Configuration Reference Home
OpenDJ Server - Trust Store Backend

Trust Store Backend

The Trust Store Backend provides an LDAP view of a file-based trust store. It is used by the administrative cryptographic framework.

Parent Component

The Trust Store Backend component inherits from the Backend

Properties

A description of each property follows.


Basic Properties: Advanced Properties:
↓ backend-id ↓ java-class
↓ base-dn
↓ enabled
↓ trust-store-file
↓ trust-store-pin
↓ trust-store-pin-environment-variable
↓ trust-store-pin-file
↓ trust-store-pin-property
↓ trust-store-type
↓ writability-mode

Basic Properties

backend-id

Description
Specifies a name to identify the associated backend.The name must be unique among all backends in the server. The backend ID may not be altered after the backend is created in the server.
Default Value
None
Allowed Values
A String
Multi-valued
No
Required
Yes
Admin Action Required
None
Advanced Property
No
Read-only
Yes

base-dn

Description
Specifies the base DN(s) for the data that the backend handles.A single backend may be responsible for one or more base DNs. Note that no two backends may have the same base DN although one backend may have a base DN that is below a base DN provided by another backend (similar to the use of sub-suffixes in the Sun Java System Directory Server). If any of the base DNs is subordinate to a base DN for another backend, then all base DNs for that backend must be subordinate to that same base DN.
Default Value
None
Allowed Values
A valid DN.
Multi-valued
Yes
Required
Yes
Admin Action Required
None. No administrative action is required by default although some action may be required on a per-backend basis before the new base DN may be used.
Advanced Property
No
Read-only
No

enabled

Description
Indicates whether the backend is enabled in the server.If a backend is not enabled, then its contents are not accessible when processing operations.
Default Value
None
Allowed Values
true
false
Multi-valued
No
Required
Yes
Admin Action Required
None
Advanced Property
No
Read-only
No

trust-store-file

Description
Specifies the path to the file that stores the trust information.It may be an absolute path, or a path that is relative to the OpenDJ instance root.
Default Value
config/ads-truststore
Allowed Values
A String
Multi-valued
No
Required
Yes
Admin Action Required
None
Advanced Property
No
Read-only
No

trust-store-pin

Description
Specifies the clear-text PIN needed to access the Trust Store Backend .
Default Value
None
Allowed Values
A String
Multi-valued
No
Required
No
Admin Action Required
None. Changes to this property will take effect the next time that the Trust Store Backend is accessed.
Advanced Property
No
Read-only
No

trust-store-pin-environment-variable

Description
Specifies the name of the environment variable that contains the clear-text PIN needed to access the Trust Store Backend .
Default Value
None
Allowed Values
A String
Multi-valued
No
Required
No
Admin Action Required
None. Changes to this property will take effect the next time that the Trust Store Backend is accessed.
Advanced Property
No
Read-only
No

trust-store-pin-file

Description
Specifies the path to the text file whose only contents should be a single line containing the clear-text PIN needed to access the Trust Store Backend .
Default Value
None
Allowed Values
A String
Multi-valued
No
Required
No
Admin Action Required
None. Changes to this property will take effect the next time that the Trust Store Backend is accessed.
Advanced Property
No
Read-only
No

trust-store-pin-property

Description
Specifies the name of the Java property that contains the clear-text PIN needed to access the Trust Store Backend .
Default Value
None
Allowed Values
A String
Multi-valued
No
Required
No
Admin Action Required
None. Changes to this property will take effect the next time that the Trust Store Backend is accessed.
Advanced Property
No
Read-only
No

trust-store-type

Description
Specifies the format for the data in the key store file.Valid values should always include 'JKS' and 'PKCS12', but different implementations may allow other values as well.
Default Value
The JVM default value is used.
Allowed Values
A String
Multi-valued
No
Required
No
Admin Action Required
None. Changes to this property take effect the next time that the key manager is accessed.
Advanced Property
No
Read-only
No

writability-mode

Description
Specifies the behavior that the backend should use when processing write operations.
Default Value
enabled
Allowed Values
disabled - Causes all write attempts to fail.

enabled - Allows write operations to be performed in that backend (if the requested operation is valid, the user has permission to perform the operation, the backend supports that type of write operation, and the global writability-mode property is also enabled).

internal-only - Causes external write attempts to fail but allows writes by replication and internal operations.


Multi-valued
No
Required
Yes
Admin Action Required
None
Advanced Property
No
Read-only
No


Advanced Properties

java-class

Description
Specifies the fully-qualified name of the Java class that provides the backend implementation.
Default Value
org.opends.server.backends.TrustStoreBackend
Allowed Values
A java class that implements or extends the class(es) :
org.opends.server.api.Backend
Multi-valued
No
Required
Yes
Admin Action Required
The Trust Store Backend must be disabled and re-enabled for changes to this setting to take effect
Advanced Property
Yes
Read-only
No