diff --git a/.github/workflows/keyfactor-starter-workflow.yml b/.github/workflows/keyfactor-starter-workflow.yml
index 8ec5771..c6ec4da 100644
--- a/.github/workflows/keyfactor-starter-workflow.yml
+++ b/.github/workflows/keyfactor-starter-workflow.yml
@@ -11,17 +11,18 @@ on:
jobs:
call-starter-workflow:
- uses: keyfactor/actions/.github/workflows/starter.yml@v4
+ uses: keyfactor/actions/.github/workflows/starter.yml@v5
with:
- command_token_url: ${{ vars.COMMAND_TOKEN_URL }} # Only required for doctool generated screenshots
- command_hostname: ${{ vars.COMMAND_HOSTNAME }} # Only required for doctool generated screenshots
- command_base_api_path: ${{ vars.COMMAND_API_PATH }} # Only required for doctool generated screenshots
+ command_token_url: ${{ vars.COMMAND_TOKEN_URL }}
+ command_hostname: ${{ vars.COMMAND_HOSTNAME }}
+ command_base_api_path: ${{ vars.COMMAND_API_PATH }}
secrets:
- token: ${{ secrets.V2BUILDTOKEN}} # REQUIRED
- gpg_key: ${{ secrets.KF_GPG_PRIVATE_KEY }} # Only required for golang builds
- gpg_pass: ${{ secrets.KF_GPG_PASSPHRASE }} # Only required for golang builds
- scan_token: ${{ secrets.SAST_TOKEN }} # REQUIRED
- entra_username: ${{ secrets.DOCTOOL_ENTRA_USERNAME }} # Only required for doctool generated screenshots
- entra_password: ${{ secrets.DOCTOOL_ENTRA_PASSWD }} # Only required for doctool generated screenshots
- command_client_id: ${{ secrets.COMMAND_CLIENT_ID }} # Only required for doctool generated screenshots
- command_client_secret: ${{ secrets.COMMAND_CLIENT_SECRET }} # Only required for doctool generated screenshots
+ token: ${{ secrets.V2BUILDTOKEN}}
+ gpg_key: ${{ secrets.KF_GPG_PRIVATE_KEY }}
+ gpg_pass: ${{ secrets.KF_GPG_PASSPHRASE }}
+ scan_token: ${{ secrets.SAST_TOKEN }}
+ entra_username: ${{ secrets.DOCTOOL_ENTRA_USERNAME }}
+ entra_password: ${{ secrets.DOCTOOL_ENTRA_PASSWD }}
+ command_client_id: ${{ secrets.COMMAND_CLIENT_ID }}
+ command_client_secret: ${{ secrets.COMMAND_CLIENT_SECRET }}
+
\ No newline at end of file
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 340a099..a080ae1 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,3 +1,6 @@
+v1.2.0
+- Add .net10 build and remove .net6
+
v1.1.2
- Modify error message to indicate comma separated API ID/API Key in the Store Password rather than pipe delimted
diff --git a/Imperva/Imperva.csproj b/Imperva/Imperva.csproj
index 44a0582..10552c1 100644
--- a/Imperva/Imperva.csproj
+++ b/Imperva/Imperva.csproj
@@ -2,23 +2,19 @@
true
- net6.0;net8.0
+ net8.0;net10.0truedisable
-
-
-
-
+
+
+ Always
-
- Always
-
diff --git a/README.md b/README.md
index 6c6a1c7..1e0f554 100644
--- a/README.md
+++ b/README.md
@@ -33,13 +33,12 @@
The Imperva Orchestrator Extension allows for the management of SSL certificates bound to web sites managed by the Imperva cloud-based firewall.
-
-
## Compatibility
This integration is compatible with Keyfactor Universal Orchestrator version 10.1 and later.
## Support
+
The Imperva Universal Orchestrator extension is supported by Keyfactor. If you require support for any issues or have feature request, please open a support ticket by either contacting your Keyfactor representative or via the Keyfactor Support Portal at https://support.keyfactor.com.
