notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photos
All times are UTC
Ukraine
The recently imposed "must be logged in" restriction is a response to increased bot traffic on the site. This affects search, commits, and vuxml pages.
Search engines are not blocked. Try using "site:www.freshports.org" and your search terms.
After the ports freeze to fix some stuff, the freeze is over. I have some work to do before FreshPorts can start processing commits again before it can start processing again. I've created an issue for that.
Port details
dogtag-pki Dogtag PKI certificate system and server components
11.10.1_2 security on this many watch lists=0 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout Package not present on quarterly.This port was created during this quarter. It will be in the next quarterly branch but not the current one.
Maintainer: joneum@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2026-07-04 20:09:10
Last Update: 2026-09-10 19:50:33
Commit Hash: 2c0f173
Also Listed In: java python
License: GPLv2
WWW:
https://github.com/dogtagpki/pki
Description:
Dogtag PKI is an enterprise-class open source Certificate Authority (CA). It supports all aspects of certificate lifecycle management, including key archival, OCSP, and smartcard management. This port provides the Certificate Authority (CA) subsystem running on Apache Tomcat, the pki command line interface, the pkispawn/pkidestroy deployment tools, and the Python client and server modules for administering Dogtag PKI certificate services.
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb - no subversion history for this port

Manual pages:
FreshPorts has no man page information for this port.
pkg-plist: as obtained via: make generate-plist
There is no configure plist information for this port.
USE_RC_SUBR (Service Scripts)
  • no SUBR information found for this port
Dependency lines:
  • dogtag-pki>0:security/dogtag-pki
To install the port:
cd /usr/ports/security/dogtag-pki/ && make install clean
To add the package, run one of these commands:
  • pkg install security/dogtag-pki
  • pkg install dogtag-pki
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: dogtag-pki
Package flavors (<flavor>: <package>)
  • py312: dogtag-pki
distinfo:
TIMESTAMP = 1787132683 SHA256 (dogtagpki-pki-v11.10.1_GH0.tar.gz) = dfd7bbabda5313b13f6c38cbdfce650ccbb053b5b1b03e1f5bda7d23ed01986c SIZE (dogtagpki-pki-v11.10.1_GH0.tar.gz) = 10417315

