mirror of
https://github.com/NationalSecurityAgency/ghidra.git
synced 2026-09-28 17:11:11 -09:00
self-signed certs to loopback connections only. Added CertTool and updated svrREADME.md. Added actions for launching windows/mac certificate manager. Improved Ghidra Server command queuing with proper command file sequencing. Added CertTool to simplify certificate generation and requests. Refactor BSim PostgreSQL delployment and cert/key use. Revised both bsim and bsim_ctl commands.
28 lines
2.5 KiB
XML
Executable File
28 lines
2.5 KiB
XML
Executable File
<serverconfig> <!-- Runtime parameters for the query server -->
|
|
<!-- Performance-tuning settings (tunable="true"). These are written to a clearly-marked,
|
|
user-editable block in postgresql.conf at 'init' and are PRESERVED by 'configure'. Edit
|
|
them here (before init) to change installation-wide defaults, or edit the tunable block in
|
|
an existing data directory's postgresql.conf (then restart). -->
|
|
<config key="shared_buffers" tunable="true">2GB</config> <!-- RAM used for the shared page cache -->
|
|
<config key="work_mem" tunable="true">16MB</config> <!-- Max memory per hash/sort operation -->
|
|
<config key="checkpoint_timeout" tunable="true">30min</config> <!-- Time between forced flushes to disk -->
|
|
<config key="listen_addresses">'*'</config> <!-- '*' = all available, '0.0.0.0' just IPv4, 'localhost' -->
|
|
<config key="ssl">on</config> <!-- SSL required for all connections (hostssl entries only) -->
|
|
<config key="ssl_cert_file">'server.crt'</config> <!-- Server certificate (generated/imported by bsim_ctl init) -->
|
|
<config key="ssl_key_file">'server.key'</config> <!-- Server private key (owner-read-only) -->
|
|
<config key="ssl_min_protocol_version">'TLSv1.2'</config> <!-- Min TLS protocol (permits TLSv1.2+TLSv1.3); matches Ghidra Server ghidra.tls.server.protocols -->
|
|
<!-- TLSv1.2 cipher suites (OpenSSL names) consistent with the Ghidra Server
|
|
jdk.tls.server.cipherSuites property. TLSv1.3 cipher suites are not configurable in
|
|
PostgreSQL 15 and use the OpenSSL defaults, which include TLS_AES_256_GCM_SHA384. -->
|
|
<config key="ssl_ciphers">'ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384'</config>
|
|
<config key="ssl_prefer_server_ciphers">on</config> <!-- Prefer the server's cipher order -->
|
|
<config key="logging_collector">on</config> <!-- Capture server logs into log_directory (Q3) -->
|
|
<config key="log_directory">'log'</config> <!-- Log directory (relative to the data directory) (Q3) -->
|
|
<config key="password_encryption">scram-sha-256</config>
|
|
|
|
<!-- <connect db="all" user="all" type="local" method="trust"/> -->
|
|
<connect db="all" user="all" addr="127.0.0.1/32" type="hostssl" method="trust"/>
|
|
<connect db="all" user="all" addr="::1/128" type="hostssl" method="trust"/>
|
|
<connect db="all" user="all" addr="all" type="hostssl" method="trust"/>
|
|
</serverconfig>
|