Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Weak cipher suite warning since 2.5M2 #1064

Closed
radokristof opened this issue Oct 1, 2019 · 18 comments · Fixed by #1241
Closed

Weak cipher suite warning since 2.5M2 #1064

radokristof opened this issue Oct 1, 2019 · 18 comments · Fixed by #1241

Comments

@radokristof
Copy link

Dear community!

Other also reported that since M2 (and it is still present in M3), we usually get a long list of warnings:

2019-09-30 03:42:34.055 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_ECDH_RSA_WITH_AES_256_CBC_SHA enabled for SslContextFactory@17b090b[provider=null,keyStore=null,trustStore=null]

First I thought it is because of the new mail binding, but others reported that they don't use mail bindings and still gets these warnings. @J-N-K said it might be related to Jetty.

I know this is just a warning, but I send a log report for myself daily to quickly identify problems in my setup. This warnings makes it unreadable because I get around 600-700 warnings a day just for this.
One temporary solution might be to set logging only for ERROR for the bundle which causes this warning, but I haven't figured it out yet which bundle is causing this.

@wborn
Copy link
Member

wborn commented Oct 1, 2019

Karaf 4.2.6 uses a newer Jetty version that logs these warnings when using weak cipher suites. I've fixed the warnings I saw in:

If you're using a customized jetty.xml you need to revert your changes so they are in sync with this commit. You can also use our default jetty.xml.

There can still be add-ons that use a SslContextFactory without excluding the weak cipher suites that may need a similar fix like #858.

@radokristof
Copy link
Author

radokristof commented Oct 1, 2019

I didn't modified that file, I don't know why it didn't got updated when I updated to M2.
I will try to replace that file, thanks!

@radokristof
Copy link
Author

radokristof commented Oct 1, 2019

The jetty.xml got updated correctly, it has the same content. So maybe another bundle is using it without excluding these suites.

Can this somehow traced back from the error which bundle is throwing this warning?

@wborn
Copy link
Member

wborn commented Oct 1, 2019

The logging does not help with pin pointing the bundle. It will most likely get logged when bundles are started so you could try pin pointing it with bundle:restart on the Karaf console.

@wborn wborn changed the title Weak chiper suite warning since 2.5M2 Weak cipher suite warning since 2.5M2 Oct 1, 2019
@radokristof
Copy link
Author

@wborn unfortunately this is not the case. This error happens randomly and I can't find any bundle which after its restart fires these warnings.

@pacive
Copy link
Member

pacive commented Nov 25, 2019

I get these warnings as well, in my case it seems to happen when the spotify binding refreshes it's OAuth token:

2019-11-25 15:07:09.640 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_RSA_WITH_AES_256_CBC_SHA256 enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.641 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.642 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.642 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_RSA_WITH_AES_256_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.643 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_RSA_WITH_AES_256_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.644 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.644 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_ECDH_RSA_WITH_AES_256_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.645 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_DHE_RSA_WITH_AES_256_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.645 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_DHE_DSS_WITH_AES_256_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.646 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_RSA_WITH_AES_128_CBC_SHA256 enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.647 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.647 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.647 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_RSA_WITH_AES_128_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.648 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_RSA_WITH_AES_128_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.648 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.648 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_ECDH_RSA_WITH_AES_128_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.649 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_DHE_RSA_WITH_AES_128_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.649 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_DHE_DSS_WITH_AES_128_CBC_SHA enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.649 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_RSA_WITH_AES_256_GCM_SHA384 enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.650 [WARN ] [ty.util.ssl.SslContextFactory.config] - Weak cipher suite TLS_RSA_WITH_AES_128_GCM_SHA256 enabled for SslContextFactory@3356100a[provider=null,keyStore=null,trustStore=null]
2019-11-25 15:07:09.807 [INFO ] [oauth2client.internal.OAuthConnector] - grant type refresh_token to URL https://accounts.spotify.com/api/token success

Not sure wether the fix should go in the oauth2client bundle or in the Spotify binding though..

@radokristof
Copy link
Author

Yes I was also able to trace it down until Spotify. But I think this is something wrong in the OAuth implementation and not the Spotify binding itself...

@cweitkamp
Copy link
Contributor

@Hilbrand As initial contributor of the Spotify Binding: Do you see these warnings too?

@wborn
Copy link
Member

wborn commented Nov 25, 2019

I see that the WebClientFactoryImpl has another method where it creates a SslContextFactory that doesn't exclude these weak ciphers:

String excludeCipherSuites[] = { "^.*_(MD5)$" };
sslContextFactory.setExcludeCipherSuites(excludeCipherSuites);

So we can probably fix those warnings by adding the same excludes as in the other method:

// Exclude weak / insecure ciphers
sslContextFactory.addExcludeCipherSuites("^.*_(MD5|SHA|SHA1)$");
// Exclude ciphers that don't support forward secrecy
sslContextFactory.addExcludeCipherSuites("^TLS_RSA_.*$");

@radokristof
Copy link
Author

Thanks @wborn it might be this causing the warnings. Should I create a PR for this?

@pacive
Copy link
Member

pacive commented Nov 25, 2019

The method is marked as deprecated, so either way we should find where this is called from and change the caller to use private SslContextFactory createSslContextFactoryFromExtensibleTrustManager() instead?

wborn added a commit to wborn/openhab-core that referenced this issue Nov 25, 2019
To prevent weak cipher/protocol warnings it's better to not customize the default excluded ciphers and protocols.
The MD5 ciphers have already been excluded by default since Jetty 9.3.11.v20160721.

Fixes openhab#1064

Signed-off-by: Wouter Born <[email protected]>
@wborn
Copy link
Member

wborn commented Nov 25, 2019

Thanks but I already made a PR @radokristof! Currently we focus on fixing/adding 2.5.0 end user functionality for the upcoming release @pacive. Deprecations don't impact end users but fixing them might cause more issues.

@radokristof
Copy link
Author

Thank you! Yes I also think that we might try this first, if it solves the issue and then we can think about replacing deprecated methods...

kaikreuzer pushed a commit that referenced this issue Nov 25, 2019
…#1241)

To prevent weak cipher/protocol warnings it's better to not customize the default excluded ciphers and protocols.
The MD5 ciphers have already been excluded by default since Jetty 9.3.11.v20160721.

Fixes #1064

Signed-off-by: Wouter Born <[email protected]>
@wborn
Copy link
Member

wborn commented Dec 7, 2019

Did you still see any warnings with this fix @radokristof, @pacive?

@radokristof
Copy link
Author

No it is gone with this fix. Thanks!

@wborn
Copy link
Member

wborn commented Dec 7, 2019

Nice to know! 😄

@pacive
Copy link
Member

pacive commented Dec 8, 2019

Nothing in my logs either!

Rosi2143 pushed a commit to Rosi2143/openhab-core that referenced this issue Dec 26, 2020
splatch pushed a commit to ConnectorIO/copybara-hab-core that referenced this issue Jul 11, 2023
…openhab#1241)

To prevent weak cipher/protocol warnings it's better to not customize the default excluded ciphers and protocols.
The MD5 ciphers have already been excluded by default since Jetty 9.3.11.v20160721.

Fixes openhab#1064

Signed-off-by: Wouter Born <[email protected]>
GitOrigin-RevId: c50766d
@openhab-bot
Copy link
Collaborator

This issue has been mentioned on openHAB Community. There might be relevant details there:

https://community.openhab.org/t/weak-cipher-suite-warnings/157840/1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

5 participants