From 0d711eac5065ccf2c2877e641297a0ba11fa43f1 Mon Sep 17 00:00:00 2001 From: ghidra1 Date: Tue, 10 Feb 2026 12:41:23 -0500 Subject: [PATCH 1/4] GP-6426 Resolved Ghidra Server hostname check issue related to self-signed certificate (Closes #8940) --- .../ghidra/server/remote/GhidraServer.java | 52 +++++++++++++++---- .../Common/support/launch.properties | 7 +++ 2 files changed, 48 insertions(+), 11 deletions(-) diff --git a/Ghidra/Features/GhidraServer/src/main/java/ghidra/server/remote/GhidraServer.java b/Ghidra/Features/GhidraServer/src/main/java/ghidra/server/remote/GhidraServer.java index 70839d598f..90421f4b4b 100644 --- a/Ghidra/Features/GhidraServer/src/main/java/ghidra/server/remote/GhidraServer.java +++ b/Ghidra/Features/GhidraServer/src/main/java/ghidra/server/remote/GhidraServer.java @@ -25,8 +25,7 @@ import java.rmi.registry.LocateRegistry; import java.rmi.registry.Registry; import java.rmi.server.*; import java.security.cert.CertificateException; -import java.util.Enumeration; -import java.util.List; +import java.util.*; import javax.rmi.ssl.SslRMIClientSocketFactory; import javax.rmi.ssl.SslRMIServerSocketFactory; @@ -752,11 +751,49 @@ public class GhidraServer extends UnicastRemoteObject implements GhidraServerHan // Ensure that remote access hostname is properly set for RMI registration String hostname = initRemoteAccessHostname(); - if (DefaultKeyManagerFactory.getPreferredKeyStore() == null) { + log.info("Ghidra Server " + Application.getApplicationVersion()); + log.info(" Server remote access address: " + hostname); + if (bindAddress == null) { + log.info(" Server listening on all interfaces"); + } + else { + log.info(" Server listening on interface: " + bindAddress.getHostAddress()); + } + + String preferredKeyStore = DefaultKeyManagerFactory.getPreferredKeyStore(); + if (preferredKeyStore == null) { + // keystore has not been identified - use self-signed certificate + log.info(" Generating self-signed certificate..."); + log.info(" Subject Alternative Names:"); + log.info(" " + hostname); + DefaultKeyManagerFactory.setDefaultIdentity(new X500Principal("CN=GhidraServer")); DefaultKeyManagerFactory.addSubjectAlternativeName(hostname); + + // Collect alternate hostnames for inclusion in certificate + Set altNames = new TreeSet<>(); + Enumeration nets = NetworkInterface.getNetworkInterfaces(); + while (nets.hasMoreElements()) { + NetworkInterface netint = nets.nextElement(); + Enumeration addrs = netint.getInetAddresses(); + while (addrs.hasMoreElements()) { + InetAddress addr = addrs.nextElement(); + altNames.add(addr.getHostAddress()); + altNames.add(addr.getHostName()); + altNames.add(addr.getCanonicalHostName()); + } + } + altNames.remove(hostname); + for (String name : altNames) { + log.info(" " + name); + DefaultKeyManagerFactory.addSubjectAlternativeName(name); + } } + else { + log.info(" Using server certificate keystore: " + preferredKeyStore); + } + if (!DefaultKeyManagerFactory.initialize()) { log.fatal("Failed to initialize PKI/SSL keystore"); System.exit(0); @@ -769,14 +806,7 @@ public class GhidraServer extends UnicastRemoteObject implements GhidraServerHan // localhost.getCanonicalHostName() + ":" + classSvrPort + "/"; // System.setProperty(RMI_CODEBASE_PROPERTY, codeBaseProp); - log.info("Ghidra Server " + Application.getApplicationVersion()); - log.info(" Server remote access address: " + hostname); - if (bindAddress == null) { - log.info(" Server listening on all interfaces"); - } - else { - log.info(" Server listening on