Trust Store Backend

The Trust Store Backend provides an LDAP view of a file-based trust store. It is used by the administrative cryptographic framework.

Parent

The Trust Store Backend object inherits from Local Backend.

Properties

Use the --advanced option to access advanced properties.

Basic Properties

backend-id

SynopsisSpecifies a name to identify the associated backend.
DescriptionThe name must be unique among all backends in the server. The backend ID may not be altered after the backend is created in the server.
Default ValueNone
Allowed ValuesA string.
Multi-valuedNo
RequiredYes
Admin Action RequiredNone
AdvancedNo
Read-OnlyYes

enabled

SynopsisIndicates whether the backend is enabled in the server.
DescriptionIf a backend is not enabled, then its contents are not accessible when processing operations.
Default ValueNone
Allowed Valuestrue
false
Multi-valuedNo
RequiredYes
Admin Action RequiredNone
AdvancedNo
Read-OnlyNo

trust-store-file

SynopsisSpecifies the path to the file that stores the trust information.
DescriptionIt may be an absolute path, or a path that is relative to the OpenDJ instance root.
Default Valueconfig/ads-truststore
Allowed ValuesA string.
Multi-valuedNo
RequiredYes
Admin Action RequiredNone
AdvancedNo
Read-OnlyNo

trust-store-pin

SynopsisSpecifies the clear-text PIN needed to access the Trust Store Backend .
Default ValueNone
Allowed ValuesA string.
Multi-valuedNo
RequiredNo
Admin Action RequiredNone
Changes to this property will take effect the next time that the Trust Store Backend is accessed.
AdvancedNo
Read-OnlyNo

trust-store-pin-environment-variable

SynopsisSpecifies the name of the environment variable that contains the clear-text PIN needed to access the Trust Store Backend .
Default ValueNone
Allowed ValuesA string.
Multi-valuedNo
RequiredNo
Admin Action RequiredNone
Changes to this property will take effect the next time that the Trust Store Backend is accessed.
AdvancedNo
Read-OnlyNo

trust-store-pin-file

SynopsisSpecifies the path to the text file whose only contents should be a single line containing the clear-text PIN needed to access the Trust Store Backend .
Default ValueNone
Allowed ValuesA string.
Multi-valuedNo
RequiredNo
Admin Action RequiredNone
Changes to this property will take effect the next time that the Trust Store Backend is accessed.
AdvancedNo
Read-OnlyNo

trust-store-pin-property

SynopsisSpecifies the name of the Java property that contains the clear-text PIN needed to access the Trust Store Backend .
Default ValueNone
Allowed ValuesA string.
Multi-valuedNo
RequiredNo
Admin Action RequiredNone
Changes to this property will take effect the next time that the Trust Store Backend is accessed.
AdvancedNo
Read-OnlyNo

trust-store-type

SynopsisSpecifies the format for the data in the key store file.
DescriptionValid values should always include 'JKS' and 'PKCS12', but different implementations may allow other values as well.
Default ValueThe JVM default value is used.
Allowed ValuesA string.
Multi-valuedNo
RequiredNo
Admin Action RequiredNone
Changes to this property take effect the next time that the key manager is accessed.
AdvancedNo
Read-OnlyNo

writability-mode

SynopsisSpecifies the behavior that the backend should use when processing write operations.
Default Valueenabled
Allowed Values

disabled: Causes all write attempts to fail.

enabled: Allows write operations to be performed in that backend (if the requested operation is valid, the user has permission to perform the operation, the backend supports that type of write operation, and the global writability-mode property is also enabled).

internal-only: Causes external write attempts to fail but allows writes by replication and internal operations.

Multi-valuedNo
RequiredYes
Admin Action RequiredNone
AdvancedNo
Read-OnlyNo

Advanced Properties

java-class

SynopsisSpecifies the fully-qualified name of the Java class that provides the backend implementation.
Default Valueorg.opends.server.backends.TrustStoreBackend
Allowed ValuesA Java class that extends or implements:
org.opends.server.api.Backend
Multi-valuedNo
RequiredYes
Admin Action RequiredThe object must be disabled and re-enabled for changes to take effect.
AdvancedYes
Read-OnlyNo