> If you want to contribute bug fixes or additional enhancements, use the **[Pull requests](../../pulls)** tab.
@@ -48,36 +47,30 @@ The Imperva Universal Orchestrator extension is supported by Keyfactor. If you r
Before installing the Imperva Universal Orchestrator extension, we recommend that you install [kfutil](https://github.com/Keyfactor/kfutil). Kfutil is a command-line tool that simplifies the process of creating store types, installing extensions, and instantiating certificate stores in Keyfactor Command.
-
The Imperva Orchestrator Extension requires the creation of an Imperva account id, API id, and API key. Please reference the [Imperva Documentation](https://docs.imperva.com/bundle/cloud-application-security/page/settings/api-keys.htm#:~:text=In%20the%20Cloud%20Security%20Console%20top%20menu%20bar%2C%20click%20Account,to%20create%20a%20new%20key) for more information on creating an API id and key for use with this integration.
-
## Imperva Certificate Store Type
To use the Imperva Universal Orchestrator extension, you **must** create the Imperva Certificate Store Type. This only needs to happen _once_ per Keyfactor Command instance.
-
-
-
-
-
#### Supported Operations
-| Operation | Is Supported |
-|--------------|------------------------------------------------------------------------------------------------------------------------|
-| Add | ✅ Checked |
-| Remove | ✅ Checked |
-| Discovery | 🔲 Unchecked |
+| Operation | Is Supported |
+|--------------|--------------|
+| Add | ✅ Checked |
+| Remove | ✅ Checked |
+| Discovery | 🔲 Unchecked |
| Reenrollment | 🔲 Unchecked |
-| Create | 🔲 Unchecked |
+| Create | 🔲 Unchecked |
#### Store Type Creation
##### Using kfutil:
`kfutil` is a custom CLI for the Keyfactor Command API and can be used to create certificate store types.
For more information on [kfutil](https://github.com/Keyfactor/kfutil) check out the [docs](https://github.com/Keyfactor/kfutil?tab=readme-ov-file#quickstart)
+
Click to expand Imperva kfutil details
##### Using online definition from GitHub:
@@ -96,10 +89,10 @@ For more information on [kfutil](https://github.com/Keyfactor/kfutil) check out
```
-
#### Manual Creation
Below are instructions on how to create the Imperva store type manually in
the Keyfactor Command Portal
+
Click to expand manual Imperva details
Create a store type called `Imperva` with the attributes in the tables below:
@@ -110,11 +103,11 @@ the Keyfactor Command Portal
| Name | Imperva | Display name for the store type (may be customized) |
| Short Name | Imperva | Short display name for the store type |
| Capability | Imperva | Store type name orchestrator will register with. Check the box to allow entry of value |
- | Supports Add | ✅ Checked | Check the box. Indicates that the Store Type supports Management Add |
- | Supports Remove | ✅ Checked | Check the box. Indicates that the Store Type supports Management Remove |
- | Supports Discovery | 🔲 Unchecked | Indicates that the Store Type supports Discovery |
- | Supports Reenrollment | 🔲 Unchecked | Indicates that the Store Type supports Reenrollment |
- | Supports Create | 🔲 Unchecked | Indicates that the Store Type supports store creation |
+ | Supports Add | ✅ Checked | Indicates that the Store Type supports Management Add |
+ | Supports Remove | ✅ Checked | Indicates that the Store Type supports Management Remove |
+ | Supports Discovery | 🔲 Unchecked | Indicates that the Store Type supports Discovery |
+ | Supports Reenrollment | 🔲 Unchecked | Indicates that the Store Type supports Reenrollment |
+ | Supports Create | 🔲 Unchecked | Indicates that the Store Type supports store creation |
| Needs Server | 🔲 Unchecked | Determines if a target server name is required when creating store |
| Blueprint Allowed | 🔲 Unchecked | Determines if store type may be included in an Orchestrator blueprint |
| Uses PowerShell | 🔲 Unchecked | Determines if underlying implementation is PowerShell |
@@ -123,18 +116,18 @@ the Keyfactor Command Portal
The Basic tab should look like this:
- 
+ 
##### Advanced Tab
| Attribute | Value | Description |
| --------- | ----- | ----- |
| Supports Custom Alias | Required | Determines if an individual entry within a store can have a custom Alias. |
- | Private Key Handling | Required | This determines if Keyfactor can send the private key associated with a certificate to the store. Required because IIS certificates without private keys would be invalid. |
+ | Private Key Handling | Required | This determines if Keyfactor can send the private key associated with a certificate to the store. |
| PFX Password Style | Default | 'Default' - PFX password is randomly generated, 'Custom' - PFX password may be specified when the enrollment job is created (Requires the Allow Custom Password application setting to be enabled.) |
The Advanced tab should look like this:
- 
+ 
> For Keyfactor **Command versions 24.4 and later**, a Certificate Format dropdown is available with PFX and PEM options. Ensure that **PFX** is selected, as this determines the format of new and renewed certificates sent to the Orchestrator during a Management job. Currently, all Keyfactor-supported Orchestrator extensions support only PFX.
