mirror of
https://github.com/drwetter/testssl.sh.git
synced 2025-01-07 17:20:57 +01:00
Merge branch '2.9dev' into run_beast_sockets
This commit is contained in:
commit
fbf40474a9
370
testssl.sh
370
testssl.sh
@ -2229,8 +2229,6 @@ test_just_one(){
|
|||||||
if [[ $sclient_success -eq 0 ]]; then
|
if [[ $sclient_success -eq 0 ]]; then
|
||||||
dhlen=$(read_dhbits_from_file $TMPFILE quiet)
|
dhlen=$(read_dhbits_from_file $TMPFILE quiet)
|
||||||
kx="$kx $dhlen"
|
kx="$kx $dhlen"
|
||||||
else
|
|
||||||
kx="$kx$grey TBD $off "
|
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
neat_list $HEXC $ciph "$kx" $enc
|
neat_list $HEXC $ciph "$kx" $enc
|
||||||
@ -2507,124 +2505,290 @@ run_allciphers() {
|
|||||||
|
|
||||||
# test for all ciphers per protocol locally configured (w/o distinguishing whether they are good or bad)
|
# test for all ciphers per protocol locally configured (w/o distinguishing whether they are good or bad)
|
||||||
run_cipher_per_proto() {
|
run_cipher_per_proto() {
|
||||||
local proto proto_text ossl_ciphers_proto
|
local proto proto_hex proto_text ossl_ciphers_proto
|
||||||
local -i nr_ciphers
|
local -i nr_ciphers nr_ossl_ciphers nr_nonossl_ciphers success
|
||||||
local n sslvers auth mac export
|
local n sslvers auth mac export hexc sslv2_ciphers="" cipher
|
||||||
local -a hexcode ciph kx enc export2
|
local -a hexcode normalized_hexcode ciph rfc_ciph kx enc export2
|
||||||
local -i i j parent child end_of_bundle round_num bundle_size num_bundles mod_check
|
local -a hexcode2 ciph2 rfc_ciph2
|
||||||
local -a ciphers_found
|
local -i i bundle end_of_bundle bundle_size num_bundles mod_check
|
||||||
local dhlen
|
local -a ciphers_found ciphers_found2 sigalg ossl_supported index
|
||||||
|
local dhlen supported_sslv2_ciphers ciphers_to_test addcmd sni temp
|
||||||
local available
|
local available
|
||||||
local id
|
local id
|
||||||
|
local has_dh_bits="$HAS_DH_BITS"
|
||||||
|
local using_sockets=true
|
||||||
|
|
||||||
pr_headlineln " Testing all locally available ciphers per protocol against the server, ordered by encryption strength "
|
"$SSL_NATIVE" && using_sockets=false
|
||||||
! "$HAS_DH_BITS" && pr_warningln " (Your $OPENSSL cannot show DH/ECDH bits)"
|
"$FAST" && using_sockets=false
|
||||||
|
[[ $TLS_NR_CIPHERS == 0 ]] && using_sockets=false
|
||||||
|
|
||||||
|
if "$using_sockets"; then
|
||||||
|
pr_headlineln " Testing per protocol via OpenSSL and sockets against the server, ordered by encryption strength "
|
||||||
|
else
|
||||||
|
pr_headlineln " Testing all locally available ciphers per protocol against the server, ordered by encryption strength "
|
||||||
|
outln
|
||||||
|
[[ $TLS_NR_CIPHERS == 0 ]] && ! "$SSL_NATIVE" && ! "$FAST" && pr_warning " Cipher mapping not available, doing a fallback to openssl"
|
||||||
|
if ! "$HAS_DH_BITS"; then
|
||||||
|
[[ $TLS_NR_CIPHERS == 0 ]] && ! "$SSL_NATIVE" && ! "$FAST" && out "."
|
||||||
|
pr_warningln " (Your $OPENSSL cannot show DH/ECDH bits)"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
outln
|
outln
|
||||||
neat_header
|
neat_header
|
||||||
outln " -ssl2 SSLv2\n -ssl3 SSLv3\n -tls1 TLS 1\n -tls1_1 TLS 1.1\n -tls1_2 TLS 1.2"| while read proto proto_text; do
|
outln " -ssl2 22 SSLv2\n -ssl3 00 SSLv3\n -tls1 01 TLS 1\n -tls1_1 02 TLS 1.1\n -tls1_2 03 TLS 1.2"| while read proto proto_hex proto_text; do
|
||||||
locally_supported "$proto" "$proto_text" || continue
|
"$using_sockets" || locally_supported "$proto" "$proto_text" || continue
|
||||||
|
"$using_sockets" && out "$proto_text "
