Files
ghidra/Ghidra/RuntimeScripts/server/server.conf
T
ghidra1 fd431fe597 GP-6829 Removed OpenTrustManager use. Restricted auto generated
self-signed certs to loopback connections only. Added CertTool and
updated svrREADME.md.  Added actions for launching windows/mac
certificate manager.  Improved Ghidra Server command queuing with proper
command file sequencing.  Added CertTool to simplify certificate
generation and requests. Refactor BSim PostgreSQL delployment and
cert/key use.  Revised both bsim and bsim_ctl commands.
2026-09-03 15:46:13 -04:00

316 lines
16 KiB
Plaintext

#**************************************************************************
# Service Wrapper Properties
#
# NOTE: It is important to know that the Ghidra Server consists of both
# a controlling wrapper process and its wrapped child process. The
# properties within this file may affect each differently - specifically
# JVM options and how they are specified. The service wrapper relies on
# wrapper.ntservice.additional.N properties within this file, while the
# wrapped Ghidra Server child process relies on wrapper.java.additional.N
# properties. Any changes to ntservice properties require reinstallation
# of the service for them to have any affect.
#**************************************************************************
# Initial Working Directory (i.e., absolute installation directory path)
wrapper.working.dir=${ghidra_home}
# Temporary directory (set WRAPPER_TMPDIR in ghidraSvr(.bat) script to modify this)
wrapper.tmp.path=${wrapper_tmpdir}
# Mac OS X launchd plist directory
wrapper.launchd.dir=/Library/LaunchDaemons
# Java Application
wrapper.java.command=${java}
# Establish default permissions for generated files
wrapper.java.umask=027
# Java Classpath
include=${classpath_frag}
# Java Additional Parameters
wrapper.java.additional.1=-Djava.net.preferIPv4Stack=true
# Establishes a minimum number of rolling server.log backups to be maintained
wrapper.java.additional.2=-DApplicationRollingFileAppender.maxBackupIndex=10
# Ensure that classpath_frag is defined for service startup
wrapper.java.additional.3=-Dclasspath_frag=${classpath_frag}
# Java temporary directory (set WRAPPER_TMPDIR in ghidraSvr(.bat) script to modify this)
wrapper.java.additional.4=-Djava.io.tmpdir=${wrapper_tmpdir}
# JNA temporary directory (set WRAPPER_TMPDIR in ghidraSvr(.bat) script to modify this).
# Note that YAJSW relies on jna_tmpdir (underscore). We set jna.tmpdir in case the Ghidra Server ever wants to do JNA.
wrapper.java.additional.5=-Djna.tmpdir=${wrapper_tmpdir}
# Limit server to specific TLS protocols for all secure connections.
# NOTE: multiple protocols must be separated with a semi-colon (e.g., TLSv1.2;TLSv1.3).
wrapper.java.additional.6=-Dghidra.tls.server.protocols=TLSv1.2;TLSv1.3
# Restrict server to specific TLS cipher suites for all secure communications
# NOTE: multiple ciphers must be separated using "\,". The specified list includes both TLSv1.2 and TLSv1.3 supported ciphers.
# TLSv1.3 info: https://www.packetmania.net/en/2023/08/21/TLS1-3-intro/
# See Commercial National Security Algorithm (CNSA) Suite Profile for TLS and DTLS 1.2 and 1.3
# RFC 9151 https://datatracker.ietf.org/doc/rfc9151/
wrapper.java.additional.7=-Djdk.tls.server.cipherSuites="TLS_DHE_RSA_WITH_AES_256_GCM_SHA384\,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\,TLS_AES_256_GCM_SHA384"
