From b93ff3b0243ada8ee0eae39883593723e4e09e11 Mon Sep 17 00:00:00 2001 From: Keyfactor Date: Fri, 31 Jul 2026 00:44:56 +0000 Subject: [PATCH 1/4] Update store_types.json for all:latest --- cmd/store_types.json | 54 -------------------------------------------- store_types.json | 54 -------------------------------------------- 2 files changed, 108 deletions(-) diff --git a/cmd/store_types.json b/cmd/store_types.json index 42ae661..a71d5e2 100644 --- a/cmd/store_types.json +++ b/cmd/store_types.json @@ -5538,15 +5538,6 @@ "Type": "MultipleChoice", "DefaultValue": "None", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired. No options are initially delivered for RFDER." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], @@ -5670,15 +5661,6 @@ "Type": "MultipleChoice", "DefaultValue": "Apache Tomcat Restart,Jetty Restart", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], @@ -5802,15 +5784,6 @@ "Type": "MultipleChoice", "DefaultValue": "None", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired. No options are initially delivered for RFKDB." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], @@ -5934,15 +5907,6 @@ "Type": "MultipleChoice", "DefaultValue": "None", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired. No options are initially delivered for RFORA." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], @@ -6102,15 +6066,6 @@ "Type": "MultipleChoice", "DefaultValue": "Apache HTTPD Restart,NGNIX Restart,HAProxy Restart,Envoy Proxy Restart", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], @@ -6234,15 +6189,6 @@ "Type": "MultipleChoice", "DefaultValue": "None", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired. No options are initially delivered for RFPkcs12." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], diff --git a/store_types.json b/store_types.json index 42ae661..a71d5e2 100644 --- a/store_types.json +++ b/store_types.json @@ -5538,15 +5538,6 @@ "Type": "MultipleChoice", "DefaultValue": "None", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired. No options are initially delivered for RFDER." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], @@ -5670,15 +5661,6 @@ "Type": "MultipleChoice", "DefaultValue": "Apache Tomcat Restart,Jetty Restart", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], @@ -5802,15 +5784,6 @@ "Type": "MultipleChoice", "DefaultValue": "None", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired. No options are initially delivered for RFKDB." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], @@ -5934,15 +5907,6 @@ "Type": "MultipleChoice", "DefaultValue": "None", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired. No options are initially delivered for RFORA." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], @@ -6102,15 +6066,6 @@ "Type": "MultipleChoice", "DefaultValue": "Apache HTTPD Restart,NGNIX Restart,HAProxy Restart,Envoy Proxy Restart", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], @@ -6234,15 +6189,6 @@ "Type": "MultipleChoice", "DefaultValue": "None", "Description": "Select the command to be run after a Management Add or ODKG job executes. Leave unselected if no command is desired. No options are initially delivered for RFPkcs12." - }, - { - "Name": "RequiresLegacyEncryption", - "DisplayName": "Requires Legacy Encryption", - "Required": false, - "DependsOn": "", - "Type": "Bool", - "DefaultValue": "False", - "Description": "Optional setting. If set to true, PkcsObjectIdentifiers.PbeWithShaAnd3KeyTripleDesCbc and PkcsObjectIdentifiers.PbewithShaAnd40BitRC2Cbc algorithms will be used to create the underlying BouncyCastle Pkcs12Store used to feed the certificate store being managed during Management jobs. Should be left not implemented or set to False for most instances." } ], "EntryParameters": [], From f982e680853202945070858c55432198efa370e9 Mon Sep 17 00:00:00 2001 From: Keyfactor Date: Tue, 11 Aug 2026 00:25:37 +0000 Subject: [PATCH 2/4] Update store_types.json for all:latest --- cmd/store_types.json | 43 ++++++++++++++++++++++++++++++++++++++++--- store_types.json | 43 ++++++++++++++++++++++++++++++++++++++++--- 2 files changed, 80 insertions(+), 6 deletions(-) diff --git a/cmd/store_types.json b/cmd/store_types.json index a71d5e2..5cc1ebd 100644 --- a/cmd/store_types.json +++ b/cmd/store_types.json @@ -286,7 +286,7 @@ "SupportedOperations": { "Add": true, "Create": false, - "Discovery": false, + "Discovery": true, "Enrollment": false, "Remove": true }, @@ -410,6 +410,16 @@ "Required": false, "IsPAMEligible": false, "Description": "An optional parameter sts:ExternalId to pass with Assume Role calls" + }, + { + "Name": "DiscoveryRoleName", + "DisplayName": "Discovery Role Name", + "Type": "String", + "DependsOn": "", + "DefaultValue": "KeyfactorACMDiscoveryRole", + "Required": false, + "IsPAMEligible": false, + "Description": "The IAM role name that exists in each target account. Used during cross-account Discovery to construct the Role ARN for cross-account access (arn:aws:iam:::role/). During a Discovery job this is supplied via the 'File name patterns to match' dialog field; this store property documents and defaults the value." } ], "EntryParameters": [ @@ -437,7 +447,7 @@ "BlueprintAllowed": true, "CustomAliasAllowed": "Optional", "ClientMachineDescription": "This is a full AWS ARN specifying a Role. This is the Role that will be assumed in any Auth scenario performing Assume Role. This will dictate what certificates are usable by the orchestrator. A preceding [profile] name should be included if a Credential Profile is to be used in Default Sdk Auth.", - "StorePathDescription": "A single specified AWS Region the store will operate in. Additional regions should get their own store defined." + "StorePathDescription": "The AWS Region the store operates in (e.g. us-east-1). Stores created by cross-account Discovery instead use a self-contained path of the form '|' (e.g. 'arn:aws:iam::123456789012:role/KeyfactorACMDiscoveryRole|us-east-1') which carries both the Role ARN to assume and the Region; for those stores the Client Machine field is informational only. Additional regions should get their own store defined." }, { "Name": "AwsSecretsManager JKS", @@ -4170,6 +4180,15 @@ "DefaultValue": "true", "Required": true, "Description": "Determine whether the server uses SSL or not (This field is automatically created)" + }, + { + "Name": "JEAEndpointName", + "DisplayName": "JEA End Point Name", + "Type": "String", + "DependsOn": "", + "DefaultValue": "", + "Required": false, + "Description": "Name of the JEA endpoint to use for the session (This field is automatically created)" } ], "EntryParameters": [ @@ -6738,6 +6757,15 @@ "DefaultValue": "true", "Required": true, "Description": "Determine whether the server uses SSL or not (This field is automatically created)" + }, + { + "Name": "JEAEndpointName", + "DisplayName": "JEA End Point Name", + "Type": "String", + "DependsOn": "", + "DefaultValue": "", + "Required": false, + "Description": "Name of the JEA endpoint to use for the session (This field is automatically created)" } ], "EntryParameters": [ @@ -6780,7 +6808,7 @@ "Add": true, "Create": false, "Discovery": false, - "Enrollment": false, + "Enrollment": true, "Remove": true }, "Properties": [ @@ -6846,6 +6874,15 @@ "DefaultValue": "false", "Required": true, "Description": "Boolean value (true or false) indicating whether to restart the SQL Server service after installing the certificate. Example: 'true' to enable service restart after installation." + }, + { + "Name": "JEAEndpointName", + "DisplayName": "JEA End Point Name", + "Type": "String", + "DependsOn": "", + "DefaultValue": "", + "Required": false, + "Description": "Name of the JEA endpoint to use for the session (This field is automatically created)" } ], "EntryParameters": [ diff --git a/store_types.json b/store_types.json index a71d5e2..5cc1ebd 100644 --- a/store_types.json +++ b/store_types.json @@ -286,7 +286,7 @@ "SupportedOperations": { "Add": true, "Create": false, - "Discovery": false, + "Discovery": true, "Enrollment": false, "Remove": true }, @@ -410,6 +410,16 @@ "Required": false, "IsPAMEligible": false, "Description": "An optional parameter sts:ExternalId to pass with Assume Role calls" + }, + { + "Name": "DiscoveryRoleName", + "DisplayName": "Discovery Role Name", + "Type": "String", + "DependsOn": "", + "DefaultValue": "KeyfactorACMDiscoveryRole", + "Required": false, + "IsPAMEligible": false, + "Description": "The IAM role name that exists in each target account. Used during cross-account Discovery to construct the Role ARN for cross-account access (arn:aws:iam:::role/). During a Discovery job this is supplied via the 'File name patterns to match' dialog field; this store property documents and defaults the value." } ], "EntryParameters": [ @@ -437,7 +447,7 @@ "BlueprintAllowed": true, "CustomAliasAllowed": "Optional", "ClientMachineDescription": "This is a full AWS ARN specifying a Role. This is the Role that will be assumed in any Auth scenario performing Assume Role. This will dictate what certificates are usable by the orchestrator. A preceding [profile] name should be included if a Credential Profile is to be used in Default Sdk Auth.", - "StorePathDescription": "A single specified AWS Region the store will operate in. Additional regions should get their own store defined." + "StorePathDescription": "The AWS Region the store operates in (e.g. us-east-1). Stores created by cross-account Discovery instead use a self-contained path of the form '|' (e.g. 'arn:aws:iam::123456789012:role/KeyfactorACMDiscoveryRole|us-east-1') which carries both the Role ARN to assume and the Region; for those stores the Client Machine field is informational only. Additional regions should get their own store defined." }, { "Name": "AwsSecretsManager JKS", @@ -4170,6 +4180,15 @@ "DefaultValue": "true", "Required": true, "Description": "Determine whether the server uses SSL or not (This field is automatically created)" + }, + { + "Name": "JEAEndpointName", + "DisplayName": "JEA End Point Name", + "Type": "String", + "DependsOn": "", + "DefaultValue": "", + "Required": false, + "Description": "Name of the JEA endpoint to use for the session (This field is automatically created)" } ], "EntryParameters": [ @@ -6738,6 +6757,15 @@ "DefaultValue": "true", "Required": true, "Description": "Determine whether the server uses SSL or not (This field is automatically created)" + }, + { + "Name": "JEAEndpointName", + "DisplayName": "JEA End Point Name", + "Type": "String", + "DependsOn": "", + "DefaultValue": "", + "Required": false, + "Description": "Name of the JEA endpoint to use for the session (This field is automatically created)" } ], "EntryParameters": [ @@ -6780,7 +6808,7 @@ "Add": true, "Create": false, "Discovery": false, - "Enrollment": false, + "Enrollment": true, "Remove": true }, "Properties": [ @@ -6846,6 +6874,15 @@ "DefaultValue": "false", "Required": true, "Description": "Boolean value (true or false) indicating whether to restart the SQL Server service after installing the certificate. Example: 'true' to enable service restart after installation." + }, + { + "Name": "JEAEndpointName", + "DisplayName": "JEA End Point Name", + "Type": "String", + "DependsOn": "", + "DefaultValue": "", + "Required": false, + "Description": "Name of the JEA endpoint to use for the session (This field is automatically created)" } ], "EntryParameters": [ From fc55b699821aa0da99df91bc43d0edde56ec5784 Mon Sep 17 00:00:00 2001 From: Keyfactor Date: Tue, 25 Aug 2026 00:18:26 +0000 Subject: [PATCH 3/4] Update store_types.json for all:latest --- cmd/store_types.json | 87 +++++++++++++++++++++++++++++++++++--------- store_types.json | 87 +++++++++++++++++++++++++++++++++++--------- 2 files changed, 138 insertions(+), 36 deletions(-) diff --git a/cmd/store_types.json b/cmd/store_types.json index 5cc1ebd..741ccd3 100644 --- a/cmd/store_types.json +++ b/cmd/store_types.json @@ -1060,6 +1060,16 @@ "Required": true, "IsPAMEligible": false, "Description": "The Akamai client_secret for authentication." + }, + { + "Name": "ContractId", + "DisplayName": "Contract ID", + "Type": "String", + "DependsOn": "", + "DefaultValue": "", + "Required": false, + "IsPAMEligible": false, + "Description": "The default Akamai Contract ID for the certificate store. When performing re-enrollment, the Contract ID entry parameter will take precedence." } ], "EntryParameters": [ @@ -1077,16 +1087,15 @@ }, { "Name": "ContractId", - "DisplayName": "Contract ID", + "DisplayName": "Contract ID Override", "Type": "String", "RequiredWhen": { "HasPrivateKey": false, "OnAdd": false, "OnRemove": false, - "OnReenrollment": true + "OnReenrollment": false }, - "DefaultValue": "SET-DEFAULT", - "Description": "The Contract ID of your account in Akamai." + "Description": "The Contract ID of your account in Akamai. If a Contract ID is defined on the certificate store, the value of this parameter will take precedence. If a Contract ID is not defined on the certificate store, a value is required for this parameter." }, { "Name": "Sans", @@ -3655,7 +3664,17 @@ "StorePathType": "", "StorePathValue": "example: '/mycerts/certstore.jks?b64cert'", "PrivateKeyAllowed": "Optional", - "JobProperties": [], + "JobProperties": [ + { + "Name": "DiscoverySuffix", + "DisplayName": "Discovery Suffix", + "Type": "String", + "DependsOn": "", + "DefaultValue": "_jks", + "Required": false, + "Description": "The secret-key-name suffix Discovery jobs use to identify candidate JKS certificate secrets. Defaults to '_jks'." + } + ], "ServerRequired": true, "PowerShell": false, "BlueprintAllowed": false, @@ -3737,7 +3756,17 @@ "StorePathType": "", "StorePathValue": "example: '/mycerts/certstore.p12?b64cert'", "PrivateKeyAllowed": "Optional", - "JobProperties": [], + "JobProperties": [ + { + "Name": "DiscoverySuffix", + "DisplayName": "Discovery Suffix", + "Type": "String", + "DependsOn": "", + "DefaultValue": "_p12", + "Required": false, + "Description": "The secret-key-name suffix Discovery jobs use to identify candidate PKCS12 certificate secrets. Defaults to '_p12'." + } + ], "ServerRequired": true, "PowerShell": false, "BlueprintAllowed": false, @@ -3815,9 +3844,21 @@ "Capability": "HCVKVPEM", "LocalStore": false, "ClientMachineDescription": "This can be any value to help uniquely identify the store. It is not used by this integration.", - "StorePathDescription": "This is the path after mount point where the certificates will be stored.", + "StorePathDescription": "This is the path to the secret containing the certificate.", + "StorePathType": "", + "StorePathValue": "example: '/mycerts/mycert_pem?b64cert'", "PrivateKeyAllowed": "Optional", - "JobProperties": [], + "JobProperties": [ + { + "Name": "DiscoverySuffix", + "DisplayName": "Discovery Suffix", + "Type": "String", + "DependsOn": "", + "DefaultValue": "_pem", + "Required": false, + "Description": "The secret-key-name suffix Discovery jobs use to identify candidate PEM certificate secrets. Defaults to '_pem'." + } + ], "ServerRequired": true, "PowerShell": false, "BlueprintAllowed": false, @@ -3850,15 +3891,6 @@ "IsPAMEligible": true, "Description": "Vault token that will be used by the Orchestrator integration for authenticating and performing operations in the Vault instance" }, - { - "Name": "SubfolderInventory", - "DisplayName": "Subfolder Inventory", - "Description": "Should certificates found in sub-paths be included when performing an inventory?", - "Type": "Bool", - "DependsOn": "", - "DefaultValue": "false", - "Required": false - }, { "Name": "IncludeCertChain", "DisplayName": "Include Certificate Chain", @@ -3876,6 +3908,15 @@ "DependsOn": "", "DefaultValue": "", "Required": false + }, + { + "Name": "PrivateKeyPath", + "DisplayName": "Private Key Path", + "Type": "String", + "DependsOn": "", + "DefaultValue": "", + "Required": false, + "Description": "This is the path to the secret that contains the PEM-encoded private