|
||||||
outln
|
outln
|
||||||
has_server_protocol "${proto:1}" || continue
|
has_server_protocol "${proto:1}" || continue
|
||||||
|
|
||||||
# The OpenSSL ciphers function, prior to version 1.1.0, could only understand -ssl2, -ssl3, and -tls1.
|
# get a list of all the cipher suites to test
|
||||||
if [[ "$proto" == "-ssl2" ]] || [[ "$proto" == "-ssl3" ]] || \
|
|
||||||
[[ $OSSL_VER_MAJOR.$OSSL_VER_MINOR == "1.1.0"* ]] || [[ $OSSL_VER_MAJOR.$OSSL_VER_MINOR == "1.1.1"* ]]; then
|
|
||||||
ossl_ciphers_proto="$proto"
|
|
||||||
else
|
|
||||||
ossl_ciphers_proto="-tls1"
|
|
||||||
fi
|
|
||||||
# get a list of all the cipher suites to test (only need the hexcode, ciph, kx, enc, and export values)
|
|
||||||
nr_ciphers=0
|
nr_ciphers=0
|
||||||
while read hexcode[nr_ciphers] n ciph[nr_ciphers] sslvers kx[nr_ciphers] auth enc[nr_ciphers] mac export2[nr_ciphers]; do
|
if "$using_sockets" || [[ $OSSL_VER_MAJOR -lt 1 ]]; then
|
||||||
nr_ciphers=$nr_ciphers+1
|
for (( i=0; i < TLS_NR_CIPHERS; i++ )); do
|
||||||
done < <($OPENSSL ciphers $ossl_ciphers_proto -V 'ALL:COMPLEMENTOFALL:@STRENGTH' 2>$ERRFILE)
|
hexc="${TLS_CIPHER_HEXCODE[i]}"
|
||||||
|
ciph[nr_ciphers]="${TLS_CIPHER_OSSL_NAME[i]}"
|
||||||
# Split ciphers into bundles of size 4**n, starting with the smallest
|
rfc_ciph[nr_ciphers]="${TLS_CIPHER_RFC_NAME[i]}"
|
||||||
# "n" that leaves the ciphers in one bundle, and then reducing "n" by
|
kx[nr_ciphers]="${TLS_CIPHER_KX[i]}"
|
||||||
# one in each round. Only test a bundle of 4**n ciphers against the
|
enc[nr_ciphers]="${TLS_CIPHER_ENC[i]}"
|
||||||
# server if it was part of a bundle of 4**(n+1) ciphers that included
|
export2[nr_ciphers]="${TLS_CIPHER_EXPORT[i]}"
|
||||||
# a cipher supported by the server. Continue until n=0.
|
ciphers_found[nr_ciphers]=false
|
||||||
|
sigalg[nr_ciphers]=""
|
||||||
# Determine the smallest bundle size that will result in their being one bundle.
|
ossl_supported[nr_ciphers]=${TLS_CIPHER_OSSL_SUPPORTED[i]}
|
||||||
for(( bundle_size=1; bundle_size < nr_ciphers; bundle_size*=4 )); do
|
if "$using_sockets" && ! "$has_dh_bits" && ( [[ ${kx[nr_ciphers]} == "Kx=ECDH" ]] || [[ ${kx[nr_ciphers]} == "Kx=DH" ]] || [[ ${kx[nr_ciphers]} == "Kx=EDH" ]] ); then
|
||||||
:
|
ossl_supported[nr_ciphers]=false
|
||||||
done
|
fi
|
||||||
|
if [[ ${#hexc} -eq 9 ]]; then
|
||||||
# set ciphers_found[1] so that the complete bundle will be tested in round 0.
|
hexcode[nr_ciphers]="${hexc:2:2},${hexc:7:2}"