@@ -146,10 +139,7 @@ the Keyfactor Command Portal
The Custom Fields tab should look like this:
- 
-
-
-
+ 
@@ -157,18 +147,17 @@ the Keyfactor Command Portal
1. **Download the latest Imperva Universal Orchestrator extension from GitHub.**
- Navigate to the [Imperva Universal Orchestrator extension GitHub version page](https://github.com/Keyfactor/imperva-orchestrator/releases/latest). Refer to the compatibility matrix below to determine the asset should be downloaded. Then, click the corresponding asset to download the zip archive.
+ Navigate to the [Imperva Universal Orchestrator extension GitHub version page](https://github.com/Keyfactor/imperva-orchestrator/releases/latest). Refer to the compatibility matrix below to determine which asset should be downloaded. Then, click the corresponding asset to download the zip archive.
| Universal Orchestrator Version | Latest .NET version installed on the Universal Orchestrator server | `rollForward` condition in `Orchestrator.runtimeconfig.json` | `imperva-orchestrator` .NET version to download |
| --------- | ----------- | ----------- | ----------- |
- | Older than `11.0.0` | | | `net6.0` |
- | Between `11.0.0` and `11.5.1` (inclusive) | `net6.0` | | `net6.0` |
- | Between `11.0.0` and `11.5.1` (inclusive) | `net8.0` | `Disable` | `net6.0` || Between `11.0.0` and `11.5.1` (inclusive) | `net8.0` | `LatestMajor` | `net8.0` |
- | `11.6` _and_ newer | `net8.0` | | `net8.0` |
+ | Between `11.0.0` and `11.5.1` (inclusive) | `net8.0` | `LatestMajor` | `net8.0` |
+ | `11.6` _and_ newer | `net8.0` | | `net8.0` |
+ | `25.5` _and_ newer | `net10.0` | | `net10.0` |
Unzip the archive containing extension assemblies to a known location.
- > **Note** If you don't see an asset with a corresponding .NET version, you should always assume that it was compiled for `net6.0`.
+ > **Note** If you don't see an asset with a corresponding .NET version, you should always assume that it was compiled for `net10.0`.
2. **Locate the Universal Orchestrator extensions directory.**
@@ -186,22 +175,16 @@ the Keyfactor Command Portal
Refer to [Starting/Restarting the Universal Orchestrator service](https://software.keyfactor.com/Core-OnPrem/Current/Content/InstallingAgents/NetCoreOrchestrator/StarttheService.htm).
-
6. **(optional) PAM Integration**
The Imperva Universal Orchestrator extension is compatible with all supported Keyfactor PAM extensions to resolve PAM-eligible secrets. PAM extensions running on Universal Orchestrators enable secure retrieval of secrets from a connected PAM provider.
