<?xml version="1.0"?>

<!--
*
* DataFlux Authentication Server ANT Configuration Script
*
-->

<project name="DataFlux Authentication Server Configuration" default="configure">
    <!--
   *
   * Several parameters are passed on the command line:
   *  debug level - info, verbose or debug
   *  temp directory - ${temp.dir}
   *  log file - ${ant.log.file}
   *  product code - ${config.currprod.12byte}
   *  property file - ${configuration.properties.file}
   *  configuration script location - ${install.cfgwizard.utilities.dir}
   *  install location for dfauthsvrc - ${SASMC_ROOT}
   *  base directory - ${basedir}
   *  source directory - ${srcdir}
   *  target to execute
   *
   -->

    <!-- Import the configuration script framework -->
    <import file="${install.cfgwizard.utilities.dir}/configuration_targets.xml" />
    <import file="${install.cfgwizard.utilities.dir}/contrib/templates/2.0/common_configuration_utilities.xml"/>

    <!-- ==================================================================== -->
    <!-- target: configure                                                    -->
    <!-- ==================================================================== -->
    <target name="configure" depends="config.init, dfauthsvrc.init, loadMetadata.init"
            description="Main entry target to initialize configuration"
    >
        <setConfigStatusFile
         target="configure"
         task="startConfiguration"
         message="${dfauthsvrc.status.UnknownFailure.msg} Configure"/>

        <!-- If on UNIX, see if the user has done what they need to do to set sasauth -->
        <dfauthsvrc.setauth />
        
        <!-- Set encryption if set_secure script is available in bin folder -->
        
                 
        <!-- check if script exists and call dfauthsvrc.setsecure for ootb -->
		<echo message="dfauthsvrc.has.migration  = ${dfauthsvrc.has.migration}" />
        <if><istrue value="${config.migration.is_selected}" />
		    <then>
				<echo message="config.migration.is_selected for setsecure = ${config.migration.is_selected}" />
			</then>
			<else>
				<echo message="config.migration.is_selected  = ${config.migration.is_selected}" />
                <if><available file="${dfauthsvr.install.dir}/bin/set_secure${util.cmd.extension}" />
                    <then>
                        <dfauthsvrc.setsecure />
                    </then>
                </if>
			</else>	
        </if>
					
        <!-- Migrate Or UIP from v3.2 run ASPROC -->
        <if><istrue value="${config.migration.is_selected}" />
            <then>
                <listMigratedObjects product12byte="${config.currprod.12byte}"/>
				<echo message="dfauthsvrc.has.migration  = ${dfauthsvrc.has.migration}" />
                <if><istrue value="${dfauthsvrc.has.migration}" />
                    <then>
                        <!--                                              -->
                        <!-- If migration is enabled, make the call to    -->
                        <!-- import the database from the SMU extension   -->
                        <!--                                              -->
						<echo message="dfauthsvrc.migration.is_enabled  = ${dfauthsvrc.migration.is_enabled}" />
                        <if>
                            
							<istrue value="${dfauthsvrc.migration.is_enabled}"/>
                            <then>
                                <property file="${dfauthsvrc.migrated.object.configobj.dir}${file.separator}${config.currprod.12byte}_Configuration.properties"
                                          prefix="migrated." />

                                <property name="dfauthsvrc.migrated.from.host" value="${migrated.dfauthsvrc.host}"/>
                                <property name="dfauthsvrc.migrated.from.port" value="${migrated.dfauthsvrc.port}"/>
                                <property name="dfauthsvrc.migrated.release.version" value="${migrated.dfauthsvrc.configobj.version}"/>
                                <property name="dfauthsvrc.migrated.encryption" value="${migrated.SMU.dfauthsvrc.encryption}"/>
                                <echo message="host and port and version  = ${dfauthsvrc.migrated.from.host} and ${dfauthsvrc.migrated.from.port} and ${dfauthsvrc.migrated.release.version}" />
                            
                            <!-- check if script exists and call dfauthsvrc.setsecure for ootb -->
                                <if><available file="${dfauthsvr.install.dir}/bin/set_secure${util.cmd.extension}" />
                                    <then>
                                        <echo message="call dfauthsvrcsetsecure from Migration enabled" />
										<dfauthsvrc.setsecure />
                                    </then>
                                </if>
                                <dfauthsvrc_migration_importdb />

                                <portAuthUsersToOMR />

                                <!--                                      -->
                                <!-- Change the software component name   -->
                                <!-- for the Authentication Server        -->
                                <!--                                      -->
                                <filterset id="dfauthsvrc_server_name">
                                    <filter token="Name" value="&#34;${dfauthsvrc.servercomponent.name}&#34;" />
                                </filterset>

                                <setmetadatavalues
                                    host="${iomsrv.metadatasrv.host}"
                                    port="${iomsrv.metadatasrv.port}"
                                    user="${metadata.connection.userid}"
                                    password="${metadata.connection.passwd}"
                                    repository="${oma.repository.foundation.name}"
                                    type="SoftwareComponent"
                                    search="@Id='${dfauthsvrc.configobj.fqid}'"
                                    attrset.id="dfauthsvrc_server_name"
                                />

                                <property name="dfauthsvrc.migration.complete" value="true" />
                            </then>
                        </if>
                    </then>
                    <else>
                        <!-- OOTB -->
                        <dfauthsvrc.ootb />
                    </else>
                </if>
            </then>
			<else>
                <!-- OOTB -->
                <dfauthsvrc.ootb />
				<if>
					<equals arg1="${dfauthsvr.old.version}" arg2="3.2" />
					<!-- check if UIP from v32 and run ASPROC -->
					<then>
						<!-- Need to set the following values so that the check on metadata for seeing if asexport has run will work. -->
						<property name="dfauthsvrc.migrated.from.host" value="${dfauthsvrc.host}"/>
						<property name="dfauthsvrc.migrated.from.port" value="${dfauthsvrc.port}"/>
						<echo message="host = ${dfauthsvrc.migrated.from.host}" />
						<echo message="port = ${dfauthsvrc.migrated.from.port}" />
						<portAuthUsersToOMR />
					</then>
				</if>
            </else>
        </if>

        <!-- Do we try and copy the license file to a local location and then update the config file. -->

        <setConfigureVersion fqid="${dfauthsvrc.configobj.fqid}" productcode="${config.currprod.12byte}" version="${dfauthsvrc.configobj.version}" />

        <!-- Insert into instructions.html -->
        <dfauthsvrc.docparts />

    </target>

    <!-- ==================================================================== -->
    <!-- target: updateConfigure                                              -->
    <!-- ==================================================================== -->
    <target name="updateConfigure"
            depends="config.init, dfauthsvrc.init, loadMetadata.init"
            description="Main entry target to update configurations">

        <echo level="info" message="Starting updateConfigure" />

        <echo message="+-------------------------------------------------------------------------------------+" />
        <echo message="|Checking current version  of ${config.currprod.legalname} to determine if an update is required." />
        <echo message="|   Configurable Object FQID        = ${dfauthsvrc.configobj.fqid}" />
        <echo message="|   Current ConfigureVersion        = ${dfauthsvrc.configobj.version}" />
        <echo message="|   Previous Order Customer Version = ${dfauthsvrc.maintenance.from.version}" />
        <echo message="|   Current Order Customer Version  = ${dfauthsvrc.maintenance.to.version}" />
        <echo message="+-------------------------------------------------------------------------------------+" />

        <setConfigStatusFile target="updateConfigure"
                             task="startUpdateConfigure"
                             message="${dfauthsvrc.status.UnknownFailure.msg} updateConfigure"/>

        <!-- If on UNIX, see if the user has done what they need to do to set sasauth -->
        <dfauthsvrc.setauth />

        <if>
            <or>
                <equals arg1="${dfauthsvrc.maintenance.from.version}" arg2="3.2" />
                <equals arg1="${dfauthsvrc.maintenance.from.version}" arg2="4.1" />
            </or>
            <then>
                <!-- Need to set the following values so that the check on metadata for seeing if asexport has run will work. -->
                <property name="dfauthsvrc.migrated.from.host" value="${dfauthsvrc.host}"/>
                <property name="dfauthsvrc.migrated.from.port" value="${dfauthsvrc.port}"/>
                <echo message="host = ${dfauthsvrc.migrated.from.host}" />
                <echo message="port = ${dfauthsvrc.migrated.from.port}" />

                <portAuthUsersToOMR />
            </then>
        </if>

        <if>
            <or>
                <equals arg1="${dfauthsvrc.maintenance.to.version}" arg2="4.1" />
                <equals arg1="${dfauthsvrc.maintenance.to.version}" arg2="4.1_M1" />
            </or>
            <then>
                <!-- The init phase already copied over and updated the needed content -->
                <!-- All we need to do is create metadata -->
                <if>
                    <not>
                        <available file="${config.lev.dir}/DataFluxAuthenticationServer/uip/32to41uipm" type="file"/>
                    </not>
                    <then>
                        <!-- Update the license to be the entered value. -->
                        <echo message="Adding updated license." />

                        <!-- backup current config file first and then replace license location -->
                        <echo message="Copying as_serv_aspsql.xml file over and keeping license location." />
                        <copy file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml" tofile="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml.lic.bak" overwrite="true" />

                        <echo message="Copying lic as_serv_aspsql.xml file over and dropping license location." />
                        <copy file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml.lic.bak" tofile="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml" overwrite="true">
                            <filterchain>
                                <linecontains negate="true">
                                    <contains value="Option name=&quot;Location&quot;"/>
                                </linecontains>
                            </filterchain>
                        </copy>

                        <checkBOM file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml" cmd=""/>
                        <replace
                            file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml"
                            token="&lt;Option name=&quot;Provider&quot;&gt;SAS&lt;/Option&gt;"
                            value="&lt;Option name=&quot;Provider&quot;&gt;SAS&lt;/Option&gt;${line.separator}&#x0009;&#x0009;&#x0009;&lt;Option name=&quot;Location&quot;&gt;${dfauthsvrc.license}&lt;/Option&gt;"
                            encoding="${dmv.file.enc}"
                        />

                        <echo message="Creating Metadata for Authentication Server." />
                        <!-- Create or update metadata -->
                        <dfauthsvrc.ootb />

                        <setConfigureVersion fqid="${dfauthsvrc.configobj.fqid}" productcode="${config.currprod.12byte}" version="${dfauthsvrc.maintenance.to.version}"/>

                        <!-- Touch file to indicate that we have done the conversion -->
                        <touch file="${config.lev.dir}/DataFluxAuthenticationServer/uip/32to41uipm" mkdirs="true"/>
                    </then>
                    <else>
                        <echo message="Metadata already created for Authentication Server." />
                    </else>
                </if>
            </then>
            <else>
                <!-- We have hit a configured version where there are no changes to apply. -->
                <!-- Log a message and let this go through. The first time through should -->
                <!-- have resulted in an update to the 2.1_M1 level. -->

                <echo message="+-------------------------------------------------------------------------------------+" />
                <echo message="| Coming from a version where no changes need to be applied to the system." />
                <echo message="+-------------------------------------------------------------------------------------+" />

                <setConfigureVersion fqid="${dfauthsvrc.configobj.fqid}" productcode="${config.currprod.12byte}" version="${dfauthsvrc.maintenance.to.version}" />