# A suitable cacerts file must be installed when using PKI authentication (-a2).
#
# NOTE: this trust store also governs connections the server itself makes as a client. JAAS
# authentication (-a4) using the LdapLoginModule connects to Active Directory over 'ldaps://'
# (see jaas.conf), and the LDAP server's certificate is authenticated using the trust
# established here. When this property is specified it is used EXCLUSIVELY and the OS and Java
# default trust stores are ignored, so the certificate authority which issued the LDAP server's
# certificate must also be present within this file or that authentication will fail.
#wrapper.java.additional.8=-Dghidra.cacerts=./Ghidra/cacerts
# When the 'ghidra.cacerts' property above is NOT specified, the OS trust store and the Java
# default trust store are used. On Unix the OS trust store is built by scanning the well-known
# CA bundle locations (see UnixSystemTrustKeyStoreUtil.java). If this system keeps its CA
# certificates somewhere not covered by those locations, the property below may specify an
# additional file or directory to be included. It is ignored when 'ghidra.cacerts' is specified,
# since the OS trust store is not loaded in that case. Does not apply to Windows or macOS.
#wrapper.java.additional.21=-Dghidra.unix.default.cacerts=
# IMPORTANT: A Ghidra server must be assigned a PKI keystore and corresponding password to access
# the key. If a keystore is not provided the server will bind to the loopback interface only
# and network connections will not be accepted. (see svrREADME.html for more information).
# The included CertTool command may be used to generate a certificate request or a self-signed
# certificate/keystore. Note that use of a self-signed certificate may complicate Ghidra client
# installation which will need to authenticate the server when connecting.
#wrapper.java.additional.9=-Dghidra.keystore=
#wrapper.java.additional.10=-Dghidra.password=
# Enable/Disable use of compression for DataBuffer serialization and Block Streams
wrapper.java.additional.11=-Ddb.buffers.DataBuffer.compressedOutput=true
# Uncomment to enable remote debug support
# The debug address will listen on all network interfaces, if desired the '*' may be
# set to a specific interface IP address (e.g., 127.0.0.1) if you wish to restrict.
# During debug it will be necessary to increase timeout values to prevent the wrapper
# from restarting the server due to unresponsiveness.
#wrapper.java.additional.12=-Xdebug
#wrapper.java.additional.13=-Xnoagent
#wrapper.java.additional.14=-Djava.compiler=NONE
#wrapper.java.additional.15=-Xrunjdwp:transport=dt_socket\,server=y\,suspend=n\,address=*:18200
