPrettyPrint.java → base/ocsp/src/main/java/com/netscape/cms/servlet/csadmin/OCSPDownloadPKCS12.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/csadmin/OCSPGetConfigEntries.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/csadmin/OCSPGetCookie.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/csadmin/OCSPGetStatus.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/csadmin/OCSPMainPageServlet.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/csadmin/OCSPTokenAuthenticate.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/csadmin/OCSPTokenAuthenticateAdmin.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/csadmin/OCSPUpdateDomainXML.java
- base/ocsp/src/main/java/com/netscape/cms/servlet/ocsp/AddCAServlet.java
- base/ocsp/src/main/java/com/netscape/cms/servlet/ocsp/AddCRLServlet.java
- base/ocsp/src/main/java/com/netscape/cms/servlet/ocsp/CheckCertServlet.java
- base/ocsp/src/main/java/com/netscape/cms/servlet/ocsp/ListCAServlet.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/ocsp/OCSPGetOCSPInfo.java
- + base/ocsp/src/main/java/com/netscape/cms/servlet/ocsp/OCSPOCSPServlet.java
- base/ocsp/src/main/java/com/netscape/cms/servlet/ocsp/RemoveCAServlet.java
- base/ocsp/src/main/java/com/netscape/ocsp/OCSPAuthority.java
- base/ocsp/src/main/java/com/netscape/ocsp/OCSPSigningUnit.java
- base/ocsp/src/main/java/org/dogtagpki/server/ocsp/OCSPConfig.java
- base/ocsp/src/main/java/org/dogtagpki/server/ocsp/OCSPEngine.java
- base/ocsp/src/main/java/org/dogtagpki/server/ocsp/OCSPWebListener.java
- base/ocsp/src/main/java/org/dogtagpki/server/ocsp/cli/OCSPCLI.java
- base/ocsp/src/main/java/org/dogtagpki/server/ocsp/cli/OCSPCRLIssuingPointAddCLI.java
- base/ocsp/src/main/java/org/dogtagpki/server/ocsp/cli/OCSPCRLIssuingPointFindCLI.java
- − base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/OCSPSecurityDomainService.java
- base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/OCSPApplication.java → base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v1/OCSPApplication.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/OCSPAccountServlet.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/OCSPAuditServlet.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/OCSPGroupServlet.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/OCSPJobServlet.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/OCSPSecurityDomainServlet.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/OCSPSelfTestServlet.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/OCSPServlet.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/OCSPUserServlet.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/EmptyACL.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/EmptyAuthMethod.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPAccountACL.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPAccountAuthMethod.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPAuditACL.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPAuditAuthMethod.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPGroupACL.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPGroupAuthMethod.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPSecurityDomainACL.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPSecurityDomainAuthMethod.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPSelfTestACL.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPSelfTestAuthMethod.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPUserACL.java
- + base/ocsp/src/main/java/org/dogtagpki/server/ocsp/rest/v2/filters/OCSPUserAuthMethod.java
- + base/ocsp/tomcat-10.1/CMakeLists.txt
- + base/ocsp/tomcat-10.1/conf/Catalina/localhost/ocsp.xml
- base/pom.xml
- + base/server-webapp/CMakeLists.txt
- + base/server-webapp/LICENSE
- + base/server-webapp/pom.xml
- + base/server-webapp/src/main/java/org/dogtagpki/server/PKIEngine.java
- + base/server-webapp/src/main/java/org/dogtagpki/server/PKIServlet.java
- + base/server-webapp/src/main/java/org/dogtagpki/server/PKIWebListener.java
- base/server/src/main/java/org/dogtagpki/server/rest/AppService.java → base/server-webapp/src/main/java/org/dogtagpki/server/rest/v1/AppService.java
- base/server/src/main/java/com/netscape/cmscore/cert/CrlPrettyPrint.java → base/server-webapp/src/main/java/org/dogtagpki/server/rest/v1/InfoService.java
- base/server/src/main/java/org/dogtagpki/server/rest/LoginService.java → base/server-webapp/src/main/java/org/dogtagpki/server/rest/v1/LoginService.java
- base/server/src/main/java/org/dogtagpki/server/rest/PKIApplication.java → base/server-webapp/src/main/java/org/dogtagpki/server/rest/v1/PKIApplication.java
- + base/server-webapp/src/main/java/org/dogtagpki/server/rest/v2/AppServlet.java
- + base/server-webapp/src/main/java/org/dogtagpki/server/rest/v2/InfoServlet.java
- + base/server-webapp/src/main/java/org/dogtagpki/server/rest/v2/LoginServlet.java
- + base/server-webapp/src/main/resources/META-INF/MANIFEST.MF
- base/server/share/webapps/ROOT/WEB-INF/web.xml → base/server-webapp/webapps/ROOT/WEB-INF/web.xml
- base/server/share/webapps/pki/index.jsp → base/server-webapp/webapps/ROOT/index.jsp
- base/acme/webapps/acme/js/jquery-3.5.1.js → base/server-webapp/webapps/ROOT/jquery-3.5.1/jquery.min.js
- base/acme/webapps/acme/css/assets/fonts/RedHatDisplay/RedHatDisplay-Medium.woff → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/RedHatDisplay/RedHatDisplay-Medium.woff
- base/acme/webapps/acme/css/assets/fonts/RedHatText/RedHatText-Medium.woff → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/RedHatText/RedHatText-Medium.woff
- base/acme/webapps/acme/css/assets/fonts/RedHatText/RedHatText-Regular.woff → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/RedHatText/RedHatText-Regular.woff
- base/acme/webapps/acme/css/assets/fonts/overpass-webfont/overpass-bold.ttf → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/overpass-webfont/overpass-bold.ttf
- base/acme/webapps/acme/css/assets/fonts/overpass-webfont/overpass-bold.woff → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/overpass-webfont/overpass-bold.woff
- base/acme/webapps/acme/css/assets/fonts/overpass-webfont/overpass-bold.woff2 → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/overpass-webfont/overpass-bold.woff2
- base/acme/webapps/acme/css/assets/fonts/overpass-webfont/overpass-light.ttf → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/overpass-webfont/overpass-light.ttf
- base/acme/webapps/acme/css/assets/fonts/overpass-webfont/overpass-light.woff → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/overpass-webfont/overpass-light.woff
- base/acme/webapps/acme/css/assets/fonts/overpass-webfont/overpass-light.woff2 → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/overpass-webfont/overpass-light.woff2
- base/acme/webapps/acme/css/assets/fonts/webfonts/fa-solid-900.ttf → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/webfonts/fa-solid-900.ttf
- base/acme/webapps/acme/css/assets/fonts/webfonts/fa-solid-900.woff → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/webfonts/fa-solid-900.woff
- base/acme/webapps/acme/css/assets/fonts/webfonts/fa-solid-900.woff2 → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/fonts/webfonts/fa-solid-900.woff2
- base/acme/webapps/acme/css/assets/images/img_avatar.svg → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/images/img_avatar.svg
- base/acme/webapps/acme/css/assets/pficon/pficon.ttf → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/pficon/pficon.ttf
- base/acme/webapps/acme/css/assets/pficon/pficon.woff → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/pficon/pficon.woff
- base/acme/webapps/acme/css/assets/pficon/pficon.woff2 → base/server-webapp/webapps/ROOT/patternfly-4.35.2/assets/pficon/pficon.woff2
- base/acme/webapps/acme/css/patternfly-4.35.2.css → base/server-webapp/webapps/ROOT/patternfly-4.35.2/patternfly.min.css
- base/acme/webapps/acme/css/patternfly.min.css.map → base/server-webapp/webapps/ROOT/patternfly-4.35.2/patternfly.min.css.map
- base/server/share/webapps/pki/WEB-INF/classes/logging.properties → base/server-webapp/webapps/pki/WEB-INF/classes/logging.properties
- base/server/share/webapps/pki/WEB-INF/web.xml → base/server-webapp/webapps/pki/WEB-INF/web.xml
- base/server/share/webapps/pki/admin/console/js/misc.js → base/server-webapp/webapps/pki/admin/console/js/misc.js
- + base/server-webapp/webapps/pki/index.jsp
- base/server/share/webapps/pki/js/backbone.js → base/server-webapp/webapps/pki/js/backbone.js
- base/server/share/webapps/pki/js/bootstrap.js → base/server-webapp/webapps/pki/js/bootstrap.js
- base/server/share/webapps/pki/js/jquery.i18n.properties.js → base/server-webapp/webapps/pki/js/jquery.i18n.properties.js
- base/server/share/webapps/pki/js/jquery.js → base/server-webapp/webapps/pki/js/jquery.js
- base/server/share/webapps/pki/js/patternfly.js → base/server-webapp/webapps/pki/js/patternfly.js
- base/server/share/webapps/pki/js/pki-account.js → base/server-webapp/webapps/pki/js/pki-account.js
- base/server/share/webapps/pki/js/pki-app.js → base/server-webapp/webapps/pki/js/pki-app.js
- base/server/share/webapps/pki/js/pki-audit.js → base/server-webapp/webapps/pki/js/pki-audit.js
- base/server/share/webapps/pki/js/pki-banner.js → base/server-webapp/webapps/pki/js/pki-banner.js
- base/server/share/webapps/pki/js/pki-group.js → base/server-webapp/webapps/pki/js/pki-group.js
- base/server/share/webapps/pki/js/pki-ui.js → base/server-webapp/webapps/pki/js/pki-ui.js
- base/server/share/webapps/pki/js/pki-user.js → base/server-webapp/webapps/pki/js/pki-user.js
- base/server/share/webapps/pki/js/pki.js → base/server-webapp/webapps/pki/js/pki.js
- base/server/share/webapps/pki/js/underscore.js → base/server-webapp/webapps/pki/js/underscore.js
- base/server/share/webapps/pki/ui/audit.html → base/server-webapp/webapps/pki/ui/audit.html
- base/server/share/webapps/pki/ui/group.html → base/server-webapp/webapps/pki/ui/group.html
- base/server/share/webapps/pki/ui/groups.html → base/server-webapp/webapps/pki/ui/groups.html
- base/server/share/webapps/pki/ui/index.jsp → base/server-webapp/webapps/pki/ui/index.jsp
- base/server/share/webapps/pki/ui/user-certs.html → base/server-webapp/webapps/pki/ui/user-certs.html
- base/server/share/webapps/pki/ui/user-roles.html → base/server-webapp/webapps/pki/ui/user-roles.html
- base/server/share/webapps/pki/ui/user.html → base/server-webapp/webapps/pki/ui/user.html
- base/server/share/webapps/pki/ui/users.html → base/server-webapp/webapps/pki/ui/users.html
- base/server/CMakeLists.txt
- base/server/bin/pki-server-run
- base/server/etc/default.cfg
- + base/server/etc/fapolicy.rules
- + base/server/examples/installation/acme.cfg
- + base/server/examples/installation/ca-clone-pqc.cfg
- + base/server/examples/installation/ca-clone-w-p12.cfg
- base/server/examples/installation/ca-clone.cfg
- base/server/examples/installation/ca-ecc.cfg
- base/server/examples/installation/ca-existing-certs-step1.cfg
- base/server/examples/installation/ca-existing-certs-step2.cfg
- base/server/examples/installation/ca-external-cert-step1.cfg
- base/server/examples/installation/ca-external-cert-step2.cfg
- + base/server/examples/installation/ca-pqc.cfg
- + base/server/examples/installation/ca-secure-ds-pqc.cfg
- base/server/examples/installation/ca-secure-ds-primary.cfg
- base/server/examples/installation/ca-secure-ds-secondary.cfg
- base/server/examples/installation/ca-secure-ds.cfg
- base/server/examples/installation/ca.cfg
- + base/server/examples/installation/est-standalone.cfg
- + base/server/examples/installation/est.cfg
- + base/server/examples/installation/kra-ecc.cfg
- base/server/examples/installation/kra-external-certs-step1.cfg
- base/server/examples/installation/kra-external-certs-step2.cfg
- + base/server/examples/installation/kra-pqc.cfg
- base/server/examples/installation/kra-standalone-step1.cfg
- base/server/examples/installation/kra-standalone-step2.cfg
- base/server/examples/installation/ocsp-clone.cfg
- base/server/examples/installation/ocsp-external-certs-step1.cfg
- base/server/examples/installation/ocsp-external-certs-step2.cfg
- base/server/examples/installation/ocsp-standalone-step1.cfg
- base/server/examples/installation/ocsp-standalone-step2.cfg
- base/server/examples/installation/ocsp.cfg
- base/server/examples/installation/subca.cfg
- base/server/healthcheck/CMakeLists.txt
- − base/server/healthcheck/pki/server/healthcheck/certs/expiration.py
