Repository navigation
Conversation
maximthomas
left a comment
There was a problem hiding this comment.
praise: The key steps now match the real connector-server commands and connect the two ends of the key.
- The Unix example uses
/setKey, which is the only spelling OpenICF'sbin/ConnectorServer.shaccepts: it dispatches on[[ "$1" == "/setKey" ]], case-sensitively (line 159 at tag 2.0.4). The old/setkeyexample fell through on Unix. - Both procedures now say that the
keyinprovisioner.openicf.connectorinfoprovider.jsonmust match the server key, and they link toxref:#connector-info-provider-conf, whose anchor is atchap-resource-conf.adoc:56.
question (blocking): Should this PR merge only once an OpenICF release with the documented key behaviour is published?
openidm-doc/src/main/asciidoc/integrators-guide/chap-resource-conf.adoc:1420, :1432, :1434-1439, :1454, :1508, :1519, :1521, :1535
The procedure links to the OpenICF releases page. Its latest release is 2.0.4, and OpenIDM's pom.xml:396 pins openicf 2.0.4. At tag 2.0.4, conf/ConnectorServer.properties:89 ships connectorserver.key=lmA6bMfENJGlIDbfrVtklXFK32s\=, which is the changeit hash according to its ## /setkey changeit comment. Neither connector-server Main.java reads an environment variable. Each key step qualifies only its first sentence with "From OpenICF 2.1 on". The refusal, the CONNECTORSERVER_KEY paragraph and the #connectorserver.key= excerpts all read as current behaviour. A reader on 2.0.4 who sets the key through the environment variable therefore gets a server that still accepts changeit, while the guide says that key is refused. OpenIDM, configured with the new key, then cannot connect. If the merge waits for that release, the qualifiers below are all that is left, and they are non-blocking. If it merges before the release, this blocks.
. Set the connector server key before you start the server for the first time. [...] because any client could authenticate with either of them. In OpenICF 2.0.x and earlier, the packaged file sets `connectorserver.key` to the hash of `changeit` and the server does not read `CONNECTORSERVER_KEY`, so run `/setKey` before the first start.
[...]
If you run `/setKey` without a key, the command prompts for the key instead, which keeps the key out of the shell history. From OpenICF 2.1 on, the command refuses `changeit` and an empty key: it leaves the configuration file unchanged and exits with status `1`.
+
From OpenICF 2.1 on, you can alternatively pass the key in clear text in the `CONNECTORSERVER_KEY` environment variable when you start the server. [...]
[...]
. Review the `ConnectorServer.properties` file in the `/path/to/openicf/conf` directory, and make any required changes. In OpenICF 2.1 and later, the configuration file has the following properties by default:Or: hold the merge until the release is out. The 2.0.x sentence is still worth keeping for readers who stay on 2.0.x.
issue (non-blocking): The unchanged unzip step names openicf-zip-1.7.1.zip, and the new key text now contradicts that version.
openidm-doc/src/main/asciidoc/integrators-guide/chap-resource-conf.adoc:1409
At tag 1.7.1, the packaged conf/ConnectorServer.properties:89 carries the changeit hash, and that version has no CONNECTORSERVER_KEY. The steps at :1420 and :1454 therefore describe a different artifact from the one this step unpacks. The release asset is also named openicf-1.7.1.zip, not openicf-zip-1.7.1.zip.
$ unzip openicf-<version>.zipsuggestion (non-blocking): Make the same key-step change in the DocBook copy of the chapter, or list that copy under "Not in this PR".
openidm-doc/src/main/docbkx/integrators-guide/chap-resource-conf.xml:1499, :1555, :1560
Both procedures in the DocBook copy still say "The default secret key value is changeit", and :1560 still uses /setkey. The man-pages profile still runs the doc-maven-plugin process/build/release goals over src/main/docbkx with buildReleaseZip set (openidm-doc/pom.xml:48-53, :79). The released openidm-doc-<version>-docs.zip therefore keeps the default that this PR removes from the guide.