interface: " + bindAddress.getHostAddress()); - } + log.info(" RMI Registry port: " + ServerPortFactory.getRMIRegistryPort()); log.info(" RMI SSL port: " + ServerPortFactory.getRMISSLPort()); log.info(" Block Stream port: " + ServerPortFactory.getStreamPort()); diff --git a/Ghidra/RuntimeScripts/Common/support/launch.properties b/Ghidra/RuntimeScripts/Common/support/launch.properties index 14f0096465..454cb7e1e5 100644 --- a/Ghidra/RuntimeScripts/Common/support/launch.properties +++ b/Ghidra/RuntimeScripts/Common/support/launch.properties @@ -51,6 +51,13 @@ VMARGS=-Djdk.tls.client.protocols=TLSv1.2,TLSv1.3 # #VMARGS=-Djavax.net.debug=ssl +# When using Java 21.0.10 or later and connecting to an older Ghidra Server (pre-12.0.3) the following +# connection error may occur. +# ... SSLHandshakeException: (certificate_unknown) No matching found +# If unable to upgrade your Ghidra Server this property setting may be uncommented to disable the +# hostname check. +#VMARGS=-Djdk.rmi.ssl.client.enableEndpointIdentification=false + # The following property will limit the number of processor cores that Ghidra # will use for thread pools. If not specified, it will use the default number # of processors returned from Runtime.getRuntime().getAvailableProcessors(). From cb8f6e2230c22ce3346eac010488ea8cebe5bbfa Mon Sep 17 00:00:00 2001 From: ghidra1 Date: Tue, 10 Feb 2026 12:57:16 -0500 Subject: [PATCH 2/4] GP-1 Updated Change History for 12.0.3 release --- .../src/global/docs/ChangeHistory.md | 25 +++++++++++++++++++ 1 file changed, 25 insertions(+) diff --git a/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.md b/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.md index 223f3bafb1..55bfee889b 100644 --- a/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.md +++ b/Ghidra/Configurations/Public_Release/src/global/docs/ChangeHistory.md @@ -1,3 +1,28 @@ +# Ghidra 12.0.3 Change History (February 2026) + +### New Features +* _Listing_. In order to mitigate possible security risks, auto comments will not longer render annotations in such a way as to make them valid annotation links. Normal comments will continue to work as usual. (GP-6414) + +### Improvements +* _Demangler_. The __Demangler GNU__ analyzer now has a timeout option. (GP-6408) +* _GUI_. Corrected Ghidra GUI to fail-fast in headless environment and avoid stack traces. (GP-6399) +* _Listing_. The `@execute` annotation is no longer supported. (GP-6413) + +### Bugs +* _Data Types_. Corrected multi-user merge issues related to non-packed structures which could negatively affect merge results. (GP-6320, Issue #8776) +* _Debugger_. Fixed a `NullPointerException` that could occur upon closing the Debugger. (GP-6376) +* _Debugger:Breakpoints_. Fixed an issue where restarting a target (e.g., the `run` command from GDB's CLI) caused duplicate breakpoint entries and GUI glitches. (GP-6027) +* _Decompiler_. Fixed _"PTRSUB off of non structured pointer type"_ exceptions caused by `void *` data-type. (GP-6388, Issue #8887) +* _Decompiler_. Fixed source of _"Forced merge caused intersection"_ exceptions when decompiling optimized string copies. (GP-6393, Issue #8651) +* _Multi-User_. Revised Ghidra Server self-signed certificate generation to include all associated FQDNs and IP addresses as subject alternative names. This will address the forced hostname check imposed with the release of JDK 21.0.10. To benefit from this change the Ghidra Server will need to be upgraded to this release. A client-side workaround is to set the