- + base/server/healthcheck/pki/server/healthcheck/certs/systemcerts.py
- − base/server/healthcheck/pki/server/healthcheck/certs/trustflags.py
- − base/server/healthcheck/pki/server/healthcheck/clones/__init__.py
- − base/server/healthcheck/pki/server/healthcheck/clones/connectivity_and_data.py
- − base/server/healthcheck/pki/server/healthcheck/clones/plugin.py
- base/server/healthcheck/pki/server/healthcheck/meta/connectivity.py
- − base/server/healthcheck/pki/server/healthcheck/meta/csconfig.py
- base/server/healthcheck/setup.py
- + base/server/mcp/.python-version
- + base/server/mcp/main.py
- + base/server/mcp/pyproject.toml
- base/server/pom.xml
- base/server/python/pki/server/__init__.py
- base/server/python/pki/server/cli/__init__.py
- + base/server/python/pki/server/cli/acl.py
- base/server/python/pki/server/cli/acme.py
- base/server/python/pki/server/cli/audit.py
- base/server/python/pki/server/cli/banner.py
- base/server/python/pki/server/cli/ca.py
- base/server/python/pki/server/cli/cert.py
- base/server/python/pki/server/cli/config.py
- base/server/python/pki/server/cli/db.py
- base/server/python/pki/server/cli/est.py
- base/server/python/pki/server/cli/group.py
- base/server/python/pki/server/cli/http.py
- + base/server/python/pki/server/cli/id.py
- base/server/python/pki/server/cli/instance.py
- base/server/python/pki/server/cli/jss.py
- base/server/python/pki/server/cli/kra.py
- base/server/python/pki/server/cli/listener.py
- base/server/python/pki/server/cli/migrate.py
- base/server/python/pki/server/cli/nss.py
- base/server/python/pki/server/cli/nuxwdog.py
- base/server/python/pki/server/cli/ocsp.py
- base/server/python/pki/server/cli/password.py
- base/server/python/pki/server/cli/range.py
- base/server/python/pki/server/cli/sd.py
- base/server/python/pki/server/cli/selftest.py
- base/server/python/pki/server/cli/subsystem.py
- base/server/python/pki/server/cli/tks.py
- base/server/python/pki/server/cli/tps.py
- base/server/python/pki/server/cli/upgrade.py
- base/server/python/pki/server/cli/user.py
- base/server/python/pki/server/cli/webapp.py
- base/server/python/pki/server/deployment/__init__.py
- base/server/python/pki/server/deployment/pkiconfig.py
- base/server/python/pki/server/deployment/pkihelper.py
- base/server/python/pki/server/deployment/pkilogging.py
- base/server/python/pki/server/deployment/pkimessages.py
- base/server/python/pki/server/deployment/pkiparser.py
- base/server/python/pki/server/deployment/scriptlets/configuration.py
- − base/server/python/pki/server/deployment/scriptlets/fapolicy_setup.py
- − base/server/python/pki/server/deployment/scriptlets/finalization.py
- − base/server/python/pki/server/deployment/scriptlets/infrastructure_layout.py
- − base/server/python/pki/server/deployment/scriptlets/initialization.py
- base/server/python/pki/server/deployment/scriptlets/instance_layout.py
- − base/server/python/pki/server/deployment/scriptlets/keygen.py
- − base/server/python/pki/server/deployment/scriptlets/security_databases.py
- − base/server/python/pki/server/deployment/scriptlets/selinux_setup.py
- base/server/python/pki/server/deployment/scriptlets/subsystem_layout.py
- base/server/python/pki/server/instance.py
- base/server/python/pki/server/pkidestroy.py
- base/server/python/pki/server/pkiserver.py
- base/server/python/pki/server/pkispawn.py
- base/server/python/pki/server/subsystem.py
- base/server/python/pki/server/upgrade.py
- base/server/sbin/pki-server
- base/server/sbin/pki-server-upgrade → base/server/sbin/pki-tomcat-start
- base/server/python/pki/server/deployment/scriptlets/webapp_deployment.py → base/server/sbin/pki-tomcat-stop
- base/server/sbin/pkidestroy
- base/server/sbin/pkispawn
- base/server/scripts/operations
- base/server/scripts/pki-server-nuxwdog
- base/server/scripts/pkidaemon
- base/server/share/conf/logging.properties
- base/server/share/conf/pki.policy
- base/server/share/conf/tomcat.conf
- base/server/share/lib/systemd/system/pki-tomcatd-nuxwdog at .service
- base/server/share/lib/systemd/system/pki-tomcatd at .service
- − base/server/share/webapps/ROOT/index.jsp
- − base/server/share/webapps/pki/admin/console/config/adminauthenticatepanel.vm
- − base/server/share/webapps/pki/admin/console/config/adminpanel.vm
- − base/server/share/webapps/pki/admin/console/config/agentauthenticatepanel.vm
- − base/server/share/webapps/pki/admin/console/config/authdbpanel.vm
- − base/server/share/webapps/pki/admin/console/config/backupkeycertpanel.vm
- − base/server/share/webapps/pki/admin/console/config/cainfopanel.vm
- − base/server/share/webapps/pki/admin/console/config/certchainpanel.vm
- − base/server/share/webapps/pki/admin/console/config/certprettyprintpanel.vm
- − base/server/share/webapps/pki/admin/console/config/certrequestpanel.vm
- − base/server/share/webapps/pki/admin/console/config/config_addhsm.vm
- − base/server/share/webapps/pki/admin/console/config/config_hsmloginpanel.vm
- − base/server/share/webapps/pki/admin/console/config/createsubsystempanel.vm
- − base/server/share/webapps/pki/admin/console/config/databasepanel.vm
- − base/server/share/webapps/pki/admin/console/config/displaycertchainpanel.vm
- − base/server/share/webapps/pki/admin/console/config/donepanel.vm
- − base/server/share/webapps/pki/admin/console/config/drminfopanel.vm
- − base/server/share/webapps/pki/admin/console/config/footer.vm
- − base/server/share/webapps/pki/admin/console/config/header.vm
- − base/server/share/webapps/pki/admin/console/config/hierarchypanel.vm
- − base/server/share/webapps/pki/admin/console/config/importadmincertpanel.vm
- − base/server/share/webapps/pki/admin/console/config/importcachainpanel.vm
- − base/server/share/webapps/pki/admin/console/config/login.vm
- − base/server/share/webapps/pki/admin/console/config/modulepanel.vm
- − base/server/share/webapps/pki/admin/console/config/namepanel.vm
- − base/server/share/webapps/pki/admin/console/config/restorekeycertpanel.vm
- − base/server/share/webapps/pki/admin/console/config/savepkcs12panel.vm
- − base/server/share/webapps/pki/admin/console/config/securitydomainloginpanel.vm
- − base/server/share/webapps/pki/admin/console/config/securitydomainpanel.vm
- − base/server/share/webapps/pki/admin/console/config/sidemenu.vm
- − base/server/share/webapps/pki/admin/console/config/sizepanel.vm
- − base/server/share/webapps/pki/admin/console/config/tksinfopanel.vm
- − base/server/share/webapps/pki/admin/console/config/welcomepanel.vm
- − base/server/share/webapps/pki/admin/console/config/wizard.vm
- − base/server/share/webapps/pki/admin/console/config/xml.vm
- base/common/src/main/java/com/netscape/certsrv/base/SessionContext.java → base/server/src/main/java/com/netscape/certsrv/base/SessionContext.java
- + base/server/src/main/java/com/netscape/certsrv/base/WebAction.java
- base/common/src/main/java/com/netscape/certsrv/base/IAuthInfo.java → base/server/src/main/java/com/netscape/certsrv/dbs/DBPagedSearch.java
- base/server/src/main/java/com/netscape/certsrv/dbs/DBVirtualList.java
- base/server/src/main/java/com/netscape/certsrv/ldap/LdapConnFactory.java
- base/server/src/main/java/com/netscape/certsrv/logging/LogEventListener.java
- base/server/src/main/java/com/netscape/certsrv/logging/event/AccessSessionEstablishEvent.java
- base/server/src/main/java/com/netscape/certsrv/logging/event/AccessSessionTerminatedEvent.java
- base/server/src/main/java/com/netscape/certsrv/logging/event/ClientAccessSessionEstablishEvent.java
- base/server/src/main/java/com/netscape/certsrv/logging/event/ClientAccessSessionTerminatedEvent.java
- base/server/src/main/java/com/netscape/certsrv/ocsp/IOCSPService.java
- base/server/src/main/java/com/netscape/certsrv/publish/Mapper.java
- base/server/src/main/java/com/netscape/certsrv/publish/Publisher.java
- base/server/src/main/java/com/netscape/certsrv/request/IPolicy.java → base/server/src/main/java/com/netscape/certsrv/request/Policy.java
- base/server/src/main/java/com/netscape/certsrv/request/RequestListener.java
- base/server/src/main/java/com/netscape/certsrv/security/SigningUnit.java
- base/server/src/main/java/com/netscape/certsrv/usrgrp/CertUserLocator.java
- base/common/src/main/java/com/netscape/certsrv/util/HttpInput.java → base/server/src/main/java/com/netscape/certsrv/util/HttpInput.java
- base/server/src/main/java/com/netscape/cms/authentication/DirBasedAuthentication.java
- base/server/src/main/java/com/netscape/cms/authentication/PortalEnroll.java
- base/server/src/main/java/com/netscape/cms/authentication/TokenAuthentication.java
- base/server/src/main/java/com/netscape/cms/authentication/UidPwdDirAuthentication.java
- base/server/src/main/java/com/netscape/cms/authentication/UidPwdPinDirAuthentication.java
- base/server/src/main/java/com/netscape/cms/authentication/UserPwdDirAuthentication.java
- base/server/src/main/java/com/netscape/cms/authorization/AAclAuthz.java
- base/server/src/main/java/com/netscape/cms/authorization/ACL.java
- base/server/src/main/java/com/netscape/cms/authorization/DirAclAuthz.java
- base/server/src/main/java/com/netscape/cms/jobs/Job.java
- base/server/src/main/java/com/netscape/cms/jobs/RequestInQueueJob.java
- base/ca/src/main/java/com/netscape/cms/listeners/RequestInQListener.java → base/server/src/main/java/com/netscape/cms/listeners/RequestInQListener.java
- base/server/src/main/java/com/netscape/cms/logging/LogFile.java
- base/server/src/main/java/com/netscape/cms/password/PasswordChecker.java
- base/server/src/main/java/com/netscape/cms/realm/PKILDAPRealm.java
- base/server/src/main/java/com/netscape/cms/realm/PKIPostgreSQLRealm.java
- base/server/src/main/java/com/netscape/cms/realm/PKIRealm.java
- base/server/src/main/java/com/netscape/cms/realm/RealmCommon.java
- base/server/src/main/java/com/netscape/cms/selftests/SelfTest.java
- + base/server/src/main/java/com/netscape/cms/selftests/SelfTestPluginConfig.java
- base/server/src/main/java/com/netscape/cms/servlet/admin/AdminServlet.java
- base/server/src/main/java/com/netscape/cms/servlet/admin/CMSAdminServlet.java
- base/server/src/main/java/com/netscape/cms/servlet/admin/GroupMemberProcessor.java
- base/server/src/main/java/com/netscape/cms/servlet/admin/PolicyAdminServlet.java
- base/server/src/main/java/com/netscape/cms/servlet/admin/UsrGrpAdminServlet.java
- + base/server/src/main/java/com/netscape/cms/servlet/base/BulkIssuanceProxyServlet.java
- + base/server/src/main/java/com/netscape/cms/servlet/base/DoRevokeProxyServlet.java
- base/server/src/main/java/com/netscape/cms/servlet/base/PKIService.java
- + base/server/src/main/java/com/netscape/cms/servlet/base/ProfileSubmitProxyServlet.java
- base/server/src/main/java/com/netscape/cms/servlet/base/ProxyServlet.java
- base/server/src/main/java/com/netscape/cms/servlet/cert/RemoteAuthConfig.java
- base/server/src/main/java/com/netscape/cms/servlet/connector/CloneServlet.java
- base/server/src/main/java/com/netscape/cms/servlet/connector/ConnectorServlet.java
- + base/server/src/main/java/com/netscape/cms/servlet/csadmin/CATokenAuthenticate.java
- + base/server/src/main/java/com/netscape/cms/servlet/csadmin/CATokenAuthenticateAdmin.java
- − base/server/src/main/java/com/netscape/cms/servlet/csadmin/ConfigCertApprovalCallback.java
- − base/server/src/main/java/com/netscape/cms/servlet/csadmin/Configurator.java
- base/server/src/main/java/com/netscape/cms/servlet/csadmin/GetConfigEntries.java
- base/server/src/main/java/com/netscape/cms/servlet/csadmin/GetStatus.java
- + base/server/src/main/java/com/netscape/cms/servlet/csadmin/KRATokenAuthenticateAdmin.java
- base/server/src/main/java/com/netscape/cms/servlet/csadmin/LDAPConfigurator.java
- base/server/src/main/java/com/netscape/cms/servlet/csadmin/SecurityDomainProcessor.java
- base/server/src/main/java/com/netscape/cms/servlet/csadmin/TokenAuthenticate.java
- base/server/src/main/java/com/netscape/cms/servlet/csadmin/UpdateNumberRange.java
- base/server/src/main/java/com/netscape/cms/servlet/key/KeyRecordParser.java
- base/server/src/main/java/com/netscape/cms/servlet/ocsp/OCSPServlet.java
- base/server/src/main/java/com/netscape/cms/servlet/processors/CMCProcessor.java
- base/server/src/main/java/com/netscape/cms/servlet/processors/CRMFProcessor.java
- base/server/src/main/java/com/netscape/cms/servlet/processors/PKIProcessor.java
- base/server/src/main/java/com/netscape/cms/servlet/processors/Processor.java
- base/server/src/main/java/com/netscape/cms/servlet/request/SearchReqs.java