f021769 to
b60ae30
Compare
|
Blocking question (merge before the OpenICF 2.1 release): merging now, so I applied the qualifiers you proposed, in both procedures:
The prompt for a key when Unzip step ( DocBook copy: listed under "Not in this PR". No documentation change since #114 has touched Re-rendered with Asciidoctor.js 3: no warnings, both cross-references resolve, step counts unchanged. |
maximthomas
left a comment
There was a problem hiding this comment.
praise: The guide is now right for the release readers can download today and for the next one.
chap-resource-conf.adoc:1420and:1508end with the 2.0.x sentence (changeit hash shipped,CONNECTORSERVER_KEYignored, run/setKeyfirst), so the procedure still works on 2.0.4, the version OpenIDM pins.- The refusal and env-var paragraphs (
:1432,:1434,:1519,:1521) and the excerpt intros (:1444,:1525) carry "From OpenICF 2.1 on" / "In OpenICF 2.1 and later". OpenICF master is2.1.0-SNAPSHOTwith no 2.0.x branch, so the version named is the next release. - The
/setKeyprompt sentence stays unqualified, which is correct: at 2.0.4 bothConnectorServer.shandConnectorServer.batalready prompt when no key is given.
issue (non-blocking): The Windows key step runs bin\ConnectorServer.bat from a directory that step 3 never takes the reader to.
openidm-doc/src/main/asciidoc/integrators-guide/chap-resource-conf.adoc:1505, :1515, :1548, :1558, :1567
Step 3 says "change to the openicf directory", but its command is C:\>cd C:\path\to\openicf\bin. The rewritten key example at :1515 (c:\path\to\openicf>bin\ConnectorServer.bat /setKey "<your key>") only works from openicf. From openicf\bin it resolves to bin\bin\ConnectorServer.bat, so cmd reports "'bin\ConnectorServer.bat' is not recognized" on the first command this PR rewrote. The mismatch already exists at the base and also affects /install, /uninstall and /run. Since this PR edits :1515, it is a cheap place to fix it.
. In a Command Prompt window, change to the `openicf` directory:
+
[source, console]
----
C:\>cd C:\path\to\openicf
----suggestion (non-blocking): The Verification section reports nine Windows steps, but the chapter renders eight.
openidm-doc/src/main/asciidoc/integrators-guide/chap-resource-conf.adoc:1496
With @asciidoctor/core 3, #java-connector-server-windows is one ordered list of 8 items at the base, at the round-1 head and at this head (:1496, :1498, :1500, :1508, :1525, :1540, :1562, :1574). The Unix procedure is one list of 7. Numbering did not change, so readers are not affected. But "seven and nine" does not match the render it describes. Changing it to "seven and eight" makes the check reproducible.
const fs = require('fs'), assert = require('assert');
const A = require('@asciidoctor/core')();
const doc = A.load(fs.readFileSync('chap-resource-conf.adoc', 'utf8'), {safe: 'safe'});
for (const [id, n] of [['java-connector-server-unix', 7], ['java-connector-server-windows', 8]]) {
const ex = doc.findBy({id})[0];
const ols = ex.findBy({context: 'olist'}).filter(o => o.getParent() === ex);
assert.deepStrictEqual(ols.map(o => o.getItems().length), [n]);
}Pin: a + continuation that breaks either procedure splits its list into two, and the assertion fails.
b60ae30 to
bc8ef9e
Compare
|
Windows Step count: you are right, the Windows procedure renders as one list of eight. The Verification section now says "seven and eight"; your The branch is rebased onto the current |
…as no default key From OpenICF 2.1 the Java connector server ships without a key and refuses to start on none, on the retired default `changeit`, or on an empty key. Drop the "default key value is changeit" text from the Unix and Windows install procedures, say that a key must be set before the first start with /setKey or CONNECTORSERVER_KEY, replace the Passw0rd sample with a placeholder, show connectorserver.key unset in the default properties, and note that the key in provisioner.openicf.connectorinfoprovider.json must match the server's key. Fixes OpenIdentityPlatform#235
…OpenICF version OpenICF 2.0.4, the latest release, still ships the changeit hash and does not read CONNECTORSERVER_KEY. Mark the refusal, the environment variable and the empty-key properties excerpt as OpenICF 2.1 behaviour, and tell 2.0.x readers to run /setKey before the first start. Use openicf-<version>.zip in the unzip step.
