PKI ACME Responder with PostgreSQL Database

From Dogtag
Jump to: navigation, search

Installing JDBC Driver

$ dnf install postgresql-jdbc
$ cd /usr/share/pki/server/common/lib
$ ln -s /usr/share/java/postgresql-jdbc/postgresql.jar

Initializing Database

To create a database:

$ sudo -u postgres psql
psql> create user acme with password 'Secret.123';
psql> create database acme owner acme;

Use the provided create.sql to initialize the ACME database.

To initialize a local database:

$ sudo -u postgres psql \
    -d acme \
    -f /usr/share/pki/acme/conf/database/postgresql/create.sql

To initialize a remote database:

$ psql <url> -f /usr/share/pki/acme/conf/database/postgresql/create.sql

Configuring ACME Responder

To configure PKI ACME responder with a PostgreSQL database:

$ cp /usr/share/pki/acme/conf/database/postgresql/database.conf /etc/pki/pki-tomcat/acme/database.conf

The configuration will be stored in /etc/pki/pki-tomcat/acme/database.conf, for example:

class=org.dogtagpki.acme.database.PostgreSQLDatabase
url=jdbc:postgresql://localhost:5432/acme
user=acme
password=Secret.123

Removing Database

Use the provided drop.sql to remove the ACME database.

To remove a local database:

$ sudo -u postgres psql \
    -d acme \
    -f /usr/share/pki/acme/conf/database/postgresql/drop.sql

To remove a remote database:

$ psql <url> -f /usr/share/pki/acme/conf/database/postgresql/drop.sql

See Also