            </else>
        </if>

        <!-- Do we try and copy the license file to a local location and then update the config file. -->
        <!-- Should this be done regadless of the version we are migrating too? -->

        <!-- Insert into UpdateInstructions.html to indicate an update was made -->
        <dfauthsvrc.maint.docparts />

        <echo level="info" message="Leaving updateConfigure" />
    </target>

    <!-- ==================================================================== -->
    <!-- target: startServer                                                  -->
    <!-- ==================================================================== -->
    <target name="startServer" depends="config.init, dfauthsvrc.init"
            description="start the server and wait until it is listening on the port"
    >
        <echo message="startServer: Entering Target" />

        <!-- Initialize the config status file -->
        <setConfigStatusFile target="startServer"
                             task="startServer"
                             message="${dfauthsvrc.status.UnknownFailure.msg} startServer"
        />

        <!-- Start the server -->
        <!-- S1215311 not checking for asproc run again .. dont want duplicate warnings     -->
                
        <echo message="starting server .." />
        <dfauthsvrc.startServer />
        

        <echo message="startServer: Leaving Target" />
    </target>

    <!-- ==================================================================== -->
    <!-- target: changeHost                                                   -->
    <!-- ==================================================================== -->
    <target name="changeHost" depends="config.init, changeHost.init, dfauthsvrc.init"
        description="Change host name for Authentication Server metadata object"
    >
        <!-- Initialize the config status file -->
        <setConfigStatusFile target="changeHost"
                             task="changeHost"
                             message="${dfauthsvrc.status.UnknownFailure.msg} changeHost"
        />

        <!-- Changes the name of the object that appears in SMC -->
        <changeMetadataObjectName
            objtype="${dfauthsvrc.configobj.type}"
            oldname="${dfauthsvrc.servercomponent.name}"/>

        <!-- We actually need to updated the text stores so that the new host information is updated -->
        <!-- changes the internal information on the SAS Authentication Server object -->
        <changeHostName configobj="dfauthsvrc">
            <propertyset>
                <propertyref name="dfauthsvrc.host"/>
                <propertyref name="dfauthsvrc.servercomponent.name"/>
                <propertyref name="configobj.name"/>
            </propertyset>
        </changeHostName>
    </target>

    <!-- ==================================================================== -->
    <!-- target: unconfigure                                                  -->
    <!-- ==================================================================== -->
    <target name="unconfigure"
        depends="config.init, unconfig.init, dfauthsvrc.init, loadMetadata.init"
        description="UnConfigure the Authentication Server metadata object."
    >
        <!-- Initialize the config status file -->
        <setConfigStatusFile target="unconfigure"
                             task="unconfigure"
                             message="${dfauthsvrc.status.UnknownFailure.msg} unconfigure"
        />

        <!-- Delete Software Component -->
        <deleteMetadataObjects objectPath="${dfauthsvrc.swcomp.folder}/${dfauthsvrc.servercomponent.name}(Application)" />

        <if>
            <available file="${config.lev.dir}/DataFluxAuthenticationServer" type="dir" />
            <then>
                <delete includeEmptyDirs="true" failonerror="false">
                   <fileset dir="${config.lev.dir}/DataFluxAuthenticationServer"/>
                </delete>
            </then>
        </if>

        <!-- Insert Docparts -->
        <insertDocpartWithReplace
               fileToModify="${config.lev.unconfiguration.instructions.file}"
               tokenToReplace="${unconfiguration.summary.dfauthsvrc.head}"
               valueToUse="${unconfiguration.dfauthsvrc.summary.head.txt}" />

        <!-- Output tail docpart -->
        <insertDocpartWithReplace
               fileToModify="${config.lev.unconfiguration.instructions.file}"
               tokenToReplace="${unconfiguration.summary.dfauthsvrc.tail}"
               valueToUse="${unconfiguration.dfauthsvrc.summary.item.txt}" />
    </target>

    <!-- ==================================================================== -->
    <!-- target: checkForErrors                                               -->
    <!-- ==================================================================== -->
    <target name="checkForErrors" depends="config.init, dfauthsvrc.init">

        <echo level="info" message="${tmpl.entering.target.msg} checkForErrors" />

        <echo message="${whatFailed.property.file}" />
        <property file="${whatFailed.property.file}" />
        <fail message="${error.msg}"/>

        <echo level="info" message="${tmpl.leaving.target.msg} checkForErrors" />

    </target>

    <!-- ==================================================================== -->
    <!-- target: reportFailures                                               -->
    <!-- Stolen from invtoptmid_config.xml and config_utilities.xml in invtoptmid  -->
    <!-- ==================================================================== -->
    <target name="reportFailures"
            depends="config.init, dfauthsvrc.init"
            description="Main entry target for generating error reports. This target is called only if a project build fails."
    >
        <echo level="info" message="${tmpl.entering.target.msg} reportFailures" />

        <util.ReportFailures />

        <echo level="info" message="${tmpl.leaving.target.msg} reportFailures" />

    </target>

    <!-- ==================================================================== -->
    <!-- target: dfauthsvrc.init                                              -->
    <!-- ==================================================================== -->
    <target name="dfauthsvrc.init" unless="dfauthsvrc.init.set"
      description="Init target for dfauthsvrc"
    >

        <!-- Only run the init target once -->
        <property name="dfauthsvrc.init.set" value="true"/>

        <!-- Set the destination location -->
        <property name="deploydir" value="${os.localhost.user.home.dir}"/>

        <echo message="basedir = ${basedir}"/>
        <echo message="srcdir = ${srcdir}"/>
        <echo message="deploydir = ${deploydir}"/>

        <!-- Need to look up the port and store it. This is so it will resolve in the instructions.html -->
        <if><isset property="onWindowsHosts"/>
            <then>
                <property name="dfauthsvr.32.dir" location="${dfauthsvr.install.dir}/../3.2/"/>
                <property name="dfauthsvr.41.dir" location="${dfauthsvr.install.dir}/../4.1/"/>
                <property name="dfauthsvr.default.account" value="REPLACEDOMAIN${file.separator}REPLACEUSER"/>
                <property name="dfauthsvrc.host.type" value="win"/>
            </then>
            <else>
                <property name="dfauthsvr.32.dir" location="${dfauthsvr.install.dir}/../../3.2/authserver/"/>
                <property name="dfauthsvr.41.dir" location="${dfauthsvr.install.dir}/../../4.1/authserver/"/>
                <property name="dfauthsvr.default.account" value="REPLACEUSER"/>
                <property name="dfauthsvrc.host.type" value="unx"/>
            </else>
        </if>

        <if>
            <available file="${dfauthsvr.32.dir}" type="dir"/>
            <then>
                <property name="dfauthsvr.old.version" value="3.2"/>
                <property name="dfauthsvr.old.dir" value="${dfauthsvr.32.dir}"/>
                <pathconvert property="dfauthsvr.old.dir.converted">
                    <path location="${dfauthsvr.old.dir}"/>
                </pathconvert>
            </then>
        </if>


        <!-- need to check if the config file has REPLACEWITHTRAN with regex -->
        <checkBOM file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml" cmd=""/>
        <loadfile srcfile="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml"
                  property="dfauth.tranpath.value"
                  encoding="${dmv.file.enc}">
            <filterchain>
                <linecontains>
                    <contains value="ASPSQL_TRANDBF "/>
                </linecontains>
            </filterchain>
        </loadfile>

        <if>
            <and>
                <isset property="dfauth.tranpath.value" />
                <not>
                    <equals arg1="${dfauth.tranpath.value}" arg2="" />
                </not>
            </and>
            <then>
            <!-- get the tranpath -->
            <propertyregex property="dfauth.tranpath"
                        override="true"
                        input="${dfauth.tranpath.value}"
                        regexp="(&lt;!ENTITY[\s\t]+ASPSQL_TRANDBF[\s\t]+&quot;)(.*)([\\/]asdb.tdb&quot;&gt;)"
                        select="\2"
            />

                <echo message="   Auth Server Tranpath directory = ${dfauth.tranpath}"/>

                <if>
                    <and>
                        <equals arg1="${dfauth.tranpath}" arg2="REPLACEWITHTRANPATH" />
                    </and>
                    <then>
                        <echo message="   Update Auth Server Tranpath"/>
                        <!-- Create the folder -->
                        <createDirWithPerms unix="rwxr-xr-x" dir="${dfauthsvr.tran.path}" />
                        <!-- Update the config file with the prompted tranpath -->
                        <replace
                            file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml"
                            token="${dfauth.tranpath}"
                            value="${dfauthsvr.tran.path}"
                            encoding="${dmv.file.enc}"
                        />
                    </then>
                    <else>
                        <echo message="   The TRANPATH that you entered was not used as it was not the same in the config file. This is the TRANPATH that was used: ${dfauth.tranpath} "/>
                        <property name="dfauthsvr.tranpath.not.changed" value="true"/>
                    </else>
                </if>

            </then>
            <else>
                <echo message="   Tranpath not found"/>
            </else>
        </if>

        <echo message="config.target.name = ${config.target.name}" />

        <property name="dfauthsvr.asproc.not.run" value="true"/>
        <property name="dfauthsvr.asproc.file.name" value="asexport_default.sas"/>


        <!-- The first check is to support UIP coming from 3.2 or 4.1.
             It only gets called if 3.2 or 4.1 is installed and we have not updated yet. -->
        <!-- The 32to41uip is created at the end of dfauthsvrc.updateFrom32 -->
        <if>
            <and>
                <available file="${dfauthsvr.old.dir}" type="dir"/>
                <not>
                    <available file="${config.lev.dir}/DataFluxAuthenticationServer/uip/32to41uip" type="file"/>
                </not>
            </and>
            <then>
                <echo message="*******************************************************************"/>
                <echo message="UIP for ${dfauthsvr.old.version} Directory: ${dfauthsvr.old.dir}" />
                <echo message="*******************************************************************"/>

                <!-- Load error messages that will be used to make sure the server has stopped. -->
                <property file="${dfauthsvrc.install.config.dir}${file.separator}initErrorMsgs.properties" />

                <dfauthsvrc.updateFrom32 dfauthVersion="${dfauthsvr.old.version}" dfauthdir="${dfauthsvr.old.dir}" />

                <!-- Set the port for the auth server so it can be used in instructions.html -->
                <var name="server.config" unset="true"/>
                <var name="server.value" unset="true"/>

                <getOptionsFromXML file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml"
                                       file.optionSet=""
                                       file.option="Port"/>

                <var name="dfauthsvrc.port" value="${server.value}"/>
                <property name="dfauthsvrc.changePort" value="true"/>

                <!-- Set the system users for the auth server so it can be used in instructions.html -->
                <var name="server.config" unset="true"/>
                <var name="server.value" unset="true"/>

                <getOptionsFromXML file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml"
                                   file.optionSet="SystemUsers"
                                   file.option="Account"/>
                <var name="dfauthsvrc.account.systemUser" value="${server.value}"/>
                <property name="dfauthsvrc.changeSystemUser" value="true"/>

                <!-- Following used in docparts -->
                <property name="dfauthsvrc.${dfauthsvr.old.version}.uip" value="true"/>

