History log of /forgerock/openidm-v4/openidm-zip/src/main/resources/security/keystore.jceks
Revision Date Author Comments Expand
7c64421614d420f1951773af3ce6a6111cef84b2 09-Feb-2014 Jake Feasel <jake.feasel@forgerock.com>

Default to empty keystore so the certificates will be generated on system start. Also changing default permissions on security/ files to be readable/writable only by the owner.

b8ea699d32da429d5f174d37f0ae4c2dbe968713 17-Oct-2013 Chad Kienle <chad.kienle@forgerock.com>

[OPENIDM-1469][CR-2341] Removed default private and secret keys from keystore. They are generated on first startup.

dd291c383b4490ed77e47d65b4c52595d915f802 07-Oct-2013 Chad Kienle <chad.kienle@forgerock.com>

Added new security enhancements for auto-generating keys and sharing keystore across cluster.

/forgerock/openidm-v4/openidm-core/src/main/java/org/forgerock/openidm/managed/ManagedObjectProperty.java /forgerock/openidm-v4/openidm-crypto/src/main/java/org/forgerock/openidm/crypto/factory/CryptoServiceFactory.java /forgerock/openidm-v4/openidm-crypto/src/main/java/org/forgerock/openidm/crypto/factory/CryptoUpdateService.java /forgerock/openidm-v4/openidm-crypto/src/main/java/org/forgerock/openidm/crypto/impl/Activator.java /forgerock/openidm-v4/openidm-crypto/src/main/java/org/forgerock/openidm/crypto/impl/CryptoServiceImpl.java /forgerock/openidm-v4/openidm-crypto/src/main/java/org/forgerock/openidm/crypto/impl/UpdatableKeyStoreSelector.java /forgerock/openidm-v4/openidm-jetty-fragment/pom.xml /forgerock/openidm-v4/openidm-jetty-fragment/src/main/java/org/forgerock/openidm/jetty/Config.java /forgerock/openidm-v4/openidm-repo-jdbc/src/main/java/org/forgerock/openidm/repo/jdbc/impl/metadata/ConfigMeta.java /forgerock/openidm-v4/openidm-repo-orientdb/src/main/java/org/forgerock/openidm/repo/orientdb/impl/DBHelper.java /forgerock/openidm-v4/openidm-security/src/main/java/org/forgerock/openidm/security/KeyStoreHandler.java /forgerock/openidm-v4/openidm-security/src/main/java/org/forgerock/openidm/security/SecurityManager.java /forgerock/openidm-v4/openidm-security/src/main/java/org/forgerock/openidm/security/impl/CertificateResourceProvider.java /forgerock/openidm-v4/openidm-security/src/main/java/org/forgerock/openidm/security/impl/EntryResourceProvider.java /forgerock/openidm-v4/openidm-security/src/main/java/org/forgerock/openidm/security/impl/JcaKeyStoreHandler.java /forgerock/openidm-v4/openidm-security/src/main/java/org/forgerock/openidm/security/impl/KeystoreResourceProvider.java /forgerock/openidm-v4/openidm-security/src/main/java/org/forgerock/openidm/security/impl/PrivateKeyResourceProvider.java /forgerock/openidm-v4/openidm-security/src/main/java/org/forgerock/openidm/security/impl/SecurityResourceProvider.java /forgerock/openidm-v4/openidm-util/src/main/java/org/forgerock/openidm/cluster/ClusterUtils.java /forgerock/openidm-v4/openidm-zip/src/main/resources/conf/boot/boot.properties /forgerock/openidm-v4/openidm-zip/src/main/resources/conf/repo.orientdb.json /forgerock/openidm-v4/openidm-zip/src/main/resources/db/scripts/mysql/openidm.sql keystore.jceks
93f72edb164ef872eab6e4d482baa186a0dd6c62 27-Sep-2011 Andi Egloff <andi.egloff@forgerock.com>

New bootstrap file; bootstraps the keystore and replaces crypto.json. Support for configuration encryption

/forgerock/openidm-v4/openidm-config/pom.xml /forgerock/openidm-v4/openidm-config/src/main/java/org/forgerock/openidm/config/crypto/ConfigCrypto.java /forgerock/openidm-v4/openidm-config/src/main/java/org/forgerock/openidm/config/installer/JSONConfigInstaller.java /forgerock/openidm-v4/openidm-config/src/main/java/org/forgerock/openidm/config/installer/JSONPrettyPrint.java /forgerock/openidm-v4/openidm-config/src/main/java/org/forgerock/openidm/config/installer/PrettyIndenter.java /forgerock/openidm-v4/openidm-config/src/main/java/org/forgerock/openidm/config/manage/ConfigObjectService.java /forgerock/openidm-v4/openidm-config/src/main/java/org/forgerock/openidm/config/persistence/ConfigBootstrapHelper.java /forgerock/openidm-v4/openidm-crypto/pom.xml /forgerock/openidm-v4/openidm-crypto/src/main/java/org/forgerock/openidm/crypto/impl/Activator.java /forgerock/openidm-v4/openidm-crypto/src/main/java/org/forgerock/openidm/crypto/impl/CryptoServiceImpl.java /forgerock/openidm-v4/openidm-functional-tests/src/it/resources/conf/orientdb-test/audit.json /forgerock/openidm-v4/openidm-functional-tests/src/it/resources/conf/orientdb-test/repo.orientdb.json /forgerock/openidm-v4/openidm-repo-jdbc/src/main/java/org/forgerock/openidm/repo/jdbc/impl/Activator.java /forgerock/openidm-v4/openidm-repo-orientdb/src/main/java/org/forgerock/openidm/repo/orientdb/impl/Activator.java /forgerock/openidm-v4/openidm-system/src/main/java/org/forgerock/openidm/core/IdentityServer.java /forgerock/openidm-v4/openidm-system/src/main/java/org/forgerock/openidm/core/ServerConstants.java /forgerock/openidm-v4/openidm-util/src/main/java/org/forgerock/openidm/config/EnhancedConfig.java /forgerock/openidm-v4/openidm-util/src/main/java/org/forgerock/openidm/config/InternalErrorException.java /forgerock/openidm-v4/openidm-util/src/main/java/org/forgerock/openidm/config/JSONEnhancedConfig.java /forgerock/openidm-v4/openidm-util/src/main/java/org/forgerock/openidm/crypto/CryptoService.java /forgerock/openidm-v4/openidm-zip/src/main/assembly/zip.xml /forgerock/openidm-v4/openidm-zip/src/main/resources/conf/boot/boot.properties /forgerock/openidm-v4/openidm-zip/src/main/resources/conf/config.properties keystore.jceks