#wrapper.startup.timeout=0
#wrapper.ping.timeout=0
# Optional debug enablement instead of using the wrapper.java.additional arguments above
# This will cause application to start in a suspended state in debug mode and increase
# timeouts to their maximum values.
#wrapper.java.debug.port=18200
# Uncomment additional java properties below to enable remote use of VisualVM for profiling.
# See JMX documentation for more information:
# http://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html
# When JMX over RMI is in use the Ghidra Server serialization filters defined by
# file Ghidra/GhidraServer/data/serial.filter may need adjustment.
#wrapper.java.additional.16=-Dcom.sun.management.jmxremote.port=9010
#wrapper.java.additional.17=-Dcom.sun.management.jmxremote.local.only=false
#wrapper.java.additional.18=-Dcom.sun.management.jmxremote.authenticate=false
#wrapper.java.additional.19=-Dcom.sun.management.jmxremote.ssl=false
# The wrapper calls java.lang.System::load in com.sun.jna.Native.
# The below line will prevent a warning from being displayed.
wrapper.java.additional.20=--enable-native-access=ALL-UNNAMED
# YAJSW will by default assume a POSIX spawn for Linux and Mac OS X systems, unfortunately it has
# not yet been implemented for Mac OS X. The default process support within YAJSW for Mac OS X is
# broken so we must force the use of BSD process support which appears to work properly. To enable
# this mode of operation the wrapper.fork_hack option must be enabled and the wrapper.posix_spawn
# option explicitly disabled. The ghidraSvr script will attempt to make these changes automatically
# for Mac OS X.
#wrapper.fork_hack=true
# Pipe server output to console/log
#wrapper.console.pipestreams=true
# Monitor for Deadlock
wrapper.java.monitor.deadlock = true
# Main server application class
wrapper.java.app.mainclass=ghidra.server.remote.GhidraServer
# Initial Java Heap Size (in MB) - this has the same affect as JVM option -Xms
# NOTE: See ntservice options at bottom of this file for installed service wrapper control
wrapper.java.initmemory=396
# Maximum Java Heap Size (in MB) - this has the same affect as JVM option -Xmx
# See svrREADME.txt file for advice (Server Memory Considerations)
# NOTE: See ntservice options at bottom of this file for installed service wrapper control
wrapper.java.maxmemory=768
# Specify the directory used to store repositories. This directory must be dedicated to this
# Ghidra Server instance and may not contain files or folders not produced by the
# Ghidra Server or its administrative scripts. Relative paths originate from the
# Ghidra installation directory, although an absolute path is preferred if not using default.
# This variable is also used by the svrAdmin script.
ghidra.repositories.dir=./repositories
# Ghidra server startup parameters.
#
# IMPORTANT: 'ghidra.keystore' property must generally be set (see setting near top of file)
#
# Command line parameters: (Add command line parameters as needed and renumber each starting from .1)
# [-ip <hostname>] [-i #.#.#.#] [-p#] [-n]
# [-a#] [-d<ad_domain>] [-e<days>] [-jaas <config_file>] [-u] [-autoProvision]
# [-anonymous] [-ssh]
# <repository_path>
#
# -ip <hostname> : identifies the remote access IPv4 address or hostname (FQDN) which should be
# used by remote clients to access the server. This name should be reflected
# in the server's specified certificate (see 'ghidra.keystore' property above).
# Additional host names or IP addresses used to access the server should also be
# included within the server's certificate (i.e., subject alternative names).
#
# The -ip option will be ignored if the 'ghidra.keystore' property has been omitted.
#
# -i #.#.#.# : server interface IPv4 address to listen on. If the 'ghidra.keystore' property has
# been omitted, only a loopback interface may optionally be specified, otherwise
# the server will listen on the default 127.0.0.1 loopback interface. If the
# 'ghidra.keystore' property has been specified, the server will listen on all
# interfaces unless this option is specified.
#
# -p# : base TCP port to be used (default: 13100) [see Note 1]
#
# -n : enable reverse name lookup for IP addresses when logging (requires proper configuration
# of reverse lookup by your DNS server)
#
# -a# : an optional authentication mode where # is a value of 0, 1, 2, or 4
# 0 - Private user password
# 1 - Active Directory via Kerberos. Requires -d<your.ad_domainname.tld>
# 2 - PKI Authentication
# 4 - JAAS Authentication. See also -jaas <config_file>
#
# -d<ad_domain> : the Active Directory domain name. Example: "-dmydomain.com"
#
# -e<days> : specifies initial/reset password expiration time in days (-a0 mode only, default is 1-day, 0 = no expiration)
#
# -jaas <config_file> : specifies the path to the JAAS config file (when using -a4), relative
# to the ghidra/server directory (if not absolute).
# See jaas.conf for examples and suggestions.
# It is the system administrator's responsibility to craft their own
# JAAS configuration directive when using the -a4 mode.
#
# -u : enable users to be prompted for user ID (does not apply to -a2 PKI mode)
#
# -autoProvision : enable the auto-creation of new Ghidra Server
# users when they successfully authenticate to the server (-a1 and -a4 modes only).
# Users removed from the authentication provider (e.g., Active Directory) will need to be
# deleted manually from the Ghidra Server using svrAdmin command.
#
# -anonymous : enables anonymous repository access (see svrREADME.html for details)
#
# -ssh : enables SSH authentication for headless clients
#
# <repository_path> : Required. Directory used to store repositories. This directory must be dedicated to this
# Ghidra Server instance and may not contain files or folders not produced
# by the Ghidra Server or its administrative scripts.
# Relative paths originate from the installation directory
# ${ghidra.repositories.dir} : config variable (defined above) which identifies the directory
# used to store repositories. Use of this variable to define the
# repositories directory must be retained.
wrapper.app.parameter.1=-a0
wrapper.app.parameter.2=${ghidra.repositories.dir}
# Establish server process owner
# This should only be used when installing as a service using a nologin
# local user account. Establishing a suitable account is left as a
# system administration task. NOTE: the use of this feature is not
# yet supported for Windows installations.
#wrapper.app.account=ghidra
#********************************************************************
# Service Wrapper Logging Properties
#********************************************************************
# Format of output for the console. (See docs for formats)
wrapper.console.format=PM
# Log Level for console output. (use INFO to see Ghidra Server activity)
wrapper.console.loglevel=INFO
# Provide additional wrapper debug logging info
#wrapper.debug=true
# Log file to use for wrapper output logging.
wrapper.logfile=wrapper.log
# Format of output for the log file. (See docs for formats)
wrapper.logfile.format=LPTM
# Log Level for wrapper.log file output. (See docs for log levels)
wrapper.logfile.loglevel=INFO
# Maximum size that the log file will be allowed to grow to before
# the log is rolled. Size is specified in bytes. The default value
# of 0, disables log rolling. May abbreviate with the 'k' (kb) or
# 'm' (mb) suffix. For example: 10m = 10 megabytes.
wrapper.logfile.maxsize=10m
# Maximum number of rolled log files which will be allowed before old
# files are deleted. The default value of 0 implies no limit.
wrapper.logfile.maxfiles=10
#********************************************************************
# Service Wrapper Windows Properties
#********************************************************************
# Title to use when running as a console
wrapper.console.title=Ghidra Server
#********************************************************************
# Service Wrapper Windows NT/2000/XP Service Properties
#********************************************************************
# WARNING - Do not modify any of these properties when an application
# using this configuration file has been installed as a service.
# Please uninstall the service before modifying this section. The
# service can then be reinstalled.
# Name of the service
wrapper.ntservice.name=ghidraSvr
# Display name of the service
wrapper.ntservice.displayname=Ghidra Server
# Description of the service
wrapper.ntservice.description=Repository server for Ghidra data files.
# Service dependencies. Add dependencies as needed starting from 1
wrapper.ntservice.dependency.1=
# Mode in which the service is installed.
wrapper.ntservice.starttype=AUTO_START
# Linux service daemon priority for Ghidra Server (start/stop)
# It is important that the network interface has started and any file-system
# dependencies are mounted prior to the Ghidra Server starting.
# NOTE: uninstall the Ghidra Server service using svrUninstall script before changing
# the property wrapper.daemon.update_rc or wrapper.daemon.run_level_dir property.
wrapper.daemon.update_rc= 98 05
# Linux service daemon link directories
wrapper.daemon.run_level_dir=/etc/rcX.d
# Allow the service to interact with the desktop.
wrapper.ntservice.interactive=false
# Restart failed service after 1 minute delay
wrapper.ntservice.failure_actions.actions=RESTART
wrapper.ntservice.failure_actions.actions_delay=60000
# Specify JVM arguments to be used by installed service wrapper process.
# Maximum Java Heap Size for installed service wrapper.
# NOTE: See also -Xmx option specification with ghidraSvr script which relates to other
# uses of the YAJSW wrapper (e.g., console mode).
wrapper.ntservice.additional.1=-Xmx512M
# Uncomment to enable detailed memory tracking capability for the installed service wrapper process.
# This will allow command such as the following to dump memory use information:
# jcmd <PID> VM.native_memory summary
# jcmd <PID> VM.native_memory detail
#wrapper.ntservice.additional.2=-XX:NativeMemoryTracking=detail