                <echo message="${dfauthsvr.old.version} to ${dfauthsvrc.release.number} Auth Port = ${dfauthsvrc.port}" />
                <echo message="${dfauthsvr.old.version} to ${dfauthsvrc.release.number} Auth System User = ${dfauthsvrc.account.systemUser}" />
            </then>
            <else>
                <!-- Update the config files with the prompted values for port and systemUser. -->
                <!-- Lets look up the port value from the Auth Server configuration file and set that so it is persisted. -->
                <var name="server.config" unset="true"/>
                <var name="server.value" unset="true"/>

                <!-- Look up in config and see if the port matches, what if they do not? If they entered something different this will impact Web Studio Server. Fed Server would need to update as well if they are different. -->

                <!-- Get the new port  -->
                <getOptionsFromXML file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml"
                                       file.optionSet=""
                                       file.option="Port"/>

                <if>
                    <equals arg1="${server.value}" arg2="00000" />
                    <then>
                        <!-- Update new Auth Server Port -->
                        <checkBOM file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml" cmd=""/>

                        <echo message="Updating port from ${server.value} to ${dfauthsvrc.port}." />

                        <replace
                            file="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml"
                            token="${server.value}"
                            value="${dfauthsvrc.port}"
                            encoding="${dmv.file.enc}"
                        />
                    </then>
                    <else>
                        <!-- The value is something other than the expected default. -->
                        <echo message="Port from config is ${server.value} which was not expected. Not changing config file." />
                        <if>
                            <not>
                                <equals arg1="${server.value}" arg2="${dfauthsvrc.port}" />
                            </not>
                            <then>
                                <echo message="Setting dfauthsvrc.port equal to ${server.value}." />
                                <var name="dfauthsvrc.port" value="${server.value}"/>
                                <property name="dfauthsvrc.changePort" value="true"/>
                            </then>
                        </if>
                    </else>
                </if>

                <!-- Update the system user to be the entered value. Should be replacing REPLACEDOMAIN\REPLACEUSER or just REPLACEUSER depending on the host. -->

                <!-- Get the new SystemUsers:Account  -->
                <getOptionsFromXML file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml"
                                       file.optionSet="SystemUsers"
                                       file.option="Account"/>

                <echo message="Default value for system user = ${dfauthsvr.default.account}" />
                <echo message="Config value for system user = ${server.value}" />
                <echo message="Auth config value for system user = ${dfauthsvrc.account.systemUser}" />

                
                <if>
                    <equals arg1="${server.value}" arg2="${dfauthsvr.default.account}" />
                    <then>
                        <!-- Update new Auth Server System User -->
                        <checkBOM file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml" cmd=""/>

                        <echo message="Updating SystemUsers:Account from ${server.value} to ${dfauthsvrc.account.systemUser}." />

                        <replace
                            file="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml"
                            token="${server.value}"
                            value="${dfauthsvrc.account.systemUser}"
                            encoding="${dmv.file.enc}"
                        />
                    </then>
                    <else>
                        <!-- The value is something other than the expected default. -->
                        <!-- Modifying for defect SS1206449. Change systemuser in config file to the dfauthsvrc.account.systemUser
                            prompted value - if there is another systemuser account in the config file. Prompted value has priority
                            over value in config file -->
                        <echo message="SystemUsers:Account from config is ${server.value} which was not expected. Adding ${dfauthsvrc.account.systemUser} as systemuser to config file." />
                        <if>
                            <not>
                                <equals arg1="${server.value}" arg2="${dfauthsvrc.account.systemUser}" />
                            </not>
                            <then>
                                <!-- Add prompter user to systemuser -->
                                <replace
                                        file="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml"
                                        token="&lt;OptionSet name=&quot;SystemUsers&quot;&gt;"
                                        value="&lt;OptionSet name=&quot;SystemUsers&quot;&gt;&#xA;&lt;Option name=&quot;Account&quot;&gt;${dfauthsvrc.account.systemUser}&lt;/Option&gt;"
                                        encoding="${dmv.file.enc}"
                                />
                            </then>
                        </if>
                    </else>
                </if>

                <echo message="${dfauthsvrc.release.number} Auth Port = ${dfauthsvrc.port}" />
                <echo message="${dfauthsvrc.release.number} Auth System User = ${dfauthsvrc.account.systemUser}" />
            </else>
        </if>

        <!-- Other Properties -->
        <property file="${dfauthsvrc.install.config.dir}${file.separator}dfauthsvrc.properties" />
        
        <!-- Adjust command based on operating system. -->
        <property name="util.cmd.extension" value=""/>
        
        <if>
            <equals arg1="${os.localhost.type}" arg2="win"/>
                <then>
                    <var name="util.cmd.extension" unset="true"/>
                    <property name="util.cmd.extension" value=".cmd"/>
                </then>
        </if>
         
        <!-- Encryption Property -->
        <property name="dfauthsvrc.encryption.value" value=""/>
        <property name="dfauthsvrc.secure.resultproperty" value="0"/>

        <!-- Source files -->
        <if>
            <not>
                <equals arg1="${os.localhost.selected.locale}" arg2="en"/>
            </not>
            <then>
                <property file="${locale.translations.txt}"/>
                <property file="${locale.translations.log}"/>
            </then>
        </if>

        <property file="${en.translations.txt}"/>
        <property file="${en.translations.log}"/>

    </target>

    <!--
   *
   * Internally called targets
   *
   -->
    <!-- = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =
      macrodef: dfauthsvrc.ootb
      Stolen from invtoptmid_config.xml and config_utilities.xml in invtoptmid
     = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = -->
    <macrodef name="dfauthsvrc.ootb">
        <sequential>
            <echo message="dfauthsvrc.ootb: Out Of the Box" />
            <!-- A good addition for config development support would to do the same thing that
                 \vertical\Products\InventoryOptimizationWorkbench\Installs\invtoptmid\Source\Config::d4iow52
                 invtoptmid_config.xml::invtoptmid.configmetadata is doing. If retry is hit from
                 the wizard, delete metadata and then add back in. -->

            <!-- We will attempt to start the server and then register it in OMR -->
            <echo message="No dfauthsvrc migration - Store metadata about the Authentication Server"/>

            <!-- Initialize the config status file -->
            <setConfigStatusFile target="configure"
                                 task="ootb"
                                 message="${dfauthsvrc.status.UnknownFailure.msg} dfauthsvrc.ootb"
            />

            <!-- ======================================================== -->
            <!-- Create an Auth Server object in OMR and store properties -->
            <!-- ======================================================== -->

            <!-- Define filter set for appxml -->
            <filterset id="swcomp.filters">
                <filter token="currprod.12byte"
                        value="${config.currprod.12byte}"
                />
                <filter token="dfauthsvrc.legal.name"
                        value="${dfauthsvrc.legal.name}"
                />
                <filter token="dfauthsvrc.software.component.name"
                        value="${dfauthsvrc.servercomponent.name}"
                />
                <filter token="softwarecomponent.desc"
                        value="${dfauthsvrc.description}"
                />
                <filter token="dfauthsvrc.release.number"
                        value="${dfauthsvrc.release.number}"
                />
                <filter token="swcomp.folder"
                        value="${dfauthsvrc.swcomp.folder}"
                />
            </filterset>

            <!-- Update the appxml file using the above filterset. -->
            <copyOneOrigFile
                srcdir="${dfauthsvrc.deployment.metadata.dir}"
                srcfile="${dfauthsvrc.software.component.file.name}.appxml"
                todir="${dfauthsvrc.temp.dir}"
                filterset.refid="swcomp.filters"
            />

            <!-- Does SoftwareComponent Exist? -->
            <getmetadatavalues host="${iomsrv.metadatasrv.host}"
                               port="${iomsrv.metadatasrv.port}"
                               user="${metadata.connection.userid}"
                               password="${metadata.connection.passwd}"
                               repository="${oma.repository.foundation.name}"
                               type="SoftwareComponent"
                               search="@Name='${dfauthsvrc.servercomponent.name}'"
                               attribute="Id"
                               delimiter=","
                               outputproperty="dfauthsvrc.softwarecomponent.id"
            />

            <if><equals arg1="${dfauthsvrc.softwarecomponent.id}" arg2="" />
                <then>
                    <!-- Now create an OMR object so we can retrieve specific properties during the FS Manager install -->
                    <echo message="*******************************************************************"/>
                    <echo message="Registering a new Authentication Server: ${dfauthsvrc.servercomponent.name}"/>
                    <echo message="*******************************************************************"/>

                    <!-- Create software component -->

                    <!-- Add the object into OMR -->
                    <createApplicationMetadata
                        file="${dfauthsvrc.temp.dir}/${dfauthsvrc.software.component.file.name}.appxml"
                        localize="-localize"
                        logfile="${config.lev.logs.configure.dir}/dfauthsvrc.CreateApplicationMetadata.log"
                    />
                </then>
                <elseif>
                    <and>
                        <istrue value="${wizard.retry}" />
                        <equals arg1="${config.target.name}" arg2="configure" />
                        <not>
                            <istrue value="${dfauthsvrc.has.migration}" />
                        </not>
                    </and>
                    <then>
                        <!-- This is the case when the user got the error message during deployment and
                             hit the retry button on the resulting error box. This allows us to clean up
                             and retry the loadMetadata action -->

                        <echo message="*******************************************************************"/>
                        <echo message="Deleting and Adding Authentication Server: ${dfauthsvrc.servercomponent.name}"/>
                        <echo message="*******************************************************************"/>

                        <!-- Remove SoftwareComponent -->
                        <deleteMetadataByFQID objecttype="SoftwareComponent"
                                              objectfqid="${dfauthsvrc.softwarecomponent.id}"
                        />

                        <!-- Now create an OMR object so we can retrieve specific properties during the FS Manager install -->
                        <!-- Create software component -->

                        <!-- Add the object into OMR -->
                        <createApplicationMetadata
                            file="${dfauthsvrc.temp.dir}/${dfauthsvrc.software.component.file.name}.appxml"
                            localize="-localize"
                            logfile="${config.lev.logs.configure.dir}/dfauthsvrc.CreateApplicationMetadata.log"
                        />
                    </then>
                </elseif>
                <else>
                    <!-- This should be where the user has configured the object once and is running the SDW
                         a second time. In this case we will attempt to update the metadata with any new information -->
                    <echo message="*******************************************************************"/>
                    <echo message="Updating Authentication Server: ${dfauthsvrc.servercomponent.name}"/>
                    <echo message="*******************************************************************"/>

                    <renameFolder metadataSearch="@Name='${dfauthsvrc.legal.short.name} 4.1'][ParentTree/Tree[@Name='${dfauthsvrc.legal.name}']/ParentTree/Tree[@Name='Applications']/ParentTree/Tree[@Name='System']"
                                  newName="${dfauthsvrc.legal.short.name}"
                                  resultsproperty="svcs.path.folder.rename.resultsproperty" />

                    <!-- Update the object in OMR -->
                    <updateApplicationMetadata
                        file="${dfauthsvrc.temp.dir}/${dfauthsvrc.software.component.file.name}.appxml"
                        applicationfqid="${dfauthsvrc.softwarecomponent.id}"
                        localize="-localize"
                        logfile="${config.lev.logs.configure.dir}/dfauthsvrc.UpdateApplicationMetadata.log"
                    />

                    <!-- propertycopy property="dfauthsvrc.configobj.fqid" from="${dfauthsvrc.softwarecomponent.id}" / -->
                </else>
            </if>

