| Port details |
- dogtag-pki Dogtag PKI certificate system and server components
- 11.10.1_2 security
=0 Package not present on quarterly.This port was created during this quarter. It will be in the next quarterly branch but not the current one. - Maintainer: joneum@FreeBSD.org
 - Port Added: 2026-07-04 20:09:10
- Last Update: 2026-09-10 19:50:33
- Commit Hash: 2c0f173
- Also Listed In: java python
- License: GPLv2
- WWW:
- https://github.com/dogtagpki/pki
- Description:
- Dogtag PKI is an enterprise-class open source Certificate Authority (CA).
It supports all aspects of certificate lifecycle management, including key
archival, OCSP, and smartcard management.
This port provides the Certificate Authority (CA) subsystem running on
Apache Tomcat, the pki command line interface, the pkispawn/pkidestroy
deployment tools, and the Python client and server modules for
administering Dogtag PKI certificate services.
¦ ¦ ¦ ¦ 
- Manual pages:
- FreshPorts has no man page information for this port.
- pkg-plist: as obtained via:
make generate-plist - There is no configure plist information for this port.
- USE_RC_SUBR (Service Scripts)
- no SUBR information found for this port
- Dependency lines:
-
- dogtag-pki>0:security/dogtag-pki
- To install the port:
- cd /usr/ports/security/dogtag-pki/ && make install clean
- To add the package, run one of these commands:
- pkg install security/dogtag-pki
- pkg install dogtag-pki
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.- PKGNAME: dogtag-pki
- Package flavors (<flavor>: <package>)
- distinfo:
- TIMESTAMP = 1787132683
SHA256 (dogtagpki-pki-v11.10.1_GH0.tar.gz) = dfd7bbabda5313b13f6c38cbdfce650ccbb053b5b1b03e1f5bda7d23ed01986c
SIZE (dogtagpki-pki-v11.10.1_GH0.tar.gz) = 10417315
Packages (timestamps in pop-ups are UTC):
- Dependencies
- NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
- Build dependencies:
-
- commons-cli.jar : java/apache-commons-cli
- commons-codec.jar : java/apache-commons-codec
- commons-io.jar : devel/apache-commons-io
- commons-lang3.jar : java/apache-commons-lang3
- commons-logging.jar : java/apache-commons-logging
- commons-net.jar : net/apache-commons-net
- httpclient.jar : www/httpclient
- httpcore.jar : www/httpcore
- jackson-annotations.jar : devel/jackson-annotations
- jackson-core.jar : devel/jackson-core
- jackson-databind.jar : devel/jackson-databind
- jackson-jaxrs-json-provider.jar : devel/jackson-jaxrs-providers
- jackson-module-jaxb-annotations.jar : devel/jackson-module-jaxb-annotations
- jakarta.activation-api.jar : devel/jakarta-activation-api
- jakarta.annotation-api.jar : devel/jakarta-annotation-api
- jakarta.xml.bind-api.jar : devel/jakarta-xml-bind-api
- javax.ws.rs-api.jar : devel/javax-ws-rs-api
- javax.activation-api.jar : devel/javax-activation-api
- jaxb-api.jar : devel/jaxb-api
- jboss-logging.jar : devel/jboss-logging
- dogtag-jss>=5.7.0 : security/dogtag-jss
- ldapjdk.jar : net/dogtag-ldap-sdk
- resteasy-servlet-initializer.jar : devel/resteasy
- slf4j-api.jar : devel/slf4j
- jaspic-api.jar : www/tomcat9
- servlet-api.jar : www/tomcat9
- py312-setuptools>0 : devel/py-setuptools@py312
- py312-wheel>0 : devel/py-wheel@py312
- cmake : devel/cmake-core
- java : java/openjdk21
- pkgconf>=1.3.0_1 : devel/pkgconf
- python3.12 : lang/python312
- py312-build>=0 : devel/py-build@py312
- py312-installer>=0 : devel/py-installer@py312
- Test dependencies:
-
- python3.12 : lang/python312
- Runtime dependencies:
-
- commons-cli.jar : java/apache-commons-cli
- commons-codec.jar : java/apache-commons-codec