To configure a PAM provider, [reference the Keyfactor Integration Catalog](https://keyfactor.github.io/integrations-catalog/content/pam) to select an extension and follow the associated instructions to install it on the Universal Orchestrator (remote).
-
> The above installation steps can be supplemented by the [official Command documentation](https://software.keyfactor.com/Core-OnPrem/Current/Content/InstallingAgents/NetCoreOrchestrator/CustomExtensions.htm?Highlight=extensions).
-
-
## Defining Certificate Stores
-
-
### Store Creation
#### Manually with the Command UI
@@ -216,8 +199,8 @@ the Keyfactor Command Portal
Click the Add button to add a new Certificate Store. Use the table below to populate the **Attributes** in the **Add** form.
- | Attribute | Description |
- | --------- |---------------------------------------------------------|
+ | Attribute | Description |
+ | --------- | ----------- |
| Category | Select "Imperva" or the customized certificate store name from the previous step. |
| Container | Optional container to associate certificate store with. |
| Client Machine | The URL that will be used as the base URL for Imperva endpoint calls. Should be https://my.imperva.com |
@@ -227,8 +210,6 @@ the Keyfactor Command Portal
-
-
#### Using kfutil CLI
Click to expand details
@@ -259,7 +240,6 @@ the Keyfactor Command Portal
-
#### PAM Provider Eligible Fields
Attributes eligible for retrieval by a PAM Provider on the Universal Orchestrator
@@ -267,24 +247,20 @@ If a PAM provider was installed _on the Universal Orchestrator_ in the [Installa
| Attribute | Description |
| --------- | ----------- |
- | StorePassword | Your Imperva API id and API key concatenated with a comma (,}. For example: 12345,12345678-1234-1234-1234-123456789ABC. Please refer to the [Imperva documentation](https://docs.imperva.com/bundle/cloud-application-security/page/settings/api-keys.htm#:~:text=In%20the%20Cloud%20Security%20Console%20top%20menu%20bar%2C%20click%20Account,to%20create%20a%20new%20key.) as to how to create an API id and key. |
+ | StorePassword | Password to use when reading/writing to store |
Please refer to the **Universal Orchestrator (remote)** usage section ([PAM providers on the Keyfactor Integration Catalog](https://keyfactor.github.io/integrations-catalog/content/pam)) for your selected PAM provider for instructions on how to load attributes orchestrator-side.
> Any secret can be rendered by a PAM provider _installed on the Keyfactor Command server_. The above parameters are specific to attributes that can be fetched by an installed PAM provider running on the Universal Orchestrator server itself.
-
> The content in this section can be supplemented by the [official Command documentation](https://software.keyfactor.com/Core-OnPrem/Current/Content/ReferenceGuide/Certificate%20Stores.htm?Highlight=certificate%20store).
-
-
-
## License
Apache License 2.0, see [LICENSE](LICENSE).
## Related Integrations
-See all [Keyfactor Universal Orchestrator extensions](https://github.com/orgs/Keyfactor/repositories?q=orchestrator).
\ No newline at end of file
+See all [Keyfactor Universal Orchestrator extensions](https://github.com/orgs/Keyfactor/repositories?q=orchestrator).
diff --git a/docsource/images/Imperva-advanced-store-type-dialog.svg b/docsource/images/Imperva-advanced-store-type-dialog.svg
new file mode 100644
index 0000000..123a979
--- /dev/null
+++ b/docsource/images/Imperva-advanced-store-type-dialog.svg
@@ -0,0 +1,67 @@
+
+
\ No newline at end of file
diff --git a/docsource/images/Imperva-basic-store-type-dialog.svg b/docsource/images/Imperva-basic-store-type-dialog.svg
new file mode 100644
index 0000000..2435418
--- /dev/null
+++ b/docsource/images/Imperva-basic-store-type-dialog.svg
@@ -0,0 +1,83 @@
+
+
\ No newline at end of file
diff --git a/docsource/images/Imperva-custom-fields-store-type-dialog.svg b/docsource/images/Imperva-custom-fields-store-type-dialog.svg
new file mode 100644
index 0000000..f2ed3ac
--- /dev/null
+++ b/docsource/images/Imperva-custom-fields-store-type-dialog.svg
@@ -0,0 +1,46 @@
+
+
\ No newline at end of file
diff --git a/scripts/store_types/bash/curl_create_store_types.sh b/scripts/store_types/bash/curl_create_store_types.sh
index 60cd525..38746d5 100755
--- a/scripts/store_types/bash/curl_create_store_types.sh
+++ b/scripts/store_types/bash/curl_create_store_types.sh
@@ -1,78 +1,20 @@
-#!/usr/bin/env bash
-
-# Creates all 1 store types via the Keyfactor Command REST API using curl.
