Force enable SSLv3 in GlobalTerminalService and throw in some troubleshooting breadcrumbs for obsolete ciphers.

This commit is contained in:
Greg Edwards
2021-04-22 03:34:53 -04:00
parent 2d4d945057
commit e64ce73119
2 changed files with 19 additions and 3 deletions

View File

@@ -207,8 +207,14 @@ namespace PkmnFoundations.GlobalTerminalService
{
if (UseSsl)
{
// todo: If we target .NET Core 3+, we can manually enable RC4 cipher suites.
// https://github.com/dotnet/runtime/issues/23818
// The DS wants to use SSLv3 and one of the following ciphers:
// 0x0004 TLS_RSA_WITH_RC4_128_MD5
// 0x0005 TLS_RSA_WITH_RC4_128_SHA
// For now, the only functional approach is to enable these ciphers in the registry or via e.g. IISCrypto.
SslStream sslClient = new SslStream(c.GetStream());
sslClient.AuthenticateAsServer(Certificate);
sslClient.AuthenticateAsServer(Certificate, false, System.Security.Authentication.SslProtocols.Ssl3, false);
return sslClient;
}
else return c.GetStream();

View File

@@ -1,8 +1,18 @@
<?xml version="1.0"?>
<configuration>
<startup><supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.0"/></startup>
<startup>
<supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.0"/>
</startup>
<runtime>
<!-- Too bad AppContexts are only supported on .NET 4.6+ and don't seem to override ciphers disabled in the registry anyway. -->
<AppContextSwitchOverrides value="Switch.System.Net.DontEnableSchUseStrongCrypto=true"/>
</runtime>
<connectionStrings>
<add name="pkmnFoundationsConnectionString" connectionString="Server=gts;Database=gts;User ID=gts;Password=gts;Pooling=true;charset=utf8" providerName="MySql.Data.MySqlClient"/>
<add name="pkmnFoundationsConnectionString" connectionString="Server=localhost;Database=gts;User ID=gts;Password=gts;Pooling=true;charset=utf8" providerName="MySql.Data.MySqlClient"/>
</connectionStrings>
</configuration>