- commons-io.jar : devel/apache-commons-io
- commons-lang3.jar : java/apache-commons-lang3
- commons-logging.jar : java/apache-commons-logging
- commons-net.jar : net/apache-commons-net
- httpclient.jar : www/httpclient
- httpcore.jar : www/httpcore
- jackson-annotations.jar : devel/jackson-annotations
- jackson-core.jar : devel/jackson-core
- jackson-databind.jar : devel/jackson-databind
- jackson-jaxrs-json-provider.jar : devel/jackson-jaxrs-providers
- jackson-module-jaxb-annotations.jar : devel/jackson-module-jaxb-annotations
- jakarta.activation-api.jar : devel/jakarta-activation-api
- jakarta.annotation-api.jar : devel/jakarta-annotation-api
- jakarta.xml.bind-api.jar : devel/jakarta-xml-bind-api
- javax.ws.rs-api.jar : devel/javax-ws-rs-api
- javax.activation-api.jar : devel/javax-activation-api
- jaxb-api.jar : devel/jaxb-api
- jboss-logging.jar : devel/jboss-logging
- dogtag-jss>=5.7.0 : security/dogtag-jss
- ldapjdk.jar : net/dogtag-ldap-sdk
- resteasy-servlet-initializer.jar : devel/resteasy
- slf4j-api.jar : devel/slf4j
- catalina.sh : www/tomcat9
- p11-kit-trust.so : security/p11-kit
- py312-cryptography>0 : security/py-cryptography@py312
- py312-lxml>0 : devel/py-lxml@py312
- py312-python-ldap>0 : net/py-python-ldap@py312
- py312-requests>0 : www/py-requests@py312
- py312-six>0 : devel/py-six@py312
- bash : shells/bash
- java : java/openjdk21
- python3.12 : lang/python312
- Library dependencies:
-
- libapr-1.so : devel/apr1
- libnspr4.so : devel/nspr
- libnss3.so : security/nss
- libldap.so.2 : net/openldap26-client
- This port is required by:
- for Run
-
- net/freeipa-server
Configuration Options:
- No options to configure
- Options name:
- security_dogtag-pki
- USES:
- cmake:indirect cpe java:build,run ldap pkgconfig python shebangfix
- FreshPorts was unable to extract/find any pkg message
- Master Sites:
|
| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
11.10.1_2 10 Sep 2026 19:50:33
    |
Jochen Neumeister (joneum)  |
security/dogtag-pki: Add CPE information
Sponsored by: Netzkommune GmbH |
11.10.1_2 04 Sep 2026 14:31:48
    |
Jochen Neumeister (joneum)  |
security/dogtag-pki: Set the boot flag with sysrc
create_rc_service() wrote <instance>_enable="YES" into rc.conf.d, which is
read after rc.conf and therefore overrode sysrc. The instance started at boot
whatever the administrator had set, and under FreeIPA it came up before the
Directory Server it needs. The flag now goes to rc.conf through sysrc.
Sponsored by: Netzkommune GmbH |
11.10.1_1 23 Aug 2026 20:31:31
    |
Xin LI (delphij)  |
security/dogtag-pki: convert OpenLDAP dependency to USES=ldap
Replace hardcoded libldap.so:net/openldap26-client in LIB_DEPENDS
with USES=ldap, letting the framework handle version selection.
PR: ports/297779
Approved by: maintainer (joneum) |
11.10.1_1 23 Aug 2026 17:48:32
    |
Jochen Neumeister (joneum)  |
security/dogtag-pki: Fix incomplete javac classpath
base/tomcat-9.0 compiles against pki-common, whose classes carry
@JsonInclude, but does not list jackson-annotations, so javac cannot
resolve the annotation. Every other subproject already lists the jar.
Sponsored by: Netzkommune GmbH |
11.10.1 21 Aug 2026 05:42:35
    |
Jochen Neumeister (joneum)  |
security/dogtag-pki: Update to 11.10.1
Switch to Java 21.
Adapt the FreeBSD parts to the reworked upstream tree: guard the SELinux
import and its call sites, replace the remaining runuser call with
subprocess privilege switching, and pass APP_SERVER_CM through the
environment, which 11.10 reads instead of the CMake define.