            <!-- Store Properties -->
            <SetObjectProperties fqid="${dfauthsvrc.configobj.fqid}"
                                 productcode="${config.currprod.12byte}"
            />

        </sequential>
    </macrodef>

    <!-- = = = = = = = = = = = = = = = = = = =
          macrodef: dfauthsvrc.docparts
          Stolen from invtoptmid_config.xml and config_utilities.xml in invtoptmid
         = = = = = = = = = = = = = = = = = = = -->
    <macrodef name="dfauthsvrc.docparts">
        <sequential>
            <echo message="dfauthsvrc.docparts" />

            <!-- Record the fact docpart insertion is beginning -->
            <setConfigStatusFile
                target="docparts"
                task="startDocparts"
                message="${dfauthsvrc.status.UnknownFailure.msg} docparts"/>

            <insertDocpartWithReplace fileToModify="${config.lev.instructions.file}"
                                      tokenToReplace="${instructions.dfauthsvrc.head}"
                                      valueToUse="${instructions.dfauthsvrc.head.txt}"
            />

            <!-- Details table: head -->
            <insertDocpartWithReplace fileToModify="${config.lev.instructions.file}"
                                      tokenToReplace="${instructions.dfauthsvrc.details.table.head}"
                                      valueToUse="${instructions.dfauthsvrc.table.head.txt}"
            />

            <!-- Details table: Host information -->
            <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                      tokenToReplace="${instructions.dfauthsvrc.details.table.item}"
                                      valueToUse="${instructions.dfauthsvrc.host.txt}"
            />

            <!-- Details table: Port information -->
            <if><isset property="dfauthsvrc.changePort" />
                <then>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.table.item}"
                                              valueToUse="${instructions.dfauthsvrc.change.port.txt}"
                    />
                </then>
                <else>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.table.item}"
                                              valueToUse="${instructions.dfauthsvrc.port.txt}"
                    />
                </else>
            </if>

            <!-- Details table: SystemUser Account information -->
            <if><isset property="dfauthsvrc.changeSystemUser" />
                <then>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.table.item}"
                                              valueToUse="${instructions.dfauthsvrc.change.systemUser.txt}"
                    />
                </then>
                <else>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.table.item}"
                                              valueToUse="${instructions.dfauthsvrc.systemUser.txt}"
                    />
                </else>
            </if>

            <!-- Details table: TRANPATH information -->
            <if><isset property="dfauthsvr.tranpath.not.changed" />
                <then>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                              valueToUse="${instructions.dfauthsvrc.tran.path.not.changed.txt}"
                    />
                </then>
            </if>

            <!-- Details table: PortUsersToOMR information 
            <if><available file="${dfauthsvr.install.dir}${file.separator}asproc/asproc" type="file"/>
                <then>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                              valueToUse="${instructions.dfauthsvrc.asproc.run.success.txt}"
                    />
                </then>
            </if>
			-->

            <!-- Details table: tail -->
            <insertDocpartWithReplace fileToModify="${config.lev.instructions.file}"
                                      tokenToReplace="${instructions.dfauthsvrc.details.table.tail}"
                                      valueToUse="${instructions.dfauthsvrc.table.tail.txt}"
            />

            <insertDocpartWithReplace fileToModify="${config.lev.instructions.file}"
                                      tokenToReplace="${instructions.dfauthsvrc.details.list.head}"
                                      valueToUse="${instructions.dfauthsvrc.list.head.txt}"
            />

            <!-- Details table: We upgraded from 3.2 or 4.1. Let the customer know. -->
            <if>
                <and>
                    <isset property="dfauthsvrc.${dfauthsvr.old.version}.uip" />
                    <available file="${config.lev.dir}/DataFluxAuthenticationServer/uip/32to41uip" type="file"/>
                </and>
                <then>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                              valueToUse="${instructions.dfauthsvrc.uip32.txt}"
                    />
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                              valueToUse="${instructions_dfauthsvrc_details_uip_old_release_disabled.txt}"
                    />
                    <!-- Let the user know what tdb file was copied in case further actions is needed. -->
                    <if><isset property="dfauthsvrc.tdb.found"/>
                        <then>
                            <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                                      tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                                      valueToUse="${instructions.dfauthsvrc.tdb.found.txt}"
                            />
                        </then>
                        <else>
                            <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                                      tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                                      valueToUse="${instructions.dfauthsvrc.tdb.not.found.txt}"
                            />
                        </else>
                    </if>
                </then>
            </if>

            <!-- Let the user know migration happened and if there are any extra steps to take. -->
            <if><isset property="dfauthsvrc.migration.complete"/>
                <then>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                              valueToUse="${instructions.dfauthsvrc.migration.txt}"
                    />
                </then>
            </if>

            <!-- Host-dependent actions -->
            <if><isset property="onWindowsHosts"/>
                <then>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                              valueToUse="${instructions.dfauthsvrc.windows.commands.txt}"
                    />
                </then>
                <else>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                              valueToUse="${instructions.dfauthsvrc.unix.commands.txt}"
                    />
                </else>
            </if>

            <insertDocpartWithReplace fileToModify="${config.lev.instructions.file}"
                                      tokenToReplace="${instructions.dfauthsvrc.details.list.tail}"
                                      valueToUse="${instructions.dfauthsvrc.list.tail.txt}"
            />
        </sequential>
    </macrodef>

    <!-- = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =
      macrodef: dfauthsvrc.startServer
     = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = -->
    <macrodef name="dfauthsvrc.startServer">
        <sequential>
            <echo message="dfauthsvrc.startServer: Entering Target" />

            <!-- Validate ports and if the port is in use let the user know where to change the value -->

            <!-- After validating, set the error message to point the user to the log file if there are any issues with startup -->

            <!-- Start the server -->
            <if>
                <isset property="onWindowsHosts"/>
                <then>
                    <!-- Get the server instance out of the meta file -->
                    <property file="${dfauthsvr.install.dir}${file.separator}data${file.separator}install${file.separator}instance.meta" prefix="startServer"/>

                    <!-- Service should be in the property "service" based on S1043850 ${service}-->
                    <execCmd
                        cmd="cmd"
                        cmd.line="/c cscript &quot;${dfauthsvr.install.dir}${file.separator}bin${file.separator}sxctl.vbs&quot; start ${startServer.service}"
                        dir="${dfauthsvr.install.dir}"
                        callingTarget="configure"/>

                </then>
                <else>
                    <!-- Should not have gotten here without SASAuth being set. Maybe move the call to here to ensure it gets set. -->
                    <!-- Once sasauth is owned by root, call ${dfauthsvr.install.dir}/bin/set_auth sasauth -->

                    <!-- Now start up the Server. -->
                    <execSpawnCmd
                        cmd="${dfauthsvr.install.dir}${file.separator}bin${file.separator}dasadmin"
                        cmd.line="start"
                        dir="${dfauthsvr.install.dir}"
                        logdir=""
                        logfile=""
                        callingTarget="configure"/>
                </else>
            </if>


            <propertycopy property="dfauth.status.msg"
                            from="dfauthsvrc.status.svr${dfauthsvrc.host.type}.not.running.msg" />
            <setConfigStatusFile target="startServer"
                                    task="startServer"
                                    message="${dfauth.status.msg}" />

            <waitfor timeoutproperty="dfauthserver.running" maxwait="60" maxwaitunit="second" checkevery="2" checkeveryunit="second">
                <socket server="${dfauthsvrc.host}" port="${dfauthsvrc.port}"/>
            </waitfor>

            <!-- Fail if the server is not detected -->
            <fail if="dfauthserver.running" message="${dfauth.status.msg}"/>

            <echo message="dfauthsvrc.startServer: Leaving Target" />
        </sequential>
    </macrodef>

    <!-- = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =
      macrodef: dfauthsvrc.stopServer
     = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = -->
    <macrodef name="dfauthsvrc.stopServer">
        <sequential>
            <echo message="dfauthsvrc.stopServer: Entering Target" />


            <!-- Stop the server -->
            <if>
                <isset property="onWindowsHosts"/>
                <then>
                    <!-- Get the server instance out of the meta file -->
                    <property file="${dfauthsvr.install.dir}${file.separator}data${file.separator}install${file.separator}instance.meta" prefix="stopServer" />

                    <!-- Service should be in the property "service" based on S1043850 ${service}-->
                    <execCmd
                        cmd="cmd"
                        cmd.line="/c cscript &quot;${dfauthsvr.install.dir}${file.separator}bin${file.separator}sxctl.vbs&quot; stop ${stopServer.service}"
                        dir="${dfauthsvr.install.dir}"
                        callingTarget="configure"/>

                </then>
                <else>
                    <!-- Should not have gotten here without SASAuth being set. Maybe move the call to here to ensure it gets set. -->
                    <!-- Once sasauth is owned by root, call ${dfauthsvr.install.dir}/bin/set_auth sasauth -->

                    <!-- Now stop the Server. -->
                    <execSpawnCmd
                        cmd="${dfauthsvr.install.dir}${file.separator}bin${file.separator}dasadmin"
                        cmd.line="stop"
                        dir="${dfauthsvr.install.dir}"
                        logdir=""
                        logfile=""
                        callingTarget="configure"/>
                </else>
            </if>

            <propertycopy property="dfauth.status.msg"
                            from="dfauthsvrc.status.svr${dfauthsvrc.host.type}.not.running.msg" />
            <setConfigStatusFile target="stopServer"
                                    task="stopServer"
                                    message="${dfauth.status.msg}" />

            <echo message="dfauthsvrc.stopServer: Leaving Target" />
        </sequential>
    </macrodef>

    <!-- = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =
        macrodef: getOptionsFromXML
     = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = -->
    <macrodef name="getOptionsFromXML">
        <attribute name="file.cfg"/>
        <attribute name="file.optionSet"/>
        <attribute name="file.option"/>
        <sequential>
            <echo message="getOptionsFromXML: Entering Target" />
            <if>
                <isset property="onWindowsHosts"/>
                <then>
                    <propertyregex property="server.config"
                                   input="@{file.cfg}"
                                   regexp="\\"
                                   replace="/"
                                   global="true" />
                </then>
                <else>
                    <var name="server.config" value="@{file.cfg}"/>
                </else>
            </if>

            <echo message="Processing file: ${server.config}" />

            <taskdef name="groovy" classname="org.codehaus.groovy.ant.Groovy" classpath="${default.groovy.path}"/>
            <groovy>
                System.properties.'javax.xml.accessExternalDTD' = "all" // Else will get failure:  Failed to read external document 'as_serv_aspsql_schema_tran.xml', because 'file' access is not allowed due to restriction set by the accessExternalDTD property.
                def parser = new groovy.xml.XmlParser()
                parser.setFeature("http://apache.org/xml/features/disallow-doctype-decl", false)   // Else will get failure:  DOCTYPE is disallowed when the feature "http://apache.org/xml/features/disallow-doctype-decl" set to true
                def cfg = parser.parse(properties.'server.config')
                if ( "" == "@{file.optionSet}" ) {
                    cfg.Option.each { option ->
                        if ( option['@name'] == "@{file.option}" ) {
                            properties.'server.value' = option.text()
                        }
                    }
                } else {
                    cfg.OptionSet.each { options ->
                        if ( options['@name'] == "@{file.optionSet}" ) {
                            options.Option.each { option ->
                                if ( option['@name'] == "@{file.option}" ) {
                                    properties.'server.value' = option.text()
                                }
                            }
                        }
                    }
                }
            </groovy>
            <echo message="getOptionsFromXML: Leaving Target" />
        </sequential>
    </macrodef>

