mirror of
				https://github.com/apache/cloudstack.git
				synced 2025-10-26 08:42:29 +01:00 
			
		
		
		
	CS-17504: Weak SSL ciphers supported by the management server
Signed-off-by: Rohit Yadav <rohit.yadav@shapeblue.com>
This commit is contained in:
		
							parent
							
								
									19e3c0168e
								
							
						
					
					
						commit
						f947fad197
					
				
							
								
								
									
										18
									
								
								client/tomcatconf/java.security.ciphers.in
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										18
									
								
								client/tomcatconf/java.security.ciphers.in
									
									
									
									
									
										Normal file
									
								
							| @ -0,0 +1,18 @@ | ||||
|  # Licensed to the Apache Software Foundation (ASF) under one | ||||
|  # or more contributor license agreements.  See the NOTICE file | ||||
|  # distributed with this work for additional information | ||||
|  # regarding copyright ownership.  The ASF licenses this file | ||||
|  # to you under the Apache License, Version 2.0 (the | ||||
|  # "License"); you may not use this file except in compliance | ||||
|  # with the License.  You may obtain a copy of the License at | ||||
|  # | ||||
|  #   http://www.apache.org/licenses/LICENSE-2.0 | ||||
|  # | ||||
|  # Unless required by applicable law or agreed to in writing, | ||||
|  # software distributed under the License is distributed on an | ||||
|  # "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY | ||||
|  # KIND, either express or implied.  See the License for the | ||||
|  # specific language governing permissions and limitations | ||||
|  # under the License. | ||||
| 
 | ||||
| jdk.tls.disabledAlgorithms=DH keySize < 128, RSA keySize < 128, DES keySize < 128, SHA1 keySize < 128, MD5 keySize < 128, RC4 | ||||
| @ -41,7 +41,7 @@ CATALINA_TMPDIR="@MSENVIRON@/temp" | ||||
| 
 | ||||
| # Use JAVA_OPTS to set java.library.path for libtcnative.so | ||||
| #JAVA_OPTS="-Djava.library.path=/usr/lib64" | ||||
| JAVA_OPTS="-Djava.awt.headless=true -Dcom.sun.management.jmxremote=false -Xmx2g -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=@MSLOGDIR@ -XX:PermSize=512M -XX:MaxPermSize=800m" | ||||
| JAVA_OPTS="-Djava.awt.headless=true -Dcom.sun.management.jmxremote=false -Xmx2g -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=@MSLOGDIR@ -XX:PermSize=512M -XX:MaxPermSize=800m -Djava.security.properties=/etc/cloudstack/management/java.security.ciphers" | ||||
| 
 | ||||
| # What user should run tomcat | ||||
| TOMCAT_USER="@MSUSER@" | ||||
|  | ||||
| @ -40,7 +40,7 @@ CATALINA_TMPDIR="@MSENVIRON@/temp" | ||||
| 
 | ||||
| # Use JAVA_OPTS to set java.library.path for libtcnative.so | ||||
| #JAVA_OPTS="-Djava.library.path=/usr/lib64" | ||||
| JAVA_OPTS="-Djava.awt.headless=true -Dcom.sun.management.jmxremote=false -Djavax.net.ssl.trustStore=/etc/cloudstack/management/cloudmanagementserver.keystore -Djavax.net.ssl.trustStorePassword=vmops.com -Xmx2g -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=@MSLOGDIR@ -XX:MaxPermSize=800m -XX:PermSize=512M" | ||||
| JAVA_OPTS="-Djava.awt.headless=true -Dcom.sun.management.jmxremote=false -Djavax.net.ssl.trustStore=/etc/cloudstack/management/cloudmanagementserver.keystore -Djavax.net.ssl.trustStorePassword=vmops.com -Xmx2g -XX:+HeapDumpOnOutOfMemoryError -XX:HeapDumpPath=@MSLOGDIR@ -XX:MaxPermSize=800m -XX:PermSize=512M -Djava.security.properties=/etc/cloudstack/management/java.security.ciphers" | ||||
| 
 | ||||
| # What user should run tomcat | ||||
| TOMCAT_USER="@MSUSER@" | ||||
|  | ||||
							
								
								
									
										1
									
								
								debian/cloudstack-management.install
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										1
									
								
								debian/cloudstack-management.install
									
									
									
									
										vendored
									
									
								
							| @ -30,6 +30,7 @@ | ||||
| /etc/cloudstack/management/tomcat6.conf | ||||
| /etc/cloudstack/management/web.xml | ||||
| /etc/cloudstack/management/environment.properties | ||||
| /etc/cloudstack/management/java.security.ciphers | ||||
| /etc/cloudstack/management/log4j-cloud.xml | ||||
| /etc/cloudstack/management/tomcat-users.xml | ||||
| /etc/cloudstack/management/context.xml | ||||
|  | ||||
| @ -294,7 +294,7 @@ rm -rf ${RPM_BUILD_ROOT}%{_datadir}/%{name}-management/webapps/client/WEB-INF/cl | ||||
| rm -rf ${RPM_BUILD_ROOT}%{_datadir}/%{name}-management/webapps/client/WEB-INF/classes/vms | ||||
| 
 | ||||
| for name in db.properties log4j-cloud.xml tomcat6-nonssl.conf tomcat6-ssl.conf %{_serverxmlname}-ssl.xml %{_serverxmlname}-nonssl.xml \ | ||||
|             catalina.policy catalina.properties classpath.conf tomcat-users.xml web.xml environment.properties ; do | ||||
|             catalina.policy catalina.properties classpath.conf tomcat-users.xml web.xml environment.properties java.security.ciphers; do | ||||
|   mv ${RPM_BUILD_ROOT}%{_datadir}/%{name}-management/webapps/client/WEB-INF/classes/$name \ | ||||
|     ${RPM_BUILD_ROOT}%{_sysconfdir}/%{name}/management/$name | ||||
| done | ||||
|  | ||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user