- base/server/src/main/java/com/netscape/cmscore/apps/CMS.java
- base/server/src/main/java/com/netscape/cmscore/apps/CMSEngine.java
- base/server/src/main/java/com/netscape/cmscore/apps/PKIWebListener.java → base/server/src/main/java/com/netscape/cmscore/apps/CMSWebListener.java
- base/server/src/main/java/com/netscape/cmscore/apps/DatabaseConfig.java
- base/server/src/main/java/com/netscape/cmscore/apps/EngineConfig.java
- base/server/src/main/java/com/netscape/cmscore/apps/ServerXml.java → base/server/src/main/java/com/netscape/cmscore/apps/ServerConfig.java
- − base/server/src/main/java/com/netscape/cmscore/apps/SubsystemInfo.java
- base/server/src/main/java/com/netscape/cmscore/apps/SubsystemConfig.java → base/server/src/main/java/com/netscape/cmscore/apps/SubsystemInfoConfig.java
- base/server/src/main/java/com/netscape/cmscore/apps/SubsystemsConfig.java
- base/server/src/main/java/com/netscape/cmscore/authentication/CertUserDBAuthentication.java
- base/server/src/main/java/com/netscape/cmscore/authentication/NullAuthentication.java
- base/server/src/main/java/com/netscape/cmscore/authentication/PasswdUserDBAuthentication.java
- base/server/src/main/java/com/netscape/cmscore/base/ArgBlock.java
- base/server/src/main/java/com/netscape/cmscore/base/ConfigStore.java
- base/server/src/main/java/com/netscape/cmscore/base/FileConfigStorage.java
- base/server/src/main/java/com/netscape/cmscore/base/LDAPConfigStorage.java
- base/server/src/main/java/com/netscape/cmscore/base/SimpleProperties.java
- base/server/src/main/java/com/netscape/cmscore/cert/CertUtils.java
- − base/server/src/main/java/com/netscape/cmscore/cert/ExtPrettyPrint.java
- − base/server/src/main/java/com/netscape/cmscore/cert/PrettyPrintFormat.java
- base/server/src/main/java/com/netscape/cmscore/connector/HttpConnFactory.java
- base/server/src/main/java/com/netscape/cmscore/connector/Resender.java
- base/server/src/main/java/com/netscape/cmscore/crmf/CRMFParser.java
- base/server/src/main/java/com/netscape/cmscore/dbs/CRLIssuingPointRecord.java
- base/server/src/main/java/com/netscape/cmscore/dbs/CertRecord.java
- base/server/src/main/java/com/netscape/cmscore/dbs/CertRecordList.java
- base/server/src/main/java/com/netscape/cmscore/dbs/DBRegistry.java
- base/server/src/main/java/com/netscape/cmscore/dbs/DBSSession.java
- base/server/src/main/java/com/netscape/cmscore/dbs/DBSearchResults.java
- base/server/src/main/java/com/netscape/cmscore/dbs/DBSubsystem.java
- base/server/src/main/java/com/netscape/cmscore/dbs/ElementProcessor.java
- base/server/src/main/java/com/netscape/cmscore/dbs/KeyRecord.java
- base/server/src/main/java/com/netscape/cmscore/dbs/LDAPDatabase.java
- + base/server/src/main/java/com/netscape/cmscore/dbs/LDAPPagedSearch.java
- base/server/src/main/java/com/netscape/cmscore/dbs/LDAPRegistry.java
- base/server/src/main/java/com/netscape/cmscore/dbs/LDAPSession.java
- base/server/src/main/java/com/netscape/cmscore/dbs/LDAPVirtualList.java
- base/server/src/main/java/com/netscape/cmscore/dbs/MetaInfoMapper.java
- base/server/src/main/java/com/netscape/cmscore/dbs/ObjectStreamMapper.java
- base/server/src/main/java/com/netscape/cmscore/request/RequestListByStatus.java → base/server/src/main/java/com/netscape/cmscore/dbs/RecordPagedList.java
- base/server/src/main/java/com/netscape/cmscore/dbs/ReplicaIDRepository.java
- base/server/src/main/java/com/netscape/cmscore/dbs/Repository.java
- base/server/src/main/java/com/netscape/cmscore/dbs/RepositoryRecord.java
- base/server/src/main/java/com/netscape/cmscore/dbs/RevocationInfoMapper.java
- base/server/src/main/java/com/netscape/cmscore/dbs/X500NameMapper.java
- base/server/src/main/java/com/netscape/cmscore/dbs/X509CertImplMapper.java
- base/server/src/main/java/com/netscape/cmscore/ldapconn/LDAPAuthenticationConfig.java
- base/server/src/main/java/com/netscape/cmscore/ldapconn/LDAPConfig.java
- base/server/src/main/java/com/netscape/cmscore/ldapconn/LDAPConnectionConfig.java
- base/server/src/main/java/com/netscape/cmscore/ldapconn/LdapAnonConnFactory.java
- base/server/src/main/java/com/netscape/cmscore/ldapconn/LdapAuthInfo.java
- base/server/src/main/java/com/netscape/cmscore/ldapconn/LdapBoundConnFactory.java
- base/server/src/main/java/com/netscape/cmscore/ldapconn/LdapBoundConnection.java
- base/server/src/main/java/com/netscape/cmscore/ldapconn/LdapConnInfo.java
- base/server/src/main/java/com/netscape/cmscore/ldapconn/PKISocketFactory.java
- base/server/src/main/java/com/netscape/cmscore/logging/Auditor.java
- base/server/src/main/java/com/netscape/cmscore/notification/EmailFormProcessor.java
- base/server/src/main/java/com/netscape/cmscore/notification/EmailResolverKeys.java
- base/server/src/main/java/com/netscape/cmscore/notification/EmailTemplate.java
- base/server/src/main/java/com/netscape/cmscore/request/ExtAttrDynMapper.java
- base/server/src/main/java/com/netscape/cmscore/request/RecoverThread.java
- base/server/src/main/java/com/netscape/cmscore/request/Request.java
- base/server/src/main/java/com/netscape/cmscore/request/RequestNotifier.java
- base/server/src/main/java/com/netscape/cmscore/request/RequestQueue.java
- base/server/src/main/java/com/netscape/cmscore/request/RequestRecord.java
- base/server/src/main/java/com/netscape/cmscore/request/RequestRepository.java
- base/server/src/main/java/com/netscape/cmscore/security/JssSubsystem.java
- base/server/src/main/java/com/netscape/cmscore/security/KeyCertUtil.java
- base/server/src/main/java/com/netscape/cmscore/session/LDAPSecurityDomainSessionTable.java
- base/server/src/main/java/com/netscape/cmscore/session/MemorySecurityDomainSessionTable.java
- base/server/src/main/java/com/netscape/cmscore/session/SessionTimer.java
- base/server/src/main/java/com/netscape/cmscore/systemd/SystemdNotifier.java
- base/server/src/main/java/com/netscape/cmscore/usrgrp/CertDNCertUserLocator.java
- base/server/src/main/java/com/netscape/cmscore/usrgrp/ExactMatchCertUserLocator.java
- base/server/src/main/java/com/netscape/cmscore/usrgrp/UGSubsystem.java
- base/server/src/main/java/com/netscape/cmscore/usrgrp/User.java
- base/server/src/main/java/com/netscape/cmscore/util/Debug.java
- base/server/src/main/java/org/dogtagpki/legacy/core/policy/GenericPolicyProcessor.java
- base/server/src/main/java/org/dogtagpki/legacy/core/policy/JavaScriptRequestProxy.java
- base/server/src/main/java/org/dogtagpki/legacy/core/policy/PolicyInstance.java
- base/server/src/main/java/org/dogtagpki/legacy/core/policy/PolicyPredicateParser.java
- base/server/src/main/java/org/dogtagpki/legacy/core/policy/PolicySet.java
- base/server/src/main/java/org/dogtagpki/legacy/core/policy/SimpleExpression.java
- base/server/src/main/java/org/dogtagpki/legacy/policy/IEnrollmentPolicy.java → base/server/src/main/java/org/dogtagpki/legacy/policy/EnrollmentPolicy.java
- − base/server/src/main/java/org/dogtagpki/legacy/policy/IPolicyRule.java
- − base/server/src/main/java/org/dogtagpki/legacy/policy/IPolicySet.java
- base/server/src/main/java/org/dogtagpki/legacy/policy/IPolicyProcessor.java → base/server/src/main/java/org/dogtagpki/legacy/policy/PolicyProcessor.java
- base/server/src/main/java/org/dogtagpki/legacy/policy/IRenewalPolicy.java → base/server/src/main/java/org/dogtagpki/legacy/policy/RenewalPolicy.java
- base/server/src/main/java/org/dogtagpki/legacy/policy/IRevocationPolicy.java → base/server/src/main/java/org/dogtagpki/legacy/policy/RevocationPolicy.java
- base/server/src/main/java/org/dogtagpki/legacy/server/policy/APolicyRule.java → base/server/src/main/java/org/dogtagpki/legacy/server/policy/PolicyRule.java
- base/server/src/main/java/org/dogtagpki/legacy/server/policy/constraints/ManualAuthentication.java
- base/server/src/main/java/org/dogtagpki/server/PKIClientSocketListener.java
- base/server/src/main/java/org/dogtagpki/server/PKIServerSocketListener.java
- base/server/src/main/java/org/dogtagpki/server/authentication/AuthManagerConfig.java
- base/server/src/main/java/org/dogtagpki/server/authentication/AuthManagersConfig.java
- base/server/src/main/java/org/dogtagpki/server/authentication/AuthenticationConfig.java
- + base/server/src/main/java/org/dogtagpki/server/authentication/RevocationCheckingConfig.java
- base/server/src/main/java/org/dogtagpki/server/authorization/AuthzManager.java
- base/server/src/main/java/org/dogtagpki/server/cli/PKIServerCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SDCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SDCreateCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SDSubsystemAddCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SDSubsystemCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SDSubsystemFindCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SDSubsystemRemoveCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SDTypeAddCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SDTypeCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemCLI.java → base/server/src/main/java/org/dogtagpki/server/cli/ServerCommandCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemACLAddCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemACLCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemACLDeleteCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemACLFindCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBAccessGrantCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBAccessRevokeCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBCreateCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBEmptyCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBIndexAddCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBIndexCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBIndexRebuildCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBInfoCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBInitCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBRemoveCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBReplicationAgreementAddCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBReplicationAgreementCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBReplicationAgreementInitCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBReplicationCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBReplicationEnableCLI.java
- − base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBReplicationSetupCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBUpgradeCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBVLVAddCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBVLVDeleteCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBVLVFindCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemDBVLVReindexCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemGroupAddCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemGroupCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemGroupFindCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemGroupMemberAddCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemGroupMemberFindCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemGroupMemberRemoveCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemIdGeneratorUpdateCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemRangeUpdateCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserAddCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserCertAddCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserCertCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserCertFindCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserCertRemoveCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserFindCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserModifyCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserRemoveCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserRoleAddCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserRoleCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserRoleFindCLI.java
- + base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserRoleRemoveCLI.java
- base/server/src/main/java/org/dogtagpki/server/cli/SubsystemUserShowCLI.java
- base/server/src/main/java/org/dogtagpki/server/connector/IRemoteRequest.java
- + base/server/src/main/java/org/dogtagpki/server/rest/base/AccountServletBase.java
- + base/server/src/main/java/org/dogtagpki/server/rest/base/AuditServletBase.java
- + base/server/src/main/java/org/dogtagpki/server/rest/base/GroupServletBase.java
- + base/server/src/main/java/org/dogtagpki/server/rest/base/JobServletBase.java