    <!-- = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =
      macrodef: dfauthsvrc.setauth
      If on UNIX let the user know they need to set the correct permissions
      on sasauth in order for Auth Server to be able to do host authentication.
    = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = -->
    <macrodef name="dfauthsvrc.setauth">
        <sequential>
            <echo message="dfauthsvrc.setauth: Entering Target" />
            <if><isset property="onUnixHosts"/>
                <then>
                    <!-- Make sure that the permissions are set correctly on the file that will need to be executed. -->
                    <chmod file="${dfauthsvr.install.dir}/lib/sasauth.inst.sh" perm="755"/>
                    <!-- If the SAS setuid option was set, try and run the options on behalf of the user -->
                    <if>
                        <and>
                            <isset property="config.sudo.setuid.is_enabled" />
                            <istrue value="${config.sudo.setuid.is_enabled}" />
                        </and>
                        <then>
                            <execCmdWithWarning
                                cmd="sudo"
                                cmd.line="${dfauthsvr.install.dir}${file.separator}lib${file.separator}sasauth.inst.sh"
                                dir="${dfauthsvr.install.dir}"
                                callingTarget="dfauthsvrc.suid"/>

                            <if>
                                <not>
                                    <equals arg1="${rc}" arg2="0" />
                                </not>
                                <then>
                                    <echo message="First try at setting permissions did not work. Trying a second command." />
                                    <execCmdWithWarning
                                        cmd="sudo"
                                        cmd.line="sh ${dfauthsvr.install.dir}${file.separator}lib${file.separator}sasauth.inst.sh"
                                        dir="${dfauthsvr.install.dir}"
                                        callingTarget="dfauthsvrc.suid"/>

                                    <if>
                                        <not>
                                            <equals arg1="${rc}" arg2="0" />
                                        </not>
                                        <then>
                                            <echo message="Seond try at setting permissions did not work. User will be asked to make the call." />
                                        </then>
                                    </if>
                                </then>
                            </if>
                        </then>
                    </if>

                    <property name="checkauth.file" value="${dfauthsvr.install.dir}/lib/sasauth"/>
                    <if>
                        <not>
                            <available file="${checkauth.file}"/>
                        </not>
                        <then>
                            <setConfigStatusFile
                             target="configure"
                             task="setauth"
                             message="${dfauthsvrc.missing.sasauth.msg}"/>

                            <fail message="${dfauthsvrc.missing.sasauth.msg}"/>
                        </then>
                    </if>

                    <setConfigStatusFile
                     target="configure"
                     task="setauth"
                     message="${dfauthsvrc.checksasauth.failure.msg}"/>

                    <execCmd
                        cmd="perl"
                        cmd.line="${dfauthsvrc.install.config.dir}/Deployment/Scripts/checkuid ${checkauth.file}"
                        dir="${dfauthsvr.install.dir}"
                        callingTarget="dfauthsvrc.suid"/>
                </then>
            </if>
            <echo message="dfauthsvrc.setauth: Leaving Target" />
        </sequential>
    </macrodef>

    <!-- = = = = = = = = = = = = = = = = = = =
      macrodef: dfauthsvrc.maint.docparts
      Stolen from invtoptmid_config.xml and config_utilities.xml in invtoptmid
     = = = = = = = = = = = = = = = = = = = -->
    <macrodef name="dfauthsvrc.maint.docparts">
        <sequential>
            <echo message="dfauthsvrc.maint.docparts" />
            <!-- Initialize the config status file -->
            <setConfigStatusFile target="configureDocParts"
                                     task="maint.docparts"
                                     message="${dfauthsvrc.status.docparts.msg}"
                />

            <!-- Docpart Section: head -->
            <insertDocpartWithReplace fileToModify="${config.lev.maintconfiginstructions.file}"
                                          tokenToReplace="${instructions.dfauthsvrc.head}"
                                          valueToUse="${instructions.dfauthsvrc.upgrade.head.txt}"
                />

            <!-- Details table: head -->
            <insertDocpartWithReplace fileToModify="${config.lev.maintconfiginstructions.file}"
                                          tokenToReplace="${instructions.dfauthsvrc.details.table.head}"
                                          valueToUse="${instructions.dfauthsvrc.table.upgrade.head.txt}"
                />

            <if>
                <equals arg1="${dfauthsvrc.maintenance.to.version}" arg2="${dfauthsvrc.release.number}" />
                <then>
                    <!-- Details table: Upgrading -->
                    <insertDocpartWithPrepend fileToModify="${config.lev.maintconfiginstructions.file}"
                                                  tokenToReplace="${instructions.dfauthsvrc.details.table.item}"
                                                  valueToUse="${instructions.dfauthsvrc.41.release.txt}"
                        />
                </then>
                <else>
                    <!-- Details table: Unknown Version -->
                    <insertDocpartWithPrepend fileToModify="${config.lev.maintconfiginstructions.file}"
                                                  tokenToReplace="${instructions.dfauthsvrc.details.table.item}"
                                                  valueToUse="${instructions.dfauthsvrc.upgrade.unknown.release.txt}"
                        />
                </else>
            </if>


            <!-- Details table: tail -->
            <insertDocpartWithReplace fileToModify="${config.lev.maintconfiginstructions.file}"
                                          tokenToReplace="${instructions.dfauthsvrc.details.table.tail}"
                                          valueToUse="${instructions.dfauthsvrc.table.upgrade.tail.txt}"
                />

            <!-- Details table: We upgraded from 3.2 or 4.1. Let the customer know. -->
            <if>
                <and>
                    <isset property="dfauthsvrc.${dfauthsvr.old.version}.uip" />
                    <available file="${config.lev.dir}/DataFluxAuthenticationServer/uip/32to41uip" type="file"/>
                </and>
                <then>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                              valueToUse="${instructions.dfauthsvrc.uip32.txt}"
                    />
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                              valueToUse="${instructions_dfauthsvrc_details_uip_old_release_disabled.txt}"
                    />
                    <!-- Let the user know what tdb file was copied in case further actions is needed. -->
                    <if><isset property="dfauthsvrc.tdb.found"/>
                        <then>
                            <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                                      tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                                      valueToUse="${instructions.dfauthsvrc.tdb.found.txt}"
                            />
                        </then>
                        <else>
                            <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                                      tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                                      valueToUse="${instructions.dfauthsvrc.tdb.not.found.txt}"
                            />
                        </else>
                    </if>
                </then>
            </if>

            <!-- Let the user know migration happened and if there are any extra steps to take. -->
            <if><isset property="dfauthsvrc.migration.complete"/>
                <then>
                    <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                              tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                              valueToUse="${instructions.dfauthsvrc.migration.txt}"
                    />
                </then>
            </if>
			<!-- Don't need asproc messages as we have it in fed server now -->
            <!-- Port users to OMR success message 
            <if><available file="${dfauthsvr.install.dir}${file.separator}asproc/asproc" type="file"/>
                <then>
                    <if><available file="${config.lev.logs.configure.dir}${file.separator}${config.currprod.12byte}_asproc.validation_result.lst" type="file"/>
                        <then>
                            <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                                      tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                                      valueToUse="${warning.dfauthsvrc.asproc.validate.run.txt}"
                            />
                        </then>
                        <else>
                            <insertDocpartWithPrepend fileToModify="${config.lev.instructions.file}"
                                                      tokenToReplace="${instructions.dfauthsvrc.details.list.item}"
                                                      valueToUse="${instructions.dfauthsvrc.asproc.run.success.txt}"
                            />
                        </else>
                    </if>
                </then>
            </if>
			-->
        </sequential>
    </macrodef>

    <!-- = = = = = = = = = = = = = = = = = = =
      macrodef: dfauthsvrc.updateFrom32
      See if Auth 3.2 is installed and if so try to bring over the system tables and update 4.1 configs.
     = = = = = = = = = = = = = = = = = = = -->
    <macrodef name="dfauthsvrc.updateFrom32">
        <attribute name="dfauthVersion" />
        <attribute name="dfauthdir" />
        <sequential>
            <echo message="*** Entering Target: dfauthsvrc.updateFrom32" />

            <!-- Look for a file that would indicate that we have done this action already -->
            <!-- If that file is not there we will do work -->
            <!-- Touch file to indicate we have done the work -->
            <if><available file="@{dfauthdir}" type="dir"/>
                <then>
                    <!-- Old Version is installed so we will attempt to move over the bits to newer version -->
                    <echo message="+-------------------------------------------------------------------------------------+" />
                    <echo message="| Moving over @{dfauthVersion} tdb and config file over to ${dfauthsvrc.release.number} install dir" />
                    <echo message="+-------------------------------------------------------------------------------------+" />

                    <!-- Stop Old Version process -->
                    <if>
                        <isset property="onWindowsHosts"/>
                        <then>
                            <!-- Get the server instance out of the meta file -->
                            <var name="name" unset="true" />
                            <property file="@{dfauthdir}/data/install/instance.meta" prefix="@{dfauthVersion}" />

                            <execCmd
                                cmd="cmd"
                                cmd.line="/c cscript &quot;@{dfauthdir}${file.separator}bin${file.separator}sxctl.vbs&quot; stop dfx-AuthServer-${@{dfauthVersion}.name}"
                                dir="@{dfauthdir}"
                                callingTarget="configure"/>

                        </then>
                        <else>
                            <!-- Now stop the Server. -->
                            <execSpawnCmd
                                cmd="@{dfauthdir}${file.separator}bin${file.separator}dasadmin"
                                cmd.line="stop"
                                dir="@{dfauthdir}"
                                logdir=""
                                logfile=""
                                callingTarget="configure"/>
                        </else>
                    </if>

                    <!-- Check the port and make sure it is available -->
                    <var name="server.config" unset="true"/>
                    <var name="server.value" unset="true"/>

                    <getOptionsFromXML file.cfg="@{dfauthdir}${file.separator}etc${file.separator}as_serv_aspsql.xml"
                                           file.optionSet=""
                                           file.option="Port"/>

                    <!-- Sleeping for 5 seconds to give the server tiume to shut down -->
                    <sleep seconds="5"/>
                    <!-- Save off the value as we will use it for a later compare -->
                    <property name="dfauthold.port" value="${server.value}" />
                    <condition property="dfauthserverold.running">
                        <socket server="${dfauthsvrc.host}" port="${server.value}"/>
                    </condition>

                    <!-- Stop New Version process -->
                    <if>
                        <isset property="onWindowsHosts"/>
                        <then>
                            <!-- Get the server instance out of the meta file -->
                            <property file="${dfauthsvr.install.dir}/data/install/instance.meta" prefix="updateFrom32" />

                            <!-- Service should be in the property "service" based on S1043850 ${service}-->
                            <execCmd
                                cmd="cmd"
                                cmd.line="/c cscript &quot;${dfauthsvr.install.dir}${file.separator}bin${file.separator}sxctl.vbs&quot; stop ${updateFrom32.service}"
                                dir="${dfauthsvr.install.dir}"
                                callingTarget="configure"/>

