GP-6829 Removed OpenTrustManager use. Restricted auto generated

self-signed certs to loopback connections only. Added CertTool and
updated svrREADME.md.  Added actions for launching windows/mac
certificate manager.  Improved Ghidra Server command queuing with proper
command file sequencing.  Added CertTool to simplify certificate
generation and requests. Refactor BSim PostgreSQL delployment and
cert/key use.  Revised both bsim and bsim_ctl commands.
This commit is contained in:
ghidra1
2026-07-02 18:15:19 -04:00
parent 1bc38d195a
commit fd431fe597
59 changed files with 8621 additions and 1472 deletions

View File

@@ -31,5 +31,5 @@
<stringAttribute key="org.eclipse.jdt.launching.MODULE_NAME" value="Framework Utility"/>
<stringAttribute key="org.eclipse.jdt.launching.PROGRAM_ARGUMENTS" value="ghidra.GhidraRun"/>
<stringAttribute key="org.eclipse.jdt.launching.PROJECT_ATTR" value="Framework Utility"/>
<stringAttribute key="org.eclipse.jdt.launching.VM_ARGUMENTS" value="-XX:+IgnoreUnrecognizedVMOptions&#13;&#10;-Djava.system.class.loader=ghidra.GhidraClassLoader&#13;&#10;-Xshare:off&#13;&#10;-Dfile.encoding=UTF8&#13;&#10;-Duser.country=US&#13;&#10;-Duser.language=en&#13;&#10;-Dsun.java2d.pmoffscreen=false&#13;&#10;-Dsun.java2d.xrender=true&#13;&#10;-Dsun.java2d.d3d=false&#13;&#10;-Xdock:name=&quot;Ghidra&quot;&#13;&#10;-Dvisualvm.display.name=Ghidra&#13;&#10;-Dpython.console.encoding=UTF-8&#13;&#10;-Djavax.xml.accessExternalDTD=&#13;&#10;-Djavax.xml.accessExternalSchema=&#13;&#10;-Djavax.xml.accessExternalStylesheet=&#13;&#10;-Dsun.awt.disablegrab=true&#13;&#10;--enable-native-access=ALL-UNNAMED&#13;&#10;--sun-misc-unsafe-memory-access=allow&#13;&#10;-XX:+UseCompactObjectHeaders"/>
<stringAttribute key="org.eclipse.jdt.launching.VM_ARGUMENTS" value="-XX:+IgnoreUnrecognizedVMOptions&#13;&#10;-Djava.system.class.loader=ghidra.GhidraClassLoader&#13;&#10;-Dghidra.disable.loopback.server.authentication=true&#13;&#10;-Xshare:off&#13;&#10;-Dfile.encoding=UTF8&#13;&#10;-Duser.country=US&#13;&#10;-Duser.language=en&#13;&#10;-Dsun.java2d.pmoffscreen=false&#13;&#10;-Dsun.java2d.xrender=true&#13;&#10;-Dsun.java2d.d3d=false&#13;&#10;-Xdock:name=&quot;Ghidra&quot;&#13;&#10;-Dvisualvm.display.name=Ghidra&#13;&#10;-Dpython.console.encoding=UTF-8&#13;&#10;-Djavax.xml.accessExternalDTD=&#13;&#10;-Djavax.xml.accessExternalSchema=&#13;&#10;-Djavax.xml.accessExternalStylesheet=&#13;&#10;-Dsun.awt.disablegrab=true&#13;&#10;--enable-native-access=ALL-UNNAMED&#13;&#10;--sun-misc-unsafe-memory-access=allow&#13;&#10;-XX:+UseCompactObjectHeaders"/>
</launchConfiguration>

View File

@@ -67,7 +67,7 @@
</P>
<P>The C-Parser has been successfully used on Visual Studio, GCC, and Objective-C header
files.&nbsp; The include files for GCC, Windows, MacOS, and ANSI C were all parsed with the
files.&nbsp; The include files for GCC, Windows, macOS, and ANSI C were all parsed with the
C-Parser plugin.&nbsp; Most vanilla C-Header files can be parsed using the C-Parser.&nbsp;
However, just as in C software development the correct include order and "-D" pre-defines
must be specified.&nbsp; Getting this correct can be much like porting an application from

View File

@@ -100,7 +100,15 @@
<H3>&nbsp;</H3>
<H3><A name="Set_PKI_Certificate"></A>PKI Certificate &nbsp;</H3>
<H3><A name="Manage_Certificates"></A>Manage Certificates (Windows and macOS only)&nbsp;</H3>
<BLOCKQUOTE>
<P>On Windows and macOS systems the menu action <B>Edit<IMG src="help/shared/arrow.gif" border="0">Manage Certificates...</B>
may be used to launch the system-provided user Certificate Manager. This dialog may be used to specify both user and
trusted certificates.</P>
</BLOCKQUOTE>
<H3><A name="Set_PKI_Certificate"></A>Set PKI Certificate &nbsp;</H3>
<BLOCKQUOTE>
<P>The Ghidra Server can be set up to perform user authentication using PKI
@@ -120,10 +128,26 @@
</BLOCKQUOTE>
<BLOCKQUOTE>
<P><IMG src="help/shared/note.png" border="0"> If the Ghidra Server
is not using PKI Certificates for user authentication, you can ignore this menu option.</P>
<P><IMG src="help/shared/note.png" border="0"> If the Ghidra Server, or other server,
is not using PKI Certificates for user authentication, you can ignore this menu option
since the certificate keystore will not be used.</P>
</BLOCKQUOTE>
</BLOCKQUOTE>
<BLOCKQUOTE>
<P><IMG src="help/shared/note.png" border="0"> Specifying the single user certificate
keystore in this fashion will prevent the OS managed keystore from being used
(applied to Windows and macOS only).</P>
</BLOCKQUOTE>
<H3><A name="Clear_PKI_Certificate"></A>Clear PKI Certificate &nbsp;</H3>
<BLOCKQUOTE>
<P>If a PKI Certificate keystore had previously been set, it may be cleared using the
menu action <B>Edit<IMG src="help/shared/arrow.gif" border="0">Clear PKI Certificate...</B>
if no longer needed or to allow OS managed certificates to be used.</P>
</BLOCKQUOTE>
</BLOCKQUOTE>
<H2><A name="Exit_Ghidra"></A>Exiting Ghidra</H2>

View File

@@ -18,6 +18,8 @@ package ghidra.framework;
import java.io.File;
import java.util.List;
import org.apache.commons.lang3.StringUtils;
import generic.jar.ResourceFile;
import ghidra.GhidraClassLoader;
import ghidra.framework.preferences.Preferences;
@@ -91,10 +93,17 @@ public class HeadlessGhidraApplicationConfiguration extends ApplicationConfigura
}
/**
* Locate certs file within the Ghidra root directory. If found this will be used
* for initializing the ApplicationTrustManager used for SSL/PKI.
* Locate 'cacerts' file within the Ghidra root directory if 'ghidra.cacerts' property has not
* already been specified. If found this will be used to establish the property which will be
* used by {@link DefaultTrustManagerFactory}.
*/
private void locateCACertsFile() {
String cacertsPath = System.getProperty(DefaultTrustManagerFactory.GHIDRA_CACERTS_PATH_PROPERTY);
if (!StringUtils.isBlank(cacertsPath)) {
return; // property will be used by DefaultTrustManagerFactory
}
for (ResourceFile appRoot : Application.getApplicationRootDirectories()) {
File cacertsFile = new File(appRoot.getAbsolutePath(), "cacerts");
if (cacertsFile.isFile()) {