From 70d9a179cdd8d975b44e1815c249e20d9f91097f Mon Sep 17 00:00:00 2001
From: Valery Kharseko <vharseko@3a-systems.ru>
Date: Wed, 16 Sep 2026 08:10:15 +0000
Subject: [PATCH] [#912] Provision the ads-truststore from an existing key store at setup time (#984)

---
 opendj-server-legacy/src/main/java/org/opends/server/tools/ConfigureDS.java |   41 +++++++++++++++++++++++++++++++++++++++++
 1 files changed, 41 insertions(+), 0 deletions(-)

diff --git a/opendj-server-legacy/src/main/java/org/opends/server/tools/ConfigureDS.java b/opendj-server-legacy/src/main/java/org/opends/server/tools/ConfigureDS.java
index 771574a..02efe2c 100644
--- a/opendj-server-legacy/src/main/java/org/opends/server/tools/ConfigureDS.java
+++ b/opendj-server-legacy/src/main/java/org/opends/server/tools/ConfigureDS.java
@@ -267,6 +267,7 @@
   private StringArgument keyManagerProviderDN;
   private StringArgument trustManagerProviderDN;
   private StringArgument certNickNames;
+  private StringArgument adsCertNickNames;
   private StringArgument keyManagerPath;
   private StringArgument serverRoot;
   private StringArgument backendType;
@@ -324,6 +325,7 @@
       updateStartTLS();
       updateKeyManager();
       updateTrustManager();
+      updateCryptoManagerCertNickname();
       updateRootUser(rootDN, rootPW);
       addFQDNDigestMD5();
       updateCryptoCipher();
@@ -440,6 +442,12 @@
                       .multiValued()
                       .valuePlaceholder(INFO_NICKNAME_PLACEHOLDER.get())
                       .buildAndAddToParser(argParser);
+      adsCertNickNames =
+              StringArgument.builder("adsCertNickName")
+                      .description(INFO_CONFIGDS_DESCRIPTION_ADS_CERTNICKNAME.get())
+                      .multiValued()
+                      .valuePlaceholder(INFO_NICKNAME_PLACEHOLDER.get())
+                      .buildAndAddToParser(argParser);
       baseDNString =
               StringArgument.builder(OPTION_LONG_BASEDN)
                       .shortIdentifier(OPTION_SHORT_BASEDN)
@@ -1159,6 +1167,39 @@
   }
 
   /**
+   * Sets the certificate nicknames the crypto manager presents for server to server
+   * communication, that is on the replication port.  The property replaces the value the
+   * template configuration holds, {@code ads-certificate}, which is the self-signed key
+   * pair the trust store backend generates: with a key pair of its own provisioned into
+   * the trust store, the server presents that one instead.
+   * <p>
+   * The value is written to the configuration rather than set with dsconfig once the
+   * server runs because the crypto manager reads the property once, when it is created at
+   * startup, and replication caches the value when a replication server or a replicated
+   * domain is created.
+   */
+  private void updateCryptoManagerCertNickname() throws ConfigureDSException
+  {
+    if (!adsCertNickNames.isPresent())
+    {
+      return;
+    }
+    final List<String> attrValues = adsCertNickNames.getValues();
+    try
+    {
+      updateConfigEntryWithAttribute(
+          DN_CRYPTO_MANAGER,
+          ATTR_SSL_CERT_NICKNAME,
+          CoreSchema.getDirectoryStringSyntax(),
+          attrValues.toArray(new Object[attrValues.size()]));
+    }
+    catch (final Exception e)
+    {
+      throw new ConfigureDSException(e, ERR_CONFIGDS_CANNOT_UPDATE_CRYPTO_MANAGER_CERT_NICKNAME.get(e));
+    }
+  }
+
+  /**
    * Check that the cipher specified is supported. This is intended to fix
    * issues with JVM that do not support the default cipher (see issue 3075 for
    * instance).

--
Gitblit v1.10.0