                        </then>
                        <else>
                            <!-- Now stop the Server. -->
                            <execSpawnCmd
                                cmd="${dfauthsvr.install.dir}${file.separator}bin${file.separator}dasadmin"
                                cmd.line="stop"
                                dir="${dfauthsvr.install.dir}"
                                logdir=""
                                logfile=""
                                callingTarget="configure"/>
                        </else>
                    </if>

                    <!-- Check the port and make sure it is available -->
                    <var name="server.config" unset="true"/>
                    <var name="server.value" unset="true"/>

                    <getOptionsFromXML file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml"
                                           file.optionSet=""
                                           file.option="Port"/>

                    <!-- If the new version port is the same as the old version port we do not need to check the port again -->
                    <!-- However if the ports are the same and the property is set, then we should go ahead and check again in case the
                         old is set because new was running. If new has the same port and the port is not active after stopping new, then
                         there should be no error back to the user.
                    -->
                    <sleep seconds="5"/>
                    <!-- Save off the value as we will use it for a later compare -->
                    <property name="dfauthnew.port" value="${server.value}" />
                    <if>
                        <and>
                            <not>
                                <equals arg1="${server.value}" arg2="00000" />
                            </not>
                            <length string="${server.value}" trim="true" when="greater" length="0" />
                        </and>
                        <then>
                            <echo message="Config file port was not the default and was not empty." />
                            <echo message="Making sure the server is shutdown on port: ${server.value}" />
                            <condition property="dfauthservernew.running">
                                <socket server="${dfauthsvrc.host}" port="${server.value}"/>
                            </condition>
                        </then>
                    </if>

                    <!-- If dfauthserverold.running is set then this is an error condition. Ask the user to kill the process and then retry again. -->
                    <!-- If dfauthservernew.running is set then this is an error condition. Ask the user to kill the process and then retry again. -->
                    <if>
                        <and>
                            <equals arg1="${dfauthold.port}" arg2="${dfauthnew.port}" />
                            <isset property="dfauthserverold.running"/>
                            <not>
                                <isset property="dfauthservernew.running"/>
                            </not>
                        </and>
                        <then>
                            <!-- We don't need to do anything. The new server was running on the port
                                 and thus made it look like old was running. However when we shutdown
                                 new the port is no longer in use. Log a message for debugging purposes. -->
                            <echo message="Port ${dfauthnew.port} is not in use. Server should be stopped." />
                        </then>
                        <else>
                            <if>
                                <and>
                                    <isset property="dfauthserverold.running"/>
                                    <isset property="dfauthservernew.running"/>
                                </and>
                                <then>
                                    <!-- Both processes are running. -->
                                    <propertycopy property="dfauth.status.msg"
                                                    from="dfauthsvrc.status.svr${dfauthsvrc.host.type}.running.3241.msg" />
                                    <setConfigStatusFile target="configureDocParts"
                                                            task="maint.docparts"
                                                            message="${dfauth.status.msg}" />
                                    <fail message="@{dfauthVersion} and 4.1_M1 still running. Kill processes and try again."/>
                                </then>
                                <elseif>
                                    <isset property="dfauthserverold.running"/>
                                    <then>
                                        <!-- Only old is running. -->
                                        <propertycopy property="dfauth.status.msg"
                                                        from="dfauthsvrc.status.svr${dfauthsvrc.host.type}.running.32.msg" />
                                        <setConfigStatusFile target="configureDocParts"
                                                                task="maint.docparts"
                                                                message="${dfauth.status.msg}" />
                                        <fail message="@{dfauthVersion} still running. Kill process and try again." />
                                    </then>
                                </elseif>
                                <elseif>
                                    <isset property="dfauthservernew.running"/>
                                    <then>
                                        <!-- Only new is running. -->
                                        <propertycopy property="dfauth.status.msg"
                                                        from="dfauthsvrc.status.svr${dfauthsvrc.host.type}.running.41.msg" />
                                        <setConfigStatusFile target="configureDocParts"
                                                                task="maint.docparts"
                                                                message="${dfauth.status.msg}" />
                                        <fail message="${dfauthsvrc.release.number} still running. Kill process and try again." />
                                    </then>
                                </elseif>
                            </if>
                        </else>
                    </if>

                    <!-- Rename the new tdb file -->
                    <if><available file="${dfauthsvr.install.dir}/var/asdb.tdb" />
                        <then>
                            <move file="${dfauthsvr.install.dir}/var/asdb.tdb" tofile="${dfauthsvr.install.dir}/var/asdb.tdb.bak"/>
                        </then>
                    </if>

                    <!-- Copy over old tdb file -->
                    <if><available file="@{dfauthdir}/var/asdb.tdb" />
                        <then>
                            <echo message="Copying @{dfauthVersion} tdb file over." />
                            <copy file="@{dfauthdir}/var/asdb.tdb" tofile="${dfauthsvr.install.dir}/var/asdb.tdb"/>
                            <property name="dfauthsvrc.tdb.found" value="true" />
                        </then>
                        <else>
                            <echo message="The @{dfauthVersion} tdb file was not in the default location and thus was not copied." />
                        </else>
                    </if>

                    <!-- Backup the new as_serv_aspsql.xml file -->
                    <!-- When copying over the as_serv_aspsql.xml file, drop the license line. We will add it back with the prompted value. -->
                    <echo message="Backing up ${dfauthsvrc.release.number} as_serv_aspsql.xml file." />
                    <if><available file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml" />
                        <then>
                            <move file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml" tofile="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml.bak"/>
                        </then>
                    </if>

                    <!-- Backup the new as_serv_aspsql_scf.dat file which is used for when the repo is in Oracle -->
                    <echo message="Backing up ${dfauthsvrc.release.number} as_serv_aspsql_scf.dat file." />
                    <if><available file="${dfauthsvr.install.dir}/var/as_serv_aspsql_scf.dat" />
                        <then>
                            <move file="${dfauthsvr.install.dir}/var/as_serv_aspsql_scf.dat" tofile="${dfauthsvr.install.dir}/var/as_serv_aspsql_scf.dat.bak"/>
                        </then>
                    </if>

                    <!-- Copy over old config files -->
                    <if>
                        <equals arg1="${config.target.name}" arg2="updateConfigure" />
                        <then>
                            <echo message="Copying @{dfauthVersion} as_serv_aspsql.xml file over and dropping license location." />
                            <copy file="@{dfauthdir}/etc/as_serv_aspsql.xml" tofile="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml" overwrite="true">
                                <filterchain>
                                    <linecontains negate="true">
                                        <contains value="Option name=&quot;Location&quot;"/>
                                    </linecontains>
                                </filterchain>
                            </copy>
                        </then>
                        <else>
                            <echo message="Copying @{dfauthVersion} as_serv_aspsql.xml file over and keeping license location." />
                            <copy file="@{dfauthdir}/etc/as_serv_aspsql.xml" tofile="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml" overwrite="true" />
                        </else>
                    </if>

                    <!-- Rename old as_serv_aspsql.xml file so old version will not start if attempted. -->
                    <echo message="Renaming @{dfauthVersion} as_serv_aspsql.xml to prevent process starting up." />
                    <move file="@{dfauthdir}/etc/as_serv_aspsql.xml" tofile="@{dfauthdir}/etc/as_serv_aspsql.xml.bak"/>

                    <if><available file="@{dfauthdir}/var/as_serv_aspsql_scf.dat" />
                        <then>
                            <echo message="Copying @{dfauthVersion} as_serv_aspsql_scf.dat file over." />
                            <copy file="@{dfauthdir}/var/as_serv_aspsql_scf.dat" tofile="${dfauthsvr.install.dir}/var/as_serv_aspsql_scf.dat" overwrite="true" />
                        </then>
                    </if>
                    <!-- If dfauthVersion is 3.2 then we need to update the files we copied over -->
                    <if>
                        <equals arg1="@{dfauthVersion}" arg2="3.2" />
                        <then>
                            <echo message="Adding TKERSA2 location." />
                            <checkBOM file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml" cmd=""/>
                            <if>
                                <isset property="onWindowsHosts"/>
                                <then>
                                    <replace
                                        file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml"
                                        token="&lt;OptionSet name=&quot;SetEnv&quot;&gt;"
                                        value="&lt;OptionSet name=&quot;SetEnv&quot;&gt;${line.separator}&#x0009;&#x0009;&lt;Option name=&quot;TKERSA2_LIB_PATH&quot;&gt;${dfauthsvr.install.dir}/bin&lt;/Option&gt;"
                                        encoding="${dmv.file.enc}"
                                    />
                                </then>
                                <else>
                                    <replace
                                        file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml"
                                        token="&lt;OptionSet name=&quot;SetEnv&quot;&gt;"
                                        value="&lt;OptionSet name=&quot;SetEnv&quot;&gt;${line.separator}&#x0009;&#x0009;&lt;Option name=&quot;TKERSA2_LIB_PATH&quot;&gt;${dfauthsvr.install.dir}/lib&lt;/Option&gt;"
                                        encoding="${dmv.file.enc}"
                                    />
                                </else>
                            </if>
                        </then>
                    </if>
                    <!-- Backup, copy and update the odbc.ini file if we are on a UNIX host -->
                    <if>
                        <not>
                            <isset property="onWindowsHosts"/>
                        </not>
                        <then>
                            <!-- Backup the new odbc.ini file which contains the DSN for Oracle if ODBC is used -->
                            <echo message="Backing up ${dfauthsvrc.release.number} odbc.ini file." />
                            <if><available file="${dfauthsvr.install.dir}/etc/odbc.ini" />
                                <then>
                                    <move file="${dfauthsvr.install.dir}/etc/odbc.ini" tofile="${dfauthsvr.install.dir}/etc/odbc.ini.bak"/>
                                </then>
                            </if>

                            <!-- Copy over old config files -->
                            <echo message="Copying @{dfauthVersion} odbc.ini file over." />
                            <copy file="@{dfauthdir}/etc/odbc.ini" tofile="${dfauthsvr.install.dir}/etc/odbc.ini" overwrite="true" />

                            <checkBOM file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}odbc.ini" cmd=""/>
                            <replace
                                file="${dfauthsvr.install.dir}/etc/odbc.ini"
                                token="${file.separator}@{dfauthVersion}${file.separator}"
                                value="${file.separator}${dfauthsvrc.release.number}${file.separator}"
                                encoding="${dmv.file.enc}"
                            />
                        </then>
                    </if>

                    <if>
                        <equals arg1="${config.target.name}" arg2="updateConfigure" />
                        <then>
                            <!-- Update the license file location -->
                            <echo message="Adding updated license." />
                            <checkBOM file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml" cmd=""/>
                            <replace
                                file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml"
                                token="&lt;Option name=&quot;Provider&quot;&gt;SAS&lt;/Option&gt;"
                                value="&lt;Option name=&quot;Provider&quot;&gt;SAS&lt;/Option&gt;${line.separator}&#x0009;&#x0009;&#x0009;&lt;Option name=&quot;Location&quot;&gt;${dfauthsvrc.license}&lt;/Option&gt;"
                                encoding="${dmv.file.enc}"
                            />
                        </then>
                    </if>

                    <!-- Replace old with new -->
                    <echo message="Replace all @{dfauthVersion} with ${dfauthsvrc.release.number}." />
                    <checkBOM file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml" cmd=""/>
                    <replace
                        file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml"
                        token="${file.separator}@{dfauthVersion}${file.separator}"
                        value="${file.separator}${dfauthsvrc.release.number}${file.separator}"
                        encoding="${dmv.file.enc}"
                    />
                    <!-- Starting of the new service is handled in a later call -->

