diff --git a/CHANGES b/CHANGES index 4fa5e9c6c1..7b399295f5 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,11 @@ +8.1.0-dev.484 | 2025-08-29 21:53:19 -0700 + + * Bump zeek-testing-cluster to pull in WebSocket TLS updates (Christian Kreibich, Corelight) + + * Bump zeek-client to pull in TLS config updates (Christian Kreibich, Corelight) + + * Management framework: add TLS options for controller's websocket server (Arne Welzel, Corelight) + 8.1.0-dev.480 | 2025-08-29 15:08:29 -0700 * Move benchmarking to Ubnutu 24 task, add to normal PR builds (Tim Wojtulewicz, Corelight) diff --git a/VERSION b/VERSION index 9624c4a737..5d67fa6322 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -8.1.0-dev.480 +8.1.0-dev.484 diff --git a/auxil/zeek-client b/auxil/zeek-client index 4440c7a05b..62e91d3abc 160000 --- a/auxil/zeek-client +++ b/auxil/zeek-client @@ -1 +1 @@ -Subproject commit 4440c7a05ba4be229ac88d70e8f4eef2465afc50 +Subproject commit 62e91d3abc726c3c17be4d70bb222b29b7bb6476 diff --git a/scripts/policy/frameworks/management/controller/config.zeek b/scripts/policy/frameworks/management/controller/config.zeek index 9fe10edaa6..0f202ccc78 100644 --- a/scripts/policy/frameworks/management/controller/config.zeek +++ b/scripts/policy/frameworks/management/controller/config.zeek @@ -61,6 +61,14 @@ export { ## for websocket clients. const default_port_websocket = 2149/tcp &redef; + ## TLS options for the controller's WebSocket server. The default is + ## to operate unencrypted. To replicate Broker's default encryption + ## without endpoint validation, set the + ## :zeek:field:`Cluster::WebSocketTLSOptions$ca_file` field to + ## "NONE" and :zeek:field:`Cluster::WebSocketTLSOptions$ciphers` to + ## "AECDH-AES256-SHA@SECLEVEL=0:AECDH-AES256-SHA:P-384". + const tls_options_websocket = Cluster::WebSocketTLSOptions() &redef; + ## Whether the controller should auto-assign Broker listening ports to ## cluster nodes that need them and don't have them explicitly specified ## in cluster configurations. diff --git a/scripts/policy/frameworks/management/controller/main.zeek b/scripts/policy/frameworks/management/controller/main.zeek index 19135149bf..48a6871e8d 100644 --- a/scripts/policy/frameworks/management/controller/main.zeek +++ b/scripts/policy/frameworks/management/controller/main.zeek @@ -1646,7 +1646,8 @@ event zeek_init() if ( cni$bound_port != 0/unknown ) { local ws_opts = Cluster::WebSocketServerOptions($listen_addr=to_addr(cni$address), - $listen_port=cni$bound_port); + $listen_port=cni$bound_port, + $tls_options=Management::Controller::tls_options_websocket); Cluster::listen_websocket(ws_opts); websocket_info = fmt("websocket port %s:%s", cni$address, cni$bound_port); } diff --git a/testing/external/commit-hash.zeek-testing-cluster b/testing/external/commit-hash.zeek-testing-cluster index 254da80396..1d70a56cca 100644 --- a/testing/external/commit-hash.zeek-testing-cluster +++ b/testing/external/commit-hash.zeek-testing-cluster @@ -1 +1 @@ -fc635b99a867a925dc23641e5bd37c93306bc981 +318f1209d92ca1c5e50c8d39af55e004e506a776