Packages (timestamps in pop-ups are UTC):
dogtag-pki
ABIaarch64amd64armv6armv7i386powerpcpowerpc64powerpc64le
FreeBSD:13:latest--n/an/an/an/an/an/a
FreeBSD:13:quarterly--n/an/an/an/an/an/a
FreeBSD:14:latest11.10.1_211.10.1_2--11.10.1_2---
FreeBSD:14:quarterly11.7.011.7.0--11.7.0---
FreeBSD:15:latest11.10.1_211.10.1_2n/a-n/an/a--
FreeBSD:15:quarterly11.7.011.7.0n/a-n/an/a--
FreeBSD:16:latest11.10.1_211.10.1_2n/a-n/an/a--
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Build dependencies:
  1. commons-cli.jar : java/apache-commons-cli
  2. commons-codec.jar : java/apache-commons-codec
  3. commons-io.jar : devel/apache-commons-io
  4. commons-lang3.jar : java/apache-commons-lang3
  5. commons-logging.jar : java/apache-commons-logging
  6. commons-net.jar : net/apache-commons-net
  7. httpclient.jar : www/httpclient
  8. httpcore.jar : www/httpcore
  9. jackson-annotations.jar : devel/jackson-annotations
  10. jackson-core.jar : devel/jackson-core
  11. jackson-databind.jar : devel/jackson-databind
  12. jackson-jaxrs-json-provider.jar : devel/jackson-jaxrs-providers
  13. jackson-module-jaxb-annotations.jar : devel/jackson-module-jaxb-annotations
  14. jakarta.activation-api.jar : devel/jakarta-activation-api
  15. jakarta.annotation-api.jar : devel/jakarta-annotation-api
  16. jakarta.xml.bind-api.jar : devel/jakarta-xml-bind-api
  17. javax.ws.rs-api.jar : devel/javax-ws-rs-api
  18. javax.activation-api.jar : devel/javax-activation-api
  19. jaxb-api.jar : devel/jaxb-api
  20. jboss-logging.jar : devel/jboss-logging
  21. dogtag-jss>=5.7.0 : security/dogtag-jss
  22. ldapjdk.jar : net/dogtag-ldap-sdk
  23. resteasy-servlet-initializer.jar : devel/resteasy
  24. slf4j-api.jar : devel/slf4j
  25. jaspic-api.jar : www/tomcat9
  26. servlet-api.jar : www/tomcat9
  27. py312-setuptools>0 : devel/py-setuptools@py312
  28. py312-wheel>0 : devel/py-wheel@py312
  29. cmake : devel/cmake-core
  30. java : java/openjdk21
  31. pkgconf>=1.3.0_1 : devel/pkgconf
  32. python3.12 : lang/python312
  33. py312-build>=0 : devel/py-build@py312
  34. py312-installer>=0 : devel/py-installer@py312
Test dependencies:
  1. python3.12 : lang/python312
Runtime dependencies:
  1. commons-cli.jar : java/apache-commons-cli
  2. commons-codec.jar : java/apache-commons-codec
  3. commons-io.jar : devel/apache-commons-io
  4. commons-lang3.jar : java/apache-commons-lang3
  5. commons-logging.jar : java/apache-commons-logging
  6. commons-net.jar : net/apache-commons-net
  7. httpclient.jar : www/httpclient
  8. httpcore.jar : www/httpcore
  9. jackson-annotations.jar : devel/jackson-annotations
  10. jackson-core.jar : devel/jackson-core
  11. jackson-databind.jar : devel/jackson-databind
  12. jackson-jaxrs-json-provider.jar : devel/jackson-jaxrs-providers
  13. jackson-module-jaxb-annotations.jar : devel/jackson-module-jaxb-annotations
  14. jakarta.activation-api.jar : devel/jakarta-activation-api
  15. jakarta.annotation-api.jar : devel/jakarta-annotation-api
  16. jakarta.xml.bind-api.jar : devel/jakarta-xml-bind-api
  17. javax.ws.rs-api.jar : devel/javax-ws-rs-api
  18. javax.activation-api.jar : devel/javax-activation-api
  19. jaxb-api.jar : devel/jaxb-api
  20. jboss-logging.jar : devel/jboss-logging
  21. dogtag-jss>=5.7.0 : security/dogtag-jss
  22. ldapjdk.jar : net/dogtag-ldap-sdk
  23. resteasy-servlet-initializer.jar : devel/resteasy
  24. slf4j-api.jar : devel/slf4j
  25. catalina.sh : www/tomcat9
  26. p11-kit-trust.so : security/p11-kit
  27. py312-cryptography>0 : security/py-cryptography@py312
  28. py312-lxml>0 : devel/py-lxml@py312
  29. py312-python-ldap>0 : net/py-python-ldap@py312
  30. py312-requests>0 : www/py-requests@py312
  31. py312-six>0 : devel/py-six@py312
  32. bash : shells/bash
  33. java : java/openjdk21
  34. python3.12 : lang/python312
Library dependencies:
  1. libapr-1.so : devel/apr1
  2. libnspr4.so : devel/nspr
  3. libnss3.so : security/nss
  4. libldap.so.2 : net/openldap26-client
This port is required by:
for Run
  1. net/freeipa-server

Configuration Options:
No options to configure
Options name:
security_dogtag-pki
USES:
cmake:indirect cpe java:build,run ldap pkgconfig python shebangfix
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (1 items)
Collapse this list.
  1. https://codeload.github.com/dogtagpki/pki/tar.gz/v11.10.1?dummy=/
Collapse this list.
Notes from UPDATING
These upgrade notes are taken from /usr/ports/UPDATING
  • 2026-08-19
    Affects: users of net/freeipa-server and security/dogtag-pki
    Author: joneum@FreeBSD.org
    Reason: 
      net/freeipa-server has been updated to 4.13.2, which also brings
      security/dogtag-pki 11.10.1.  Two of the changes concern the configuration
      of an already deployed pki-tomcat instance, which no package may rewrite:
      dogtag-pki now builds with Java 21 instead of Java 17, and FreeIPA
      corrects the ACME paths, which used to point at the Linux location
      /etc/pki.  A server installed from scratch needs none of this.  On an
      existing one run the following as root, in this order:
    