                    <!-- Touch file to indicate that we have done the conversion -->
                    <touch file="${config.lev.dir}/DataFluxAuthenticationServer/uip/32to41uip" mkdirs="true"/>
                </then>
            </if>
            <echo message="*** Leaving Target: dfauthsvrc.updateFrom32" />
        </sequential>
    </macrodef>

    <!-- =================================
          macrodef: checkBOM
         ================================= -->
    <macrodef name="checkBOM">
      <attribute name="file.cfg"/>
      <attribute name="cmd"/>
        <sequential>
            <echo message="*** Entering Target: checkBOM" />
            <if><isset property="onWindowsHosts"/>
                <then>
                    <propertyregex property="server.config"
                                   input="@{file.cfg}"
                                   regexp="\\"
                                   replace="/"
                                   global="true" />
                </then>
                <else>
                    <var name="server.config" value="@{file.cfg}"/>
                </else>
            </if>
            <taskdef name="groovy" classname="org.codehaus.groovy.ant.Groovy" classpath="${default.groovy.path}"/>
            <groovy>
                def fn           = properties.'server.config'
                def fis             = new FileInputStream("${fn}")
                def bom         = new byte[4]
                // default to UTF-8
                properties.'dmv.file.enc'     = "UTF-8"
                try {
                    fis.read(bom)
                    //convert to hex strings each being a char
                    String hex0 = Integer.toHexString(bom[0] &amp; 0xFF)
                    String hex1 = Integer.toHexString(bom[1] &amp; 0xFF)
                    String hex2 = Integer.toHexString(bom[2] &amp; 0xFF)
                    String hex3 = Integer.toHexString(bom[3] &amp; 0xFF)

                    if (((hex0 == "ff") &amp;&amp; (hex1 == "fe") &amp;&amp;
                         (hex2 == "00") &amp;&amp; (hex3 == "00")) ||
                        ((hex0 == "fe") &amp;&amp; (hex1 == "ff") &amp;&amp;
                         (hex2 == "00") &amp;&amp; (hex3 == "00")))
                    {
                        properties.'dmv.file.enc' = "UTF-32"
                        if(properties.verbose == "true") { println "found UTF-32 encoding"}
                    }

                    if( (hex0 == "ff" &amp;&amp; hex1 == "fe") ||
                        (hex0 == "fe" &amp;&amp; hex1 == "ff"))
                    {
                        properties.'dmv.file.enc' = "UTF-16"
                        if(properties.verbose == "true") { println "found UTF-16 encoding" }
                    }
                    if ((hex0 == "ef") &amp;&amp;
                        (hex1 == "bb") &amp;&amp;
                        (hex2 == "bf"))
                    {
                        properties.'dmv.file.enc' = "UTF-8"
                        if(properties.verbose == "true") { println "found UTF-8 encoding"}
                    }
                    if(properties.verbose == "true") { println "use encoding: ${properties.'dmv.file.enc'}"}
                } catch(e) {
                    println " failed to read file: ${fn}"
                } finally { fis.close() }
            </groovy>
            <echo message="*** Leaving Target: checkBOM" />
        </sequential>
    </macrodef>

    <!--                                                                   -->
    <!-- dfauthsvrc_migration_importdb - If a database has been exported   -->
    <!--                                 import it.                        -->
    <!--                                                                   -->
    <macrodef name="dfauthsvrc_migration_importdb">
        <sequential>
            <echo message="*** Entering Target: dfauthsvrc_migration_importdb" />
            <!-- Initialize the config status file -->
            <listMigratedObjects product12byte="dfauthsvrc" debug="true" />

            <echo level="info" message="Import database from migration package."/>

            <property name="dfauthsvrc.database.file.name" value="smu_dfauthdb.tbk"/>
            <property name="dfauthsvrc.database.file" value="${dfauthsvrc.migrated.object.configobj.dir}${file.separator}${dfauthsvrc.database.file.name}"/>

            <if>
                <not><available file="${dfauthsvrc.database.file}" type="file"/></not>
                    <then>
                        <echo level="info" message="The migration package does not contain a Authentication Server database file, so there is no database to migrate."/>
                    </then>
                <else>

                    <echo level="info" message="The migration found a Authentication Server database file. There is a database to migrate."/>

                    <!-- Adjust command based on operating system. -->
                    <property name="dfauthsvrc.resultproperty" value="0"/>
                    <!--
                    <property name="util.cmd.extension" value=""/>
                    
                    <if>
                        <equals arg1="${os.localhost.type}" arg2="win"/>
                            <then>
                                <var name="util.cmd.extension" unset="true"/>
                                <property name="util.cmd.extension" value=".cmd"/>
                            </then>
                    </if>
                    -->
                    <!-- Check to see if there is an existing version of the database file. -->
                    <if>
                        <available file="${dfauthsvr.install.dir}/var/asdb.tdb"/>
                        <!-- Do we backup the file then migrate over or simply replace? -->
                            <then>
                                <!-- Alter file name based on Operating system -->
                                <if>
                                    <equals arg1="${os.localhost.type}" arg2="win"/>
                                        <then>
                                            <property name="dbFileName" value="ASDB.TDB"/>
                                            <property name="dbBkupExt" value="BAK"/>
                                        </then>
                                        <else>
                                            <property name="dbFileName" value="asdb.tdb"/>
                                            <property name="dbBkupExt" value="bak"/>
                                        </else>
                                </if>
                                <!-- Move the file for later use if needed -->
                                <move file="${dfauthsvr.install.dir}/var/${dbFileName}" tofile="${dfauthsvr.install.dir}/var/${dbFileName}.${dbBkupExt}"/>
                            </then>
                        <else>
                            <!-- Fragements for Windows/UNIX Operating systems. -->
                            <exec executable="${dfauthsvr.install.dir}/bin/dasutil${util.cmd.extension}" failonerror="true" resultproperty="dfauthsvrc.resultproperty">
                                <arg value="restore" />
                                <arg value="-db" />
                                <arg value="asdb" />
                                <arg value="${dfauthsvrc.database.file}" />
                            </exec>
                        </else>
                    </if>

                </else>
            </if>
            <echo message="*** Leaving Target: dfauthsvrc_migration_importdb" />
        </sequential>
    </macrodef>

    <!--                                                                   -->
    <!-- portAuthUsersToOMR - Port the Auth server data to OMR             -->
    <!--                                                                   -->
    <macrodef name="portAuthUsersToOMR">
        <sequential>
            <echo message="*** Entering Target: portAuthUsersToOMR" />

            <!-- insert metadata query here to check if asproc is run -->
            <if>
                <and>
                    <istrue value="${dfauthsvr.asproc.not.run}"/>
                    <or>
                        <equals arg1="${dfauthsvrc.migrated.release.version}" arg2="4.1" />
                        <equals arg1="${dfauthsvrc.maintenance.from.version}" arg2="3.2" />
                        <equals arg1="${dfauthsvrc.maintenance.from.version}" arg2="4.1" />
						<equals arg1="${dfauthsvr.old.version}" arg2="3.2" />
                    </or>
                </and>
                <then>
                    <!-- Check if asproc has run and touch file -->
                    <echo message="ASProc run check" />
                    <getmetadatavalues    host="${iomsrv.metadatasrv.host}"
                        port="${iomsrv.metadatasrv.port}"
                        user="${metadata.connection.userid}"
                        password="${metadata.connection.passwd}"
                        repository="${oma.repository.foundation.name}"
                        type="TextStore"
                        search="@StoredText='iom://${dfauthsvrc.migrated.from.host}:${dfauthsvrc.migrated.from.port};Bridge;clsid=2d1bcdbf-f900-4ca9-85f6-95ecdbaf2122'"
                        attribute="Id"
                        delimiter=" "
                        outputproperty="dfauthsvrc.asproc.id"/>
                    <!-- code to touch file if ASProc run else fail and exit with message to user -->
                    <if>
                        <equals arg1="${dfauthsvrc.asproc.id}" arg2="" />
                        <then>
                            <!-- See if the user wants to maually run the asproc on their own -->
                            <if>
                                <and>
                                    <isset property="dfauth.autorun.asproc" />
                                    <isfalse value="${dfauth.autorun.asproc}" />
                                </and>
                                <then>
                                    <insertWarning valueToUse="${warning.dfauthsvrc.asproc.run.unchecked.txt}" />
                                    <propertyfile file="${whatFailed.property.file}">
                                        <entry key="warningsEncountered" value="true" />
                                    </propertyfile>
                                </then>
                            </if>

                            <!-- Backup config file and modify original to make system user the trusted user-->
                            <echo message="Backing up as_serv_aspsql.xml file." />
                            <if><available file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml" />
                                <then>
                                    <copy file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml" tofile="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml.bak" overwrite="true"/>
                                    <checkBOM file.cfg="${dfauthsvr.install.dir}${file.separator}etc${file.separator}as_serv_aspsql.xml" cmd=""/>
                                    <replace
                                        file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml"
                                        token="&lt;OptionSet name=&quot;TrustedUsers&quot;&gt;"
                                        value="&lt;OptionSet name=&quot;TrustedUsers&quot;&gt;&#xA;&lt;Option name=&quot;Account&quot;&gt;${dfauthsvrc.account.systemUser}&lt;/Option&gt;"
                                        encoding="${dmv.file.enc}"
                                    />
                                </then>
                            </if>
                            <!-- Start the server -->
                            <echo message="Start the Authentication Server." />
                            <dfauthsvrc.startServer />

                            <!-- Run ASProc if asproc checked-->
                            <if><istrue value="${dfauth.autorun.asproc}" />
                                <then>
                                        <echo message="Run ASPROC to migrate users." />
                                        <dfauthsvrc_run_asproc />
                                </then>
                            </if>
                            
                            <!-- Stop the server -->
                            <echo message="Stop the Authentication Server." />
                            <dfauthsvrc.stopServer />

                            <!-- Reset the configuration file -->
                            <if><available file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml.bak" />
                                <then>
                                    <copy file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml" tofile="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml.asproc" overwrite="true"/>
                                    <copy file="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml.bak" tofile="${dfauthsvr.install.dir}/etc/as_serv_aspsql.xml" overwrite="true"/>
                                </then>
                            </if>
                        </then>
                        <else>
                            <!-- ASPROC was run with success. Create touch file to be used later in config process -->
                            <if>
                                <not>
                                    <available file="${dfauthsvr.install.dir}${file.separator}asproc/asproc" type="file" />
                                </not>
                                <then>
                                    <touch file="${dfauthsvr.install.dir}${file.separator}asproc/asproc" mkdirs="true" />
                                </then>
                            </if>
                        </else>
                    </if>
                </then>
            </if>

            <echo message="*** Leaving Target: portAuthUsersToOMR" />

        </sequential>
    </macrodef>

    <!--                                                                   -->
    <!-- dfauthsvrc_run_asproc - ?????             -->
    <!--                                                                   -->
    <macrodef name="dfauthsvrc_run_asproc">
        <sequential>
            <echo message="*** Entering Target: dfauthsvrc_run_asproc" />

