From f589cc1e267d6d7b67a6463b4495b7a9c982669f Mon Sep 17 00:00:00 2001 From: Matthew Harmsen Date: Sat, 28 Jul 2012 18:59:30 -0700 Subject: PKI Deployment Scriptlets * TRAC Ticket #263 - Dogtag 10: Fix 'pkidestroy' problem of sporadically "not" removing "/etc/sysconfig/{pki_instance_id}" . . . * TRAC Ticket #264 - Dogtag 10: Enable various other subsystems for configuration . . . * TRAC Ticket #261 - Dogtag 10: Revisit command-line options of 'pkispawn' and 'pkidestroy' . . . * TRAC Ticket #268 - Dogtag 10: Create a parameter for optional restart of configured PKI instance . . . * TRAC Ticket #270 - Dogtag 10: Add missing parameters to 'pkideployment.cfg' . . . * TRAC Ticket #265 - Dogtag 10: Provide configurable options for PKI client information . . . * TRAC Ticket #275 - Dogtag 10: Add debug information (comments) to Tomcat 7 "logging.properties" * TRAC Ticket #276 - Dogtag 10: Relocate all 'pin' data to the 'sensitive' dictionary * TRAC Ticket #277 - Dogtag 10: Create an 'archive' for 'manifest' and 'pkideployment.cfg' files * TRAC Ticket #278 - Dogtag 10: Fix Miscellaneous PKI Deployment Scriptlet Issues . . . --- base/deploy/config/pkideployment.cfg | 28 +++++++++++++++++++++------- 1 file changed, 21 insertions(+), 7 deletions(-) (limited to 'base/deploy/config') diff --git a/base/deploy/config/pkideployment.cfg b/base/deploy/config/pkideployment.cfg index d0acd7f33..ae02bb450 100644 --- a/base/deploy/config/pkideployment.cfg +++ b/base/deploy/config/pkideployment.cfg @@ -10,10 +10,12 @@ [Sensitive] pki_admin_password= pki_backup_password= +pki_client_database_password= pki_client_pkcs12_password= pki_clone_pkcs12_password= pki_ds_password= pki_security_domain_password= +pki_token_password= ############################################################################### ## 'Common' Data: ## ## ## @@ -42,8 +44,10 @@ pki_audit_signing_nickname= pki_audit_signing_signing_algorithm=SHA256withRSA pki_audit_signing_subject_dn= pki_audit_signing_token= -pki_backup_file= pki_backup_keys=False +pki_client_database_dir= +pki_client_database_purge=True +pki_client_dir= pki_ds_base_dn= pki_ds_bind_dn=cn=Directory Manager pki_ds_database= @@ -53,6 +57,7 @@ pki_ds_ldaps_port=636 pki_ds_remove_data=True pki_ds_secure_connection=False pki_group=pkiuser +pki_restart_configured_instance=True pki_security_domain_hostname= pki_security_domain_https_port=8443 pki_security_domain_name= @@ -69,6 +74,7 @@ pki_subsystem_key_type=rsa pki_subsystem_nickname= pki_subsystem_subject_dn= pki_subsystem_token= +pki_token_name=internal pki_user=pkiuser ############################################################################### ## 'Apache' Data: ## @@ -99,12 +105,16 @@ pki_https_port=443 [Tomcat] pki_ajp_port=8009 pki_clone=False +pki_clone_pkcs12_path= +pki_clone_replication_security=None +pki_clone_uri= pki_enable_java_debugger=False +pki_enable_proxy=False pki_http_port=8080 pki_https_port=8443 pki_instance_name=pki-tomcat -pki_proxy_http_port= -pki_proxy_https_port= +pki_proxy_http_port=80 +pki_proxy_https_port=443 pki_security_manager=false pki_tomcat_server_port=8005 ############################################################################### @@ -132,6 +142,10 @@ pki_ca_signing_signing_algorithm=SHA256withRSA pki_ca_signing_subject_dn= pki_ca_signing_token= pki_external=False +pki_external_ca_cert_chain_path= +pki_external_ca_cert_path= +pki_external_csr_path= +pki_external_step_two=False pki_ocsp_signing_key_algorithm=SHA256withRSA pki_ocsp_signing_key_size=2048 pki_ocsp_signing_key_type=rsa @@ -142,7 +156,7 @@ pki_ocsp_signing_token= pki_subordinate=False pki_subsystem=CA pki_subsystem_name= -pki_war_name=ca.war +pki_war_file=ca.war ############################################################################### ## 'KRA' Data: ## ## ## @@ -167,7 +181,7 @@ pki_transport_nickname= pki_transport_signing_algorithm=SHA256withRSA pki_transport_subject_dn= pki_transport_token= -pki_war_name=kra.war +pki_war_file=kra.war ############################################################################### ## 'OCSP' Data: ## ## ## @@ -185,7 +199,7 @@ pki_ocsp_signing_subject_dn= pki_ocsp_signing_token= pki_subsystem=OCSP pki_subsystem_name= -pki_war_name=ocsp.war +pki_war_file=ocsp.war ############################################################################### ## 'RA' Data: ## ## ## @@ -205,7 +219,7 @@ pki_subsystem_name= [TKS] pki_subsystem=TKS pki_subsystem_name= -pki_war_name=tks.war +pki_war_file=tks.war ############################################################################### ## 'TPS' Data: ## ## ## -- cgit