GT-2685 Improved Ghidra Server interface binding and remote address

identification.  Minor fixes to database cleanup and project conversion.
This commit is contained in:
ghidra1
2019-05-30 19:22:46 -04:00
parent 8495cc68ee
commit 17bb619048
15 changed files with 268 additions and 211 deletions

View File

@@ -106,9 +106,10 @@ ghidra.repositories.dir=./repositories
# Ghidra server startup parameters.
#
# Command line parameters: (Add command line parameters as needed and renumber each starting from .1)
# [-ip###.###.###.###] [-p#] [-a#] [-anonymous] [-ssh] [-d<ntDomain>] [-e<days>] [-u] [-n] <repositories_path>
# [-ip <hostname>] [-i ###.###.###.###] [-p#] [-a#] [-anonymous] [-ssh] [-d<ntDomain>] [-e<days>] [-u] [-n] <repositories_path>
#
# -ip###.###.###.### : ip address to bound to (by default, uses IP address bound to hostname)
# -ip <hostname> : remote access hostname or IP address to be used by clients
# -i #.#.#.# : interface IPv4 address to accept connections on (default all interfaces)
# -p# : base TCP port to be used (default: 13100)
# -a# : an optional authentication mode where # is a value 0 or 2
# 0 - Private user password

View File

@@ -58,6 +58,7 @@ typewriter {
<LI><a href="#troubleshooting">Troubleshooting</a></LI>
<UL>
<LI><a href="#checkinFailures">Failures Creating Repository Folders / Checking in Files</a></LI>
<LI><a href="#connectErrors">Client/Server connection errors</a></LI>
<LI><a href="#windowsMissingTempDirectory">MS Windows - ERROR Missing Temp Directory</a></LI>
<LI><a href="#windows7and8_scriptErrors">MS Windows 7 and 8 - ghidraSvr.bat, svrInstall.bat,
or svrUninstall.bat Error</a></LI>
@@ -203,11 +204,12 @@ name/address queries.
</P>
<P>
It is also highly recommended that the server&apos;s local hostname (with and with domain name) be
mapped to its IP address with the hosts file (<typewriter>/etc/hosts</typewriter> on Linux). If
this is not desirable for your setup, then the server should be explicitly bound to a specific IP
address (see the <typewriter>-ip</typewriter> parameter in the <a href="#serverOptions">Server
Options</a> section).
By default the server will attempt to identify an appropriate remote access IP address which will
be written to the log at startup. In addition, the server will only bind/listen to incoming
connections on this address by default. It is important to understand between the published address
and the listening address. See the <typewriter>-ip</typewriter> parameter and
<typewriter>-i</typewriter> options in the <a href="#serverOptions">Server
Options</a> section for more details.
</P>
(<a href="#top">Back to Top</a>)
@@ -289,8 +291,20 @@ public key files may be made without restarting the Ghidra Server.
login for <typewriter>-a0</typewriter> authentication mode. Without this option, the users
client-side login ID will be assumed.</LI>
<br>
<LI><typewriter>-ip&lt;#.#.#.#&gt;</typewriter><br>Forces the server to be bound to a specific
IP address on the server. This option is required when a server has multiple IP interfaces.</LI>
<LI><typewriter>-ip &lt;hostname&gt;</typewriter><br>Identifies the remote access IP address or
hostname (FQDN) which should be used by remote clients to access the server. By default the
host name reported by the operating system is resolved to an IP address, if this fails the
local loopback address is used. The server log will indicate the remote access hostname
at startup. This option may be required when a server has multiple IP interfaces, relies on
a dynamic DNS or other network address translation for incoming connections.
This option establishes the property value for <i>java.rmi.server.hostname</i>.
</LI>
<br>
<LI><typewriter>-i &lt;#.#.#.#&gt;</typewriter><br>Forces the server to be bound to a specific
IP interface on the server. If specified and the <typewriter>-ip</typewriter> option is not,
the address specified by <typewriter>-i</typewriter> will establish the remote access IP
address as well as restricting the listing interface. If this option is not specified connections
will be accepted on any interface.</LI>
<br>
<LI><typewriter>-p#</typewriter><br>Allows the base TCP port to be specified (default: 13100). The
server utilizes three (3) TCP ports starting with the specified base port (e.g., 13100,13101 and 13102).
@@ -707,7 +721,7 @@ cacerts keystore file location is <typewriter>Ghidra/cacerts</typewriter>
and is also specified by the <typewriter>ghidra.cacerts</typewriter> property setting within the
<typewriter>server.conf</typewriter> file. Uncomment this specification within the
<typewriter>server.conf</typewriter> file to activate use of the <typewriter>cacerts</typewriter>
for all incoming SSL connections (i.e., all Ghidra client users must install and employ the
for all incoming SSL/TLS connections (i.e., all Ghidra client users must install and employ the
use of their personal PKI signing certificate for both headed and headless use - see
<a href="#pkiCertificates">PKI Certificates</a>). Clients can also impose server authentication
for all HTTPS and Ghidra Server connections by creating the <typewriter>cacerts</typewriter> file
@@ -858,6 +872,17 @@ If you see continuous failures to create repository folders or failures to check
the disk space on the server or folder permissions. When the server runs out of disk space, it
cannot create folders or check in files.
</P>
<br>
<a name="connectErrors"><h3><u>Client/Server connection errors</u></h3></a>
<P>
The Ghidra Server has transitioned to using SSL/TLS connections when accessing the server's RMI
registry. This change in communication protocol can cause unexpected symptoms when attempting to
connect incompatible versions of Ghidra. When an older incompatible Ghidra client attempts to access a
newer SSL/TLS enabled Ghidra Server registry, the following connection error will occur:
<PRE>
non-JRMP server at remote endpoint
</PRE>
<br>
<a name="windowsMissingTempDirectory"><h3><u>MS Windows - ERROR Missing Temp Directory</u></h3></a>