…from the openicf directory Step 3 of the Windows procedure said "change to the openicf directory" but changed to openicf\bin, while every later command runs bin\ConnectorServer.bat from openicf. Change to openicf instead.
bc8ef9e to
38f9998
Compare
|
Rebased onto the current The three commits are unchanged: |
maximthomas
left a comment
There was a problem hiding this comment.
praise: The Windows procedure now runs every command from the directory its steps name.
openidm-doc/src/main/asciidoc/integrators-guide/chap-resource-conf.adoc:1505isC:\>cd C:\path\to\openicf. It matches step 3's text at:1500and thec:\path\to\openicf>bin\ConnectorServer.batprompts for/setKey,/install,/uninstalland/runat:1515,:1548,:1558,:1567.- The description's Verification line now reports seven and eight steps, the counts Asciidoctor.js 3 renders for
#java-connector-server-unixand#java-connector-server-windows.
Fixes #235
The problem
The integrator's guide tells readers that the Java connector server key defaults to
changeit. From OpenICF 2.1 on, the connector server ships without a key: the packagedconf/ConnectorServer.propertiesleavesconnectorserver.keyunset, and the server refuses to start without a key, on the hash ofchangeit, or on the hash of an empty key. A reader who follows the guide as written gets a server that will not start.The sample
ConnectorServer.propertiesexcerpts in the same procedures also showconnectorserver.keyset to a fixed hash, which the packaged file no longer carries.The change
chap-resource-conf.adoc, in both the Unix (#java-connector-server-unix) and the Windows (#java-connector-server-windows) install procedures:changeit." and say that a key must be set before the first start./setKeyexample, with a"<your key>"placeholder instead ofPassw0rd. Note that/setKeywithout a key prompts for it, and that from OpenICF 2.1 on it refuseschangeitand an empty key with exit status 1.CONNECTORSERVER_KEY(OpenICF 2.1 and later) and its precedence: a key in the properties file wins over the variable. On Windows, point out that a variable set only in the Command Prompt window does not reach the Windows service, so the service needs/setKey.changeitand the server does not readCONNECTORSERVER_KEY, so/setKeymust run before the first start.keyinprovisioner.openicf.connectorinfoprovider.jsonmust match the server's key, with a link to "Accessing Remote Connectors".#connectorserver.key=in the default properties excerpts as the OpenICF 2.1 default, and say that/setKeyfills it with the hash of the key./setkeyoutput (a classpath echo) withKey has been successfully updated.openicf-<version>.zipinstead ofopenicf-zip-1.7.1.zip, which is neither the release asset name nor a version this text describes.C:\path\to\openicfinstead ofopenicf\bin, since every later command,/setKeyincluded, runsbin\ConnectorServer.batfromopenicf.Verification
Rendered the chapter with Asciidoctor.js 3: no warnings, the
connector-info-provider-conftarget resolves for both new cross-references, and the Unix and Windows procedures keep their seven and eight steps.Not in this PR
OpenIdentityPlatform/doc.openidentityplatform.org(openidm/modules/integrators-guide/pages/chap-resource-conf.adoc) needs the same change there.openidm-doc/src/main/docbkx/integrators-guide/chap-resource-conf.xml) still says the key defaults tochangeit. No documentation change since Update target JDK to 17 and move to JakartaEE 10 (Pax Web 11) #114 has touchedsrc/main/docbkx, but theman-pagesprofile still builds it into the release docs zip; whether to sync or drop that copy belongs in its own issue.