Browse Source

Fimprove SSL certificate reload robustness and config clarity

pull/15301/head
Andrii Landiak 6 months ago
parent
commit
255bb38dc2
  1. 2
      application/src/main/resources/thingsboard.yml
  2. 8
      common/transport/lwm2m/src/main/java/org/thingsboard/server/transport/lwm2m/server/DefaultLwM2mTransportService.java
  3. 2
      common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/config/ssl/SslCredentialsWebServerCustomizer.java
  4. 14
      common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/service/CertificateReloadManager.java
  5. 2
      transport/coap/src/main/resources/tb-coap-transport.yml
  6. 2
      transport/http/src/main/resources/tb-http-transport.yml
  7. 2
      transport/lwm2m/src/main/resources/tb-lwm2m-transport.yml
  8. 2
      transport/mqtt/src/main/resources/tb-mqtt-transport.yml

2
application/src/main/resources/thingsboard.yml

@ -1402,7 +1402,7 @@ transport:
# Enable/disable automatic SSL certificates reload
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:true}"
# Check interval in seconds for certificates reload
check_interval: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL:60}"
check_interval_seconds: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL_SECONDS:60}"
# CoAP server parameters
coap:

8
common/transport/lwm2m/src/main/java/org/thingsboard/server/transport/lwm2m/server/DefaultLwM2mTransportService.java

@ -235,7 +235,13 @@ public class DefaultLwM2mTransportService implements LwM2MTransportService, Smar
log.info("Creating new LwM2M server with updated certificates...");
LeshanServer newServer = getLhServer();
newServer.start();
try {
newServer.start();
} catch (Exception e) {
log.error("Failed to start new LwM2M server, rolling back", e);
newServer.destroy();
throw e;
}
try {
LwM2mServerListener newListener = new LwM2mServerListener(handler);

2
common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/config/ssl/SslCredentialsWebServerCustomizer.java

@ -147,7 +147,7 @@ public class SslCredentialsWebServerCustomizer implements WebServerFactoryCustom
@Override
public void addBundleRegisterHandler(BiConsumer<String, SslBundle> registerHandler) {
log.debug("addBundleRegisterHandler is not supported for dynamic SSL bundles");
}
}

14
common/transport/transport-api/src/main/java/org/thingsboard/server/common/transport/service/CertificateReloadManager.java

@ -28,6 +28,7 @@ import org.thingsboard.server.common.transport.config.ssl.SslCredentialsConfig;
import org.thingsboard.server.queue.util.TbTransportComponent;
import java.io.IOException;
import java.io.InputStream;
import java.nio.file.Files;
import java.nio.file.Path;
import java.security.MessageDigest;
@ -50,7 +51,7 @@ public class CertificateReloadManager implements SmartInitializingSingleton, Dis
@Value("${transport.ssl.certificate.reload.enabled:true}")
private boolean reloadEnabled;
@Value("${transport.ssl.certificate.reload.check_interval:60}")
@Value("${transport.ssl.certificate.reload.check_interval_seconds:60}")
private long checkIntervalInSeconds;
@Autowired
@ -258,9 +259,14 @@ public class CertificateReloadManager implements SmartInitializingSingleton, Dis
return "";
}
MessageDigest md = MessageDigest.getInstance("SHA-256");
byte[] bytes = Files.readAllBytes(path);
byte[] hash = md.digest(bytes);
return Base64.getEncoder().encodeToString(hash);
byte[] buf = new byte[8192];
try (InputStream is = Files.newInputStream(path)) {
int bytesRead;
while ((bytesRead = is.read(buf)) != -1) {
md.update(buf, 0, bytesRead);
}
}
return Base64.getEncoder().encodeToString(md.digest());
} catch (Exception e) {
log.warn("Failed to calculate checksum for certificate file: {}", path, e);
return "";

2
transport/coap/src/main/resources/tb-coap-transport.yml

@ -178,7 +178,7 @@ transport:
# Enable/disable automatic SSL certificates reload
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:true}"
# Check interval in seconds for certificates reload
check_interval: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL:60}"
check_interval_seconds: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL_SECONDS:60}"
# CoAP server parameters
coap:

2
transport/http/src/main/resources/tb-http-transport.yml

@ -209,7 +209,7 @@ transport:
# Enable/disable automatic SSL certificates reload
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:true}"
# Check interval in seconds for certificates reload
check_interval: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL:60}"
check_interval_seconds: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL_SECONDS:60}"
# Queue configuration parameters
queue:

2
transport/lwm2m/src/main/resources/tb-lwm2m-transport.yml

@ -309,7 +309,7 @@ transport:
# Enable/disable automatic SSL certificates reload
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:true}"
# Check interval in seconds for certificates reload
check_interval: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL:60}"
check_interval_seconds: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL_SECONDS:60}"
# Queue configuration properties
queue:

2
transport/mqtt/src/main/resources/tb-mqtt-transport.yml

@ -242,7 +242,7 @@ transport:
# Enable/disable automatic SSL certificates reload
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:true}"
# Check interval in seconds for certificates reload
check_interval: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL:60}"
check_interval_seconds: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL_SECONDS:60}"
# Queue configuration parameters
queue:

Loading…
Cancel
Save