-#
-# Authentication (first matching method is used):
-# OAuth access token: KEYFACTOR_AUTH_ACCESS_TOKEN
-# OAuth client creds: KEYFACTOR_AUTH_CLIENT_ID + KEYFACTOR_AUTH_CLIENT_SECRET
-# + KEYFACTOR_AUTH_TOKEN_URL
-# Basic auth (AD): KEYFACTOR_USERNAME + KEYFACTOR_PASSWORD + KEYFACTOR_DOMAIN
-#
-# Always required:
-# KEYFACTOR_HOSTNAME Command hostname (e.g. my-command.example.com)
-#
-# Auto-generated by doctool generate-store-type-scripts — do not edit by hand.
-
-if [ -z "${KEYFACTOR_HOSTNAME}" ]; then
- echo "ERROR: KEYFACTOR_HOSTNAME is required"
- exit 1
-fi
-
-BASE_URL="https://${KEYFACTOR_HOSTNAME}/keyfactorapi"
-
-# ---------------------------------------------------------------------------
-# Resolve auth
-# ---------------------------------------------------------------------------
-if [ -n "${KEYFACTOR_AUTH_ACCESS_TOKEN}" ]; then
- BEARER_TOKEN="${KEYFACTOR_AUTH_ACCESS_TOKEN}"
-elif [ -n "${KEYFACTOR_AUTH_CLIENT_ID}" ] && [ -n "${KEYFACTOR_AUTH_CLIENT_SECRET}" ] && [ -n "${KEYFACTOR_AUTH_TOKEN_URL}" ]; then
- echo "Fetching OAuth token..."
- BEARER_TOKEN=$(curl -s -X POST "${KEYFACTOR_AUTH_TOKEN_URL}" \
- -H "Content-Type: application/x-www-form-urlencoded" \
- --data-urlencode "grant_type=client_credentials" \
- --data-urlencode "client_id=${KEYFACTOR_AUTH_CLIENT_ID}" \
- --data-urlencode "client_secret=${KEYFACTOR_AUTH_CLIENT_SECRET}" | jq -r '.access_token')
- if [ -z "${BEARER_TOKEN}" ] || [ "${BEARER_TOKEN}" = "null" ]; then
- echo "ERROR: Failed to fetch OAuth token from ${KEYFACTOR_AUTH_TOKEN_URL}"
- exit 1
- fi
-elif [ -n "${KEYFACTOR_USERNAME}" ] && [ -n "${KEYFACTOR_PASSWORD}" ] && [ -n "${KEYFACTOR_DOMAIN}" ]; then
- BEARER_TOKEN=""
-else
- echo "ERROR: Authentication required. Set one of:"
- echo " KEYFACTOR_AUTH_ACCESS_TOKEN"
- echo " KEYFACTOR_AUTH_CLIENT_ID + KEYFACTOR_AUTH_CLIENT_SECRET + KEYFACTOR_AUTH_TOKEN_URL"
- echo " KEYFACTOR_USERNAME + KEYFACTOR_PASSWORD + KEYFACTOR_DOMAIN"
- exit 1
-fi
-
-if [ -n "${BEARER_TOKEN}" ]; then
- CURL_AUTH=("-H" "Authorization: Bearer ${BEARER_TOKEN}")
-else
- CURL_AUTH=("-u" "${KEYFACTOR_USERNAME}@${KEYFACTOR_DOMAIN}:${KEYFACTOR_PASSWORD}")
-fi
-
-create_store_type() {
- local name="$1"
- local body="$2"
- echo "Creating ${name} store type..."