following JVM property within `support/launch.properties` by adding the line: `VMARGS=-Djdk.rmi.ssl.client.enableEndpointIdentification=false`. (GP-6426, Issue #8940) +* _Processors_. Fixed bug in AARCH64 `sha1h` instruction to shift instead of rotate bits. (GP-4501, Issue #6398) +* _Processors_. Fixed 80251 disassembly errors for instructions referencing the SPX register. (GP-5905, Issue #8395) +* _Processors_. Fixed disassembly of MIPS16e2 `lui` instruction to only parse on extended words. (GP-6419) +* _Search_. Fixed a memory leak in the `Find References...` action. (GP-6395, Issue #8921) + +### Notable API Changes +* _Data Types_. (GP-6320) Structure offset-based insert methods `Structure.insertAtOffset` will now skip forward over existing zero-length components at the insert offset before performing insert of new component. + # Ghidra 12.0.2 Change History (January 2026) ### New Features From 09f14c92d3da6e5d5f6b7dea115409719db3cce1 Mon Sep 17 00:00:00 2001 From: ghidra1 Date: Tue, 10 Feb 2026 13:16:51 -0500 Subject: [PATCH 3/4] GP-0 Corrected Ghidra Server tests to include subject alternative names --- .../ghidra/server/remote/ServerTestUtil.java | 22 +++++++++++++++++-- 1 file changed, 20 insertions(+), 2 deletions(-) diff --git a/Ghidra/Test/IntegrationTest/src/test.slow/java/ghidra/server/remote/ServerTestUtil.java b/Ghidra/Test/IntegrationTest/src/test.slow/java/ghidra/server/remote/ServerTestUtil.java index 2728663074..5aebdaa0d7 100644 --- a/Ghidra/Test/IntegrationTest/src/test.slow/java/ghidra/server/remote/ServerTestUtil.java +++ b/Ghidra/Test/IntegrationTest/src/test.slow/java/ghidra/server/remote/ServerTestUtil.java @@ -20,7 +20,7 @@ import java.net.*; import java.rmi.registry.LocateRegistry; import java.rmi.registry.Registry; import java.security.KeyStore.PrivateKeyEntry; -import java.util.ArrayList; +import java.util.*; import java.util.function.Consumer; import java.util.zip.ZipEntry; import java.util.zip.ZipInputStream; @@ -955,7 +955,25 @@ public class ServerTestUtil { TEST_PKI_SERVER_PASSPHRASE + "): " + serverKeystorePath); PKIUtils.createKeyEntry("test-sig", TEST_PKI_SERVER_DN, 2, caEntry, serverKeystoreFile, - "PKCS12", null, TEST_PKI_SERVER_PASSPHRASE.toCharArray()); + "PKCS12", getLocalHostnames(), TEST_PKI_SERVER_PASSPHRASE.toCharArray()); + } + + private static Collection getLocalHostnames() throws SocketException { + + // Collect alternate hostnames for inclusion in certificate + Set altNames = new TreeSet<>(); + Enumeration nets = NetworkInterface.getNetworkInterfaces(); + while (nets.hasMoreElements()) { + NetworkInterface netint = nets.nextElement(); + Enumeration addrs = netint.getInetAddresses(); + while (addrs.hasMoreElements()) { + InetAddress addr = addrs.nextElement(); + altNames.add(addr.getHostAddress()); + altNames.add(addr.getHostName()); + altNames.add(addr.getCanonicalHostName()); + } + } + return altNames; } /** From 84e89eca9d0bc392544f7dd3897ed099a1756123 Mon Sep 17 00:00:00 2001 From: Ryan Kurtz Date: Wed, 11 Feb 2026 04:53:03 -0500 Subject: [PATCH 4/4] GP-0: Upping patch to 12.0.4 --- Ghidra/application.properties | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Ghidra/application.properties b/Ghidra/application.properties index 9e1f98909f..72fc7ab7f8 100644 --- a/Ghidra/application.properties +++ b/Ghidra/application.properties @@ -1,5 +1,5 @@ application.name=Ghidra -application.version=12.0.3 +application.version=12.0.4 application.release.name=DEV application.layout.version=3 application.gradle.min=8.5