- + base/server/src/main/java/org/dogtagpki/server/rest/base/SecurityDomainServletBase.java
- + base/server/src/main/java/org/dogtagpki/server/rest/base/SelfTestServletBase.java
- + base/server/src/main/java/org/dogtagpki/server/rest/base/UserServletBase.java
- base/server/src/main/java/org/dogtagpki/server/rest/ACLInterceptor.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/ACLInterceptor.java
- base/server/src/main/java/org/dogtagpki/server/rest/AccountService.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/AccountService.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v1/ApiDeprecationFilter.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v1/ApiDisabledResource.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v1/ApiStatusHelper.java
- base/server/src/main/java/org/dogtagpki/server/rest/AuditService.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/AuditService.java
- base/server/src/main/java/org/dogtagpki/server/rest/AuthMethodInterceptor.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/AuthMethodInterceptor.java
- base/server/src/main/java/com/netscape/cms/servlet/request/CMSRequestDAO.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/CMSRequestDAO.java
- base/server/src/main/java/org/dogtagpki/server/rest/FeatureService.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/FeatureService.java
- base/server/src/main/java/org/dogtagpki/server/rest/GroupService.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/GroupService.java
- base/server/src/main/java/org/dogtagpki/server/rest/JobService.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/JobService.java
- base/server/src/main/java/org/dogtagpki/server/rest/MessageFormatInterceptor.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/MessageFormatInterceptor.java
- base/server/src/main/java/org/dogtagpki/server/rest/PKIExceptionMapper.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/PKIExceptionMapper.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v1/RESTMessageV1.java
- base/server/src/main/java/org/dogtagpki/server/rest/SecurityDomainService.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/SecurityDomainService.java
- base/server/src/main/java/org/dogtagpki/server/rest/SelfTestService.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/SelfTestService.java
- base/server/src/main/java/org/dogtagpki/server/rest/SessionContextInterceptor.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/SessionContextInterceptor.java
- base/server/src/main/java/org/dogtagpki/server/rest/UserService.java → base/server/src/main/java/org/dogtagpki/server/rest/v1/UserService.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/AccountServlet.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/AuditServlet.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/FeatureServlet.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/GroupServlet.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/JobServlet.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/PKIServlet.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/SecurityDomainServlet.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/SelfTestServlet.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/UserServlet.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/ACLFilter.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/AccountACL.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/AccountAuthMethod.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/AuditACL.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/AuditAuthMethod.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/AuthMethodFilter.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/GroupACL.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/GroupAuthMethod.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/SecurityDomainACL.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/SecurityDomainAuthMethod.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/SelfTestACL.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/SelfTestAuthMethod.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/UserACL.java
- + base/server/src/main/java/org/dogtagpki/server/rest/v2/filters/UserAuthMethod.java
- base/server/src/main/resources/LogMessages.properties
- base/server/src/main/resources/UserMessages.properties
- base/server/src/test/java/com/netscape/cmscore/authentication/AuthTokenTest.java
- base/server/src/test/java/com/netscape/cmscore/dbs/CertRecordListTest.java
- base/server/src/test/java/com/netscape/cmscore/dbs/DBRegistryTest.java
- base/server/src/test/java/com/netscape/cmscore/password/PlainPasswordFileTest.java
- base/server/src/test/java/com/netscape/cmscore/request/AgentApprovalsTest.java
- base/server/src/test/java/com/netscape/cmscore/request/ExtAttrDynMapperTest.java
- base/server/src/test/java/com/netscape/cmscore/request/ExtDataHashtableTest.java
- base/server/src/test/java/com/netscape/cmscore/request/RequestQueueTest.java
- base/server/src/test/java/com/netscape/cmscore/request/RequestRecordTest.java
- base/server/src/test/java/com/netscape/cmscore/request/RequestTest.java
- base/server/src/test/java/com/netscape/cmscore/test/CMSBaseTestCase.java → base/server/src/test/java/com/netscape/cmscore/test/CMSBaseTestHelper.java
- base/server/upgrade/10.0.1/02-CloningInterfaceChanges.py
- base/server/upgrade/10.0.1/03-AddRestServlet.py
- base/server/upgrade/10.0.99/04-FixLogFileOwnership.py
- base/server/upgrade/10.10.0/02-FixMissingCertAndRequestData.py
- base/server/upgrade/10.10.2/01-AddProfileCaAuditSigningCert.py
- base/server/upgrade/10.11.0/06-UpdateJavaHome.py
- base/server/upgrade/10.2.4/02-FixNuxwdogListenerClass.py
- base/server/upgrade/10.2.6/01-RemoveInaccessableURLsFromServerXML.py
- base/server/upgrade/10.7.0/01-UpdateAuditEvents.py
- base/server/upgrade/10.7.0/02-UpdateNetscapeSecurityClasses.py
- base/server/upgrade/10.7.1/01-RemoveResteasyPath.py
- base/server/upgrade/10.8.0/01-FixCommonFolder.py
- base/server/upgrade/10.8.0/03-FixDefaultTomcatFiles.py
- base/server/upgrade/10.8.0/04-RemoveUserDatabase.py
- base/server/upgrade/10.8.3/01-FixECAdminCertProfile.py
- base/server/upgrade/10.9.0/02-AddACMEServerCertProfile.py
- base/server/upgrade/10.9.0/03-DisableOpenJDKFIPS.py
- base/server/upgrade/10.9.0/04-AddMissingCertProfiles.py
- + base/server/upgrade/11.10.0/01-FixPerms.py
- + base/server/upgrade/11.10.0/02-AddAJPPacketSize.py
- base/server/upgrade/11.3.0/01-FixSSKDirUserCertProfileAuth.py
- base/server/upgrade/11.4.0/01-RelocateCMCAuth.py
- + base/server/upgrade/11.5.0/01-RemoveUnusedParams.py
- + base/server/upgrade/11.5.0/02-DropTomcatJSSDependency.py
- + base/server/upgrade/11.5.0/03-FixSignedAuditParams.py
- + base/server/upgrade/11.5.0/04-RemoveCertCSRfromConfig.py
- + base/server/upgrade/11.6.0/01-CleanUpSubsystemConfig.py
- + base/server/upgrade/11.6.0/02-AddSerialNumberUpdateJob.py
- + base/server/upgrade/11.6.0/03-ConfigurePasswordPolicyConstraints.py
- + base/server/upgrade/11.7.0/01-ConfigureOCSPByName.py
- + base/server/upgrade/11.7.0/02-EnableURLRewrite.py
- + base/server/upgrade/11.8.0/01-DisableJavaSecurityManager.py
- + base/server/upgrade/11.9.0/01-EnableEST.py
- + base/server/upgrade/11.9.0/02-EnableESTFullCMC.py
- + base/server/upgrade/11.9.0/03-UpdateConfJavaVersion.py
- + base/server/upgrade/11.9.0/04-UpdateMLDSAProfiles.py
- + base/server/upgrade/11.9.0/05-UpdateJDKFIPS.py
- + base/server/upgrade/11.9.0/06-UpdateConfigurationPermission.py
- base/tks/CMakeLists.txt
- + base/tks/bin/pki-tks-run
- base/tks/pom.xml
- base/tks/shared/conf/CS.cfg
- base/tks/shared/webapps/tks/WEB-INF/web.xml
- + base/tks/src/main/java/com/netscape/cms/servlet/admin/TKSACLAdminServlet.java
- + base/tks/src/main/java/com/netscape/cms/servlet/admin/TKSAuthAdminServlet.java
- base/tks/src/main/java/com/netscape/cms/servlet/admin/TKSCMSAdminServlet.java
- + base/tks/src/main/java/com/netscape/cms/servlet/admin/TKSJobsAdminServlet.java
- + base/tks/src/main/java/com/netscape/cms/servlet/admin/TKSLogAdminServlet.java
- + base/tks/src/main/java/com/netscape/cms/servlet/admin/TKSUsrGrpAdminServlet.java
- + base/tks/src/main/java/com/netscape/cms/servlet/base/TKSPortsServlet.java
- base/tks/src/main/java/com/netscape/cms/servlet/csadmin/ImportTransportCert.java
- + base/tks/src/main/java/com/netscape/cms/servlet/csadmin/TKSDownloadPKCS12.java
- + base/tks/src/main/java/com/netscape/cms/servlet/csadmin/TKSGetConfigEntries.java
- + base/tks/src/main/java/com/netscape/cms/servlet/csadmin/TKSGetStatus.java
- + base/tks/src/main/java/com/netscape/cms/servlet/csadmin/TKSMainPageServlet.java
- + base/tks/src/main/java/com/netscape/cms/servlet/csadmin/TKSRegisterUser.java
- base/tks/src/main/java/org/dogtagpki/server/tks/TKSEngineConfig.java
- base/tks/src/main/java/org/dogtagpki/server/tks/TKSWebListener.java
- base/tks/src/main/java/org/dogtagpki/server/tks/cli/TKSCLI.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/base/TPSConnectorProcessor.java
- base/tks/src/main/java/org/dogtagpki/server/tks/rest/TKSApplication.java → base/tks/src/main/java/org/dogtagpki/server/tks/rest/v1/TKSApplication.java
- base/tks/src/main/java/org/dogtagpki/server/tks/rest/TPSConnectorService.java → base/tks/src/main/java/org/dogtagpki/server/tks/rest/v1/TPSConnectorService.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/TKSAccountServlet.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/TKSAuditServlet.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/TKSGroupServlet.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/TKSJobServlet.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/TKSSelfTestServlet.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/TKSServlet.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/TKSUserServlet.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/TPSConnectorServlet.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/EmptyACL.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/EmptyAuthMethod.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TKSAccountACL.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TKSAccountAuthMethod.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TKSAuditACL.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TKSAuditAuthMethod.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TKSGroupACL.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TKSGroupAuthMethod.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TKSSelfTestACL.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TKSSelfTestAuthMethod.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TKSUserACL.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TKSUserAuthMethod.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TPSConnectorACL.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/rest/v2/filters/TPSConnectorAuthMethod.java
- base/tks/src/main/java/org/dogtagpki/server/tks/servlet/NistSP800_108KDF.java
- base/tks/src/main/java/org/dogtagpki/server/tks/servlet/SecureChannelProtocol.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/servlet/TKSCreateKeySetData.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/servlet/TKSEncryptData.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/servlet/TKSRandomData.java
- + base/tks/src/main/java/org/dogtagpki/server/tks/servlet/TKSSessionKey.java
- base/tks/src/main/java/org/dogtagpki/server/tks/servlet/TokenServlet.java
- + base/tks/tomcat-10.1/CMakeLists.txt
- + base/tks/tomcat-10.1/conf/Catalina/localhost/tks.xml
- + base/tomcat-10.1/CMakeLists.txt
- + base/tomcat-10.1/conf/Catalina/localhost/ROOT.xml
- + base/tomcat-10.1/conf/Catalina/localhost/pki.xml
- + base/tomcat-10.1/conf/Catalina/localhost/rewrite.config
- + base/tomcat-10.1/conf/catalina.properties
- + base/tomcat-10.1/pom.xml
- + base/tomcat-10.1/src/main/java/com/netscape/cms/tomcat/AbstractPKIAuthenticator.java
- + base/tomcat-10.1/src/main/java/com/netscape/cms/tomcat/ExternalAuthenticationValve.java
- base/tomcat/src/main/java/com/netscape/cms/tomcat/ExternalPrincipal.java → base/tomcat-10.1/src/main/java/com/netscape/cms/tomcat/ExternalPrincipal.java
- base/tomcat/src/main/java/com/netscape/cms/tomcat/PKIListener.java → base/tomcat-10.1/src/main/java/com/netscape/cms/tomcat/PKIListener.java
- + base/tomcat-10.1/src/main/java/com/netscape/cms/tomcat/ProxyRealm.java
- base/common/src/main/java/com/netscape/certsrv/notification/IEmailTemplate.java → base/tomcat-10.1/src/main/java/com/netscape/cms/tomcat/SSLAuthenticatorWithFallback.java
