Commit Graph
9 Commits
Author SHA1 Message Date
Kenneth Skovhede 2ca0d13177 Use OS-default cert validator
If the user has not specified any overrides, use the OS default validator.

Prior to this PR all certs were validated by the .NET default chain validator, which is more strict with regards to revocation checks. With this PR, the OS default is now used to validate certificates.
2026-07-08 17:46:41 +02:00
Kenneth Skovhede 92d6d666ee Add OCSP failure handling option
This updates the SSL/TLS validation to optionally ignore failures in OCSP/CRL list. If the revocation servers are offline or unavailable, the SSL requests will fail.

With the new option, `--ignore-revocation-failure`, it is now possible to ignore this class of errors and let the connections work anyway.

By default, this is off so we have the strictest possible security.

As part of this PR, there were a few places that did validation/override of certificates. With this change all calls route into the single `SslCertificateValidator` class so all certificate validations are done the same from ServerUtil, reporting modules and backends.
2026-06-27 11:43:28 +02:00
Kenneth Skovhede c0f40e19ca Updated copyright year to 2026 across the project 2026-04-16 15:21:24 +02:00
Kenneth Skovhede 6c7843b332 Unified options
This PR adds a unified way of supplying timeouts to each of the backends.

It also adds an opt-in way of adding commonly used options, so parsing and usage can be standardized across multiple backends.
2025-03-19 15:27:02 +01:00
Kenneth Skovhede fac12ba772 Further consolidated the data folder.
Added support for `--portable-mode` and `--server-datafolder` for the CLI, ServerUtil, and Agent.

Fixed a few places where file reads were not cached properly.

Moved some responsibilities of UpdaterManager into DataFolderManager.

This now supports storing `machineid.txt` and `installation.txt` inside the path pointed to by `--server-datafolder` or alternatively with `--portable-mode`.

It is possible that some fringe backwards compatibility is lost with this update.

Fixed an issue with AutoUpdater crashing on check/download.

This fixes #5902
2025-01-28 13:01:35 +01:00
Kenneth SkovhedeandGitHub 9464caf622 Feature/update license 2025 (#5851)
* Fixed some minor whitespace issues

* Updated all copyright to 2025
2025-01-07 09:40:39 +01:00
Marcelo Ceccon fd591d9af2 Fix to Webdav issue around certificate validation
Fix to Webdav to process the options accept-specified-ssl-hash and accept-any-ssl-certificate

Minor refactoring
2024-10-10 10:36:47 +02:00
Kenneth Skovhede 692836cf97 Added section for debugging BackendTool.
Fixed an issue with loading an HTTP client outside the webserver.
2024-09-13 14:32:06 +02:00
Marcelo Ceccon c7c46aed7d Replacing deprecated WebClient for HttpClient
This is a proposal for replacing the deprecated WebClient with the HttpClient.

This commit implements the core functionality following the HttpClientFactory pattern as suggested by the framework. It also supports an alternative approach in areas where the HttpClient pattern is not desirable.

The first backend component to be migrated is WebDav, and the HttpClient pattern is also applied to the update downloader.

Once merged, other backend components can be migrated, eventually removing the deprecated WebClient from the codebase.

Additionally, the debug-profind-file option from webdav, which was a remnant from early development, is removed as it is no longer useful for debugging different webdav server responses.
2024-09-06 10:46:46 +02:00