If the user has not specified any overrides, use the OS default validator.
Prior to this PR all certs were validated by the .NET default chain validator, which is more strict with regards to revocation checks. With this PR, the OS default is now used to validate certificates.
This updates the SSL/TLS validation to optionally ignore failures in OCSP/CRL list. If the revocation servers are offline or unavailable, the SSL requests will fail.
With the new option, `--ignore-revocation-failure`, it is now possible to ignore this class of errors and let the connections work anyway.
By default, this is off so we have the strictest possible security.
As part of this PR, there were a few places that did validation/override of certificates. With this change all calls route into the single `SslCertificateValidator` class so all certificate validations are done the same from ServerUtil, reporting modules and backends.
This PR adds a unified way of supplying timeouts to each of the backends.
It also adds an opt-in way of adding commonly used options, so parsing and usage can be standardized across multiple backends.
Added support for `--portable-mode` and `--server-datafolder` for the CLI, ServerUtil, and Agent.
Fixed a few places where file reads were not cached properly.
Moved some responsibilities of UpdaterManager into DataFolderManager.
This now supports storing `machineid.txt` and `installation.txt` inside the path pointed to by `--server-datafolder` or alternatively with `--portable-mode`.
It is possible that some fringe backwards compatibility is lost with this update.
Fixed an issue with AutoUpdater crashing on check/download.
This fixes#5902
This is a proposal for replacing the deprecated WebClient with the HttpClient.
This commit implements the core functionality following the HttpClientFactory pattern as suggested by the framework. It also supports an alternative approach in areas where the HttpClient pattern is not desirable.
The first backend component to be migrated is WebDav, and the HttpClient pattern is also applied to the update downloader.
Once merged, other backend components can be migrated, eventually removing the deprecated WebClient from the codebase.
Additionally, the debug-profind-file option from webdav, which was a remnant from early development, is removed as it is no longer useful for debugging different webdav server responses.