-
Notifications
You must be signed in to change notification settings - Fork 139
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
The SerialNumberUpdateJob has been added to update the ranges for sequential serial numbers, similar to SerialNumberUpdateTask. The job can be scheduled to run automatically at specific times, or can be run immediately by calling pki ca-job-start, whereas the task only supports a fixed interval. An upgrade script has been added to add the default config params for SerialNumberUpdateJob into existing instances. In the future it might be possible to replace SerialNumberUpdateTask with SerialNumberUpdateJob automatically. https://github.com/dogtagpki/pki/wiki/Configuring-SerialNumberUpdateJob
- Loading branch information
Showing
3 changed files
with
85 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
46 changes: 46 additions & 0 deletions
46
base/ca/src/main/java/org/dogtagpki/server/ca/job/SerialNumberUpdateJob.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,46 @@ | ||
// | ||
// Copyright Red Hat, Inc. | ||
// | ||
// SPDX-License-Identifier: GPL-2.0-or-later | ||
// | ||
package org.dogtagpki.server.ca.job; | ||
|
||
import java.util.Calendar; | ||
import java.util.Date; | ||
|
||
import org.dogtagpki.server.ca.CAEngine; | ||
|
||
import com.netscape.certsrv.base.IExtendedPluginInfo; | ||
import com.netscape.cms.jobs.Job; | ||
|
||
public class SerialNumberUpdateJob extends Job implements IExtendedPluginInfo { | ||
|
||
public static org.slf4j.Logger logger = org.slf4j.LoggerFactory.getLogger(SerialNumberUpdateJob.class); | ||
|
||
public SerialNumberUpdateJob() { | ||
} | ||
|
||
@Override | ||
public String[] getConfigParams() { | ||
return null; | ||
} | ||
|
||
@Override | ||
public String[] getExtendedPluginInfo() { | ||
return null; | ||
} | ||
|
||
@Override | ||
public void run() { | ||
Calendar calendar = Calendar.getInstance(); | ||
Date time = calendar.getTime(); | ||
logger.info("SerialNumberUpdateJob: Running " + mId + " job at " + time); | ||
|
||
try { | ||
CAEngine engine = (CAEngine) super.engine; | ||
engine.updateSerialNumbers(); | ||
} catch (Exception e) { | ||
logger.warn("SerialNumberUpdateJob: " + e.getMessage(), e); | ||
} | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,36 @@ | ||
# | ||
# Copyright Red Hat, Inc. | ||
# | ||
# SPDX-License-Identifier: GPL-2.0-or-later | ||
# | ||
import pki.server.upgrade | ||
|
||
|
||
class AddSerialNumberUpdateJob(pki.server.upgrade.PKIServerUpgradeScriptlet): | ||
|
||
def __init__(self): | ||
super().__init__() | ||
self.message = 'Add SerialNumberUpdateJob' | ||
|
||
def upgrade_subsystem(self, instance, subsystem): | ||
|
||
if subsystem.name != 'ca': | ||
return | ||
|
||
self.backup(subsystem.cs_conf) | ||
|
||
class_name = subsystem.config.get('jobsScheduler.impl.SerialNumberUpdateJob.class') | ||
if class_name is None: | ||
subsystem.config['jobsScheduler.impl.SerialNumberUpdateJob.class'] = \ | ||
'org.dogtagpki.server.ca.job.SerialNumberUpdateJob' | ||
|
||
enabled = subsystem.config.get('jobsScheduler.job.serialNumberUpdate.enabled') | ||
if enabled is None: | ||
subsystem.config['jobsScheduler.job.serialNumberUpdate.enabled'] = 'false' | ||
|
||
plugin_name = subsystem.config.get('jobsScheduler.job.serialNumberUpdate.pluginName') | ||
if plugin_name is None: | ||
subsystem.config['jobsScheduler.job.serialNumberUpdate.pluginName'] = \ | ||
'SerialNumberUpdateJob' | ||
|
||
subsystem.save() |