        # ipactl stop
        # pkg upgrade
        # sysrc -f /etc/rc.conf.d/pki_tomcatd_pki_tomcat \
            pki_tomcatd_pki_tomcat_java_home=/usr/local/openjdk21
        # sed -i '' -e 's|/usr/local/openjdk17|/usr/local/openjdk21|' \
            /var/db/pki/pki-tomcat/conf/tomcat.conf
        # sed -i '' -e 's|/etc/pki/pki-tomcat/|/var/db/pki/pki-tomcat/conf/|g' \
            /var/db/pki/pki-tomcat/conf/acme/database.conf \
            /var/db/pki/pki-tomcat/conf/acme/realm.conf \
            /var/db/pki/pki-tomcat/conf/acme/configsources.conf
        # ipa-server-upgrade
        # ipactl status
    
      The last command has to list all seven services as RUNNING, and neither of
      these two checks may print anything:
    
        # grep openjdk17 /etc/rc.conf.d/pki_tomcatd_pki_tomcat \
            /var/db/pki/pki-tomcat/conf/tomcat.conf
        # grep -r /etc/pki /var/db/pki/pki-tomcat/conf/acme
    
      A missed JDK change makes pki-tomcatd fail with "UnsupportedClassVersion-
      Error: class file version 65.0"; missed ACME paths keep the ACME web
      application from starting, which in turn blocks the shutdown of
      pki-tomcatd.
    
    

Number of commits found: 12

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
11.10.1_2
10 Sep 2026 19:50:33
commit hash: 2c0f1733ef5223a52b61de0a78c7e1de2b2ac87bcommit hash: 2c0f1733ef5223a52b61de0a78c7e1de2b2ac87bcommit hash: 2c0f1733ef5223a52b61de0a78c7e1de2b2ac87bcommit hash: 2c0f1733ef5223a52b61de0a78c7e1de2b2ac87b files touched by this commit
Jochen Neumeister (joneum) search for other commits by this committer
security/dogtag-pki: Add CPE information

Sponsored by: Netzkommune GmbH
11.10.1_2
04 Sep 2026 14:31:48
commit hash: 26394c900fb6bd86dc9ab7021dab2f935efb1817commit hash: 26394c900fb6bd86dc9ab7021dab2f935efb1817commit hash: 26394c900fb6bd86dc9ab7021dab2f935efb1817commit hash: 26394c900fb6bd86dc9ab7021dab2f935efb1817 files touched by this commit
Jochen Neumeister (joneum) search for other commits by this committer
security/dogtag-pki: Set the boot flag with sysrc

create_rc_service() wrote <instance>_enable="YES" into rc.conf.d, which is
read after rc.conf and therefore overrode sysrc. The instance started at boot
whatever the administrator had set, and under FreeIPA it came up before the
Directory Server it needs. The flag now goes to rc.conf through sysrc.

Sponsored by:	Netzkommune GmbH
11.10.1_1
23 Aug 2026 20:31:31
commit hash: 086564f40cbe516359b9a1b735a314f7cb55ef93commit hash: 086564f40cbe516359b9a1b735a314f7cb55ef93commit hash: 086564f40cbe516359b9a1b735a314f7cb55ef93commit hash: 086564f40cbe516359b9a1b735a314f7cb55ef93 files touched by this commit
Xin LI (delphij) search for other commits by this committer
security/dogtag-pki: convert OpenLDAP dependency to USES=ldap

Replace hardcoded libldap.so:net/openldap26-client in LIB_DEPENDS
with USES=ldap, letting the framework handle version selection.

