1313import java .io .FileInputStream ;
1414import java .io .FileNotFoundException ;
1515import java .io .FileOutputStream ;
16+ import java .io .IOException ;
1617import java .io .InputStream ;
1718import java .io .InputStreamReader ;
1819import java .io .OutputStream ;
121122import com .mirth .connect .server .mybatis .KeyValuePair ;
122123import com .mirth .connect .server .tools .ClassPathResource ;
123124import com .mirth .connect .server .util .DatabaseUtil ;
125+ import com .mirth .connect .server .util .FilePermissionUtil ;
124126import com .mirth .connect .server .util .PasswordRequirementsChecker ;
125127import com .mirth .connect .server .util .ResourceUtil ;
126128import com .mirth .connect .server .util .SqlConfig ;
@@ -195,8 +197,6 @@ public class DefaultConfigurationController extends ConfigurationController {
195197 private static final String XSTREAM_ALLOW_TYPES = "xstream.allowtypes" ;
196198 private static final String XSTREAM_ALLOW_TYPE_HIERARCHIES = "xstream.allowtypehierarchies" ;
197199
198- private static final String DEFAULT_STOREPASS = "81uWxplDtB" ;
199-
200200 // singleton pattern
201201 private static ConfigurationController instance = null ;
202202
@@ -1239,22 +1239,6 @@ public void initializeSecuritySettings() {
12391239 keyStore .load (keyStoreFileIs , keyStorePassword );
12401240 logger .debug ("found and loaded keystore: " + keyStoreFile .getAbsolutePath ());
12411241 } else {
1242- /*
1243- * If a new keystore is being created, and the passwords are the defaults, then
1244- * create new passwords.
1245- */
1246- if (Arrays .equals (keyStorePassword , DEFAULT_STOREPASS .toCharArray ()) && Arrays .equals (keyPassword , DEFAULT_STOREPASS .toCharArray ())) {
1247- String keyStorePasswordStr = generateNewPassword ();
1248- mirthConfig .setProperty ("keystore.storepass" , keyStorePasswordStr );
1249- keyStorePassword = keyStorePasswordStr .toCharArray ();
1250-
1251- String keyPasswordStr = generateNewPassword ();
1252- mirthConfig .setProperty ("keystore.keypass" , keyPasswordStr );
1253- keyPassword = keyPasswordStr .toCharArray ();
1254-
1255- saveMirthConfig ();
1256- }
1257-
12581242 keyStore .load (null , keyStorePassword );
12591243 logger .debug ("keystore file not found, created new one" );
12601244 }
@@ -1263,6 +1247,7 @@ public void initializeSecuritySettings() {
12631247 generateDefaultCertificate (provider , keyStore , keyPassword );
12641248
12651249 // write the keystore back to the file
1250+ FilePermissionUtil .createOwnerOnlyFile (keyStoreFile );
12661251 fos = new FileOutputStream (keyStoreFile );
12671252 keyStore .store (fos , keyStorePassword );
12681253 } catch (Exception e ) {
@@ -1273,19 +1258,6 @@ public void initializeSecuritySettings() {
12731258 }
12741259 }
12751260
1276- /**
1277- * Creates a random 12-character alphanumeric password.
1278- */
1279- private String generateNewPassword () {
1280- String characters = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789" ;
1281- SecureRandom random = new SecureRandom ();
1282- StringBuilder builder = new StringBuilder ();
1283- for (int i = 1 ; i <= 12 ; i ++) {
1284- builder .append (characters .charAt (random .nextInt (characters .length ())));
1285- }
1286- return builder .toString ();
1287- }
1288-
12891261 @ Override
12901262 public void initializeDatabaseSettings () {
12911263 try {
0 commit comments