Allow adding/changing Jetty server certificates via REST API #2905
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Depends on openhab/openhab-distro#1383
This adds a REST resource to add/change the Jetty server certificate. An empty DTO resets the certificate to a self-signed certificate.
Originally I thought about a
WatchService
for certificate files but this seems unnecessary. If certificates are changed on a regular basis (like with Let's encrypt), it is easy to add a post-hook script that uses keytool to insert the certificates retrieved in the keystore. For changing long-term certificates, the REST API is enough.