- + base/tomcat-10.1/src/main/resources/META-INF/MANIFEST.MF
- base/tomcat-9.0/CMakeLists.txt
- base/tomcat-9.0/conf/Catalina/localhost/rewrite.config
- base/tomcat-9.0/pom.xml
- base/tomcat/src/main/java/com/netscape/cms/tomcat/AbstractPKIAuthenticator.java → base/tomcat-9.0/src/main/java/com/netscape/cms/tomcat/AbstractPKIAuthenticator.java
- base/tomcat/src/main/java/com/netscape/cms/tomcat/ExternalAuthenticationValve.java → base/tomcat-9.0/src/main/java/com/netscape/cms/tomcat/ExternalAuthenticationValve.java
- + base/tomcat-9.0/src/main/java/com/netscape/cms/tomcat/ExternalPrincipal.java
- + base/tomcat-9.0/src/main/java/com/netscape/cms/tomcat/PKIListener.java
- base/tomcat-9.0/src/main/java/com/netscape/cms/tomcat/ProxyRealm.java
- base/tomcat-9.0/src/main/resources/META-INF/MANIFEST.MF
- + base/tomcat/CMakeLists.txt
- base/tomcat/pom.xml
- base/tomcat/src/main/java/com/netscape/cms/tomcat/NuxwdogPasswordStore.java
- + base/tomcat/src/main/resources/META-INF/MANIFEST.MF
- base/tools/CMakeLists.txt
- base/tools/bin/pki
- + base/tools/bin/revoker
- + base/tools/build-hsm-compat-verify.sh
- + base/tools/build-kratool.sh
- + base/tools/examples/certs/device.conf
- + base/tools/examples/cmc/testuser-cmc-revocation-request.cfg
- + base/tools/examples/cmc/testuser-cmc-revocation-submit.cfg
- + base/tools/hsm-compat-verify-pom.xml
- + base/tools/kratool-pom.xml
- + base/tools/pki-hsm-compat-verify.spec
- + base/tools/pki-kratool.spec
- base/tools/pom.xml
- base/tools/src/main/java/com/netscape/cmstools/AtoB.java
- base/tools/src/main/java/com/netscape/cmstools/CMCRequest.java
- base/tools/src/main/java/com/netscape/cmstools/CRMFPopClient.java
- + base/tools/src/main/java/com/netscape/cmstools/CryptoToolsUtil.java
- base/tools/src/main/java/com/netscape/cmstools/HttpClient.java
- base/tools/src/main/java/com/netscape/cmstools/KRATool.java
- base/tools/src/main/java/com/netscape/cmstools/OCSPClient.java
- base/tools/src/main/java/com/netscape/cmstools/PKCS10Client.java
- base/tools/src/main/java/com/netscape/cmstools/PKCS12Export.java
- base/tools/src/main/java/com/netscape/cmstools/acme/ACMEDisableCLI.java
- base/tools/src/main/java/com/netscape/cmstools/acme/ACMEEnableCLI.java
- base/tools/src/main/java/com/netscape/cmstools/acme/ACMEInfoCLI.java
- base/tools/src/main/java/com/netscape/cmstools/authority/AuthorityCLI.java
- base/tools/src/main/java/com/netscape/cmstools/authority/AuthorityCreateCLI.java
- base/tools/src/main/java/com/netscape/cmstools/authority/AuthorityDisableCLI.java
- base/tools/src/main/java/com/netscape/cmstools/authority/AuthorityEnableCLI.java
- base/tools/src/main/java/com/netscape/cmstools/authority/AuthorityFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/authority/AuthorityKeyExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/authority/AuthorityRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/authority/AuthorityShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACLI.java
- + base/tools/src/main/java/com/netscape/cmstools/ca/CACRLCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/ca/CACRLUpdateCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertHoldCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/ca/CACertIssueCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertReleaseHoldCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertRequestActionCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertRequestCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertRequestFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertRequestProfileFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertRequestProfileShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertRequestReviewCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertRequestShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertRequestSubmitCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertRevokeCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertSigningExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertSigningShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertStatusCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertSubsystemExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertSubsystemShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertTransportExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/CACertTransportShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ca/PublisherOCSPAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/cli/InfoCLI.java
- base/tools/src/main/java/com/netscape/cmstools/cli/MainCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/cli/PasswordCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/cli/PasswordGenerateCLI.java
- − base/tools/src/main/java/com/netscape/cmstools/cli/ProxyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/cli/SubsystemCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/cli/SubsystemCommandCLI.java
- base/tools/src/main/java/com/netscape/cmstools/client/ClientCertFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/client/ClientCertImportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/client/ClientCertModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/client/ClientCertRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/client/ClientCertRequestCLI.java
- base/tools/src/main/java/com/netscape/cmstools/client/ClientCertShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/client/ClientCertValidateCLI.java
- base/tools/src/main/java/com/netscape/cmstools/client/ClientInitCLI.java
- base/tools/src/main/java/com/netscape/cmstools/config/ConfigCLI.java
- base/tools/src/main/java/com/netscape/cmstools/config/ConfigExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/feature/FeatureCLI.java
- base/tools/src/main/java/com/netscape/cmstools/feature/FeatureFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/feature/FeatureShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/group/GroupAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/group/GroupCLI.java
- base/tools/src/main/java/com/netscape/cmstools/group/GroupFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/group/GroupMemberAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/group/GroupMemberCLI.java
- base/tools/src/main/java/com/netscape/cmstools/group/GroupMemberFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/group/GroupMemberRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/group/GroupMemberShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/group/GroupModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/group/GroupRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/group/GroupShowCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/hsmCompatVerifyClnt.java
- + base/tools/src/main/java/com/netscape/cmstools/hsmCompatVerifyServ.java
- base/tools/src/main/java/com/netscape/cmstools/job/JobCLI.java
- base/tools/src/main/java/com/netscape/cmstools/job/JobFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/job/JobShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/job/JobStartCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRACLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRACertCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRACertTransportExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRACertTransportShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyArchiveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyGenerateCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyRecoverCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyRequestFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyRequestReviewCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyRequestShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyRetrieveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyTemplateFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/kra/KRAKeyTemplateShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/logging/ActivityCLI.java
- base/tools/src/main/java/com/netscape/cmstools/logging/ActivityFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/logging/ActivityShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/logging/AuditCLI.java
- base/tools/src/main/java/com/netscape/cmstools/logging/AuditFileFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/logging/AuditFileRetrieveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/logging/AuditModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/logging/AuditShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSCertCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSCertExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSCertFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSCertImportCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/nss/NSSCertInfo.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSCertIssueCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/nss/NSSCertModifyCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/nss/NSSCertRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSCertRequestCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSCertShowCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/nss/NSSCertVerifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSCreateCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSKeyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSKeyCreateCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSKeyExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSKeyFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSKeyImportCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/nss/NSSKeyRemoveCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/nss/NSSKeyShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/nss/NSSRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/ocsp/OCSPCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/ocsp/OCSPCertCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/ocsp/OCSPCertVerifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs11/PKCS11CertExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs11/PKCS11KeyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs12/PKCS12CertAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs12/PKCS12CertExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs12/PKCS12CertFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs12/PKCS12CertImportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs12/PKCS12CertModCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs12/PKCS12CertRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs12/PKCS12ExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs12/PKCS12ImportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs12/PKCS12KeyFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs12/PKCS12KeyRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs7/PKCS7CertExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs7/PKCS7CertFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs7/PKCS7CertImportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs7/PKCS7ExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/pkcs7/PKCS7ImportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/profile/ProfileAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/profile/ProfileCLI.java
- base/tools/src/main/java/com/netscape/cmstools/profile/ProfileDisableCLI.java
- base/tools/src/main/java/com/netscape/cmstools/profile/ProfileEditCLI.java
- base/tools/src/main/java/com/netscape/cmstools/profile/ProfileEnableCLI.java
- base/tools/src/main/java/com/netscape/cmstools/profile/ProfileFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/profile/ProfileModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/profile/ProfileRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/profile/ProfileShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/range/RangeRequestCLI.java
- base/tools/src/main/java/com/netscape/cmstools/selftests/SelfTestCLI.java
- base/tools/src/main/java/com/netscape/cmstools/selftests/SelfTestFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/selftests/SelfTestRunCLI.java