Give pki-tomcatd a bounded stop. jsvc records the pid of its child in
the pidfile while the parent handles SIGTERM, and Tomcat can deadlock in
JSS while closing LDAP connections, so rc(8) would wait forever and
stall the system shutdown.
Changes: https://github.com/dogtagpki/pki/releases
Sponsored by: Netzkommune GmbH |
11.7.0_6 13 Aug 2026 08:58:48
    |
Jochen Neumeister (joneum)  |
security/dogtag-pki: bound the rc onestop call during pkidestroy
The Tomcat stop path called `service <instance> onestop` and blocked on
rc.subr's wait_for_pids() indefinitely when the jsvc/JVM did not exit
(e.g. a wedged webapp during pkidestroy). Bound the call with a timeout
and fall back to SIGKILL so pkidestroy/uninstall can never hang.
Sponsored by: Netzkommune GmbH |
11.7.0_5 06 Aug 2026 16:42:39
    |
Jochen Neumeister (joneum)  |
security/dogtag-pki: Enable ACME support and improve rc integration
Enable the ACME responder that was previously disabled in the port:
* Build with WITH_ACME and install the ACME webapp, configuration
templates (database, issuer, realm, engine), the pki-acme-run
script and pki-acme.jar
* Patch hardcoded Linux paths in the ACME components to their
FreeBSD locations (/usr/local/share/pki, /var/db/pki)
* Link jaxb-api.jar and javax.activation-api.jar into the server
common libs, required by the ACME webapp at runtime
Improve the FreeBSD rc.d integration:
* Generate java_opts and PKI_VERSION for the rc service directly
from the instance's tomcat.conf instead of referencing an
environment file
* Add remove_rc_service() to cleanly remove the rc script, the
service configuration and the rc.conf knob when an instance is
destroyed, and use it in the instance removal scriptlet
Sponsored by: Netzkommune GmbH |
11.7.0_4 21 Jul 2026 22:48:18
    |
Jochen Neumeister (joneum)  |
security/dogtag-pki: Rework server and CA packaging
* Add the Java 17 build for the Dogtag server and CA components.
* Install the Dogtag server, CA, Tomcat, tools and web application JARs.
* Add the Java, REST, LDAP, JSS and Tomcat dependencies required by
the server runtime.
* Install pkispawn, pkidestroy, pkidaemon and pki-server.
* Add the pkiuser user and group.
* Install the server and CA configuration templates, upgrade data,
registry files, web applications and runtime library links.
* Generate and install the Dogtag VERSION file.
* Adapt the server tools, configuration and Tomcat integration to the
FreeBSD filesystem layout.
* Replace systemd-specific service handling with FreeBSD rc.conf and
Tomcat multi-instance service support.
* Update pkg-plist for the expanded server and CA runtime.
Sponsored by: Netzkommune GmbH |
11.7.0_3 11 Jul 2026 17:50:43
    |
Jochen Neumeister (joneum)  |
security/dogtag-pki: Add pkiuser account
Create the pkiuser system account required by Dogtag PKI. |
11.7.0_2 11 Jul 2026 13:18:32
    |
Jochen Neumeister (joneum)  |
security/dogtag-pki: Fix PKI version file path
Read share/pki/VERSION from LOCALBASE instead of the Linux
/usr/share/pki path.
Sponsored by: Netzkommune GmbH |
11.7.0_1 11 Jul 2026 12:07:50
    |
Jochen Neumeister (joneum)  |
security/dogtag-pki: Install PKI version file
Install share/pki/VERSION so the Python pki module can determine
the Dogtag PKI specification version at runtime.
Sponsored by: Netzkommune GmbH |
11.7.0 04 Jul 2026 20:08:06
    |
Jochen Neumeister (joneum)  |
security/dogtag-pki: Add new Port
Dogtag PKI is an enterprise-class open source certificate system
providing Certificate Authority, Key Recovery Authority, OCSP,
and other PKI services.
This port installs the Dogtag PKI Python client and server modules.
It is required by the upcoming net/freeipa-server port.
WWW: https://www.dogtagpki.org/
Sponsored by: Netzkommune GmbH |