{
"Resources": [
{
"Uri": "/cli/v1/certificate",
"Interfaces": [
{
"Type": "Patch",
"Description": "Operate certificate"
}
]
},
{
"Uri": "/cli/v1/certificate/import",
"Interfaces": [
{
"Type": "Patch",
"Description": "import certificate",
"Usage": "ipmcset -t certificate -d import -v <localpath/URL> <type> [passphrase]",
"ReqBody": {
"Type": "object",
"Required": true,
"Properties": {
"path": {
"Type": "string",
"Validator": [
{
"Type": "Regex",
"Formula": "^((https|sftp|nfs|cifs|scp)://.{1,1000}|/tmp/.{1,246})$"
}
],
"Required": true,
"Sensitive": true,
"Description": "\nLocalpath e.g.: /tmp/customer.pfx \nURL : protocol://[username:password@]IP[:port]/directory/filename \n The parameters in the URL are described as follows: \n The protocol must be https,sftp,cifs,scp or nfs. \nThe URL can contain only letters, digits, and special characters. The directory or file name cannot contain @.\nUse double quotation marks (\") to enclose the URL that contains a space or double quotation marks (\"). Escape the double quotation marks (\") and back slash (\\) contained in the URL. \nFor example, if you want to enter: \na b\\cd\" \nEnter: \n\"a b\\\\cd\\\"\" "
},
"type": {
"Type": "integer",
"Validator": [
{
"Type": "Enum",
"Formula": [
1
]
}
],
"Required": true,
"Description": "\nTypes are: \n 1 custom certificate, customized p12 or pfx certificate that contains private keys."
},
"passphrase": {
"Type": "string",
"Validator": [
{
"Type": "Length",
"Formula": [
0,
32
]
}
],
"Sensitive": true,
"Required": false
}
}
},
"RspBody": {
"IsLocalFile": "${Statements/IsLocalFile()}",
"ValidateResult": "${Statements/GetValidateResult()}"
},
"Statements": {
"IsLocalFile": {
"Steps": [
{
"Type": "Script",
"Formula": "return string.sub(ReqBody.path, 1, 1) == '/'"
}
]
},
"IsImportActionPermitted": {
"Steps": [
{
"Type": "Plugin",
"Formula": "orchestrator.utils.is_import_permitted('URI', ReqBody.path, 'cert', 'path', ProcessingFlow[1].Destination.Result)"
}
]
},
"GetValidateResult": {
"Input": "${ProcessingFlow[2]/Destination/Extra}",
"Steps": [
{
"Type": "Script",
"Formula": "if Input then return Input else return ProcessingFlow[3].Destination.Extra end"
},
{
"Type": "Script",
"Formula": "if Input then return Input.ValidateResult else return '0' end"
},
{
"Type": "Convert",
"Formula": "StringToNumber"
}
]
}
},
"ProcessingFlow": [
{
"Type": "Method",
"Path": "/bmc/kepler/Managers/1/Security/File",
"Interface": "bmc.kepler.Managers.Security.File",
"Name": "IsPermitted",
"Params": [
"${ReqBody/path}",
"rw"
],
"Destination": {
"Result": "Result"
}
},
{
"Type": "Method",
"Path": "/bmc/kepler/CertificateService",
"Interface": "bmc.kepler.CertificateService",
"Name": "ImportCertificate",
"Params": [
1,
"URI",
"${ReqBody/path}",
0,
true,
"${ReqBody/passphrase}",
{}
],
"Destination": {
"Extra": "Extra"
},
"CallIf": {
"${ReqBody/passphrase}": "#WITH",
"${Statements/IsLocalFile()}": true,
"${Statements/IsImportActionPermitted()}": true
}
},
{
"Type": "Method",
"Path": "/bmc/kepler/CertificateService",
"Interface": "bmc.kepler.CertificateService",
"Name": "ImportCertificate",
"Params": [
1,
"URI",
"${ReqBody/path}",
0,
true,
"",
{}
],
"Destination": {
"Extra": "Extra"
},
"CallIf": {
"${ReqBody/passphrase}": "#WITHOUT",
"${Statements/IsLocalFile()}": true,
"${Statements/IsImportActionPermitted()}": true
}
},
{
"Type": "Task",
"Path": "/bmc/kepler/CertificateService",
"Interface": "bmc.kepler.CertificateService",
"Name": "ImportCertificate",
"Params": [
1,
"URI",
"${ReqBody/path}",
0,
true,
"${ReqBody/passphrase}",
{}
],
"CallIf": {
"${ReqBody/passphrase}": "#WITH",
"${Statements/IsLocalFile()}": false
}
},
{
"Type": "Task",
"Path": "/bmc/kepler/CertificateService",
"Interface": "bmc.kepler.CertificateService",
"Name": "ImportCertificate",
"Params": [
1,
"URI",
"${ReqBody/path}",
0,
true,
"",
{}
],
"CallIf": {
"${ReqBody/passphrase}": "#WITHOUT",
"${Statements/IsLocalFile()}": false
}
}
],
"Echoes": [
"ipmcset/certificate_import",
""
]
}
]
}
]
}