mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add configurable cipher suites for tls listening (#10505)
* feat: add configurable cipher suites for tls listening * tls.VersionName is go 1.21, copy the function
This commit is contained in:
Generated
+3
-1
@@ -368,6 +368,7 @@ curl -X GET http://coder-server:8080/api/v2/deployment/config \
|
||||
"host": "string",
|
||||
"port": "string"
|
||||
},
|
||||
"allow_insecure_ciphers": true,
|
||||
"cert_file": ["string"],
|
||||
"client_auth": "string",
|
||||
"client_ca_file": "string",
|
||||
@@ -376,7 +377,8 @@ curl -X GET http://coder-server:8080/api/v2/deployment/config \
|
||||
"enable": true,
|
||||
"key_file": ["string"],
|
||||
"min_version": "string",
|
||||
"redirect_http": true
|
||||
"redirect_http": true,
|
||||
"supported_ciphers": ["string"]
|
||||
},
|
||||
"trace": {
|
||||
"capture_logs": true,
|
||||
|
||||
Generated
+23
-15
@@ -2289,6 +2289,7 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
|
||||
"host": "string",
|
||||
"port": "string"
|
||||
},
|
||||
"allow_insecure_ciphers": true,
|
||||
"cert_file": ["string"],
|
||||
"client_auth": "string",
|
||||
"client_ca_file": "string",
|
||||
@@ -2297,7 +2298,8 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
|
||||
"enable": true,
|
||||
"key_file": ["string"],
|
||||
"min_version": "string",
|
||||
"redirect_http": true
|
||||
"redirect_http": true,
|
||||
"supported_ciphers": ["string"]
|
||||
},
|
||||
"trace": {
|
||||
"capture_logs": true,
|
||||
@@ -2658,6 +2660,7 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
|
||||
"host": "string",
|
||||
"port": "string"
|
||||
},
|
||||
"allow_insecure_ciphers": true,
|
||||
"cert_file": ["string"],
|
||||
"client_auth": "string",
|
||||
"client_ca_file": "string",
|
||||
@@ -2666,7 +2669,8 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
|
||||
"enable": true,
|
||||
"key_file": ["string"],
|
||||
"min_version": "string",
|
||||
"redirect_http": true
|
||||
"redirect_http": true,
|
||||
"supported_ciphers": ["string"]
|
||||
},
|
||||
"trace": {
|
||||
"capture_logs": true,
|
||||
@@ -4278,6 +4282,7 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
|
||||
"host": "string",
|
||||
"port": "string"
|
||||
},
|
||||
"allow_insecure_ciphers": true,
|
||||
"cert_file": ["string"],
|
||||
"client_auth": "string",
|
||||
"client_ca_file": "string",
|
||||
@@ -4286,24 +4291,27 @@ AuthorizationObject can represent a "set" of objects, such as: all workspaces in
|
||||
"enable": true,
|
||||
"key_file": ["string"],
|
||||
"min_version": "string",
|
||||
"redirect_http": true
|
||||
"redirect_http": true,
|
||||
"supported_ciphers": ["string"]
|
||||
}
|
||||
```
|
||||
|
||||
### Properties
|
||||
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
| ------------------ | ------------------------------------ | -------- | ------------ | ----------- |
|
||||
| `address` | [clibase.HostPort](#clibasehostport) | false | | |
|
||||
| `cert_file` | array of string | false | | |
|
||||
| `client_auth` | string | false | | |
|
||||
| `client_ca_file` | string | false | | |
|
||||
| `client_cert_file` | string | false | | |
|
||||
| `client_key_file` | string | false | | |
|
||||
| `enable` | boolean | false | | |
|
||||
| `key_file` | array of string | false | | |
|
||||
| `min_version` | string | false | | |
|
||||
| `redirect_http` | boolean | false | | |
|
||||
| Name | Type | Required | Restrictions | Description |
|
||||
| ------------------------ | ------------------------------------ | -------- | ------------ | ----------- |
|
||||
| `address` | [clibase.HostPort](#clibasehostport) | false | | |
|
||||
| `allow_insecure_ciphers` | boolean | false | | |
|
||||
| `cert_file` | array of string | false | | |
|
||||
| `client_auth` | string | false | | |
|
||||
| `client_ca_file` | string | false | | |
|
||||
| `client_cert_file` | string | false | | |
|
||||
| `client_key_file` | string | false | | |
|
||||
| `enable` | boolean | false | | |
|
||||
| `key_file` | array of string | false | | |
|
||||
| `min_version` | string | false | | |
|
||||
| `redirect_http` | boolean | false | | |
|
||||
| `supported_ciphers` | array of string | false | | |
|
||||
|
||||
## codersdk.TelemetryConfig
|
||||
|
||||
|
||||
Generated
+21
@@ -874,6 +874,17 @@ Two optional fields can be set in the Strict-Transport-Security header; 'include
|
||||
|
||||
HTTPS bind address of the server.
|
||||
|
||||
### --tls-allow-insecure-ciphers
|
||||
|
||||
| | |
|
||||
| ----------- | --------------------------------------------------- |
|
||||
| Type | <code>bool</code> |
|
||||
| Environment | <code>$CODER_TLS_ALLOW_INSECURE_CIPHERS</code> |
|
||||
| YAML | <code>networking.tls.tlsAllowInsecureCiphers</code> |
|
||||
| Default | <code>false</code> |
|
||||
|
||||
By default, only ciphers marked as 'secure' are allowed to be used. See https://github.com/golang/go/blob/master/src/crypto/tls/cipher_suites.go#L82-L95.
|
||||
|
||||
### --tls-cert-file
|
||||
|
||||
| | |
|
||||
@@ -884,6 +895,16 @@ HTTPS bind address of the server.
|
||||
|
||||
Path to each certificate for TLS. It requires a PEM-encoded file. To configure the listener to use a CA certificate, concatenate the primary certificate and the CA certificate together. The primary certificate should appear first in the combined file.
|
||||
|
||||
### --tls-ciphers
|
||||
|
||||
| | |
|
||||
| ----------- | -------------------------------------- |
|
||||
| Type | <code>string-array</code> |
|
||||
| Environment | <code>$CODER_TLS_CIPHERS</code> |
|
||||
| YAML | <code>networking.tls.tlsCiphers</code> |
|
||||
|
||||
Specify specific TLS ciphers that allowed to be used. See https://github.com/golang/go/blob/master/src/crypto/tls/cipher_suites.go#L53-L75.
|
||||
|
||||
### --tls-client-auth
|
||||
|
||||
| | |
|
||||
|
||||
Reference in New Issue
Block a user