fix: disable server TLS 1.0, 1.x and 1.2 SHA1 (#22168)

Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
This commit is contained in:
Jian Qiu
2025-02-24 17:30:09 +08:00
committed by GitHub
co-authored by Qiu Jian
parent f32665adf2
commit 68aef7f31c
3 changed files with 26 additions and 20 deletions
+22 -20
View File
@@ -78,6 +78,8 @@ type Application struct {
isTLS bool
enableProfiling bool
allowTLS1x bool
}
const (
@@ -139,6 +141,12 @@ func (app *Application) SetDefaultTimeout(to time.Duration) *Application {
return app
}
func (app *Application) AllowTLS1x() *Application {
log.Infof("Allow TLS1.0&1.1")
app.allowTLS1x = true
return app
}
func SplitPath(path string) []string {
ret := make([]string, 0)
for _, seg := range strings.Split(path, "/") {
@@ -361,6 +369,7 @@ func (app *Application) defaultHandle(w http.ResponseWriter, r *http.Request, ri
w.Header().Set("Server", "Yunion AppServer/Go/2018.4")
w.Header().Set("X-Frame-Options", "SAMEORIGIN")
w.Header().Set("X-XSS-Protection", "1; mode=block")
w.Header().Set("X-Content-Type-Options", "nosniff")
if app.isTLS {
w.Header().Set("Strict-Transport-Security", "max-age=31536000; includeSubDomains")
}
@@ -478,7 +487,18 @@ func (app *Application) initServer(addr string) *http.Server {
cipherSuites := []uint16{}
for _, suite := range tls.CipherSuites() {
cipherSuites = append(cipherSuites, suite.ID)
if !strings.HasSuffix(suite.Name, "_SHA") {
cipherSuites = append(cipherSuites, suite.ID)
}
}
minTLSVer := uint16(tls.VersionTLS12)
if app.allowTLS1x {
minTLSVer = tls.VersionTLS10
}
tlsConf := &tls.Config{
CipherSuites: cipherSuites,
MinVersion: minTLSVer,
}
s := &http.Server{
@@ -493,9 +513,7 @@ func (app *Application) initServer(addr string) *http.Server {
// issue like: https://github.com/megaease/easegress/issues/481
ErrorLog: olog.New(io.Discard, "", olog.LstdFlags),
TLSConfig: &tls.Config{
CipherSuites: cipherSuites,
},
TLSConfig: tlsConf,
}
return s
}
@@ -603,22 +621,6 @@ func (app *Application) listenAndServeInternal(s *http.Server, certFile, keyFile
}
}
func isJsonContentType(r *http.Request) bool {
contType := strings.ToLower(r.Header.Get("Content-Type"))
if strings.HasPrefix(contType, "application/json") {
return true
}
return false
}
func isFormContentType(r *http.Request) bool {
contType := strings.ToLower(r.Header.Get("Content-Type"))
if strings.HasPrefix(contType, "application/json") {
return true
}
return false
}
type TContentType string
const (
+3
View File
@@ -40,6 +40,9 @@ func InitApp(options *common_options.BaseOptions, dbAccess bool) *appsrv.Applica
if options.EnableAppProfiling {
app.EnableProfiling()
}
if options.AllowTLS1x {
app.AllowTLS1x()
}
return app
}
+1
View File
@@ -119,6 +119,7 @@ type BaseOptions struct {
PlatformNames map[string]string `help:"identity name of this platform by language"`
EnableAppProfiling bool `help:"enable profiling API" default:"false"`
AllowTLS1x bool `help:"allow obsolete insecure TLS V1.0&1.1" default:"false" json:"allow_tls1x"`
EnableChangeOwnerAutoRename bool `help:"Allows renaming when changing names" default:"false"`
EnableDefaultPolicy bool `help:"Enable defualt policies" default:"true"`