{
    "Resources": [
        {
            "Uri": "/cli/v1/certificate",
            "Interfaces": [
                {
                    "Type": "Patch",
                    "Description": "Operate certificate"
                }
            ]
        },
        {
            "Uri": "/cli/v1/certificate/import",
            "Interfaces": [
                {
                    "Type": "Patch",
                    "Description": "import certificate",
                    "Usage": "ipmcset -t certificate -d import -v <localpath/URL> <type> [passphrase]",
                    "ReqBody": {
                        "Type": "object",
                        "Required": true,
                        "Properties": {
                            "path": {
                                "Type": "string",
                                "Validator": [
                                    {
                                        "Type": "Regex",
                                        "Formula": "^((https|sftp|nfs|cifs|scp)://.{1,1000}|/tmp/.{1,246})$"
                                    }
                                ],
                                "Required": true,
                                "Sensitive": true,
                                "Description": "\nLocalpath  e.g.: /tmp/customer.pfx \nURL            : protocol://[username:password@]IP[:port]/directory/filename \n    The parameters in the URL are described as follows: \n        The protocol must be https,sftp,cifs,scp or nfs. \nThe URL can contain only letters, digits, and special characters. The directory or file name cannot contain @.\nUse double quotation marks (\") to enclose the URL that contains a space or double quotation marks (\"). Escape the double quotation marks (\") and back slash (\\) contained in the URL. \nFor example, if you want to enter: \na b\\cd\" \nEnter: \n\"a b\\\\cd\\\"\" "
                            },
                            "type": {
                                "Type": "integer",
                                "Validator": [
                                    {
                                        "Type": "Enum",
                                        "Formula": [
                                            1
                                        ]
                                    }
                                ],
                                "Required": true,
                                "Description": "\nTypes are: \n     1        custom certificate, customized p12 or pfx certificate that contains private keys."
                            },
                            "passphrase": {
                                "Type": "string",
                                "Validator": [
                                    {
                                        "Type": "Length",
                                        "Formula": [
                                            0,
                                            32
                                        ]
                                    }
                                ],
                                "Sensitive": true,
                                "Required": false
                            }
                        }
                    },
                    "RspBody": {
                        "IsLocalFile": "${Statements/IsLocalFile()}",
                        "ValidateResult": "${Statements/GetValidateResult()}"
                    },
                    "Statements": {
                        "IsLocalFile": {
                            "Steps": [
                                {
                                    "Type": "Script",
                                    "Formula": "return string.sub(ReqBody.path, 1, 1) == '/'"
                                }
                            ]
                        },
                        "IsImportActionPermitted": {
                            "Steps": [
                                {
                                    "Type": "Plugin",
                                    "Formula": "orchestrator.utils.is_import_permitted('URI', ReqBody.path, 'cert', 'path', ProcessingFlow[1].Destination.Result)"
                                }
                            ]
                        },
                        "GetValidateResult": {
                            "Input": "${ProcessingFlow[2]/Destination/Extra}",
                            "Steps": [
                                {
                                    "Type": "Script",
                                    "Formula": "if Input then return Input else return ProcessingFlow[3].Destination.Extra end"
                                },
                                {
                                    "Type": "Script",
                                    "Formula": "if Input then return Input.ValidateResult else return '0' end"
                                },
                                {
                                    "Type": "Convert",
                                    "Formula": "StringToNumber"
                                }
                            ]
                        }
                    },
                    "ProcessingFlow": [
                        {
                            "Type": "Method",
                            "Path": "/bmc/kepler/Managers/1/Security/File",
                            "Interface": "bmc.kepler.Managers.Security.File",
                            "Name": "IsPermitted",
                            "Params": [
                                "${ReqBody/path}",
                                "rw"
                            ],
                            "Destination": {
                                "Result": "Result"
                            }
                        },
                        {
                            "Type": "Method",
                            "Path": "/bmc/kepler/CertificateService",
                            "Interface": "bmc.kepler.CertificateService",
                            "Name": "ImportCertificate",
                            "Params": [
                                1,
                                "URI",
                                "${ReqBody/path}",
                                0,
                                true,
                                "${ReqBody/passphrase}",
                                {}
                            ],
                            "Destination": {
                                "Extra": "Extra"
                            },
                            "CallIf": {
                                "${ReqBody/passphrase}": "#WITH",
                                "${Statements/IsLocalFile()}": true,
                                "${Statements/IsImportActionPermitted()}": true
                            }
                        },
                        {
                            "Type": "Method",
                            "Path": "/bmc/kepler/CertificateService",
                            "Interface": "bmc.kepler.CertificateService",
                            "Name": "ImportCertificate",
                            "Params": [
                                1,
                                "URI",
                                "${ReqBody/path}",
                                0,
                                true,
                                "",
                                {}
                            ],
                            "Destination": {
                                "Extra": "Extra"
                            },
                            "CallIf": {
                                "${ReqBody/passphrase}": "#WITHOUT",
                                "${Statements/IsLocalFile()}": true,
                                "${Statements/IsImportActionPermitted()}": true
                            }
                        },
                        {
                            "Type": "Task",
                            "Path": "/bmc/kepler/CertificateService",
                            "Interface": "bmc.kepler.CertificateService",
                            "Name": "ImportCertificate",
                            "Params": [
                                1,
                                "URI",
                                "${ReqBody/path}",
                                0,
                                true,
                                "${ReqBody/passphrase}",
                                {}
                            ],
                            "CallIf": {
                                "${ReqBody/passphrase}": "#WITH",
                                "${Statements/IsLocalFile()}": false
                            }
                        },
                        {
                            "Type": "Task",
                            "Path": "/bmc/kepler/CertificateService",
                            "Interface": "bmc.kepler.CertificateService",
                            "Name": "ImportCertificate",
                            "Params": [
                                1,
                                "URI",
                                "${ReqBody/path}",
                                0,
                                true,
                                "",
                                {}
                            ],
                            "CallIf": {
                                "${ReqBody/passphrase}": "#WITHOUT",
                                "${Statements/IsLocalFile()}": false
                            }
                        }
                    ],
                    "Echoes": [
                        "ipmcset/certificate_import",
                        ""
                    ]
                }
            ]
        }
    ]
}