Repository navigation
Add TLS for the wire protocol and Studio - #19
Merged
Merged
Conversation
tls, tls_certificate_file and tls_key_file configure the server side. tls_ca_file tells clients what to trust, falling back to the server's own certificate and then the system store.
The wire listener and Studio share one TLS context, and Studio marks its session cookie Secure. The server finishes the handshake before sending the banner and gives up after 10 seconds, and clients bound their connect and banner read the same way, so a plaintext client on a TLS port no longer hangs either side.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #5
Turning on
tlsmakes both listeners use TLS with the same certificate: the wire protocol on its usual port and Studio over HTTPS.New settings:
tls(off by default)tls_certificate_file, a PEM chaintls_key_file, an unencrypted PKCS#8 PEM key (EC, RSA or Ed25519)tls_ca_fileon the client sidehstore connectverifies the certificate and host name. It truststls_ca_filefirst, then the server's own certificate, then the system store, so self-signed setups work without extra steps.hstore pingskips the host name check, which keeps the Docker healthcheck working against 127.0.0.1. Studio setsSecureon its cookie whenever it serves HTTPS.While testing I found that a plaintext client on a TLS port hung forever: the client waited for the banner and the server waited for a ClientHello. Both sides now give up after 10 seconds, and the server logs it.
Tested:
wireProtocolRunsOverTlschecks a trusted client, a client using the system store (rejected) and a plaintext client (fails within the timeout).tlsWithoutACertificateIsRejectedAtStartupchecks startup with tls on and no certificate.studioServesHttpsWithSecureCookieschecks Studio over HTTPS and the Secure cookie.server/src/test/resources/tls../mvnw installis green.