{"id":2560,"date":"2015-11-04T07:59:52","date_gmt":"2015-11-04T06:59:52","guid":{"rendered":"http:\/\/vm.piszki.pl\/?p=2560"},"modified":"2015-11-04T09:56:39","modified_gmt":"2015-11-04T08:56:39","slug":"serwer-ma-slaby-tymczasowy-klucz-publiczny-diffiego-hellmana","status":"publish","type":"post","link":"https:\/\/vm.piszki.pl\/?p=2560","title":{"rendered":"vRealize Hyperic (Tomcat 6) &#8211; Serwer ma s\u0142aby, tymczasowy klucz publiczny Diffiego-Hellmana"},"content":{"rendered":"<p align=\"justify\">vRealize Hyperic 5.8.4 ma w konfiguracji ustawione domy\u015blne dla Tomcat 6 parametry po\u0142\u0105czenia szyfrowanego. U\u017cywaj\u0105c najnowszych przegl\u0105darek Chrome i Firefox mo\u017cemy przez to zderzy\u0107 si\u0119 z komunikatem \u201cSerwer ma s\u0142aby, tymczasowy klucz publiczny Diffiego-Hellmana\u201d. Na szcz\u0119\u015bcie mo\u017cna temu bardzo szybko zaradzi\u0107 poprawiaj\u0105c sekcj\u0119 \u201cConnector\u201d w pliku serwer.xml. Opisana przeze mnie zmiana mo\u017ce by\u0107 wprowadzona zar\u00f3wno w wersji instalowanej na serwerze Windows jak i tej instalowanej jako vRealize Hyperic Appliance.<\/p>\n<p align=\"justify\"><a href=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2015\/10\/diffie.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; float: none; padding-top: 0px; padding-left: 0px; margin-left: auto; display: block; padding-right: 0px; margin-right: auto; border-width: 0px;\" title=\"diffie\" src=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2015\/10\/diffie_thumb.png\" alt=\"diffie\" width=\"459\" height=\"151\" border=\"0\" \/><\/a><\/p>\n<p><!--more--><\/p>\n<p align=\"justify\">Plik z ustawieniami znajduje si\u0119 w katalogu \/opt\/hyperic\/server-current\/hq-engine\/hq-server\/conf\/ (appliance). Otwieramy server.xml i edytujemy sekcj\u0119 Connector, prawid\u0142owe ustawienia wygl\u0105daj\u0105 tak:<\/p>\n<pre class=\"csharpcode\">&lt;Connector port=<span class=\"str\">\"${server.webapp.secure.port}\"<\/span> \r\n          executor=<span class=\"str\">\"tomcatThreadPool\"<\/span> maxHttpHeaderSize=<span class=\"str\">\"8192\"<\/span>\r\n         emptySessionPath=<span class=\"str\">\"true\"<\/span> protocol=<span class=\"str\">\"HTTP\/1.1\"<\/span> SSLEnabled=<span class=\"str\">\"true\"<\/span>\r\n         scheme=<span class=\"str\">\"https\"<\/span> secure=<span class=\"str\">\"true\"<\/span> clientAuth=<span class=\"str\">\"false\"<\/span> \r\n         keystoreFile=<span class=\"str\">\"${server.keystore.path}\"<\/span>\r\n         keystorePass=<span class=\"str\">\"${server.keystore.password}\"<\/span>\r\n         truststoreFile=<span class=\"str\">\"${server.keystore.path}\"<\/span>\r\n         truststorePass=<span class=\"str\">\"${server.keystore.password}\"<\/span> \r\n         ciphers=<span class=\"str\">\"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,\r\n               TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA,\r\n               TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA,\r\n               TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA\"<\/span>\r\n         sslProtocol=<span class=\"str\">\"TLS\"<\/span>\r\n         protocols=<span class=\"str\">\"TLSv1,TLSv1.1,TLSv1.2\"<\/span>                               \r\n         URIEncoding=<span class=\"str\">\"UTF-8\"<\/span>\/&gt;\r\n<\/pre>\n<p>Po wprowadzeniu stosownych zmian restartujemy serwer.<\/p>\n<pre><\/pre>\n<div style='text-align:left' class='yasr-auto-insert-visitor'><\/div>","protected":false},"excerpt":{"rendered":"<p>vRealize Hyperic 5.8.4 ma w konfiguracji ustawione domy\u015blne dla Tomcat 6 parametry po\u0142\u0105czenia szyfrowanego. U\u017cywaj\u0105c najnowszych przegl\u0105darek Chrome i Firefox mo\u017cemy przez to zderzy\u0107 si\u0119 z komunikatem \u201cSerwer ma s\u0142aby, tymczasowy klucz publiczny Diffiego-Hellmana\u201d. Na szcz\u0119\u015bcie mo\u017cna temu bardzo szybko &hellip; <a href=\"https:\/\/vm.piszki.pl\/?p=2560\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1532,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"yasr_overall_rating":0,"yasr_post_is_review":"","yasr_auto_insert_disabled":"","yasr_review_type":"","footnotes":""},"categories":[48],"tags":[54],"class_list":["post-2560","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-drobne-poprawki","tag-hyperic"],"yasr_visitor_votes":{"stars_attributes":{"read_only":false,"span_bottom":false},"number_of_votes":0,"sum_votes":0},"_links":{"self":[{"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/posts\/2560"}],"collection":[{"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2560"}],"version-history":[{"count":5,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/posts\/2560\/revisions"}],"predecessor-version":[{"id":2584,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/posts\/2560\/revisions\/2584"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/media\/1532"}],"wp:attachment":[{"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}