mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
fix: disable server TLS 1.0, 1.x and 1.2 SHA1 (#22168)
Co-authored-by: Qiu Jian <qiujian@yunionyun.com>
This commit is contained in:
+22
-20
@@ -78,6 +78,8 @@ type Application struct {
|
||||
isTLS bool
|
||||
|
||||
enableProfiling bool
|
||||
|
||||
allowTLS1x bool
|
||||
}
|
||||
|
||||
const (
|
||||
@@ -139,6 +141,12 @@ func (app *Application) SetDefaultTimeout(to time.Duration) *Application {
|
||||
return app
|
||||
}
|
||||
|
||||
func (app *Application) AllowTLS1x() *Application {
|
||||
log.Infof("Allow TLS1.0&1.1")
|
||||
app.allowTLS1x = true
|
||||
return app
|
||||
}
|
||||
|
||||
func SplitPath(path string) []string {
|
||||
ret := make([]string, 0)
|
||||
for _, seg := range strings.Split(path, "/") {
|
||||
@@ -361,6 +369,7 @@ func (app *Application) defaultHandle(w http.ResponseWriter, r *http.Request, ri
|
||||
w.Header().Set("Server", "Yunion AppServer/Go/2018.4")
|
||||
w.Header().Set("X-Frame-Options", "SAMEORIGIN")
|
||||
w.Header().Set("X-XSS-Protection", "1; mode=block")
|
||||
w.Header().Set("X-Content-Type-Options", "nosniff")
|
||||
if app.isTLS {
|
||||
w.Header().Set("Strict-Transport-Security", "max-age=31536000; includeSubDomains")
|
||||
}
|
||||
@@ -478,7 +487,18 @@ func (app *Application) initServer(addr string) *http.Server {
|
||||
|
||||
cipherSuites := []uint16{}
|
||||
for _, suite := range tls.CipherSuites() {
|
||||
cipherSuites = append(cipherSuites, suite.ID)
|
||||
if !strings.HasSuffix(suite.Name, "_SHA") {
|
||||
cipherSuites = append(cipherSuites, suite.ID)
|
||||
}
|
||||
}
|
||||
|
||||
minTLSVer := uint16(tls.VersionTLS12)
|
||||
if app.allowTLS1x {
|
||||
minTLSVer = tls.VersionTLS10
|
||||
}
|
||||
tlsConf := &tls.Config{
|
||||
CipherSuites: cipherSuites,
|
||||
MinVersion: minTLSVer,
|
||||
}
|
||||
|
||||
s := &http.Server{
|
||||
@@ -493,9 +513,7 @@ func (app *Application) initServer(addr string) *http.Server {
|
||||
// issue like: https://github.com/megaease/easegress/issues/481
|
||||
ErrorLog: olog.New(io.Discard, "", olog.LstdFlags),
|
||||
|
||||
TLSConfig: &tls.Config{
|
||||
CipherSuites: cipherSuites,
|
||||
},
|
||||
TLSConfig: tlsConf,
|
||||
}
|
||||
return s
|
||||
}
|
||||
@@ -603,22 +621,6 @@ func (app *Application) listenAndServeInternal(s *http.Server, certFile, keyFile
|
||||
}
|
||||
}
|
||||
|
||||
func isJsonContentType(r *http.Request) bool {
|
||||
contType := strings.ToLower(r.Header.Get("Content-Type"))
|
||||
if strings.HasPrefix(contType, "application/json") {
|
||||
return true
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func isFormContentType(r *http.Request) bool {
|
||||
contType := strings.ToLower(r.Header.Get("Content-Type"))
|
||||
if strings.HasPrefix(contType, "application/json") {
|
||||
return true
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
type TContentType string
|
||||
|
||||
const (
|
||||
|
||||
@@ -40,6 +40,9 @@ func InitApp(options *common_options.BaseOptions, dbAccess bool) *appsrv.Applica
|
||||
if options.EnableAppProfiling {
|
||||
app.EnableProfiling()
|
||||
}
|
||||
if options.AllowTLS1x {
|
||||
app.AllowTLS1x()
|
||||
}
|
||||
return app
|
||||
}
|
||||
|
||||
|
||||
@@ -119,6 +119,7 @@ type BaseOptions struct {
|
||||
PlatformNames map[string]string `help:"identity name of this platform by language"`
|
||||
|
||||
EnableAppProfiling bool `help:"enable profiling API" default:"false"`
|
||||
AllowTLS1x bool `help:"allow obsolete insecure TLS V1.0&1.1" default:"false" json:"allow_tls1x"`
|
||||
|
||||
EnableChangeOwnerAutoRename bool `help:"Allows renaming when changing names" default:"false"`
|
||||
EnableDefaultPolicy bool `help:"Enable defualt policies" default:"true"`
|
||||
|
||||
Reference in New Issue
Block a user