- response=$(curl -s -o /dev/null -w "%{http_code}" \
- -X POST "${BASE_URL}/certificatestoretypes" \
- -H "Content-Type: application/json" \
- -H "x-keyfactor-requested-with: APIClient" \
- "${CURL_AUTH[@]}" \
- -d "${body}")
- if [ "$response" = "200" ] || [ "$response" = "201" ]; then
- echo " OK (HTTP ${response})"
- else
- echo " FAILED (HTTP ${response})"
- fi
-}
-
-# ---------------------------------------------------------------------------
-# Imperva — The URL that will be used as the base URL for Imperva endpoint calls. Should be https://my.imperva.com
-# ---------------------------------------------------------------------------
-create_store_type "Imperva" '{
+#!/bin/bash
+# Store Type creation script using curl
+# Generated by Doctool
+
+set -e
+
+# Configuration - set these variables before running
+KEYFACTOR_HOSTNAME="${KEYFACTOR_HOSTNAME}"
+KEYFACTOR_API_PATH="${KEYFACTOR_API_PATH:-KeyfactorAPI}"
+KEYFACTOR_AUTH_TOKEN="${KEYFACTOR_AUTH_TOKEN}"
+
+echo "Creating store type: Imperva"
+curl -s -X POST "https://${KEYFACTOR_HOSTNAME}/${KEYFACTOR_API_PATH}/CertificateStoreTypes" \
+ -H "Authorization: Bearer ${KEYFACTOR_AUTH_TOKEN}" \
+ -H "Content-Type: application/json" \
+ -H "x-keyfactor-requested-with: APIClient" \
+ -d '{
"Name": "Imperva",
"ShortName": "Imperva",
"Capability": "Imperva",
@@ -98,9 +40,6 @@ create_store_type "Imperva" '{
}
},
"Properties": [],
- "EntryParameters": [],
- "StorePathDescription": "Your Imperva account id. Please refer to the [Imperva documentation](https://docs.imperva.com/howto/bd68301b) as to how to find your Imperva account id."
+ "EntryParameters": []
}'
-
-echo "Completed."
diff --git a/scripts/store_types/bash/kfutil_create_store_types.sh b/scripts/store_types/bash/kfutil_create_store_types.sh
index 9c0558f..64530bb 100755
--- a/scripts/store_types/bash/kfutil_create_store_types.sh
+++ b/scripts/store_types/bash/kfutil_create_store_types.sh
@@ -1,28 +1,9 @@
-#!/usr/bin/env bash
+#!/bin/bash
+# Store Type creation script using kfutil
+# Generated by Doctool
-# Creates all 1 store types using kfutil.
-# kfutil reads definitions from the Keyfactor integration catalog.
-#
-# Auth environment variables (first matching method is used):
-# OAuth access token: KEYFACTOR_AUTH_ACCESS_TOKEN
-# OAuth client creds: KEYFACTOR_AUTH_CLIENT_ID + KEYFACTOR_AUTH_CLIENT_SECRET
-# + KEYFACTOR_AUTH_TOKEN_URL
-# Basic auth (AD): KEYFACTOR_HOSTNAME + KEYFACTOR_USERNAME + KEYFACTOR_PASSWORD
-# + KEYFACTOR_DOMAIN
-#
-# Auto-generated by doctool generate-store-type-scripts — do not edit by hand.