- base/tools/src/main/java/com/netscape/cmstools/selftests/SelfTestShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/KRAConnectorAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/KRAConnectorCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/KRAConnectorRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/KRAConnectorShowCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/system/SDCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/system/SDJoinCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/system/SDLeaveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/SecurityDomainCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/SecurityDomainHostAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/SecurityDomainHostCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/SecurityDomainHostFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/SecurityDomainHostRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/SecurityDomainHostShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/SecurityDomainJoinCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/SecurityDomainLeaveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/system/SecurityDomainShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TKSCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TKSCertTransportImportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TKSKeyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TKSKeyCreateCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TKSKeyExportCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TKSKeyRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TKSKeyReplaceCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TKSKeyShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TPSConnectorAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TPSConnectorCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TPSConnectorFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TPSConnectorModCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TPSConnectorRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tks/TPSConnectorShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/TPSCLI.java
- + base/tools/src/main/java/com/netscape/cmstools/tps/TPSClientCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/authenticator/AuthenticatorAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/authenticator/AuthenticatorCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/authenticator/AuthenticatorFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/authenticator/AuthenticatorModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/authenticator/AuthenticatorRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/authenticator/AuthenticatorShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/cert/TPSCertCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/cert/TPSCertFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/cert/TPSCertShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/config/ConfigModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/config/ConfigShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/connector/ConnectorAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/connector/ConnectorCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/connector/ConnectorFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/connector/ConnectorModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/connector/ConnectorRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/connector/ConnectorShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileMappingAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileMappingCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileMappingFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileMappingModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileMappingRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileMappingShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/profile/ProfileShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/token/TokenAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/token/TokenCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/token/TokenFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/token/TokenModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/token/TokenRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/tps/token/TokenShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserCertAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserCertCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserCertFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserCertRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserCertShowCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserMembershipAddCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserMembershipCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserMembershipFindCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserMembershipRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserModifyCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserRemoveCLI.java
- base/tools/src/main/java/com/netscape/cmstools/user/UserShowCLI.java
- base/tools/src/main/native/bulkissuance/CMakeLists.txt
- − base/tools/src/main/native/p12tool/CMakeLists.txt
- − base/tools/src/main/native/p12tool/basicutil.c
- − base/tools/src/main/native/p12tool/basicutil.h
- − base/tools/src/main/native/p12tool/berparse.c
- − base/tools/src/main/native/p12tool/derprint.c
- − base/tools/src/main/native/p12tool/ffs.c
- − base/tools/src/main/native/p12tool/moreoids.c
- − base/tools/src/main/native/p12tool/p12tool.c
- − base/tools/src/main/native/p12tool/p12tool.h
- − base/tools/src/main/native/p12tool/pk11table.c
- − base/tools/src/main/native/p12tool/pk11table.h
- − base/tools/src/main/native/p12tool/pppolicy.c
- − base/tools/src/main/native/p12tool/secpwd.c
- − base/tools/src/main/native/p12tool/secutil.c
- − base/tools/src/main/native/p12tool/secutil.h
- − base/tools/src/main/native/p7tool/CMakeLists.txt
- − base/tools/src/main/native/p7tool/NSPRerrs.h
- − base/tools/src/main/native/p7tool/SECerrs.h
- − base/tools/src/main/native/p7tool/SSLerrs.h
- − base/tools/src/main/native/p7tool/p7tool.c
- − base/tools/src/main/native/p7tool/pppolicy.c
- − base/tools/src/main/native/p7tool/secerror.c
- − base/tools/src/main/native/p7tool/secerror.h
- − base/tools/src/main/native/p7tool/secpwd.c
- − base/tools/src/main/native/p7tool/secutil.c
- − base/tools/src/main/native/p7tool/secutil.h
- base/tools/src/main/native/pistool/include/pistool.h
- base/tools/src/main/native/pistool/include/secutil.h
- base/tools/src/main/native/pistool/src/CMakeLists.txt
- base/tools/src/main/native/pistool/src/delete.c
- base/tools/src/main/native/pistool/src/file.c
- base/tools/src/main/native/pistool/src/help.c
- base/tools/src/main/native/pistool/src/key.c
- base/tools/src/main/native/pistool/src/list.c
- base/tools/src/main/native/pistool/src/pistool.c
- base/tools/src/main/native/pistool/src/pppolicy.c
- base/tools/src/main/native/pistool/src/secerror.c
- base/tools/src/main/native/pistool/src/secpwd.c
- base/tools/src/main/native/pistool/src/secutil.c
- base/tools/src/main/native/pistool/src/util.c
- − base/tools/src/main/native/revoker/CMakeLists.txt
- − base/tools/src/main/native/revoker/getopt.c
- − base/tools/src/main/native/revoker/revoker.c
- base/tools/src/main/native/setpin/CMakeLists.txt
- base/tools/src/main/native/setpin/b64.c
- base/tools/src/main/native/setpin/options.c
- base/tools/src/main/native/setpin/options.h
- base/tools/src/main/native/setpin/setpin.c
- base/tools/src/main/native/setpin/setpin_options.c
- base/tools/src/main/native/setpin/setpin_options.h
- − base/tools/src/main/native/sslget/CMakeLists.txt
- − base/tools/src/main/native/sslget/getopt.c
- − base/tools/src/main/native/sslget/sslget.c
- base/tools/src/main/native/tkstool/CMakeLists.txt
- base/tools/src/main/native/tkstool/delete.c
- base/tools/src/main/native/tkstool/file.c
- base/tools/src/main/native/tkstool/help.c
- base/tools/src/main/native/tkstool/key.c
- base/tools/src/main/native/tkstool/list.c
- base/tools/src/main/native/tkstool/pppolicy.c
- base/tools/src/main/native/tkstool/secerror.c
- base/tools/src/main/native/tkstool/secpwd.c
- base/tools/src/main/native/tkstool/secutil.c
- base/tools/src/main/native/tkstool/tkstool.c
- base/tools/src/main/native/tkstool/util.c
- base/tools/src/main/native/tpsclient/CMakeLists.txt
- base/tools/src/main/native/tpsclient/src/CMakeLists.txt
- base/tools/src/main/native/tpsclient/tools/raclient/RA_Client.h → base/tools/src/main/native/tpsclient/src/include/main/RA_Client.h
- base/tools/src/main/native/tpsclient/tools/raclient/RA_Conn.h → base/tools/src/main/native/tpsclient/src/include/main/RA_Conn.h
- base/tools/src/main/native/tpsclient/tools/raclient/RA_Token.h → base/tools/src/main/native/tpsclient/src/include/main/RA_Token.h
- + base/tools/src/main/native/tpsclient/src/main/RA_Client.cpp
- base/tools/src/main/native/tpsclient/tools/raclient/RA_Conn.cpp → base/tools/src/main/native/tpsclient/src/main/RA_Conn.cpp
- base/tools/src/main/native/tpsclient/tools/raclient/RA_Token.cpp → base/tools/src/main/native/tpsclient/src/main/RA_Token.cpp
- + base/tools/src/main/native/tpsclient/src/main/TPSClientCLI.cpp
- base/tools/src/main/native/tpsclient/src/main/Util.cpp
- base/tools/src/main/native/tpsclient/tools/raclient/CMakeLists.txt
- base/tools/src/main/native/tpsclient/tools/raclient/RA_Client.cpp → base/tools/src/main/native/tpsclient/tools/raclient/tpsclient.cpp
- base/tools/src/main/shell/PKICertImport.bash
- + base/tools/src/main/shell/hsmCompatVerifyClnt.bash
- + base/tools/src/main/shell/hsmCompatVerifyServ.bash
- base/tools/src/test/resources/certs/ca_sub_signing.conf
- base/tools/src/test/shell/test_PKICertImport.bash
- base/tools/templates/CMakeLists.txt
- base/tools/templates/pki_java_command_wrapper.in
- base/tools/templates/pretty_print_cert_command_wrapper.in
- base/tools/templates/pretty_print_crl_command_wrapper.in
- base/tps/CMakeLists.txt
- base/tps/auth/ds/example.ldif
- base/tps/bin/pki-tps-enroll
- base/tps/bin/pki-tps-format
- + base/tps/bin/pki-tps-pin-reset
- + base/tps/bin/pki-tps-run
- base/tps/pom.xml
- + base/tps/shared/applets/1.5.64260792.ijc
- + base/tps/shared/applets/1.5.65cbf5a6.ijc
- base/tps/shared/conf/CS.cfg
- base/tps/shared/webapps/tps/WEB-INF/web.xml
- + base/tps/src/main/java/com/netscape/cms/servlet/admin/TPSLogAdminServlet.java
- + base/tps/src/main/java/com/netscape/cms/servlet/admin/TPSUsrGrpAdminServlet.java
- + base/tps/src/main/java/com/netscape/cms/servlet/csadmin/TPSGetConfigEntries.java
- + base/tps/src/main/java/com/netscape/cms/servlet/csadmin/TPSGetStatus.java
- base/tps/src/main/java/org/dogtagpki/server/tps/TPSAccountService.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/TPSAccountServletBase.java
- base/tps/src/main/java/org/dogtagpki/server/tps/TPSEngine.java
- base/tps/src/main/java/org/dogtagpki/server/tps/TPSPhoneHome.java
- base/tps/src/main/java/org/dogtagpki/server/tps/TPSServlet.java
- base/tps/src/main/java/org/dogtagpki/server/tps/TPSSession.java
- base/tps/src/main/java/org/dogtagpki/server/tps/TPSWebListener.java
- base/tps/src/main/java/org/dogtagpki/server/tps/TokenDB.java
- base/tps/src/main/java/org/dogtagpki/server/tps/channel/SecureChannel.java
- base/tps/src/main/java/org/dogtagpki/server/tps/channel/SecureChannelProtocol.java
- base/tps/src/main/java/org/dogtagpki/server/tps/cli/TPSCLI.java
- base/tps/src/main/java/org/dogtagpki/server/tps/cms/CARemoteRequestHandler.java
- base/tps/src/main/java/org/dogtagpki/server/tps/cms/ConnectionManager.java
- base/tps/src/main/java/org/dogtagpki/server/tps/cms/KRARemoteRequestHandler.java
- base/tps/src/main/java/org/dogtagpki/server/tps/cms/TKSComputeSessionKeyResponse.java
- base/tps/src/main/java/org/dogtagpki/server/tps/cms/TKSRemoteRequestHandler.java
- base/tps/src/main/java/org/dogtagpki/server/tps/mapping/BaseMappingResolver.java
- base/tps/src/main/java/org/dogtagpki/server/tps/mapping/FilterMappingResolver.java
- base/tps/src/main/java/org/dogtagpki/server/tps/processor/CertEnrollInfo.java
- base/tps/src/main/java/org/dogtagpki/server/tps/processor/TPSEnrollProcessor.java
- base/tps/src/main/java/org/dogtagpki/server/tps/processor/TPSProcessor.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/base/AuthenticatorProcessor.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/base/ConnectorProcessor.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/base/ProfileMappingProcessor.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/base/ProfileProcessor.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/base/TPSCertProcessor.java
