diff --git a/pkg/appsrv/appsrv.go b/pkg/appsrv/appsrv.go index 9dd8c194f8..3fffe63667 100644 --- a/pkg/appsrv/appsrv.go +++ b/pkg/appsrv/appsrv.go @@ -78,6 +78,8 @@ type Application struct { isTLS bool enableProfiling bool + + allowTLS1x bool } const ( @@ -139,6 +141,12 @@ func (app *Application) SetDefaultTimeout(to time.Duration) *Application { return app } +func (app *Application) AllowTLS1x() *Application { + log.Infof("Allow TLS1.0&1.1") + app.allowTLS1x = true + return app +} + func SplitPath(path string) []string { ret := make([]string, 0) for _, seg := range strings.Split(path, "/") { @@ -361,6 +369,7 @@ func (app *Application) defaultHandle(w http.ResponseWriter, r *http.Request, ri w.Header().Set("Server", "Yunion AppServer/Go/2018.4") w.Header().Set("X-Frame-Options", "SAMEORIGIN") w.Header().Set("X-XSS-Protection", "1; mode=block") + w.Header().Set("X-Content-Type-Options", "nosniff") if app.isTLS { w.Header().Set("Strict-Transport-Security", "max-age=31536000; includeSubDomains") } @@ -478,7 +487,18 @@ func (app *Application) initServer(addr string) *http.Server { cipherSuites := []uint16{} for _, suite := range tls.CipherSuites() { - cipherSuites = append(cipherSuites, suite.ID) + if !strings.HasSuffix(suite.Name, "_SHA") { + cipherSuites = append(cipherSuites, suite.ID) + } + } + + minTLSVer := uint16(tls.VersionTLS12) + if app.allowTLS1x { + minTLSVer = tls.VersionTLS10 + } + tlsConf := &tls.Config{ + CipherSuites: cipherSuites, + MinVersion: minTLSVer, } s := &http.Server{ @@ -493,9 +513,7 @@ func (app *Application) initServer(addr string) *http.Server { // issue like: https://github.com/megaease/easegress/issues/481 ErrorLog: olog.New(io.Discard, "", olog.LstdFlags), - TLSConfig: &tls.Config{ - CipherSuites: cipherSuites, - }, + TLSConfig: tlsConf, } return s } @@ -603,22 +621,6 @@ func (app *Application) listenAndServeInternal(s *http.Server, certFile, keyFile } } -func isJsonContentType(r *http.Request) bool { - contType := strings.ToLower(r.Header.Get("Content-Type")) - if strings.HasPrefix(contType, "application/json") { - return true - } - return false -} - -func isFormContentType(r *http.Request) bool { - contType := strings.ToLower(r.Header.Get("Content-Type")) - if strings.HasPrefix(contType, "application/json") { - return true - } - return false -} - type TContentType string const ( diff --git a/pkg/cloudcommon/app/app.go b/pkg/cloudcommon/app/app.go index 52bb14345b..0e0f257c8d 100644 --- a/pkg/cloudcommon/app/app.go +++ b/pkg/cloudcommon/app/app.go @@ -40,6 +40,9 @@ func InitApp(options *common_options.BaseOptions, dbAccess bool) *appsrv.Applica if options.EnableAppProfiling { app.EnableProfiling() } + if options.AllowTLS1x { + app.AllowTLS1x() + } return app } diff --git a/pkg/cloudcommon/options/options.go b/pkg/cloudcommon/options/options.go index f65b8863c0..adca07ab99 100644 --- a/pkg/cloudcommon/options/options.go +++ b/pkg/cloudcommon/options/options.go @@ -119,6 +119,7 @@ type BaseOptions struct { PlatformNames map[string]string `help:"identity name of this platform by language"` EnableAppProfiling bool `help:"enable profiling API" default:"false"` + AllowTLS1x bool `help:"allow obsolete insecure TLS V1.0&1.1" default:"false" json:"allow_tls1x"` EnableChangeOwnerAutoRename bool `help:"Allows renaming when changing names" default:"false"` EnableDefaultPolicy bool `help:"Enable defualt policies" default:"true"`