+set -e
-if ! command -v kfutil &> /dev/null; then
- echo "kfutil could not be found. Please install kfutil"
- echo "See https://github.com/Keyfactor/kfutil#quickstart"
- exit 1
-fi
+echo "Creating store type: Imperva"
+kfutil store-types create Imperva
-if [ -z "$KEYFACTOR_HOSTNAME" ]; then
- echo "KEYFACTOR_HOSTNAME not set — launching kfutil login"
- kfutil login
-fi
-
-kfutil store-types create --name "Imperva"
-
-echo "Done. All store types created."
diff --git a/scripts/store_types/powershell/kfutil_create_store_types.ps1 b/scripts/store_types/powershell/kfutil_create_store_types.ps1
index ada0c3e..4f8f7a7 100644
--- a/scripts/store_types/powershell/kfutil_create_store_types.ps1
+++ b/scripts/store_types/powershell/kfutil_create_store_types.ps1
@@ -1,29 +1,6 @@
-# Creates all 1 store types using kfutil.
-# kfutil reads definitions from the Keyfactor integration catalog.
-#
-# Auth environment variables (first matching method is used):
-# OAuth access token: KEYFACTOR_AUTH_ACCESS_TOKEN
-# OAuth client creds: KEYFACTOR_AUTH_CLIENT_ID + KEYFACTOR_AUTH_CLIENT_SECRET
-# + KEYFACTOR_AUTH_TOKEN_URL
-# Basic auth (AD): KEYFACTOR_HOSTNAME + KEYFACTOR_USERNAME + KEYFACTOR_PASSWORD
-# + KEYFACTOR_DOMAIN
-#
-# Auto-generated by doctool generate-store-type-scripts — do not edit by hand.
+# Store Type creation script using kfutil
+# Generated by Doctool
-# Uncomment if kfutil is not in your PATH
-# Set-Alias -Name kfutil -Value 'C:\Program Files\Keyfactor\kfutil\kfutil.exe'
+Write-Host "Creating store type: Imperva"
+kfutil store-types create Imperva
-if ($null -eq (Get-Command "kfutil" -ErrorAction SilentlyContinue)) {
- Write-Host "kfutil could not be found. Please install kfutil"
- Write-Host "See https://github.com/Keyfactor/kfutil#quickstart"
- exit 1
-}
-
-if (-not $env:KEYFACTOR_HOSTNAME) {
- Write-Host "KEYFACTOR_HOSTNAME not set — launching kfutil login"
- & kfutil login
-}
-
-& kfutil store-types create --name "Imperva"
-
-Write-Host "Done. All store types created."
diff --git a/scripts/store_types/powershell/restmethod_create_store_types.ps1 b/scripts/store_types/powershell/restmethod_create_store_types.ps1
index 9fbe64c..b33a881 100644
--- a/scripts/store_types/powershell/restmethod_create_store_types.ps1
+++ b/scripts/store_types/powershell/restmethod_create_store_types.ps1
@@ -1,70 +1,19 @@
-# Creates all 1 store types via the Keyfactor Command REST API
-# using PowerShell Invoke-RestMethod.
-#
-# Authentication (first matching method is used):
-# OAuth access token: KEYFACTOR_AUTH_ACCESS_TOKEN
-# OAuth client creds: KEYFACTOR_AUTH_CLIENT_ID + KEYFACTOR_AUTH_CLIENT_SECRET
-# + KEYFACTOR_AUTH_TOKEN_URL
-# Basic auth (AD): KEYFACTOR_USERNAME + KEYFACTOR_PASSWORD + KEYFACTOR_DOMAIN
-#
-# Always required:
-# KEYFACTOR_HOSTNAME Command hostname (e.g. my-command.example.com)
-#
-# Auto-generated by doctool generate-store-type-scripts — do not edit by hand.
