mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-08 23:51:17 +02:00
Added ability to specify allowed TLS cipher suites.
This commit is contained in:
@@ -81,6 +81,27 @@ func (s *server) setupListener(opts Opts) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
func parseCipherSuites(names []string) ([]uint16, error) {
|
||||
cipherNameMap := make(map[string]uint16)
|
||||
|
||||
for _, cipherSuite := range tls.CipherSuites() {
|
||||
cipherNameMap[cipherSuite.Name] = cipherSuite.ID
|
||||
}
|
||||
for _, cipherSuite := range tls.InsecureCipherSuites() {
|
||||
cipherNameMap[cipherSuite.Name] = cipherSuite.ID
|
||||
}
|
||||
|
||||
result := make([]uint16, len(names))
|
||||
for i, name := range names {
|
||||
id, present := cipherNameMap[name]
|
||||
if !present {
|
||||
return nil, fmt.Errorf("unknown TLS cipher suite name specified %q", name)
|
||||
}
|
||||
result[i] = id
|
||||
}
|
||||
return result, nil
|
||||
}
|
||||
|
||||
// setupTLSListener sets the server TLS listener if the HTTPS server is enabled.
|
||||
// The HTTPS server can be disabled by setting the SecureBindAddress to "-" or by
|
||||
// leaving it empty.
|
||||
@@ -104,6 +125,14 @@ func (s *server) setupTLSListener(opts Opts) error {
|
||||
}
|
||||
config.Certificates = []tls.Certificate{cert}
|
||||
|
||||
if len(opts.TLS.CipherSuites) > 0 {
|
||||
cipherSuites, err := parseCipherSuites(opts.TLS.CipherSuites)
|
||||
if err != nil {
|
||||
return fmt.Errorf("could not parse cipher suites: %v", err)
|
||||
}
|
||||
config.CipherSuites = cipherSuites
|
||||
}
|
||||
|
||||
if len(opts.TLS.MinVersion) > 0 {
|
||||
switch opts.TLS.MinVersion {
|
||||
case "TLS1.2":
|
||||
|
||||
@@ -261,6 +261,40 @@ var _ = Describe("Server", func() {
|
||||
expectHTTPListener: false,
|
||||
expectTLSListener: true,
|
||||
}),
|
||||
Entry("with an ipv4 valid https bind address, and valid TLS config with CipherSuites", &newServerTableInput{
|
||||
opts: Opts{
|
||||
Handler: handler,
|
||||
SecureBindAddress: "127.0.0.1:0",
|
||||
TLS: &options.TLS{
|
||||
Key: &ipv4KeyDataSource,
|
||||
Cert: &ipv4CertDataSource,
|
||||
CipherSuites: []string{
|
||||
"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA",
|
||||
"TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA",
|
||||
},
|
||||
},
|
||||
},
|
||||
expectedErr: nil,
|
||||
expectHTTPListener: false,
|
||||
expectTLSListener: true,
|
||||
}),
|
||||
Entry("with an ipv4 valid https bind address, and invalid TLS config with unknown CipherSuites", &newServerTableInput{
|
||||
opts: Opts{
|
||||
Handler: handler,
|
||||
SecureBindAddress: "127.0.0.1:0",
|
||||
TLS: &options.TLS{
|
||||
Key: &ipv4KeyDataSource,
|
||||
Cert: &ipv4CertDataSource,
|
||||
CipherSuites: []string{
|
||||
"TLS_RSA_WITH_RC4_64_SHA",
|
||||
"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA",
|
||||
},
|
||||
},
|
||||
},
|
||||
expectedErr: errors.New("error setting up TLS listener: could not parse cipher suites: unknown TLS cipher suite name specified \"TLS_RSA_WITH_RC4_64_SHA\""),
|
||||
expectHTTPListener: false,
|
||||
expectTLSListener: true,
|
||||
}),
|
||||
Entry("with an ipv6 valid http bind address", &newServerTableInput{
|
||||
opts: Opts{
|
||||
Handler: handler,
|
||||
@@ -454,6 +488,40 @@ var _ = Describe("Server", func() {
|
||||
expectHTTPListener: false,
|
||||
expectTLSListener: true,
|
||||
}),
|
||||
Entry("with an ipv6 valid https bind address, and valid TLS config with CipherSuites", &newServerTableInput{
|
||||
opts: Opts{
|
||||
Handler: handler,
|
||||
SecureBindAddress: "[::1]:0",
|
||||
TLS: &options.TLS{
|
||||
Key: &ipv4KeyDataSource,
|
||||
Cert: &ipv4CertDataSource,
|
||||
CipherSuites: []string{
|
||||
"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA",
|
||||
"TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA",
|
||||
},
|
||||
},
|
||||
},
|
||||
expectedErr: nil,
|
||||
expectHTTPListener: false,
|
||||
expectTLSListener: true,
|
||||
}),
|
||||
Entry("with an ipv6 valid https bind address, and invalid TLS config with unknown CipherSuites", &newServerTableInput{
|
||||
opts: Opts{
|
||||
Handler: handler,
|
||||
SecureBindAddress: "[::1]:0",
|
||||
TLS: &options.TLS{
|
||||
Key: &ipv4KeyDataSource,
|
||||
Cert: &ipv4CertDataSource,
|
||||
CipherSuites: []string{
|
||||
"TLS_RSA_WITH_RC4_64_SHA",
|
||||
"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA",
|
||||
},
|
||||
},
|
||||
},
|
||||
expectedErr: errors.New("error setting up TLS listener: could not parse cipher suites: unknown TLS cipher suite name specified \"TLS_RSA_WITH_RC4_64_SHA\""),
|
||||
expectHTTPListener: false,
|
||||
expectTLSListener: true,
|
||||
}),
|
||||
)
|
||||
})
|
||||
|
||||
|
||||
Reference in New Issue
Block a user