diff --git a/testssl.sh b/testssl.sh index 340dfd1..cae9f3a 100755 --- a/testssl.sh +++ b/testssl.sh @@ -4177,7 +4177,7 @@ run_cipher_match(){ fi done [[ -z "$ciphers_to_test" ]] && [[ -z "$tls13_ciphers_to_test" ]] && break - $OPENSSL s_client $(s_client_options "$proto -cipher "\'${ciphers_to_test:1}\'" -ciphersuites "\'${tls13_ciphers_to_test:1}\'" $STARTTLS $BUGS -connect $NODEIP:$PORT $PROXY $SNI") >$TMPFILE 2>$ERRFILE $TMPFILE 2>$ERRFILE $TMPFILE 2>$ERRFILE $TMPFILE 2>$ERRFILE $TMPFILE 2>$ERRFILE $TMPFILE 2>$ERRFILE $TMPFILE 2>$ERRFILE sclient_connect_successful $? $TMPFILE @@ -6487,7 +6487,7 @@ sub_cipherlists() { "$FAST" && continue [[ $(has_server_protocol "${proto:1}") -eq 1 ]] && continue fi - $OPENSSL s_client $(s_client_options "-cipher "$1" -ciphersuites "\'$2\'" $BUGS $STARTTLS -connect $NODEIP:$PORT $PROXY $SNI $proto") 2>$ERRFILE >$TMPFILE $ERRFILE >$TMPFILE >$ERRFILE >$TMPFILE + $OPENSSL s_client $(s_client_options "$STARTTLS -tls1_2 $BUGS -cipher $ciphers_to_test$tested_cipher -connect $NODEIP:$PORT $PROXY $SNI") >$ERRFILE >$TMPFILE if sclient_connect_successful $? $TMPFILE ; then cipher=$(get_cipher $TMPFILE) order+=" $cipher" @@ -7617,7 +7617,7 @@ check_tls12_pref() { while true; do # no ciphers from "ALL$tested_cipher:$batchremoved" left # now we check $batchremoved, and remove the minus signs first: - $OPENSSL s_client $(s_client_options "$STARTTLS -tls1_2 $BUGS -cipher "$batchremoved" -connect $NODEIP:$PORT $PROXY $SNI") >$ERRFILE >$TMPFILE + $OPENSSL s_client $(s_client_options "$STARTTLS -tls1_2 $BUGS -cipher $batchremoved -connect $NODEIP:$PORT $PROXY $SNI") >$ERRFILE >$TMPFILE if sclient_connect_successful $? $TMPFILE ; then batchremoved_success=true # signals that we have some of those ciphers and need to put everything together later on cipher=$(get_cipher $TMPFILE) @@ -7650,7 +7650,7 @@ check_tls12_pref() { [[ ! "$tested_cipher:" =~ :-$cipher: ]] && ciphers_to_test+=":$cipher" done [[ -z "$ciphers_to_test" ]] && break - $OPENSSL s_client $(s_client_options "$STARTTLS -tls1_2 $BUGS -cipher "${ciphers_to_test:1}" -connect $NODEIP:$PORT $PROXY $SNI") >$ERRFILE >$TMPFILE + $OPENSSL s_client $(s_client_options "$STARTTLS -tls1_2 $BUGS -cipher ${ciphers_to_test:1} -connect $NODEIP:$PORT $PROXY $SNI") >$ERRFILE >$TMPFILE if sclient_connect_successful $? $TMPFILE ; then cipher=$(get_cipher $TMPFILE) order+=" $cipher" @@ -7732,7 +7732,7 @@ cipher_pref_check() { else ciphers_to_test="-ciphersuites ${ciphers_to_test:1}" fi - $OPENSSL s_client $(s_client_options "$STARTTLS -"$proto" $BUGS $ciphers_to_test -connect $NODEIP:$PORT $PROXY $SNI") >$ERRFILE >$TMPFILE + $OPENSSL s_client $(s_client_options "$STARTTLS -$proto $BUGS $ciphers_to_test -connect $NODEIP:$PORT $PROXY $SNI") >$ERRFILE >$TMPFILE sclient_connect_successful $? $TMPFILE || break cipher=$(get_cipher $TMPFILE) [[ -z "$cipher" ]] && break @@ -7984,7 +7984,7 @@ cipher_pref_check() { else ciphers_to_test="-ciphersuites $first_chacha_cipher:$first_cipher" fi - $OPENSSL s_client $(s_client_options "$STARTTLS -"$proto" $BUGS $ciphers_to_test -connect $NODEIP:$PORT $PROXY $SNI") >$ERRFILE >$TMPFILE + $OPENSSL s_client $(s_client_options "$STARTTLS -$proto $BUGS $ciphers_to_test -connect $NODEIP:$PORT $PROXY $SNI") >$ERRFILE >$TMPFILE if sclient_connect_successful $? $TMPFILE; then cipher="$(get_cipher $TMPFILE)" [[ "$cipher" =~ CHACHA20 ]] && prioritize_chacha=true @@ -9179,7 +9179,7 @@ etsi_ets_visibility_info() { len1=$((2*0x${dercert:j:2})) j+=2 fi - access_description[nr_visnames]=""$(hex2binary "${dercert:j:len1}")"" + access_description[nr_visnames]="$(hex2binary "${dercert:j:len1}")" nr_visnames+=1 done fi @@ -10826,7 +10826,7 @@ run_server_defaults() { # would have been found by get_server_certificate(). So, try again with a TLSv1.2 ClientHello. $OPENSSL s_client $(s_client_options "$STARTTLS $BUGS -no_tls1_3 -connect $NODEIP:$PORT $PROXY $SNI") $ERRFILE >$TMPFILE else - $OPENSSL s_client $(s_client_options "$STARTTLS $BUGS "$OPTIMAL_PROTO" -connect $NODEIP:$PORT $PROXY $SNI") $ERRFILE >$TMPFILE + $OPENSSL s_client $(s_client_options "$STARTTLS $BUGS $OPTIMAL_PROTO -connect $NODEIP:$PORT $PROXY $SNI") $ERRFILE >$TMPFILE fi if sclient_connect_successful $? $TMPFILE; then sessticket_lifetime_hint=$(awk '/session ticket lifetime/ { if (!found) print; found=1 }' $TMPFILE) @@ -11334,7 +11334,7 @@ run_fs() { elif [[ "$proto" =~ curves2 ]]; then curves_option="-curves $curves_list2" fi - $OPENSSL s_client $(s_client_options "-${proto#*-} -cipher "\'${ciphers_to_test:1}\'" -ciphersuites "\'${tls13_ciphers_to_test:1}\'" $curves_option $STARTTLS $BUGS -connect $NODEIP:$PORT $PROXY $SNI") &>$TMPFILE $TMPFILE $TMPFILE $TMPFILE $TMPFILE $TMPFILE $ERRFILE >$TMPFILE + $OPENSSL s_client $(s_client_options "$proto -connect $NODEIP:$PORT $BUGS $SNI -nextprotoneg $NPN_PROTOs") $ERRFILE >$TMPFILE [[ $? -ne 0 ]] && ret=1 else tls_sockets "03" "$TLS12_CIPHER" "all" @@ -12308,7 +12308,7 @@ starttls_xmpp_dialog() { namespace="jabber:client" [[ "$STARTTLS_PROTOCOL" == xmpp-server ]] && namespace="jabber:server" - starttls_io "" 'starttls(.*)features' 1 && + starttls_io "" 'starttls(.*)features' 1 && starttls_io "" '" 'JUSTSEND' 2 ret=$? @@ -13052,9 +13052,9 @@ parse_sslv2_serverhello() { # Just in case somebody's interested in the exact error, we deliver it ;-) debugme echo -n ">TLS< alert message discovered: ${v2_hello_ascii} " case "${v2_hello_ascii:10:2}" in - 01) debugme echo "(01/warning: 0x"${v2_hello_ascii:12:2}"/$(tls_alert "${v2_hello_ascii:12:2}"))" ;; - 02) debugme echo "(02/fatal: 0x"${v2_hello_ascii:12:2}"/$(tls_alert "${v2_hello_ascii:12:2}"))" ;; - *) debugme echo "("${v2_hello_ascii:10:2}" : "${v2_hello_ascii:12:2}"))" ;; + 01) debugme echo "(01/warning: 0x${v2_hello_ascii:12:2}/$(tls_alert "${v2_hello_ascii:12:2}"))" ;; + 02) debugme echo "(02/fatal: 0x${v2_hello_ascii:12:2}/$(tls_alert "${v2_hello_ascii:12:2}"))" ;; + *) debugme echo "(${v2_hello_ascii:10:2} : ${v2_hello_ascii:12:2})" ;; esac ret=0 elif [[ $v2_hello_initbyte != "8" ]] || [[ $v2_hello_handshake != "04" ]]; then @@ -19763,7 +19763,7 @@ run_beast(){ esac elif [[ $subret -eq 2 ]]; then sclient_supported "-$proto" || continue - $OPENSSL s_client $(s_client_options "-state -"${proto}" $STARTTLS $BUGS -connect $NODEIP:$PORT $PROXY $SNI") 2>>$ERRFILE >$TMPFILE >$ERRFILE >$TMPFILE $TMPFILE 2>>$ERRFILE $TMPFILE 2>>$ERRFILE $TMPFILE 2>>$ERRFILE $TMPFILE 2>>$ERRFILE $TMPFILE 2>>$ERRFILE $TMPFILE 2>>$ERRFILE $TMPFILE 2>$ERRFILE $TMPFILE 2>$ERRFILE $TMPFILE 2>>$ERRFILE + $OPENSSL s_client $(s_client_options "$STARTTLS_OPTIMAL_PROTO $BUGS -connect $NODEIP:$PORT $PROXY -msg $STARTTLS $SNI") $TMPFILE 2>>$ERRFILE if