Browse Source

fix gmtls bugs

tags/1.6.4
liuyuanmu 2 years ago
parent
commit
4e7f67ca75
8 changed files with 52 additions and 43 deletions
  1. +1
    -1
      core
  2. +24
    -12
      deploy/deploy-gateway/src/main/resources/config/application-gw.properties
  3. +1
    -1
      deploy/deploy-peer/src/main/resources/assembly.xml
  4. +22
    -25
      deploy/deploy-peer/src/main/resources/config/application-peer.properties
  5. +1
    -1
      framework
  6. +1
    -1
      libs/bft-smart
  7. +1
    -1
      libs/httpservice
  8. +1
    -1
      libs/utils

+ 1
- 1
core

@@ -1 +1 @@
Subproject commit 2a94f2761eb6a52bd5ca85b80c9fe875c1e1f765
Subproject commit 5f939eada8afe0c0a10a3b8d8b651b69da728077

+ 24
- 12
deploy/deploy-gateway/src/main/resources/config/application-gw.properties View File

@@ -2,18 +2,30 @@
server.compression.enabled=true
server.compression.mime-types=application/json,application/xml,text/html,text/xml,text/plain

# SSL
server.ssl.protocol=
server.ssl.enabled-protocols=
server.ssl.ciphers=
server.ssl.key-store=
server.ssl.key-store-type=PKCS12
server.ssl.key-alias=
server.ssl.key-store-password=
server.ssl.trust-store=
server.ssl.trust-store-password=
server.ssl.trust-store-type=JKS
server.ssl.hostNameVerifier=NO-OP
# TLS
#server.ssl.key-store=
#server.ssl.key-store-type=PKCS12
#server.ssl.key-alias=
#server.ssl.key-store-password=123456
#server.ssl.protocol=TLS
#server.ssl.enabled-protocols=TLSv1.2
#server.ssl.trust-store=
#server.ssl.trust-store-password=
#server.ssl.trust-store-type=JKS
#server.ssl.hostNameVerifier=NO-OP

# GMTLS
#server.ssl.key-store=
#server.ssl.key-store-type=PKCS12
#server.ssl.key-alias=
#server.ssl.key-store-password=
#server.ssl.protocol=GMTLS
#server.ssl.enabled-protocols=GMTLS,TLSv1.2
#server.ssl.ciphers=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,ECC_SM4_CBC_SM3,ECDHE_SM4_GCM_SM3,ECDHE_SM4_CBC_SM3
#server.ssl.trust-store=
#server.ssl.trust-store-password=
#server.ssl.trust-store-type=JKS
#server.ssl.hostNameVerifier=NO-OP

# 浏览器鉴权,设置用户名/密码,若没有配置则区块链浏览器完全开放
spring.security.user.name=jdchain


+ 1
- 1
deploy/deploy-peer/src/main/resources/assembly.xml View File

@@ -25,7 +25,7 @@
<lineEnding>unix</lineEnding>
</fileSet>
<fileSet>
<directory>${basedir}/../../libs/utils/utils-sm-tls/lib</directory>
<directory>${basedir}/../../libs/utils/utils-crypto-sm/lib</directory>
<outputDirectory>libs</outputDirectory>
</fileSet>
<fileSet>


+ 22
- 25
deploy/deploy-peer/src/main/resources/config/application-peer.properties View File

@@ -2,37 +2,34 @@
server.compression.enabled=true
server.compression.mime-types=application/json,application/xml,text/html,text/xml,text/plain

# 管理服务TLS配置
server.ssl.enabled=false
server.ssl.client-auth=none
server.ssl.protocol=
server.ssl.enabled-protocols=
server.ssl.ciphers=
server.ssl.key-store=
server.ssl.key-store-type=PKCS12
server.ssl.key-alias=
server.ssl.key-store-password=
server.ssl.trust-store=
server.ssl.trust-store-password=
server.ssl.trust-store-type=JKS

server.ssl.protocol=
server.ssl.enabled-protocols=
server.ssl.ciphers=
server.ssl.hostNameVerifier=NO-OP
# TLS
#server.ssl.enabled=true
#server.ssl.client-auth=need
#server.ssl.key-store=
#server.ssl.key-store-type=PKCS12
#server.ssl.key-alias=
#server.ssl.key-store-password=123456
#server.ssl.protocol=TLS
#server.ssl.enabled-protocols=TLSv1.2
#server.ssl.trust-store=
#server.ssl.trust-store-password=
#server.ssl.trust-store-type=JKS
#server.ssl.hostNameVerifier=NO-OP

#GM TLS配置
#示例:
# GMTLS
#server.ssl.enabled=true
#server.ssl.key-store=cert/sm2.node0.both.pfx
#server.ssl.client-auth=need
#server.ssl.key-store=
#server.ssl.key-store-type=PKCS12
#server.ssl.key-alias=
#server.ssl.key-store-password=12345678
#server.ssl.key-store-password=
#server.ssl.protocol=GMTLS
#server.ssl.hostNameVerifier=NO-OP
#server.ssl.enabled-protocols=TLSv1.2,GMSSLv1.1
#server.ssl.enabled-protocols=GMTLS,TLSv1.2
#server.ssl.ciphers=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,ECC_SM4_CBC_SM3,ECDHE_SM4_GCM_SM3,ECDHE_SM4_CBC_SM3

#server.ssl.trust-store=
#server.ssl.trust-store-password=
#server.ssl.trust-store-type=JKS
#server.ssl.hostNameVerifier=NO-OP

management.endpoints.web.exposure.include=prometheus
management.metrics.tags.application=peer


+ 1
- 1
framework

@@ -1 +1 @@
Subproject commit e66f85cb7daf317f990b2b07e57e904ed1c30034
Subproject commit d7094b0b5e4c958e5960dc06966c327e91c410f0

+ 1
- 1
libs/bft-smart

@@ -1 +1 @@
Subproject commit 07e6e3b417161354c9636e650fd0f42953b7d2ab
Subproject commit 79669fba3b0653f0e44298834db70d9c8ba2515e

+ 1
- 1
libs/httpservice

@@ -1 +1 @@
Subproject commit dfa6ca1934f6fdee473ecf2fddf3c767aaeea03b
Subproject commit 32c12b630e3b89bb573314474ac7f53fc945c94e

+ 1
- 1
libs/utils

@@ -1 +1 @@
Subproject commit 30412b092d052e142e8a5f6ef40ee00bea63f458
Subproject commit 69b5cbc663dd47c60a9914ae20ad07866a2656d5

Loading…
Cancel
Save