PR:		ports/297779
Approved by:	maintainer (joneum)
11.10.1_1
23 Aug 2026 17:48:32
commit hash: 668d78489ef285d867779f284ce13b101908a8e1commit hash: 668d78489ef285d867779f284ce13b101908a8e1commit hash: 668d78489ef285d867779f284ce13b101908a8e1commit hash: 668d78489ef285d867779f284ce13b101908a8e1 files touched by this commit
Jochen Neumeister (joneum) search for other commits by this committer
security/dogtag-pki: Fix incomplete javac classpath

base/tomcat-9.0 compiles against pki-common, whose classes carry
@JsonInclude, but does not list jackson-annotations, so javac cannot
resolve the annotation.  Every other subproject already lists the jar.

Sponsored by:	Netzkommune GmbH
11.10.1
21 Aug 2026 05:42:35
commit hash: 46d65614f63fe4d2b40f823ca6b3a143e6095149commit hash: 46d65614f63fe4d2b40f823ca6b3a143e6095149commit hash: 46d65614f63fe4d2b40f823ca6b3a143e6095149commit hash: 46d65614f63fe4d2b40f823ca6b3a143e6095149 files touched by this commit
Jochen Neumeister (joneum) search for other commits by this committer
security/dogtag-pki: Update to 11.10.1

Switch to Java 21.

Adapt the FreeBSD parts to the reworked upstream tree: guard the SELinux
import and its call sites, replace the remaining runuser call with
subprocess privilege switching, and pass APP_SERVER_CM through the
environment, which 11.10 reads instead of the CMake define.

Give pki-tomcatd a bounded stop.  jsvc records the pid of its child in
the pidfile while the parent handles SIGTERM, and Tomcat can deadlock in
JSS while closing LDAP connections, so rc(8) would wait forever and
stall the system shutdown.

Changes:	https://github.com/dogtagpki/pki/releases

Sponsored by:		Netzkommune GmbH
11.7.0_6
13 Aug 2026 08:58:48
commit hash: 27b780cf30fd1e4b7f2f2faa7371599baa311c93commit hash: 27b780cf30fd1e4b7f2f2faa7371599baa311c93commit hash: 27b780cf30fd1e4b7f2f2faa7371599baa311c93commit hash: 27b780cf30fd1e4b7f2f2faa7371599baa311c93 files touched by this commit
Jochen Neumeister (joneum) search for other commits by this committer
security/dogtag-pki: bound the rc onestop call during pkidestroy

The Tomcat stop path called `service <instance> onestop` and blocked on
rc.subr's wait_for_pids() indefinitely when the jsvc/JVM did not exit
(e.g. a wedged webapp during pkidestroy). Bound the call with a timeout
and fall back to SIGKILL so pkidestroy/uninstall can never hang.

Sponsored by:	Netzkommune GmbH
11.7.0_5
06 Aug 2026 16:42:39
commit hash: e4c7f141999c1c895ec7277ce76da4671986fdb8commit hash: e4c7f141999c1c895ec7277ce76da4671986fdb8commit hash: e4c7f141999c1c895ec7277ce76da4671986fdb8commit hash: e4c7f141999c1c895ec7277ce76da4671986fdb8 files touched by this commit
Jochen Neumeister (joneum) search for other commits by this committer
security/dogtag-pki: Enable ACME support and improve rc integration

Enable the ACME responder that was previously disabled in the port:

* Build with WITH_ACME and install the ACME webapp, configuration
  templates (database, issuer, realm, engine), the pki-acme-run
  script and pki-acme.jar
* Patch hardcoded Linux paths in the ACME components to their
  FreeBSD locations (/usr/local/share/pki, /var/db/pki)
* Link jaxb-api.jar and javax.activation-api.jar into the server
  common libs, required by the ACME webapp at runtime

Improve the FreeBSD rc.d integration:

* Generate java_opts and PKI_VERSION for the rc service directly
  from the instance's tomcat.conf instead of referencing an
  environment file
* Add remove_rc_service() to cleanly remove the rc script, the
  service configuration and the rc.conf knob when an instance is
  destroyed, and use it in the instance removal scriptlet

