From 78318987187d92805afaa35e4b435d0d0c5c4e42 Mon Sep 17 00:00:00 2001 From: Kenneth Skovhede Date: Tue, 30 Jul 2024 08:34:34 +0200 Subject: [PATCH 1/2] Updating the default protocol tol TLS 1.3 if the system supports it --- .../AlternativeFTP/AlternativeFTPBackend.cs | 37 +++++++++++++++---- 1 file changed, 29 insertions(+), 8 deletions(-) diff --git a/Duplicati/Library/Backend/AlternativeFTP/AlternativeFTPBackend.cs b/Duplicati/Library/Backend/AlternativeFTP/AlternativeFTPBackend.cs index 7e5a89c92..6c99dcb61 100644 --- a/Duplicati/Library/Backend/AlternativeFTP/AlternativeFTPBackend.cs +++ b/Duplicati/Library/Backend/AlternativeFTP/AlternativeFTPBackend.cs @@ -29,6 +29,7 @@ using System; using System.Collections.Generic; using System.IO; using System.Linq; +using System.Net; using System.Net.Security; using System.Security.Authentication; using System.Threading; @@ -41,13 +42,37 @@ namespace Duplicati.Library.Backend.AlternativeFTP // ReSharper disable once RedundantExtendsListEntry public class AlternativeFtpBackend : IBackend, IStreamingBackend { + private static SslProtocols GetDefaultSslProtocols() + { + // Use the defaults from FluentFTP + var result = new FtpConfig().SslProtocols; + + // Probe if the system supports TLS 1.3 + var restore = ServicePointManager.SecurityProtocol; + try + { + // If we can set this, it looks like the system supports TLS 1.3 + ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls13; + result = SslProtocols.Tls12 | SslProtocols.Tls13; + } + catch + { + } + finally + { + ServicePointManager.SecurityProtocol = restore; + } + + return result; + } + private System.Net.NetworkCredential _userInfo; private const string OPTION_ACCEPT_SPECIFIED_CERTIFICATE = "accept-specified-ssl-hash"; // Global option private const string OPTION_ACCEPT_ANY_CERTIFICATE = "accept-any-ssl-certificate"; // Global option private const FtpDataConnectionType DEFAULT_DATA_CONNECTION_TYPE = FtpDataConnectionType.AutoPassive; private const FtpEncryptionMode DEFAULT_ENCRYPTION_MODE = FtpEncryptionMode.None; - private const SslProtocols DEFAULT_SSL_PROTOCOLS = SslProtocols.Default; + private static readonly SslProtocols DEFAULT_SSL_PROTOCOLS = GetDefaultSslProtocols(); private const string CONFIG_KEY_AFTP_ENCRYPTION_MODE = "aftp-encryption-mode"; private const string CONFIG_KEY_AFTP_DATA_CONNECTION_TYPE = "aftp-data-connection-type"; private const string CONFIG_KEY_AFTP_SSL_PROTOCOLS = "aftp-ssl-protocols"; @@ -184,10 +209,8 @@ namespace Duplicati.Library.Backend.AlternativeFTP } // Process the aftp-encryption-mode option - string encryptionModeString; FtpEncryptionMode encryptionMode; - - if (!options.TryGetValue(CONFIG_KEY_AFTP_ENCRYPTION_MODE, out encryptionModeString) || string.IsNullOrWhiteSpace(encryptionModeString)) + if (!options.TryGetValue(CONFIG_KEY_AFTP_ENCRYPTION_MODE, out var encryptionModeString) || string.IsNullOrWhiteSpace(encryptionModeString)) { encryptionModeString = null; } @@ -198,10 +221,8 @@ namespace Duplicati.Library.Backend.AlternativeFTP } // Process the aftp-ssl-protocols option - string sslProtocolsString; SslProtocols sslProtocols; - - if (!options.TryGetValue(CONFIG_KEY_AFTP_SSL_PROTOCOLS, out sslProtocolsString) || string.IsNullOrWhiteSpace(sslProtocolsString)) + if (!options.TryGetValue(CONFIG_KEY_AFTP_SSL_PROTOCOLS, out var sslProtocolsString) || string.IsNullOrWhiteSpace(sslProtocolsString)) { sslProtocolsString = null; } @@ -473,7 +494,7 @@ namespace Duplicati.Library.Backend.AlternativeFTP } catch (Exception e) { - if (e.InnerException != null) { e = e.InnerException; } + if (e.InnerException != null) { e = e.InnerException; } throw new