mirror of
https://github.com/NationalSecurityAgency/ghidra.git
synced 2026-10-01 17:11:44 -09:00
GT-2685 Improved Ghidra Server interface binding and remote address
identification. Minor fixes to database cleanup and project conversion.
This commit is contained in:
@@ -106,9 +106,10 @@ ghidra.repositories.dir=./repositories
|
||||
# Ghidra server startup parameters.
|
||||
#
|
||||
# Command line parameters: (Add command line parameters as needed and renumber each starting from .1)
|
||||
# [-ip###.###.###.###] [-p#] [-a#] [-anonymous] [-ssh] [-d<ntDomain>] [-e<days>] [-u] [-n] <repositories_path>
|
||||
# [-ip <hostname>] [-i ###.###.###.###] [-p#] [-a#] [-anonymous] [-ssh] [-d<ntDomain>] [-e<days>] [-u] [-n] <repositories_path>
|
||||
#
|
||||
# -ip###.###.###.### : ip address to bound to (by default, uses IP address bound to hostname)
|
||||
# -ip <hostname> : remote access hostname or IP address to be used by clients
|
||||
# -i #.#.#.# : interface IPv4 address to accept connections on (default all interfaces)
|
||||
# -p# : base TCP port to be used (default: 13100)
|
||||
# -a# : an optional authentication mode where # is a value 0 or 2
|
||||
# 0 - Private user password
|
||||
|
||||
@@ -58,6 +58,7 @@ typewriter {
|
||||
<LI><a href="#troubleshooting">Troubleshooting</a></LI>
|
||||
<UL>
|
||||
<LI><a href="#checkinFailures">Failures Creating Repository Folders / Checking in Files</a></LI>
|
||||
<LI><a href="#connectErrors">Client/Server connection errors</a></LI>
|
||||
<LI><a href="#windowsMissingTempDirectory">MS Windows - ERROR Missing Temp Directory</a></LI>
|
||||
<LI><a href="#windows7and8_scriptErrors">MS Windows 7 and 8 - ghidraSvr.bat, svrInstall.bat,
|
||||
or svrUninstall.bat Error</a></LI>
|
||||
@@ -203,11 +204,12 @@ name/address queries.
|
||||
</P>
|
||||
|
||||
<P>
|
||||
It is also highly recommended that the server's local hostname (with and with domain name) be
|
||||
mapped to its IP address with the hosts file (<typewriter>/etc/hosts</typewriter> on Linux). If
|
||||
this is not desirable for your setup, then the server should be explicitly bound to a specific IP
|
||||
address (see the <typewriter>-ip</typewriter> parameter in the <a href="#serverOptions">Server
|
||||
Options</a> section).
|
||||
By default the server will attempt to identify an appropriate remote access IP address which will
|
||||
be written to the log at startup. In addition, the server will only bind/listen to incoming
|
||||
connections on this address by default. It is important to understand between the published address
|
||||
and the listening address. See the <typewriter>-ip</typewriter> parameter and
|
||||
<typewriter>-i</typewriter> options in the <a href="#serverOptions">Server
|
||||
Options</a> section for more details.
|
||||
</P>
|
||||
|
||||
(<a href="#top">Back to Top</a>)
|
||||
@@ -289,8 +291,20 @@ public key files may be made without restarting the Ghidra Server.
|
||||
login for <typewriter>-a0</typewriter> authentication mode. Without this option, the users
|
||||
client-side login ID will be assumed.</LI>
|
||||
<br>
|
||||
<LI><typewriter>-ip<#.#.#.#></typewriter><br>Forces the server to be bound to a specific
|
||||
IP address on the server. This option is required when a server has multiple IP interfaces.</LI>
|
||||
<LI><typewriter>-ip <hostname></typewriter><br>Identifies the remote access IP address or
|
||||
hostname (FQDN) which should be used by remote clients to access the server. By default the
|
||||
host name reported by the operating system is resolved to an IP address, if this fails the
|
||||
local loopback address is used. The server log will indicate the remote access hostname
|
||||
at startup. This option may be required when a server has multiple IP interfaces, relies on
|
||||
a dynamic DNS or other network address translation for incoming connections.
|
||||
This option establishes the property value for <i>java.rmi.server.hostname</i>.
|
||||
</LI>
|
||||
<br>
|
||||
<LI><typewriter>-i <#.#.#.#></typewriter><br>Forces the server to be bound to a specific
|
||||
IP interface on the server. If specified and the <typewriter>-ip</typewriter> option is not,
|
||||
the address specified by <typewriter>-i</typewriter> will establish the remote access IP
|
||||
address as well as restricting the listing interface. If this option is not specified connections
|
||||
will be accepted on any interface.</LI>
|
||||
<br>
|
||||
<LI><typewriter>-p#</typewriter><br>Allows the base TCP port to be specified (default: 13100). The
|
||||
server utilizes three (3) TCP ports starting with the specified base port (e.g., 13100,13101 and 13102).
|
||||
@@ -707,7 +721,7 @@ cacerts keystore file location is <typewriter>Ghidra/cacerts</typewriter>
|
||||
and is also specified by the <typewriter>ghidra.cacerts</typewriter> property setting within the
|
||||
<typewriter>server.conf</typewriter> file. Uncomment this specification within the
|
||||
<typewriter>server.conf</typewriter> file to activate use of the <typewriter>cacerts</typewriter>
|
||||
for all incoming SSL connections (i.e., all Ghidra client users must install and employ the
|
||||
for all incoming SSL/TLS connections (i.e., all Ghidra client users must install and employ the
|
||||
use of their personal PKI signing certificate for both headed and headless use - see
|
||||
<a href="#pkiCertificates">PKI Certificates</a>). Clients can also impose server authentication
|
||||
for all HTTPS and Ghidra Server connections by creating the <typewriter>cacerts</typewriter> file
|
||||
@@ -858,6 +872,17 @@ If you see continuous failures to create repository folders or failures to check
|
||||
the disk space on the server or folder permissions. When the server runs out of disk space, it
|
||||
cannot create folders or check in files.
|
||||
</P>
|
||||
<br>
|
||||
|
||||
<a name="connectErrors"><h3><u>Client/Server connection errors</u></h3></a>
|
||||
<P>
|
||||
The Ghidra Server has transitioned to using SSL/TLS connections when accessing the server's RMI
|
||||
registry. This change in communication protocol can cause unexpected symptoms when attempting to
|
||||
connect incompatible versions of Ghidra. When an older incompatible Ghidra client attempts to access a
|
||||
newer SSL/TLS enabled Ghidra Server registry, the following connection error will occur:
|
||||
<PRE>
|
||||
non-JRMP server at remote endpoint
|
||||
</PRE>
|
||||
|
||||
<br>
|
||||
<a name="windowsMissingTempDirectory"><h3><u>MS Windows - ERROR Missing Temp Directory</u></h3></a>
|
||||
|
||||
Reference in New Issue
Block a user