Sponsored by:	Netzkommune GmbH
11.7.0_4
21 Jul 2026 22:48:18
commit hash: f2225e8d4d81c59a27e7d9b6334de4c1e77be799commit hash: f2225e8d4d81c59a27e7d9b6334de4c1e77be799commit hash: f2225e8d4d81c59a27e7d9b6334de4c1e77be799commit hash: f2225e8d4d81c59a27e7d9b6334de4c1e77be799 files touched by this commit
Jochen Neumeister (joneum) search for other commits by this committer
security/dogtag-pki: Rework server and CA packaging

* Add the Java 17 build for the Dogtag server and CA components.
* Install the Dogtag server, CA, Tomcat, tools and web application JARs.
* Add the Java, REST, LDAP, JSS and Tomcat dependencies required by
  the server runtime.
* Install pkispawn, pkidestroy, pkidaemon and pki-server.
* Add the pkiuser user and group.
* Install the server and CA configuration templates, upgrade data,
  registry files, web applications and runtime library links.
* Generate and install the Dogtag VERSION file.
* Adapt the server tools, configuration and Tomcat integration to the
  FreeBSD filesystem layout.
* Replace systemd-specific service handling with FreeBSD rc.conf and
  Tomcat multi-instance service support.
* Update pkg-plist for the expanded server and CA runtime.

Sponsored by:	Netzkommune GmbH
11.7.0_3
11 Jul 2026 17:50:43
commit hash: 3957ae215e3ae2fd72d0d06a7972e21631069bf5commit hash: 3957ae215e3ae2fd72d0d06a7972e21631069bf5commit hash: 3957ae215e3ae2fd72d0d06a7972e21631069bf5commit hash: 3957ae215e3ae2fd72d0d06a7972e21631069bf5 files touched by this commit
Jochen Neumeister (joneum) search for other commits by this committer
security/dogtag-pki: Add pkiuser account

Create the pkiuser system account required by Dogtag PKI.
11.7.0_2
11 Jul 2026 13:18:32
commit hash: e0acf9672e0435801383ded22177dde2e1517aabcommit hash: e0acf9672e0435801383ded22177dde2e1517aabcommit hash: e0acf9672e0435801383ded22177dde2e1517aabcommit hash: e0acf9672e0435801383ded22177dde2e1517aab files touched by this commit
Jochen Neumeister (joneum) search for other commits by this committer
security/dogtag-pki: Fix PKI version file path

Read share/pki/VERSION from LOCALBASE instead of the Linux
/usr/share/pki path.

Sponsored by:	Netzkommune GmbH
11.7.0_1
11 Jul 2026 12:07:50
commit hash: 5973deb895a2a1ff95e8b2cf57f8ef7672120e5ccommit hash: 5973deb895a2a1ff95e8b2cf57f8ef7672120e5ccommit hash: 5973deb895a2a1ff95e8b2cf57f8ef7672120e5ccommit hash: 5973deb895a2a1ff95e8b2cf57f8ef7672120e5c files touched by this commit
Jochen Neumeister (joneum) search for other commits by this committer
security/dogtag-pki: Install PKI version file

Install share/pki/VERSION so the Python pki module can determine
the Dogtag PKI specification version at runtime.

Sponsored by:	Netzkommune GmbH
11.7.0
04 Jul 2026 20:08:06
commit hash: 89302dca83cdc4abd0f4128b21b6d207496a7222commit hash: 89302dca83cdc4abd0f4128b21b6d207496a7222commit hash: 89302dca83cdc4abd0f4128b21b6d207496a7222commit hash: 89302dca83cdc4abd0f4128b21b6d207496a7222 files touched by this commit
Jochen Neumeister (joneum) search for other commits by this committer
security/dogtag-pki: Add new Port

Dogtag PKI is an enterprise-class open source certificate system
providing Certificate Authority, Key Recovery Authority, OCSP,
and other PKI services.

This port installs the Dogtag PKI Python client and server modules.
It is required by the upcoming net/freeipa-server port.

WWW: https://www.dogtagpki.org/

Sponsored by:	Netzkommune GmbH

Number of commits found: 12