Exception(string.Format(Strings.ErrorDeleteFile, e.Message), e); } } From 0f6f5bf5814f2a2be201b6dc701f6a8e5ac7097d Mon Sep 17 00:00:00 2001 From: Kenneth Skovhede Date: Thu, 1 Aug 2024 10:11:27 +0200 Subject: [PATCH 2/2] Changed to rely on `SslProtocols.None` to use the system defaults for choosing protocols --- .../AlternativeFTP/AlternativeFTPBackend.cs | 30 ++----------------- 1 file changed, 3 insertions(+), 27 deletions(-) diff --git a/Duplicati/Library/Backend/AlternativeFTP/AlternativeFTPBackend.cs b/Duplicati/Library/Backend/AlternativeFTP/AlternativeFTPBackend.cs index 6c99dcb61..e8cd77335 100644 --- a/Duplicati/Library/Backend/AlternativeFTP/AlternativeFTPBackend.cs +++ b/Duplicati/Library/Backend/AlternativeFTP/AlternativeFTPBackend.cs @@ -42,37 +42,13 @@ namespace Duplicati.Library.Backend.AlternativeFTP // ReSharper disable once RedundantExtendsListEntry public class AlternativeFtpBackend : IBackend, IStreamingBackend { - private static SslProtocols GetDefaultSslProtocols() - { - // Use the defaults from FluentFTP - var result = new FtpConfig().SslProtocols; - - // Probe if the system supports TLS 1.3 - var restore = ServicePointManager.SecurityProtocol; - try - { - // If we can set this, it looks like the system supports TLS 1.3 - ServicePointManager.SecurityProtocol = SecurityProtocolType.Tls13; - result = SslProtocols.Tls12 | SslProtocols.Tls13; - } - catch - { - } - finally - { - ServicePointManager.SecurityProtocol = restore; - } - - return result; - } - private System.Net.NetworkCredential _userInfo; private const string OPTION_ACCEPT_SPECIFIED_CERTIFICATE = "accept-specified-ssl-hash"; // Global option private const string OPTION_ACCEPT_ANY_CERTIFICATE = "accept-any-ssl-certificate"; // Global option private const FtpDataConnectionType DEFAULT_DATA_CONNECTION_TYPE = FtpDataConnectionType.AutoPassive; private const FtpEncryptionMode DEFAULT_ENCRYPTION_MODE = FtpEncryptionMode.None; - private static readonly SslProtocols DEFAULT_SSL_PROTOCOLS = GetDefaultSslProtocols(); + private static readonly SslProtocols DEFAULT_SSL_PROTOCOLS = SslProtocols.None; // NOTE: None means "use system default" private const string CONFIG_KEY_AFTP_ENCRYPTION_MODE = "aftp-encryption-mode"; private const string CONFIG_KEY_AFTP_DATA_CONNECTION_TYPE = "aftp-data-connection-type"; private const string CONFIG_KEY_AFTP_SSL_PROTOCOLS = "aftp-ssl-protocols"; @@ -125,7 +101,7 @@ namespace Duplicati.Library.Backend.AlternativeFTP { get { - return new List(new ICommandLineArgument[] { + return new List([ new CommandLineArgument("auth-password", CommandLineArgument.ArgumentType.Password, Strings.DescriptionAuthPasswordShort, Strings.DescriptionAuthPasswordLong), new CommandLineArgument("auth-username", CommandLineArgument.ArgumentType.String, Strings.DescriptionAuthUsernameShort, Strings.DescriptionAuthUsernameLong), new CommandLineArgument("disable-upload-verify", CommandLineArgument.ArgumentType.Boolean, Strings.DescriptionDisableUploadVerifyShort, Strings.DescriptionDisableUploadVerifyLong), @@ -135,7 +111,7 @@ namespace Duplicati.Library.Backend.AlternativeFTP new CommandLineArgument(CONFIG_KEY_AFTP_UPLOAD_DELAY, CommandLineArgument.ArgumentType.Timespan, Strings.DescriptionUploadDelayShort, Strings.DescriptionUploadDelayLong, DEFAULT_UPLOAD_DELAY_STRING), new CommandLineArgument(CONFIG_KEY_AFTP_LOGTOCONSOLE, CommandLineArgument.ArgumentType.Boolean, Strings.DescriptionLogToConsoleShort, Strings.DescriptionLogToConsoleLong), new CommandLineArgument(CONFIG_KEY_AFTP_LOGPRIVATEINFOTOCONSOLE, CommandLineArgument.ArgumentType.Boolean, Strings.DescriptionLogPrivateInfoToConsoleShort, Strings.DescriptionLogPrivateInfoToConsoleLong, "false"), - }); + ]); } }