From bf3876c925cd16b8e81a6de9b7815fc6551cb609 Mon Sep 17 00:00:00 2001 From: ghidra1 Date: Fri, 22 Jan 2021 19:50:02 -0500 Subject: [PATCH] GP-622 revised to allow connections to utilize TLSv1.3 by default with Java 11 --- .../ghidra/net/SSLContextInitializer.java | 15 ++++++++++++- .../Common/support/launch.properties | 21 +++++++++++++++++-- 2 files changed, 33 insertions(+), 3 deletions(-) diff --git a/Ghidra/Framework/Generic/src/main/java/ghidra/net/SSLContextInitializer.java b/Ghidra/Framework/Generic/src/main/java/ghidra/net/SSLContextInitializer.java index 4bfc178c75..fa631e97fa 100644 --- a/Ghidra/Framework/Generic/src/main/java/ghidra/net/SSLContextInitializer.java +++ b/Ghidra/Framework/Generic/src/main/java/ghidra/net/SSLContextInitializer.java @@ -36,7 +36,17 @@ import ghidra.util.Msg; */ public class SSLContextInitializer implements ModuleInitializer { - private static final String DEFAULT_TLS_PROTOCOL = "TLSv1.2"; + // NOTE: specifying a default protocol of "TLS" will defer the default + // protocol selection to the underlying protocol implementation. + // The protocol may be specified as a comma-separated list of protocol + // versions where the leftmost takes precendence during the initial + // negotiation. The Java security policy may be modified to disable + // the use of specific protocols via the jdk.tls.disabledAlgorithms + // property. The security property file is located within the + // java installation at jre/lib/security/java.security + + // Default list of allowed TLS protocols for outbound connections + private static final String DEFAULT_TLS_PROTOCOL = "TLS"; private static final String PROTOCOL_PROPERTY = "ghidra.net.ssl.protocol"; @@ -97,6 +107,9 @@ public class SSLContextInitializer implements ModuleInitializer { HttpsURLConnection.setDefaultHostnameVerifier(new HttpsHostnameVerifier()); } + // Establish default HTTPS socket factory + HttpsURLConnection.setDefaultSSLSocketFactory(sslContext.getSocketFactory()); + return true; } diff --git a/Ghidra/RuntimeScripts/Common/support/launch.properties b/Ghidra/RuntimeScripts/Common/support/launch.properties index 05dab23e0e..5212b28141 100644 --- a/Ghidra/RuntimeScripts/Common/support/launch.properties +++ b/Ghidra/RuntimeScripts/Common/support/launch.properties @@ -24,8 +24,25 @@ VMARGS_LINUX=-Dsun.java2d.uiScale=1 VMARGS_LINUX=-Dawt.useSystemAAFontSettings=on VMARGS_WINDOWS=-Dsun.java2d.d3d=false -# Set acceptable HTTPS protocols -VMARGS=-Dhttps.protocols=TLSv1,TLSv1.1,TLSv1.2 +# Set acceptable TLS protocol version(s) for outbound client SSL connections. +# The Ghidra application establishes the default SSLContext based upon +# this list of acceptable protocols. Omiting this property setting or +# simply specifying TLS without a version will defer to the underlying TLS +# protocol implementation and its preferred defaults. During the connection +# handshake both sides will agree upon a preferred protocol. The default +# SSLContext established within Ghidra is intended to support all +# Ghidra Servers client connections and other SSL-based +# network connections such as https, although it is possible for a +# connection-specific SSLContext to be established which bypasses this +# setting (e.g., log4j, bndlib). +#VMARGS=-Dghidra.net.ssl.protocol=TLSv1.3,TLSv1.2 + +# Set acceptable HTTPS protocols for outbound HTTPS client connections for those +# cases which do not use the default SSLContext and associated socket factory +# (e.g., Apache HttpClientBuilder). Specifying TLS without a version will defer +# to the underlying TLS protocol implementation. +#VMARGS=-Dhttps.protocols=TLSv1.3,TLSv1.2 +VMARGS=-Dhttps.protocols=TLS # Force PKI authentication of all HTTPS and Ghidra Server connections (i.e., # server authentication)