- base/tps/src/main/java/org/dogtagpki/server/tps/rest/ActivityService.java → base/tps/src/main/java/org/dogtagpki/server/tps/rest/v1/ActivityService.java
- base/tps/src/main/java/org/dogtagpki/server/tps/rest/AuthenticatorService.java → base/tps/src/main/java/org/dogtagpki/server/tps/rest/v1/AuthenticatorService.java
- base/tps/src/main/java/org/dogtagpki/server/tps/rest/ConnectorService.java → base/tps/src/main/java/org/dogtagpki/server/tps/rest/v1/ConnectorService.java
- base/tps/src/main/java/org/dogtagpki/server/tps/rest/ProfileMappingService.java → base/tps/src/main/java/org/dogtagpki/server/tps/rest/v1/ProfileMappingService.java
- base/tps/src/main/java/org/dogtagpki/server/tps/rest/TPSApplication.java → base/tps/src/main/java/org/dogtagpki/server/tps/rest/v1/TPSApplication.java
- base/tps/src/main/java/org/dogtagpki/server/tps/rest/TPSCertService.java → base/tps/src/main/java/org/dogtagpki/server/tps/rest/v1/TPSCertService.java
- base/tps/src/main/java/org/dogtagpki/server/tps/rest/TPSProfileService.java → base/tps/src/main/java/org/dogtagpki/server/tps/rest/v1/TPSProfileService.java
- base/tps/src/main/java/org/dogtagpki/server/tps/rest/TokenService.java → base/tps/src/main/java/org/dogtagpki/server/tps/rest/v1/TokenService.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/ActivityServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/AuthenticatorServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/ConfigServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/ConnectorServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/ProfileMappingServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/TPSAccountServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/TPSAuditServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/TPSCertServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/TPSGroupServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/TPSJobServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/TPSProfileServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/TPSSelfTestServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/TPSServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/TPSUserServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/TokenServlet.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/AuthenticatorACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/AuthenticatorAuthMethod.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/ConfigACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/ConfigAuthMethod.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/ConnectorACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/ConnectorAuthMethod.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/EmptyACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/EmptyAuthMethod.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/ProfileMappingACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/ProfileMappingAuthMethod.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSAccountACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSAccountAuthMethod.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSAuditACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSAuditAuthMethod.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSGroupACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSGroupAuthMethod.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSProfileACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSProfileAuthMethod.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSSelfTestACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSSelfTestAuthMethod.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSUserACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TPSUserAuthMethod.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TokenACL.java
- + base/tps/src/main/java/org/dogtagpki/server/tps/rest/v2/filters/TokenAuthMethod.java
- + base/tps/tomcat-10.1/CMakeLists.txt
- + base/tps/tomcat-10.1/conf/Catalina/localhost/tps.xml
- build.sh
- cmake/Modules/DefineCompilerFlags.cmake
- cmake/Modules/DefinePythonSitePackages.cmake
- − cmake/Modules/FindMozLDAP.cmake
- cmake/Modules/JUnit.cmake
- cmake/Modules/Java.cmake
- cmake/config.h.in
- + docs/README/README-doc-convention.adoc
- + docs/README/include-cfg.list
- + docs/README/include-install.list
- + docs/README/others.list
- docs/admin/Nuxwdog.md
- − docs/admin/Offline_System_Certificate_Renewal.md
- docs/admin/PKI_Health_Check_Tool.md
- docs/admin/Session_Timeout.md
- docs/admin/TPS_Token_Lifecycle.md
- docs/installation/acme/Configuring_ACME_Database.md → docs/admin/acme/Configuring-ACME-Database.adoc
- docs/installation/acme/Configuring_ACME_Issuer.md → docs/admin/acme/Configuring-ACME-Issuer.adoc
- docs/installation/acme/Configuring-ACME-Metadata.adoc → docs/admin/acme/Configuring-ACME-Metadata.adoc
- docs/installation/acme/Configuring_ACME_Realm.md → docs/admin/acme/Configuring-ACME-Realm.adoc
- + docs/admin/acme/Configuring-ACME-Responder.adoc
- docs/installation/acme/Configuring-ACME-with-DS-Database.adoc → docs/admin/acme/Configuring-ACME-with-DS-Database.adoc
- docs/installation/acme/Configuring-ACME-with-DS-Realm.adoc → docs/admin/acme/Configuring-ACME-with-DS-Realm.adoc
- docs/installation/acme/Configuring-ACME-with-InMemory-Database.adoc → docs/admin/acme/Configuring-ACME-with-InMemory-Database.adoc
- docs/installation/acme/Configuring-ACME-with-InMemory-Realm.adoc → docs/admin/acme/Configuring-ACME-with-InMemory-Realm.adoc
- docs/installation/acme/Configuring-ACME-with-NSS-Issuer.adoc → docs/admin/acme/Configuring-ACME-with-NSS-Issuer.adoc
- docs/installation/acme/Configuring-ACME-with-OpenLDAP-Database.adoc → docs/admin/acme/Configuring-ACME-with-OpenLDAP-Database.adoc
- docs/installation/acme/Configuring-ACME-with-PKI-Issuer.adoc → docs/admin/acme/Configuring-ACME-with-PKI-Issuer.adoc
- docs/installation/acme/Configuring-ACME-with-PostgreSQL-Database.adoc → docs/admin/acme/Configuring-ACME-with-PostgreSQL-Database.adoc
- docs/installation/acme/Configuring-ACME-with-PostgreSQL-Realm.adoc → docs/admin/acme/Configuring-ACME-with-PostgreSQL-Realm.adoc
- docs/admin/ServerSideKeygen.adoc → docs/admin/configuration-for-server-side-keygen.adoc
- + docs/admin/est/Managing-DS-Realm.adoc
- + docs/admin/est/Managing-PostgreSQL-Realm.adoc
- docs/admin/images/Server-SideKeygenEnroll_approval.png → docs/admin/images/server-side_keygen_enroll_approval.png
- docs/admin/images/Server-SideKeygenEnroll_manual.png → docs/admin/images/server-side_keygen_enroll_manual.png
- docs/admin/images/Server-SideKeygen_LDAP_auth.png → docs/admin/images/server-side_keygen_ldap_auth.png
- + docs/admin/offline-system-certificate-renewal.adoc
- docs/admin/server/Configuring-HTTPS-Connector-with-JKS-File.adoc
- docs/admin/server/Configuring-HTTPS-Connector-with-NSS-Database.adoc
- docs/admin/server/Configuring-HTTPS-Connector-with-PEM-Files.adoc
- docs/admin/server/Configuring-HTTPS-Connector-with-PKCS12-File.adoc
- docs/changes/v11.1.0/Server-Changes.adoc
- + docs/changes/v11.10.0/API-Changes.adoc
- + docs/changes/v11.10.0/Packaging-Changes.adoc
- + docs/changes/v11.10.0/Server-Changes.adoc
- + docs/changes/v11.10.0/Tools-Changes.adoc
- + docs/changes/v11.5.0/Packaging-Changes.adoc
- + docs/changes/v11.5.0/Server-Changes.adoc
- + docs/changes/v11.5.0/Tools-Changes.adoc
- + docs/changes/v11.6.0/API-Changes.adoc
- + docs/changes/v11.6.0/Packaging-Changes.adoc
- + docs/changes/v11.6.0/Server-Changes.adoc
- + docs/changes/v11.6.0/Tools-Changes.adoc
- + docs/changes/v11.7.0/Server-Changes.adoc
- + docs/changes/v11.7.0/Tools-Changes.adoc
- + docs/changes/v11.9.0/Server-Changes.adoc
- + docs/changes/v11.9.0/Tools-Changes.adoc
- + docs/design/Cert_Enrollment_Profiles/Bootstrap-Profiles.adoc
- + docs/design/Cert_Enrollment_Profiles/CA-Certificate-Profiles.adoc
- + docs/design/Cert_Enrollment_Profiles/Certificate-Profiles.adoc
- + docs/dogtagpki-docs-convention-readme.adoc
- − docs/installation/Installing_ACME_Responder.md
- − docs/installation/Installing_Basic_PKI_Server.md
- − docs/installation/Installing_CA.md
- − docs/installation/Installing_CA_Clone.md
- − docs/installation/Installing_CA_Clone_with_HSM.md
- − docs/installation/Installing_CA_with_Custom_CA_Signing_Key.md
- − docs/installation/Installing_CA_with_ECC.md
- − docs/installation/Installing_CA_with_Existing_Keys_in_HSM.md
- − docs/installation/Installing_CA_with_Existing_Keys_in_Internal_Token.md
- − docs/installation/Installing_CA_with_External_CA_Signing_Certificate.md
- − docs/installation/Installing_CA_with_HSM.md
- − docs/installation/Installing_CA_with_Secure_Database_Connection.md
- − docs/installation/Installing_KRA.md
- − docs/installation/Installing_KRA_Clone.md
- − docs/installation/Installing_KRA_Clone_with_HSM.md
- − docs/installation/Installing_KRA_with_Custom_Keys.md
- − docs/installation/Installing_KRA_with_ECC.md
- − docs/installation/Installing_KRA_with_External_Certificates.md
- − docs/installation/Installing_KRA_with_HSM.md
- − docs/installation/Installing_KRA_with_Secure_Database_Connection.md
- − docs/installation/Installing_OCSP.md
- − docs/installation/Installing_OCSP_Clone.md
- − docs/installation/Installing_OCSP_Clone_with_HSM.md
- − docs/installation/Installing_OCSP_with_Custom_Keys.md
- − docs/installation/Installing_OCSP_with_ECC.md
- − docs/installation/Installing_OCSP_with_External_Certificates.md
- − docs/installation/Installing_OCSP_with_HSM.md
- − docs/installation/Installing_OCSP_with_Secure_Database_Connection.md
- − docs/installation/Installing_PKI_Server_with_Custom_NSS_Databases.md
- − docs/installation/Installing_TKS.md
- − docs/installation/Installing_TKS_with_ECC.md
- − docs/installation/Installing_TKS_with_HSM.md
- − docs/installation/Installing_TKS_with_Secure_Database_Connection.md
- − docs/installation/Installing_TPS.md
- − docs/installation/Installing_TPS_Clone.md
- − docs/installation/Installing_TPS_with_HSM.md
- − docs/installation/Installing_TPS_with_Secure_Database_Connection.md
- − docs/installation/acme/Deploying_ACME_on_OpenShift.md
- − docs/installation/acme/Deploying_ACME_on_Podman.md
- − docs/installation/acme/Installing_ACME_Responder.md
- − docs/installation/acme/Installing_PKI_ACME_Responder.md
- + docs/installation/acme/installing-acme-responder-using-pki-server-acme-cli.adoc
- + docs/installation/acme/installing-acme-responder-using-pkispawn.adoc
- + docs/installation/acme/installing-acme-responder.adoc
- docs/installation/ca/Installing_CA_Clone_with_HSM.md → docs/installation/ca/installing-ca-clone-with-hsm.adoc
- + docs/installation/ca/installing-ca-clone-with-ldaps-connection.adoc
- docs/installation/ca/Installing_CA_Clone_with_Secure_Database_Connection.md → docs/installation/ca/installing-ca-clone-with-ldaps-using-bootstrap-ds-certs.adoc
- docs/installation/ca/Installing_CA_Clone.md → docs/installation/ca/installing-ca-clone.adoc
- docs/installation/ca/Installing_CA_with_Custom_CA_Signing_Key.md → docs/installation/ca/installing-ca-with-custom-ca-signing-key.adoc
- docs/installation/ca/Installing_CA_with_ECC.md → docs/installation/ca/installing-ca-with-ecc.adoc
- docs/installation/ca/Installing_CA_with_Existing_Keys_in_HSM.md → docs/installation/ca/installing-ca-with-existing-keys-in-hsm.adoc
- docs/installation/ca/Installing_CA_with_Existing_Keys_in_Internal_Token.md → docs/installation/ca/installing-ca-with-existing-keys-in-internal-token.adoc
- docs/installation/ca/Installing_CA_with_External_CA_Signing_Certificate.md → docs/installation/ca/installing-ca-with-external-ca-signing-certificate.adoc
- docs/installation/ca/Installing_CA_with_HSM.md → docs/installation/ca/installing-ca-with-hsm.adoc
- docs/installation/ca/Installing_CA_with_Secure_Database_Connection.md → docs/installation/ca/installing-ca-with-ldaps-connection.adoc
- docs/installation/ca/Installing_CA.md → docs/installation/ca/installing-ca-with-pqc.adoc
- docs/installation/ca/Installing-CA-with-Random-Serial-Numbers-v3.adoc → docs/installation/ca/installing-ca-with-random-serial-numbers-v3.adoc
- docs/installation/ca/Installing-CA-with-RSA-PSS.adoc → docs/installation/ca/installing-ca-with-rsa-pss.adoc
- + docs/installation/ca/installing-ca.adoc
- docs/installation/ca/Installing_Subordinate_CA.md → docs/installation/ca/installing-subordinate-ca.adoc
- − docs/installation/est/Installing_EST.md
- + docs/installation/est/configure-est-realm-db.adoc
- + docs/installation/est/configuring-est-fullcmc-example.adoc
- + docs/installation/est/installing-est-pki-server.adoc
