GP-622 revised to allow connections to utilize TLSv1.3 by default with

Java 11
This commit is contained in:
ghidra1
2021-01-22 19:50:02 -05:00
parent b5c7e7104c
commit bf3876c925
2 changed files with 33 additions and 3 deletions

View File

@@ -24,8 +24,25 @@ VMARGS_LINUX=-Dsun.java2d.uiScale=1
VMARGS_LINUX=-Dawt.useSystemAAFontSettings=on
VMARGS_WINDOWS=-Dsun.java2d.d3d=false
# Set acceptable HTTPS protocols
VMARGS=-Dhttps.protocols=TLSv1,TLSv1.1,TLSv1.2
# Set acceptable TLS protocol version(s) for outbound client SSL connections.
# The Ghidra application establishes the default SSLContext based upon
# this list of acceptable protocols. Omiting this property setting or
# simply specifying TLS without a version will defer to the underlying TLS
# protocol implementation and its preferred defaults. During the connection
# handshake both sides will agree upon a preferred protocol. The default
# SSLContext established within Ghidra is intended to support all
# Ghidra Servers client connections and other SSL-based
# network connections such as https, although it is possible for a
# connection-specific SSLContext to be established which bypasses this
# setting (e.g., log4j, bndlib).
#VMARGS=-Dghidra.net.ssl.protocol=TLSv1.3,TLSv1.2
# Set acceptable HTTPS protocols for outbound HTTPS client connections for those
# cases which do not use the default SSLContext and associated socket factory
# (e.g., Apache HttpClientBuilder). Specifying TLS without a version will defer
# to the underlying TLS protocol implementation.
#VMARGS=-Dhttps.protocols=TLSv1.3,TLSv1.2
VMARGS=-Dhttps.protocols=TLS
# Force PKI authentication of all HTTPS and Ghidra Server connections (i.e.,
# server authentication)