key. Optional \u2014 omit for CA trust chain / certificate-only PEM stores that have no private key. Unlike other Key-Value store types, no sibling-secret convention is assumed when this is omitted." } ], "EntryParameters": [], @@ -3899,7 +3940,17 @@ "StorePathType": "", "StorePathValue": "example: '/mycerts/certstore.pfx?b64cert'", "PrivateKeyAllowed": "Optional", - "JobProperties": [], + "JobProperties": [ + { + "Name": "DiscoverySuffix", + "DisplayName": "Discovery Suffix", + "Type": "String", + "DependsOn": "", + "DefaultValue": "_pfx", + "Required": false, + "Description": "The secret-key-name suffix Discovery jobs use to identify candidate PFX certificate secrets. Defaults to '_pfx'." + } + ], "ServerRequired": true, "PowerShell": false, "BlueprintAllowed": false, diff --git a/store_types.json b/store_types.json index 5cc1ebd..741ccd3 100644 --- a/store_types.json +++ b/store_types.json @@ -1060,6 +1060,16 @@ "Required": true, "IsPAMEligible": false, "Description": "The Akamai client_secret for authentication." + }, + { + "Name": "ContractId", + "DisplayName": "Contract ID", + "Type": "String", + "DependsOn": "", + "DefaultValue": "", + "Required": false, + "IsPAMEligible": false, + "Description": "The default Akamai Contract ID for the certificate store. When performing re-enrollment, the Contract ID entry parameter will take precedence." } ], "EntryParameters": [ @@ -1077,16 +1087,15 @@ }, { "Name": "ContractId", - "DisplayName": "Contract ID", + "DisplayName": "Contract ID Override", "Type": "String", "RequiredWhen": { "HasPrivateKey": false, "OnAdd": false, "OnRemove": false, - "OnReenrollment": true + "OnReenrollment": false }, - "DefaultValue": "SET-DEFAULT", - "Description": "The Contract ID of your account in Akamai." + "Description": "The Contract ID of your account in Akamai. If a Contract ID is defined on the certificate store, the value of this parameter will take precedence. If a Contract ID is not defined on the certificate store, a value is required for this parameter." }, { "Name": "Sans", @@ -3655,7 +3664,17 @@ "StorePathType": "", "StorePathValue": "example: '/mycerts/certstore.jks?b64cert'", "PrivateKeyAllowed": "Optional", - "JobProperties": [], + "JobProperties": [ + { + "Name": "DiscoverySuffix", + "DisplayName": "Discovery Suffix", + "Type": "String", + "DependsOn": "", + "DefaultValue": "_jks", + "Required": false, + "Description": "The secret-key-name suffix Discovery jobs use to identify candidate JKS certificate secrets. Defaults to '_jks'." + } + ], "ServerRequired": true, "PowerShell": false, "BlueprintAllowed": false, @@ -3737,7 +3756,17 @@ "StorePathType": "", "StorePathValue": "example: '/mycerts/certstore.p12?b64cert'", "PrivateKeyAllowed": "Optional", - "JobProperties": [], + "JobProperties": [ + { + "Name": "DiscoverySuffix", + "DisplayName": "Discovery Suffix", + "Type": "String", + "DependsOn": "", + "DefaultValue": "_p12", + "Required": false, + "Description": "The secret-key-name suffix Discovery jobs use to identify candidate PKCS12 certificate secrets. Defaults to '_p12'." + } + ], "ServerRequired": true, "PowerShell": false, "BlueprintAllowed": false, @@ -3815,9 +3844,21 @@ "Capability": "HCVKVPEM", "LocalStore": false, "ClientMachineDescription": "This can be any value to help uniquely identify the store. It is not used by this integration.", - "StorePathDescription": "This is the path after mount point where the certificates will be stored.", + "StorePathDescription": "This is the path to the secret containing the certificate.", + "StorePathType": "", + "StorePathValue": "example: '/mycerts/mycert_pem?b64cert'", "PrivateKeyAllowed": "Optional", - "JobProperties": [], + "JobProperties": [ + { + "Name": "DiscoverySuffix", + "DisplayName": "Discovery Suffix", + "Type": "String", + "DependsOn": "", + "DefaultValue": "_pem", + "Required": false, + "Description": "The secret-key-name suffix Discovery jobs use to identify candidate PEM certificate secrets. Defaults to '_pem'." + } + ], "ServerRequired": true, "PowerShell": false, "BlueprintAllowed": false, @@ -3850,15 +3891,6 @@ "IsPAMEligible": true, "Description": "Vault token that will be used by the Orchestrator integration for authenticating and performing operations in the Vault instance" }, - { - "Name": "SubfolderInventory", - "DisplayName": "Subfolder Inventory", - "Description": "Should certificates found in sub-paths be included when performing an inventory?", - "Type": "Bool", - "DependsOn": "", - "DefaultValue": "false", - "Required": false - }, { "Name": "IncludeCertChain", "DisplayName": "Include Certificate Chain", @@ -3876,6 +3908,15 @@ "DependsOn": "", "DefaultValue": "", "Required": false + }, + { + "Name": "PrivateKeyPath", + "DisplayName": "Private Key Path", + "Type": "String", + "DependsOn": "", + "DefaultValue": "", + "Required": false, + "Description": "This is the path to the secret that contains the PEM-encoded private key. Optional \u2014 omit for CA trust chain / certificate-only PEM stores that have no private key. Unlike other Key-Value store types, no sibling-secret convention is assumed when this is omitted." } ], "EntryParameters": [], @@ -3899,7 +3940,17 @@ "StorePathType": "", "StorePathValue": "example: '/mycerts/certstore.pfx?b64cert'", "PrivateKeyAllowed": "Optional", - "JobProperties": [], + "JobProperties": [ + { + "Name": "DiscoverySuffix", + "DisplayName": "Discovery Suffix", + "Type": "String", + "DependsOn": "", + "DefaultValue": "_pfx", + "Required": false, + "Description": "The secret-key-name suffix Discovery jobs use to identify candidate PFX certificate secrets. Defaults to '_pfx'." + } + ], "ServerRequired": true, "PowerShell": false, "BlueprintAllowed": false, From c385782c565ce3370142df0655b406ae669cc82b Mon Sep 17 00:00:00 2001 From: Keyfactor Date: Thu, 27 Aug 2026 01:44:31 +0000 Subject: [PATCH 4/4] Update store_types.json for all:latest --- cmd/store_types.json | 12 +++++++++++- store_types.json | 12 +++++++++++- 2 files changed, 22 insertions(+), 2 deletions(-) diff --git a/cmd/store_types.json b/cmd/store_types.json index 741ccd3..bfd5f8c 100644 --- a/cmd/store_types.json +++ b/cmd/store_types.json @@ -5349,7 +5349,17 @@ "DefaultValue": "", "Required": false, "IsPAMEligible": false, - "Description": "Template stack used for device push of certificates via Template." + "Description": "A semicolon delimited list of Template Stacks used for device push of certificates via Template (i.e. `Stack 1`, `Stack 1;Stack2`, or `Stack 1; Stack 2`, etc.)." + }, + { + "Name": "PushFailureBehavior", + "DisplayName": "Push Failure Behavior", + "Type": "MultipleChoice", + "DependsOn": "", + "DefaultValue": "Failure,Warning", + "Required": false, + "IsPAMEligible": false, + "Description": "Controls the job result when Panorama fails to commit to a device group, template, or template stack. 'Failure' will fail the management job and trigger a retry, while 'Warning' records the failure message but marks the job as completed." } ], "EntryParameters": [], diff --git a/store_types.json b/store_types.json index 741ccd3..bfd5f8c 100644 --- a/store_types.json +++ b/store_types.json @@ -5349,7 +5349,17 @@ "DefaultValue": "", "Required": false, "IsPAMEligible": false, - "Description": "Template stack used for device push of certificates via Template." + "Description": "A semicolon delimited list of Template Stacks used for device push of certificates via Template (i.e. `Stack 1`, `Stack 1;Stack2`, or `Stack 1; Stack 2`, etc.)." + }, + { + "Name": "PushFailureBehavior", + "DisplayName": "Push Failure Behavior", + "Type": "MultipleChoice", + "DependsOn": "", + "DefaultValue": "Failure,Warning", + "Required": false, + "IsPAMEligible": false, + "Description": "Controls the job result when Panorama fails to commit to a device group, template, or template stack. 'Failure' will fail the management job and trigger a retry, while 'Warning' records the failure message but marks the job as completed." } ], "EntryParameters": [],