From 41b432a70e126c514bd4b3b30e450d4b639435dc Mon Sep 17 00:00:00 2001 From: liuyuanmu Date: Thu, 17 Mar 2022 21:37:14 +0800 Subject: [PATCH] update GM TLS configs --- .../src/main/resources/config/application-gw.properties | 7 +++---- .../src/main/resources/config/application-peer.properties | 3 +-- 2 files changed, 4 insertions(+), 6 deletions(-) diff --git a/deploy/deploy-gateway/src/main/resources/config/application-gw.properties b/deploy/deploy-gateway/src/main/resources/config/application-gw.properties index f29231f9..5a2e78f7 100644 --- a/deploy/deploy-gateway/src/main/resources/config/application-gw.properties +++ b/deploy/deploy-gateway/src/main/resources/config/application-gw.properties @@ -18,14 +18,13 @@ server.ssl.trust-store-password= server.ssl.trust-store-type=JKS server.ssl.hostNameVerifier=NO-OP -#GM TLS Config -#Enable Condition: http.secure=true && server.ssl.protocol=GMSSLv1.1 -#Example: +#GM TLS配置 +#示例: #server.ssl.key-store=cert/sm2.node0.both.pfx #server.ssl.key-store-type=PKCS12 #server.ssl.key-alias= #server.ssl.key-store-password=12345678 -#server.ssl.protocol=GMSSLv1.1 +#server.ssl.protocol=GMTLS #server.ssl.hostNameVerifier=NO-OP #server.ssl.enabled-protocols=TLSv1.2,GMSSLv1.1 #server.ssl.ciphers=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,ECC_SM4_CBC_SM3,ECDHE_SM4_GCM_SM3,ECDHE_SM4_CBC_SM3 diff --git a/deploy/deploy-peer/src/main/resources/config/application-peer.properties b/deploy/deploy-peer/src/main/resources/config/application-peer.properties index 944badce..6c4ef922 100644 --- a/deploy/deploy-peer/src/main/resources/config/application-peer.properties +++ b/deploy/deploy-peer/src/main/resources/config/application-peer.properties @@ -22,14 +22,13 @@ server.ssl.ciphers= server.ssl.hostNameVerifier=NO-OP #GM TLS配置 -#启用条件: server.ssl.enabled=true && server.ssl.protocol=GMSSLv1.1 #示例: #server.ssl.enabled=true #server.ssl.key-store=cert/sm2.node0.both.pfx #server.ssl.key-store-type=PKCS12 #server.ssl.key-alias= #server.ssl.key-store-password=12345678 -#server.ssl.protocol=GMSSLv1.1 +#server.ssl.protocol=GMTLS #server.ssl.hostNameVerifier=NO-OP #server.ssl.enabled-protocols=TLSv1.2,GMSSLv1.1 #server.ssl.ciphers=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,ECC_SM4_CBC_SM3,ECDHE_SM4_GCM_SM3,ECDHE_SM4_CBC_SM3