- + docs/installation/est/installing-est-pkispawn.adoc
- + docs/installation/est/installing-est.adoc
- docs/installation/kra/Installing_KRA_Clone_with_HSM.md → docs/installation/kra/installing-kra-clone-with-hsm.adoc
- docs/installation/kra/Installing_KRA_Clone.md → docs/installation/kra/installing-kra-clone.adoc
- docs/installation/kra/Installing_KRA_on_Separate_Instance.md → docs/installation/kra/installing-kra-on-separate-instance.adoc
- docs/installation/kra/Installing_KRA_with_Custom_Keys.md → docs/installation/kra/installing-kra-with-custom-keys.adoc
- docs/installation/kra/Installing_KRA_with_ECC.md → docs/installation/kra/installing-kra-with-ecc.adoc
- docs/installation/kra/Installing_KRA_with_External_Certificates.md → docs/installation/kra/installing-kra-with-external-certificates.adoc
- docs/installation/kra/Installing_KRA_with_HSM.md → docs/installation/kra/installing-kra-with-hsm.adoc
- docs/installation/kra/Installing_KRA_with_Secure_Database_Connection.md → docs/installation/kra/installing-kra-with-ldaps-connection.adoc
- + docs/installation/kra/installing-kra-with-pqc.adoc
- docs/installation/kra/Installing-KRA-with-Random-Serial-Numbers-v3.adoc → docs/installation/kra/installing-kra-with-random-serial-numbers-v3.adoc
- docs/installation/kra/Installing_KRA.md → docs/installation/kra/installing-kra.adoc
- docs/installation/kra/Installing_Standalone_KRA.adoc → docs/installation/kra/installing-standalone-kra.adoc
- docs/installation/ocsp/Installing_OCSP_Clone_with_HSM.md → docs/installation/ocsp/installing-ocsp-clone-with-hsm.adoc
- docs/installation/ocsp/Installing_OCSP_Clone.md → docs/installation/ocsp/installing-ocsp-clone.adoc
- docs/installation/ocsp/Installing_OCSP_with_Custom_Keys.md → docs/installation/ocsp/installing-ocsp-with-custom-keys.adoc
- docs/installation/ocsp/Installing_OCSP_with_ECC.md → docs/installation/ocsp/installing-ocsp-with-ecc.adoc
- docs/installation/ocsp/Installing_OCSP_with_External_Certificates.md → docs/installation/ocsp/installing-ocsp-with-external-certificates.adoc
- docs/installation/ocsp/Installing_OCSP_with_HSM.md → docs/installation/ocsp/installing-ocsp-with-hsm.adoc
- docs/installation/ocsp/Installing_OCSP_with_Secure_Database_Connection.md → docs/installation/ocsp/installing-ocsp-with-ldaps-connection.adoc
- docs/installation/ocsp/Installing_OCSP.md → docs/installation/ocsp/installing-ocsp.adoc
- docs/installation/ocsp/Installing_Standalone_OCSP.adoc → docs/installation/ocsp/installing-standalone-ocsp.adoc
- + docs/installation/others/creating-ds-instance.adoc
- + docs/installation/others/enabling-ssl-connection-in-ds-with-bootstrap-cert.adoc
- + docs/installation/others/fqdn-configuration.adoc
- + docs/installation/others/getting-ds-cert-issued-by-actual-ca.adoc
- + docs/installation/others/installation-prerequisites.adoc
- + docs/installation/others/installing-ds-packages.adoc
- docs/installation/podman/Deploying_PKI_ACME_Responder_on_Podman.md
- − docs/installation/server/FQDN_Configuration.adoc
- − docs/installation/server/Installing_Basic_PKI_Server.md
- + docs/installation/server/installing-basic-pki-server.adoc
- docs/installation/server/Installing_PKI_Server_with_Custom_NSS_Databases.md → docs/installation/server/installing-pki-server-with-custom-nss-databases.adoc
- docs/installation/tks/Installing_TKS_Clone.md → docs/installation/tks/installing-tks-clone.adoc
- docs/installation/tks/Installing_TKS_with_ECC.md → docs/installation/tks/installing-tks-with-ecc.adoc
- docs/installation/tks/Installing_TKS_with_HSM.md → docs/installation/tks/installing-tks-with-hsm.adoc
- docs/installation/tks/Installing_TKS_with_Secure_Database_Connection.md → docs/installation/tks/installing-tks-with-ldaps-connection.adoc
- docs/installation/tks/Installing_TKS.md → docs/installation/tks/installing-tks.adoc
- docs/installation/tps/Installing_TPS_Clone.md → docs/installation/tps/installing-tps-clone.adoc
- docs/installation/tps/Installing_TPS_with_HSM.md → docs/installation/tps/installing-tps-with-hsm.adoc
- docs/installation/tps/Installing_TPS_with_Secure_Database_Connection.md → docs/installation/tps/installing-tps-with-ldaps-connection.adoc
- docs/installation/tps/Installing_TPS.md → docs/installation/tps/installing-tps.adoc
- docs/manuals/man1/AuditVerify.1.md
- docs/manuals/man1/PKCS10Client.1.md
- docs/manuals/man1/pki-user.1.md
- docs/manuals/man5/pki-server-logging.5.md
- docs/manuals/man5/pki_default.cfg.5.md
- docs/manuals/man8/pki-server-nuxwdog.8.md
- docs/manuals/man8/pkidestroy.8.md
- docs/manuals/man8/pkispawn.8.md
- docs/upgrade/README.adoc
- + docs/upgrade/v11.9/Upgrading-PKI-Database.adoc
- + docs/upgrade/v11.9/upgrading-est-configuration.adoc
- + docs/user/tools/Generating-CSR/Generating-Certificate-Request-with-CRMFPopClient.adoc
- + docs/user/tools/Generating-CSR/Generating-Certificate-Request-with-NSS.adoc
- + docs/user/tools/Generating-CSR/Generating-Certificate-Request-with-OpenSSL.adoc
- + docs/user/tools/Generating-CSR/Generating-Certificate-Request-with-PKCS10Client.adoc
- + docs/user/tools/Generating-CSR/Generating-Certificate-Request-with-PKI-NSS.adoc
- + docs/user/tools/Generating-CSR/Generating-Certificate-Request.adoc
- + docs/user/tools/Getting-KRA-Transport-Certificate.adoc
- + docs/user/tools/PKI-CLI.adoc
- + docs/user/tools/PKI-Client-CLI.adoc
- + docs/user/tools/PKI-NSS-CLI.adoc
- + docs/user/tools/PKI-NSS-Certificate-CLI.adoc
- + docs/user/tools/PKI-NSS-Key-CLI.adoc
- + docs/user/tools/Submitting-Certificate-Request-with-Key-Archival.adoc
- + docs/user/tools/Submitting-Certificate-Request.adoc
- docs/user/tools/Using-PKI-CA-Certificate-CLI.adoc
- pki.spec
- pom.xml
- tests/README.adoc
- + tests/ansible/ansible.cfg
- + tests/ansible/est/README.md
- + tests/ansible/est/defaults/main.yml
- + tests/ansible/est/handlers/main.yml
- + tests/ansible/est/meta/main.yml
- + tests/ansible/est/tasks/main.yml
- + tests/ansible/est/tests/inventory
- + tests/ansible/est/tests/test.yml
- + tests/ansible/est/vars/main.yml
- + tests/ansible/ocsp/README.md
- + tests/ansible/ocsp/defaults/main.yml
- + tests/ansible/ocsp/handlers/main.yml
- + tests/ansible/ocsp/meta/main.yml
- + tests/ansible/ocsp/tasks/certificate_self_validation_with_crl.yml
- + tests/ansible/ocsp/tasks/main.yml
- + tests/ansible/ocsp/tests/inventory
- + tests/ansible/ocsp/tests/test.yml
- + tests/ansible/ocsp/vars/main.yml
- + tests/ansible/pki-playbook.yml
- + tests/ansible/requirements.txt
- tests/bin/ds-artifacts-save.sh
- tests/bin/ds-container-certs-import.sh → tests/bin/ds-certs-import.sh
- − tests/bin/ds-container-create.sh
- − tests/bin/ds-container-remove.sh
- − tests/bin/ds-container-start.sh
- − tests/bin/ds-container-stop.sh
- tests/bin/ds-create.sh
- tests/bin/ds-remove.sh
- + tests/bin/ds-start.sh
- + tests/bin/ds-stop.sh
- − tests/bin/init-workflow.sh
- tests/bin/ipa-artifacts-save.sh
- tests/bin/ipa-test.sh
- tests/bin/pki-artifacts-save.sh
- + tests/bin/pki-info.py
- tests/bin/pki-lint → tests/bin/python-flake8.sh
- + tests/bin/python-lint.sh
- − tests/bin/rpminspect.sh
- tests/bin/runner-init.sh
- + tests/bin/test-init.sh
- tests/bin/test-sslserver-cert-ext.sh
- tests/bin/test-sslserver-csr-ext.sh
- tests/ca/bin/ca-agent-cert-create.sh
- tests/ca/bin/ca-agent-cert-revoke.sh
- tests/ca/bin/ca-agent-cert-unrevoke.sh
- tests/ca/bin/ca-agent-create.sh
- + tests/ca/bin/ca-cert-next-range.sh
- + tests/ca/bin/ca-cert-range-config.sh
- + tests/ca/bin/ca-cert-range-objects.sh
- + tests/ca/bin/ca-replica-next-range.sh
- + tests/ca/bin/ca-replica-range-config.sh
- + tests/ca/bin/ca-replica-range-objects.sh
- + tests/ca/bin/ca-request-next-range.sh
- + tests/ca/bin/ca-request-range-config.sh
- + tests/ca/bin/ca-request-range-objects.sh
- + tests/ca/bin/pki-ca-cert-find.py
- + tests/ca/bin/pki-ca-cert-request-find.py
- + tests/ca/bin/pki-ca-cert-request-template-find.py
- + tests/ca/bin/pki-ca-cert-request-template-show.py
- + tests/ca/bin/pki-ca-user-find.py
- + tests/ca/bin/sslserver-create.sh
- tests/ca/bin/test-ca-auditor-cert.sh
- tests/ca/bin/test-ca-auditor-create.sh
- tests/ca/bin/test-ca-auditor-logs.sh
- tests/ca/bin/test-ca-certs.sh
- tests/ca/bin/test-ca-signing-cert-ext.sh
- tests/ca/bin/test-ca-signing-cert.sh
- tests/ca/bin/test-ca-signing-csr-ext.sh
- + tests/ca/bin/test-ms-subca-signing-cert-ext.sh
- tests/ca/bin/test-subca-signing-cert-ext.sh
- tests/ca/bin/test-subca-signing-csr-ext.sh
- tests/ca/bin/test-subsystem-cert.sh
- tests/dogtag/acceptance/install-tests/ca-installer.sh
- tests/dogtag/dev_java_tests/run_junit_tests.sh
- − tests/dogtag/dev_java_tests/src/BeakerTestSuite.java
- − tests/dogtag/dev_java_tests/src/com/netscape/beakertests/CATestJunit.java
- − tests/dogtag/dev_java_tests/src/com/netscape/beakertests/PKIJUnitTest.java
- − tests/dogtag/dev_java_tests/src/com/netscape/beakertests/PKITestSuite.java
- − tests/dogtag/dev_java_tests/src/com/netscape/beakertests/SampleTest1.java
- tests/dogtag/pytest-ansible/installation/roles/Test_Execution/tasks/configure_shared.yml
- tests/dogtag/pytest-ansible/pki/testlib/common/utils.py
- tests/dogtag/pytest-ansible/pytest/banner/test_banner_cli.py
- tests/dogtag/pytest-ansible/requirements.txt
- tests/dogtag/shared/env.sh
- tests/dogtag/shared/java/argparser/ArgParser.java
- tests/dogtag/shared/java/common/ComCrypto.java
- tests/dogtag/shared/java/http/HTTPClient.java
- + tests/kra/bin/kra-replica-next-range.sh
- + tests/kra/bin/kra-replica-range-config.sh
- + tests/kra/bin/kra-replica-range-objects.sh
- + tests/kra/bin/pki-kra-key-archive.py
- + tests/kra/bin/pki-kra-key-find.py
- + tests/kra/bin/pki-kra-key-mod.py
- + tests/kra/bin/pki-kra-key-request-find.py
- + tests/kra/bin/pki-kra-key-retrieve.py
- + tests/kra/bin/pki-kra-user-find.py
- tests/kra/bin/test-cert-key-archival.sh
- tests/pki-rpminspect.yaml
- tests/pylintrc
- tests/tox.ini
- themes/dogtag/CMakeLists.txt
- themes/dogtag/common-ui/CMakeLists.txt
- − themes/dogtag/common-ui/shared/esc/demo/logo.jpg
- − themes/dogtag/common-ui/shared/esc/demo/style.css
- − themes/dogtag/common-ui/shared/esc/home/logo.jpg
- − themes/dogtag/common-ui/shared/esc/home/style.css
- − themes/dogtag/common-ui/shared/esc/images/BannerBackground.gif
- − themes/dogtag/common-ui/shared/esc/images/ContinueButton.gif
- − themes/dogtag/common-ui/shared/esc/images/NetKey-Small.gif
- − themes/dogtag/common-ui/shared/esc/images/NetKeyInsert.gif
- − themes/dogtag/common-ui/shared/esc/images/NetKeyLogo.gif
- − themes/dogtag/common-ui/shared/esc/images/NetKeyPair.gif
- − themes/dogtag/common-ui/shared/esc/images/NetKeyProgress.gif
- − themes/dogtag/common-ui/shared/esc/images/NetKeyQuestionMark.gif
- − themes/dogtag/common-ui/shared/esc/images/PadLock.gif
- − themes/dogtag/common-ui/shared/esc/images/PurchaseButton.gif
- − themes/dogtag/common-ui/shared/esc/images/ReactivateButton.gif
- − themes/dogtag/common-ui/shared/esc/images/ReleaseButton.gif
- − themes/dogtag/common-ui/shared/esc/images/SecureButton.gif
- − themes/dogtag/common-ui/shared/esc/images/SuspendButton.gif
- − themes/dogtag/common-ui/shared/esc/images/TryAgainButton.gif
- − themes/dogtag/common-ui/shared/esc/images/bg.jpg
- − themes/dogtag/common-ui/shared/esc/images/logo.gif
- − themes/dogtag/common-ui/shared/esc/so/images/indicator.gif
- − themes/dogtag/common-ui/shared/esc/so/images/logo.gif
- − themes/dogtag/common-ui/shared/esc/so/logo.jpg
- − themes/dogtag/common-ui/shared/esc/so/style.css
- − themes/dogtag/common-ui/shared/esc/sow/css/style.css
- − themes/dogtag/common-ui/shared/esc/sow/images/indicator.gif
- − themes/dogtag/common-ui/shared/esc/sow/images/logo.gif
- − themes/dogtag/common-ui/shared/esc/sow/logo.jpg
- − themes/dogtag/common-ui/shared/esc/sow/style.css
- − themes/dogtag/common-ui/shared/esc/style.css
- − themes/dogtag/common-ui/shared/fonts/fontawesome-webfont.woff
- themes/dogtag/console-ui/src/CMakeLists.txt
- tools/update-jquery.sh
- tools/update-patternfly.sh
- update_version.sh
The diff was not included because it is too large.
View it on GitLab: https://salsa.debian.org/freeipa-team/dogtag-pki/-/compare/0982e23079279131794ecbb67475c4a8bd18cc6b...da07c70dec3ac4fe4917409f978f2ae2a06c3c2b
--
View it on GitLab: https://salsa.debian.org/freeipa-team/dogtag-pki/-/compare/0982e23079279131794ecbb67475c4a8bd18cc6b...da07c70dec3ac4fe4917409f978f2ae2a06c3c2b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/pkg-freeipa-devel/attachments/20260927/9ffc5536/attachment-0001.htm>
More information about the Pkg-freeipa-devel
mailing list