+# Store Type creation script using Invoke-RestMethod
+# Generated by Doctool
-if (-not $env:KEYFACTOR_HOSTNAME) {
- Write-Error "KEYFACTOR_HOSTNAME is required"
- exit 1
-}
-
-$uri = "https://$($env:KEYFACTOR_HOSTNAME)/keyfactorapi/certificatestoretypes"
-$headers = @{
- 'Content-Type' = "application/json"
- 'x-keyfactor-requested-with' = "APIClient"
-}
+# Configuration - set these variables before running
+$KeyfactorHostname = $env:KEYFACTOR_HOSTNAME
+$KeyfactorApiPath = if ($env:KEYFACTOR_API_PATH) { $env:KEYFACTOR_API_PATH } else { "KeyfactorAPI" }
+$KeyfactorAuthToken = $env:KEYFACTOR_AUTH_TOKEN
-# ---------------------------------------------------------------------------
-# Resolve auth
-# ---------------------------------------------------------------------------
-if ($env:KEYFACTOR_AUTH_ACCESS_TOKEN) {
- $headers['Authorization'] = "Bearer $($env:KEYFACTOR_AUTH_ACCESS_TOKEN)"
-} elseif ($env:KEYFACTOR_AUTH_CLIENT_ID -and $env:KEYFACTOR_AUTH_CLIENT_SECRET -and $env:KEYFACTOR_AUTH_TOKEN_URL) {
- Write-Host "Fetching OAuth token..."
- $tokenBody = @{
- grant_type = 'client_credentials'
- client_id = $env:KEYFACTOR_AUTH_CLIENT_ID
- client_secret = $env:KEYFACTOR_AUTH_CLIENT_SECRET
- }
- $tokenResp = Invoke-RestMethod -Method Post -Uri $env:KEYFACTOR_AUTH_TOKEN_URL -Body $tokenBody
- $headers['Authorization'] = "Bearer $($tokenResp.access_token)"
-} elseif ($env:KEYFACTOR_USERNAME -and $env:KEYFACTOR_PASSWORD -and $env:KEYFACTOR_DOMAIN) {
- $cred = [System.Convert]::ToBase64String(
- [System.Text.Encoding]::ASCII.GetBytes(
- "$($env:KEYFACTOR_USERNAME)@$($env:KEYFACTOR_DOMAIN):$($env:KEYFACTOR_PASSWORD)"))
- $headers['Authorization'] = "Basic $cred"
-} else {
- Write-Error ("Authentication required. Set one of:`n" +
- " KEYFACTOR_AUTH_ACCESS_TOKEN`n" +
- " KEYFACTOR_AUTH_CLIENT_ID + KEYFACTOR_AUTH_CLIENT_SECRET + KEYFACTOR_AUTH_TOKEN_URL`n" +
- " KEYFACTOR_USERNAME + KEYFACTOR_PASSWORD + KEYFACTOR_DOMAIN")
- exit 1
-}
-
-function New-StoreType {
- param([string]$Name, [string]$Body)
- Write-Host "Creating $Name store type..."
- try {
- Invoke-RestMethod -Method Post -Uri $uri -Headers $headers -Body $Body -ContentType "application/json" | Out-Null
- Write-Host " OK"
- } catch {
- Write-Warning " FAILED: $($_.Exception.Message)"
- }
+$Headers = @{
+ "Authorization" = "Bearer $KeyfactorAuthToken"
+ "Content-Type" = "application/json"
+ "x-keyfactor-requested-with" = "APIClient"
}
-# ---------------------------------------------------------------------------
-# Imperva — The URL that will be used as the base URL for Imperva endpoint calls. Should be https://my.imperva.com
-# ---------------------------------------------------------------------------
-New-StoreType "Imperva" @'
+Write-Host "Creating store type: Imperva"
+$Body = @'
{
"Name": "Imperva",
"ShortName": "Imperva",
@@ -91,10 +40,9 @@ New-StoreType "Imperva" @'
}
},
"Properties": [],
- "EntryParameters": [],
- "StorePathDescription": "Your Imperva account id. Please refer to the [Imperva documentation](https://docs.imperva.com/howto/bd68301b) as to how to find your Imperva account id."
+ "EntryParameters": []
}
'@
+Invoke-RestMethod -Uri "https://$KeyfactorHostname/$KeyfactorApiPath/CertificateStoreTypes" -Method POST -Headers $Headers -Body $Body
-Write-Host "Completed."