Files
ghidra/Ghidra/Features/BSim/data/serverconfig.xml
ghidra1 fd431fe597 GP-6829 Removed OpenTrustManager use. Restricted auto generated
self-signed certs to loopback connections only. Added CertTool and
updated svrREADME.md.  Added actions for launching windows/mac
certificate manager.  Improved Ghidra Server command queuing with proper
command file sequencing.  Added CertTool to simplify certificate
generation and requests. Refactor BSim PostgreSQL delployment and
cert/key use.  Revised both bsim and bsim_ctl commands.
2026-09-03 15:46:13 -04:00

28 lines
2.5 KiB
XML
Executable File

<serverconfig> <!-- Runtime parameters for the query server -->
<!-- Performance-tuning settings (tunable="true"). These are written to a clearly-marked,
user-editable block in postgresql.conf at 'init' and are PRESERVED by 'configure'. Edit
them here (before init) to change installation-wide defaults, or edit the tunable block in
an existing data directory's postgresql.conf (then restart). -->
<config key="shared_buffers" tunable="true">2GB</config> <!-- RAM used for the shared page cache -->
<config key="work_mem" tunable="true">16MB</config> <!-- Max memory per hash/sort operation -->
<config key="checkpoint_timeout" tunable="true">30min</config> <!-- Time between forced flushes to disk -->
<config key="listen_addresses">'*'</config> <!-- '*' = all available, '0.0.0.0' just IPv4, 'localhost' -->
<config key="ssl">on</config> <!-- SSL required for all connections (hostssl entries only) -->
<config key="ssl_cert_file">'server.crt'</config> <!-- Server certificate (generated/imported by bsim_ctl init) -->
<config key="ssl_key_file">'server.key'</config> <!-- Server private key (owner-read-only) -->
<config key="ssl_min_protocol_version">'TLSv1.2'</config> <!-- Min TLS protocol (permits TLSv1.2+TLSv1.3); matches Ghidra Server ghidra.tls.server.protocols -->
<!-- TLSv1.2 cipher suites (OpenSSL names) consistent with the Ghidra Server
jdk.tls.server.cipherSuites property. TLSv1.3 cipher suites are not configurable in
PostgreSQL 15 and use the OpenSSL defaults, which include TLS_AES_256_GCM_SHA384. -->
<config key="ssl_ciphers">'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384'</config>
<config key="ssl_prefer_server_ciphers">on</config> <!-- Prefer the server's cipher order -->
<config key="logging_collector">on</config> <!-- Capture server logs into log_directory (Q3) -->
<config key="log_directory">'log'</config> <!-- Log directory (relative to the data directory) (Q3) -->
<config key="password_encryption">scram-sha-256</config>
<!-- <connect db="all" user="all" type="local" method="trust"/> -->
<connect db="all" user="all" addr="127.0.0.1/32" type="hostssl" method="trust"/>
<connect db="all" user="all" addr="::1/128" type="hostssl" method="trust"/>
<connect db="all" user="all" addr="all" type="hostssl" method="trust"/>
</serverconfig>