sclient_auth $? $TMPFILE; then all_failed=false add_proto_offered "${STARTTLS_OPTIMAL_PROTO/-/}" yes @@ -23809,19 +23809,19 @@ determine_optimal_proto() { # $ENABLE_PHA is false. if [[ -z "$URL_PATH" ]] || [[ "$URL_PATH" == / ]] || \ { "$HAS_TLS13" && ! "$HAS_ENABLE_PHA" && [[ -z "$proto" || "$proto" == -tls1_3 ]] && [[ $(has_server_protocol "tls1_3") -ne 1 ]]; }; then - $OPENSSL s_client $(s_client_options "$proto $BUGS -connect "$NODEIP:$PORT" -msg $PROXY $SNI") $TMPFILE 2>>$ERRFILE + $OPENSSL s_client $(s_client_options "$proto $BUGS -connect $NODEIP:$PORT -msg $PROXY $SNI") $TMPFILE 2>>$ERRFILE else - safe_echo "$GET_REQ11" | $OPENSSL s_client $(s_client_options "$proto $BUGS -connect "$NODEIP:$PORT" -msg $PROXY $SNI -ign_eof -enable_pha") >$TMPFILE 2>>$ERRFILE & + safe_echo "$GET_REQ11" | $OPENSSL s_client $(s_client_options "$proto $BUGS -connect $NODEIP:$PORT -msg $PROXY $SNI -ign_eof -enable_pha") >$TMPFILE 2>>$ERRFILE & wait_kill $! $((HEADER_MAXSLEEP * 10)) if [[ $? -eq 0 ]]; then # Issue HTTP GET again as it properly finished within $HEADER_MAXSLEEP and didn't hang. # Doing it again in the foreground to get an accurate return code. - safe_echo "$GET_REQ11" | $OPENSSL s_client $(s_client_options "$proto $BUGS -connect "$NODEIP:$PORT" -msg $PROXY $SNI -ign_eof -enable_pha") >$TMPFILE 2>>$ERRFILE + safe_echo "$GET_REQ11" | $OPENSSL s_client $(s_client_options "$proto $BUGS -connect $NODEIP:$PORT -msg $PROXY $SNI -ign_eof -enable_pha") >$TMPFILE 2>>$ERRFILE else # Issuing HTTP GET caused $OPENSSL to hang, so just try to determine # protocol support without also trying to collect information about # client authentication. - $OPENSSL s_client $(s_client_options "$proto $BUGS -connect "$NODEIP:$PORT" -msg $PROXY $SNI") $TMPFILE 2>>$ERRFILE + $OPENSSL s_client $(s_client_options "$proto $BUGS -connect $NODEIP:$PORT -msg $PROXY $SNI") $TMPFILE 2>>$ERRFILE fi fi @@ -23849,13 +23849,13 @@ determine_optimal_proto() { if [[ "$tmp" == tls1_3 ]] && [[ -n "$URL_PATH" ]] && [[ "$URL_PATH" != / ]] && ! "$HAS_ENABLE_PHA"; then if [[ "$(has_server_protocol "tls1_2")" -eq 0 ]] || [[ "$(has_server_protocol "tls1_1")" -eq 0 ]] || \ [[ "$(has_server_protocol "tls1")" -eq 0 ]] || [[ "$(has_server_protocol "ssl3")" -eq 0 ]]; then - safe_echo "$GET_REQ11" | $OPENSSL s_client $(s_client_options "$BUGS -connect "$NODEIP:$PORT" -msg $PROXY $SNI -ign_eof -no_tls1_3") >$TEMPDIR/client_auth_test.txt 2>>$ERRFILE & + safe_echo "$GET_REQ11" | $OPENSSL s_client $(s_client_options "$BUGS -connect $NODEIP:$PORT -msg $PROXY $SNI -ign_eof -no_tls1_3") >$TEMPDIR/client_auth_test.txt 2>>$ERRFILE & wait_kill $! $((HEADER_MAXSLEEP * 10)) # If the HTTP properly finished within $HEADER_MAXSLEEP and didn't hang, then # do it again in the foreground to get an accurate return code. If it did hang, # there is no way to test for client authentication, so don't try. if [[ $? -eq 0 ]]; then - safe_echo "$GET_REQ11" | $OPENSSL s_client $(s_client_options "$BUGS -connect "$NODEIP:$PORT" -msg $PROXY $SNI -ign_eof -no_tls1_3") >$TEMPDIR/client_auth_test.txt 2>>$ERRFILE + safe_echo "$GET_REQ11" | $OPENSSL s_client $(s_client_options "$BUGS -connect $NODEIP:$PORT -msg $PROXY $SNI -ign_eof -no_tls1_3") >$TEMPDIR/client_auth_test.txt 2>>$ERRFILE sclient_auth $? $TEMPDIR/client_auth_test.txt fi elif [[ "$CLIENT_AUTH" == none ]]; then