            <!-- Run asproc -->
            <!-- Define filter set for asproc -->
            <filterset id="asproc.filters">
                <filter token="iomsrv.metadatasrv.host"
                        value="${iomsrv.metadatasrv.host}"
                />
                <filter token="oma.person.admin.login.userid"
                        value="${metadata.connection.userid}"
                />
                <filter token="iomsrv.metadatasrv.port"
                        value="${iomsrv.metadatasrv.port}"
                />
                <filter token="dfauthsvrc.host"
                        value="${dfauthsvrc.host}"
                />
                <filter token="dfauthsvrc.account.systemUser"
                        value="${dfauthsvrc.account.systemUser}"
                />
                <filter token="dfauthsvrc.port"
                        value="${dfauthsvrc.port}"
                />
                <filter token="dfauthsvrc.migrated.from.host"
                        value="${dfauthsvrc.migrated.from.host}"
                />
                <filter token="dfauthsvrc.migrated.from.port"
                        value="${dfauthsvrc.migrated.from.port}"
                />
            </filterset>

            <!-- Update the appxml file using the above filterset. -->
            
            <copyOrigFiles
                srcdir="${dfauthsvrc.deployment.migrate.dir}"
                todir="${dfauthsvrc.deployment.metadata.dir}"
                filterset.refid="asproc.filters"
            />
            <!-- Set properties for log and list options when calling asproc -->
            <property name="dfauthsvr.asproc.log" value="LOG"/>
            <property name="dfauthsvr.asproc.print" value="PRINT"/>

            <executeSASprogram inputProgramPath="${dfauthsvrc.deployment.metadata.dir}${file.separator}asexport_default.sas"
                   optionResultProperty="dfauthsvr.asproc.result"
                   outputfile="${config.lev.logs.configure.dir}${file.separator}${config.currprod.12byte}_asproc.result.log"
                   additionalArgs="${dfauthsvrc.sascode.additional.args}"
                   output="${dfauthsvr.asproc.log}"
            />
            
            <if>
                <not>
                    <equals arg1="${dfauthsvr.asproc.result}" arg2="0"/>
                </not>
                <then>
                    <insertWarning valueToUse="${warning.dfauthsvrc.asproc.run.failed.txt}" />
                    <propertyfile file="${whatFailed.property.file}">
                        <entry key="warningsEncountered" value="true" />
                    </propertyfile>
                </then>
                <else>
                    <property name="dfauthsvr.asproc.not.run" value="false"/>
                    <!-- Touch file to indicate that asproc ran successfully -->
                    <touch file="${dfauthsvr.install.dir}${file.separator}asproc/asproc" mkdirs="true"/>
                </else>
            </if>
            <!-- generate the validation job log first -->
            <executeSASprogram inputProgramPath="${dfauthsvrc.deployment.metadata.dir}${file.separator}asexport_default_validate.sas"
                           optionResultProperty="dfauthsvr.asproc.validate.log.result"
                           outputfile="${config.lev.logs.configure.dir}${file.separator}${config.currprod.12byte}_asproc.validation_result.log"
                           additionalArgs="${dfauthsvrc.sascode.additional.args}"
                           output="${dfauthsvr.asproc.log}"
            />
                        
            <!-- generate the validation job list file -->            
            <executeSASprogram inputProgramPath="${dfauthsvrc.deployment.metadata.dir}${file.separator}asexport_default_validate.sas"
                           optionResultProperty="dfauthsvr.asproc.validate.print.result"
                           outputfile="${config.lev.logs.configure.dir}${file.separator}${config.currprod.12byte}_asproc.validation_result.lst"
                           additionalArgs="${dfauthsvrc.sascode.additional.args}"
                           output="${dfauthsvr.asproc.print}"
            />
            
            <!-- Check if the lst file was created and set property for docparts -->
            <if><available file="${config.lev.logs.configure.dir}${file.separator}${config.currprod.12byte}_asproc.validation_result.lst" />
                <then>
                    <insertWarning valueToUse="${warning.dfauthsvrc.asproc.validate.run.txt}" />
                    <propertyfile file="${whatFailed.property.file}">
                        <entry key="warningsEncountered" value="true" />
                    </propertyfile>
                </then>
            </if>                
            
            
            <echo message="*** Leaving Target: dfauthsvrc_run_asproc" />
        </sequential>
    </macrodef>

    <!--                                                                   -->
    <!-- executeSASprogram - ?????             -->
    <!--                                                                   -->
    <macrodef name="executeSASprogram">
        <!-- This option needs to be in uppercase as that's what SAS prefers -->
        <attribute name="inputProgramPath"/>
        <!-- The property to store the result it -->
        <attribute name="optionResultProperty"/>
        <attribute name="outputfile" default="${config.lev.logs.configure.dir}${file.separator}/${config.currprod.12byte}_executeSASprogram.log"/>
        <attribute name="dir" default="${temp.dir}"/>
        <attribute name="additionalArgs" default=""/>
        <attribute name="output" default="${dfauthsvr.asproc.log}"/>

        <sequential>
            <echo message="*** Entering Target: executeSASprogram" />

            <!-- Set SAS command-line options only for Windows -->
            <var name="splash.option" value=""/>
            <var name="icon.option" value=""/>
            <var name="sasconfigfile.option.name" value=""/>
            <var name="sasconfigfile.option.value" value=""/>
            <var name="sasconfigfile.cfg.path" value=""/>

            <if><isset property="onWindowsHosts"/>
                <then>
                    <var name="splash.option" value="-nosplash"/>
                    <var name="icon.option" value="-icon"/>

                    <!-- windows hosts use the -config option to specify the sasv9.cfg file -->
                    <var name="sasconfigfile.option.name" value="-config"/>
                    <var name="sasconfigfile.option.value" value="${sas.config.file}"/>
                </then>
                <else>
                    <!-- non windows hosts need to use the SASCFGPATH environment variable to properly process multiple sasv9.cfg files -->
                    <var name="sasconfigfile.cfg.path" value="${sas.config.file}" />
                </else>
            </if>

            <setConfigStatusFile target="portAuthUsersToOMR"
                                 task="portAuthUsersToOMR"
                                 message="${dfauthsvrc.status.asproc.failure.msg}"
            />


            <exec executable="${sas.exec.file}" logError="true" dir="@{dir}" resultproperty="@{optionResultProperty}">
                <env key="SASCFGPATH" value="${sasconfigfile.cfg.path}"/>
                <env key="metapassword" value="${metadata.connection.passwd}"/>
                <env key="aspassword" value="${dfauthsvrc.account.passwd}"/>
                <arg value="@{inputProgramPath}"/>
                <arg value="-@{output}"/>
                <arg value="&quot;@{outputfile}&quot;"/>
                <arg value="${sasconfigfile.option.name}"/>
                <arg value="${sasconfigfile.option.value}"/>
                <arg value="${splash.option}"/>
                <arg value="${icon.option}"/>
                <arg line="@{additionalArgs}"/>
            </exec>
            <echo message="*** Leaving Target: executeSASprogram" />

         </sequential>
    </macrodef>
    
    <!-- = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =
      macrodef: dfauthsvrc.setsecure
      Set the correct encryption algorithm.
    = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = -->
    <macrodef name="dfauthsvrc.setsecure">
        <sequential>
            <echo message="dfauthsvrc.setsecure: Entering Target" />
            
            <!-- Set encryption for OOTB & Migration -->
            <echo message="dfauthsvrc.migration.is_enabled from setsecure = ${dfauthsvrc.migration.is_enabled}" />
            <if><isfalse value="${dfauthsvrc.migration.is_enabled}"/>
                <!-- OOTB -->
				<then>
                    <!-- OOTB and FIPS is selected -->
					<echo message="Setsecure OOTB Code" />
					<echo message="iomsrv.fipsencryption.is_enabled = ${iomsrv.fipsencryption.is_enabled}" />
                    <if><istrue value="${iomsrv.fipsencryption.is_enabled}"/>
					    <then>
							<var name="dfauthsvrc.encryption.value" unset="true"/>
                            <property name="dfauthsvrc.encryption.value" value="fips"/>
						</then>
						<elseif><equals arg1="${iomsrv.netencralg.name}" arg2="SASProprietary"/>
						    <then>
                                <echo message="iomsrv.netencralg.name = ${iomsrv.netencralg.name} is it SASProprietary" />
								<var name="dfauthsvrc.encryption.value" unset="true"/>
                                <property name="dfauthsvrc.encryption.value" value="sas"/>
                            </then>
                        </elseif>
                        <else>
                            <var name="dfauthsvrc.encryption.value" unset="true"/>
                            <property name="dfauthsvrc.encryption.value" value="aes"/>
                        </else>
                    </if>
					<echo message="dfauthsvrc.encryption.value = ${dfauthsvrc.encryption.value} for OOTB" />
                </then>
                <else>
                    <!-- Migration mode -->
					<echo message="Setsecure Migration Mode" />
					<echo message="iomsrv.netencralg.name = ${iomsrv.netencralg.name} is it SASProprietary" />
					<echo message="dfauthsvrc.migrated.encryption = ${dfauthsvrc.migrated.encryption} is it SASProprietary" />
					<echo message="iomsrv.fipsencryption.is_enabled = ${iomsrv.fipsencryption.is_enabled}" />
					
					<!-- If FIPS on source then set FIPS and AES -->
                    <if><istrue value="${iomsrv.fipsencryption.is_enabled}"/>
					    <then>
							<var name="dfauthsvrc.encryption.value" unset="true"/>
                            <property name="dfauthsvrc.encryption.value" value="fips"/>
						</then>
						<!-- Not FIPS -->
						<else>
							<if><equals arg1="${iomsrv.netencralg.name}" arg2="SASProprietary"/>
								<then>
									<if><equals arg1="${dfauthsvrc.migrated.encryption}" arg2="SASProprietary"/>
										<then>
											<echo message="Migration SMU SASProprietary" />
											<var name="dfauthsvrc.encryption.value" unset="true"/>
											<property name="dfauthsvrc.encryption.value" value="sas"/>
										</then>
										<else>
											<echo message="Migration SMU aes" />
											<var name="dfauthsvrc.encryption.value" unset="true"/>
											<property name="dfauthsvrc.encryption.value" value="aes"/>
											<echo message="dfauthsvrc.encryption.value = ${dfauthsvrc.encryption.value} should be AES" />
										</else>
									</if>
								</then>
								<else>
									<echo message="Migration SMU aes" />
									<var name="dfauthsvrc.encryption.value" unset="true"/>
									<property name="dfauthsvrc.encryption.value" value="aes"/>
									<echo message="dfauthsvrc.encryption.value = ${dfauthsvrc.encryption.value} should be AES" />
								</else>
							</if>
						</else>
					</if>
					<echo message="dfauthsvrc.encryption.value = ${dfauthsvrc.encryption.value} for MIG" />
                </else>
            </if>
            
            <!-- call the script and pass the value -->
            <setConfigStatusFile
                 target="configure"
                 task="dfauthsvrc.setsecure"
                 message="${dfauthsvrc.status.UnknownFailure.msg} dfauthsvrc.setsecure"/>
                     
            <exec executable="${dfauthsvr.install.dir}/bin/set_secure${util.cmd.extension}" failonerror="true" resultproperty="dfauthsvrc.secure.resultproperty">
                <arg value="${dfauthsvrc.encryption.value}" />
            </exec>
    
            <echo message="dfauthsvrc.setsecure: Leaving Target" />
        </sequential>
    </macrodef>

</project>

