mirror of
https://github.com/drwetter/testssl.sh.git
synced 2026-10-04 23:48:13 +02:00
Merge pull request #3167 from testssl/fix_starttls_io_3.2
Fix starttls_io() in 3.2
This commit is contained in:
+9
-8
@@ -11669,13 +11669,14 @@ run_alpn() {
|
|||||||
|
|
||||||
# arg1: send string
|
# arg1: send string
|
||||||
# arg2: success string: an egrep pattern
|
# arg2: success string: an egrep pattern
|
||||||
# arg3: number of loops we should read from the buffer (optional, otherwise STARTTLS_SLEEP)
|
# arg3: number of loops we should read from the buffer. As of 2026 we were good with max 2, see #3154
|
||||||
|
# To be safe we're using 4 in calling starttls_io() to look for the pattern in $2
|
||||||
|
#
|
||||||
starttls_io() {
|
starttls_io() {
|
||||||
local nr_waits=$STARTTLS_SLEEP
|
local nr_waits=$3
|
||||||
local buffer=""
|
local buffer=""
|
||||||
local -i i
|
local -i i
|
||||||
|
|
||||||
[[ -n "$3" ]] && waitsleep=$3
|
|
||||||
[[ -z "$2" ]] && echo "FIXME $((LINENO))"
|
[[ -z "$2" ]] && echo "FIXME $((LINENO))"
|
||||||
|
|
||||||
# If there's a sending part it's IO. Postgres sends via socket and replies via
|
# If there's a sending part it's IO. Postgres sends via socket and replies via
|
||||||
@@ -11696,7 +11697,7 @@ starttls_io() {
|
|||||||
for ((i=1; i < nr_waits; i++ )); do
|
for ((i=1; i < nr_waits; i++ )); do
|
||||||
[[ "$DEBUG" -ge 2 ]] && echo -en "\nS: " && echo $buffer
|
[[ "$DEBUG" -ge 2 ]] && echo -en "\nS: " && echo $buffer
|
||||||
if [[ "$buffer" =~ $2 ]]; then
|
if [[ "$buffer" =~ $2 ]]; then
|
||||||
debugme echo " ---> reply matched \"$2\""
|
debugme echo " ---> reply # $i matched \"$2\""
|
||||||
# the fd sometimes still seem to contain chars which confuses the following TLS handshake, trying to empty:
|
# the fd sometimes still seem to contain chars which confuses the following TLS handshake, trying to empty:
|
||||||
# dd of=/dev/null bs=512 count=1 <&5 2>/dev/null
|
# dd of=/dev/null bs=512 count=1 <&5 2>/dev/null
|
||||||
return 0
|
return 0
|
||||||
@@ -11912,9 +11913,9 @@ starttls_xmpp_dialog() {
|
|||||||
namespace="jabber:client"
|
namespace="jabber:client"
|
||||||
[[ "$STARTTLS_PROTOCOL" == xmpp-server ]] && namespace="jabber:server"
|
[[ "$STARTTLS_PROTOCOL" == xmpp-server ]] && namespace="jabber:server"
|
||||||
|
|
||||||
starttls_io "<stream:stream xmlns:stream='http://etherx.jabber.org/streams' xmlns='"$namespace"' to='"$XMPP_HOST"' version='1.0'>" 'starttls(.*)features' 1 &&
|
starttls_io "<stream:stream xmlns:stream='http://etherx.jabber.org/streams' xmlns='"$namespace"' to='"$XMPP_HOST"' version='1.0'>" 'starttls(.*)features' 4 &&
|
||||||
starttls_io "<starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'/>" '<proceed' 1
|
starttls_io "<starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'/>" '<proceed' 4
|
||||||
# starttls_io "<stream:stream xmlns:stream='http://etherx.jabber.org/streams' xmlns='"$namespace"' to='"$XMPP_HOST"' version='1.0'>" 'JUSTSEND' 2
|
# starttls_io "<stream:stream xmlns:stream='http://etherx.jabber.org/streams' xmlns='"$namespace"' to='"$XMPP_HOST"' version='1.0'>" 'JUSTSEND' 4
|
||||||
ret=$?
|
ret=$?
|
||||||
debugme echo "=== finished xmpp STARTTLS dialog with ${ret} ==="
|
debugme echo "=== finished xmpp STARTTLS dialog with ${ret} ==="
|
||||||
return $ret
|
return $ret
|
||||||
@@ -11939,7 +11940,7 @@ starttls_postgres_dialog() {
|
|||||||
|
|
||||||
debugme echo "=== starting postgres STARTTLS dialog ==="
|
debugme echo "=== starting postgres STARTTLS dialog ==="
|
||||||
socksend "${starttls_init}" 0 && debugme echo "${debugpad}initiated STARTTLS" &&
|
socksend "${starttls_init}" 0 && debugme echo "${debugpad}initiated STARTTLS" &&
|
||||||
starttls_io "" S 1 && debugme echo "${debugpad}received ack (=\"S\") for STARTTLS"
|
starttls_io "" S 4 && debugme echo "${debugpad}received ack (=\"S\") for STARTTLS"
|
||||||
ret=$?
|
ret=$?
|
||||||
debugme echo "=== finished postgres STARTTLS dialog with ${ret} ==="
|
debugme echo "=== finished postgres STARTTLS dialog with ${ret} ==="
|
||||||
return $ret
|
return $ret
|
||||||
|
|||||||
Reference in New Issue
Block a user