|
||||||
ciphers_found[1]=true
|
if [[ "${hexc:2:2}" == "00" ]]; then
|
||||||
# Some servers can't handle a handshake with >= 128 ciphers.
|
normalized_hexcode[nr_ciphers]="x${hexc:7:2}"
|
||||||
for (( round_num=0; bundle_size>=128; bundle_size/=4 )); do
|
else
|
||||||
round_num=$round_num+1
|
normalized_hexcode[nr_ciphers]="x${hexc:2:2}${hexc:7:2}"
|
||||||
for (( i=4**$round_num; i<2*4**$round_num; i++ )); do
|
fi
|
||||||
ciphers_found[i]=true
|
else
|
||||||
|
hexc="$(tolower "$hexc")"
|
||||||
|
hexcode[nr_ciphers]="${hexc:2:2},${hexc:7:2},${hexc:12:2}"
|
||||||
|
normalized_hexcode[nr_ciphers]="x${hexc:2:2}${hexc:7:2}${hexc:12:2}"
|
||||||
|
fi
|
||||||
|
if ( "$using_sockets" || "${TLS_CIPHER_OSSL_SUPPORTED[i]}" ); then
|
||||||
|
if [[ ${#hexc} -eq 9 ]] && [[ "$proto_text" != "SSLv2" ]]; then
|
||||||
|
if [[ "$proto_text" == "TLS 1.3" ]]; then
|
||||||
|
[[ "${hexc:2:2}" == "13" ]] && nr_ciphers+=1
|
||||||
|
elif [[ "$proto_text" == "TLS 1.2" ]]; then
|
||||||
|
[[ "${hexc:2:2}" != "13" ]] && nr_ciphers+=1
|
||||||
|
elif [[ ! "${TLS_CIPHER_RFC_NAME[i]}" =~ "SHA256" ]] && [[ ! "${TLS_CIPHER_RFC_NAME[i]}" =~ "SHA384" ]] && \
|
||||||
|
[[ "${TLS_CIPHER_RFC_NAME[i]}" != *"_CCM" ]] && [[ "${TLS_CIPHER_RFC_NAME[i]}" != *"_CCM_8" ]]; then
|
||||||
|
nr_ciphers+=1
|
||||||
|
fi
|
||||||
|
elif [[ ${#hexc} -eq 14 ]] && [[ "$proto_text" == "SSLv2" ]]; then
|
||||||
|
sslv2_ciphers+=", ${hexcode[nr_ciphers]}"
|
||||||
|
nr_ciphers+=1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
done
|
done
|
||||||
done
|
else
|
||||||
for (( 1; bundle_size>=1; bundle_size/=4 )); do
|
# The OpenSSL ciphers function, prior to version 1.1.0, could only understand -ssl2, -ssl3, and -tls1.
|
||||||
# Note that since the number of ciphers isn't a power of 4, the number
|
if [[ "$proto" == "-ssl2" ]] || [[ "$proto" == "-ssl3" ]] || \
|
||||||
# of bundles may be may be less than 4**(round_num+1), and the final
|
[[ $OSSL_VER_MAJOR.$OSSL_VER_MINOR == "1.1.0"* ]] || [[ $OSSL_VER_MAJOR.$OSSL_VER_MINOR == "1.1.1"* ]]; then
|
||||||
# bundle may have fewer than bundle_size ciphers.
|
ossl_ciphers_proto="$proto"
|
||||||
num_bundles=$nr_ciphers/$bundle_size
|
else
|
||||||
mod_check=$nr_ciphers%$bundle_size
|
ossl_ciphers_proto="-tls1"
|
||||||
[[ $mod_check -ne 0 ]] && num_bundles=$num_bundles+1
|
fi
|
||||||
for (( i=0; i<num_bundles; i++ )); do
|
while read hexc n ciph[nr_ciphers] sslvers kx[nr_ciphers] auth enc[nr_ciphers] mac export2[nr_ciphers]; do
|
||||||
# parent=index of bundle from previous round that includes this bundle of ciphers
|
if [[ "$proto_text" == "TLS 1.2" ]] || \
|
||||||
parent=4**$round_num+$i/4
|
( [[ "${ciph[nr_ciphers]}" != *"-SHA256" ]] && [[ "${ciph[nr_ciphers]}" != *"-SHA384" ]] && \
|
||||||
# child=index for this bundle of ciphers
|
[[ "${ciph[nr_ciphers]}" != *"-CCM" ]] && [[ "${ciph[nr_ciphers]}" != *"-CCM8" ]] && \
|
||||||
child=4*4**$round_num+$i
|
[[ ! "${ciph[nr_ciphers]}" =~ "-CHACHA20-POLY1305" ]] ); then
|
||||||
if ${ciphers_found[parent]}; then
|
ciphers_found[nr_ciphers]=false
|
||||||
ciphers_to_test=""
|
if [[ ${#hexc} -eq 9 ]]; then
|
||||||
end_of_bundle=$i*$bundle_size+$bundle_size
|
if [[ "${hexc:2:2}" == "00" ]]; then
|
||||||
[[ $end_of_bundle -gt $nr_ciphers ]] && end_of_bundle=$nr_ciphers
|
normalized_hexcode[nr_ciphers]="x${hexc:7:2}"
|
||||||
for (( j=i*bundle_size; j<end_of_bundle; j++ )); do
|
else
|
||||||
ciphers_to_test="${ciphers_to_test}:${ciph[j]}"
|
normalized_hexcode[nr_ciphers]="x${hexc:2:2}${hexc:7:2}"
|
||||||
done
|
fi
|
||||||
ciphers_found[child]=false
|
else
|
||||||
if [[ "$proto" =~ ssl ]]; then
|
normalized_hexcode[nr_ciphers]="$(tolower "x${hexc:2:2}${hexc:7:2}${hexc:12:2}")"
|
||||||
# SSLv2 and SSLv3 do not have SNI
|
fi
|
||||||
$OPENSSL s_client -cipher "${ciphers_to_test:1}" $proto $STARTTLS $BUGS -connect $NODEIP:$PORT $PROXY >$TMPFILE 2>$ERRFILE </dev/null
|
sigalg[nr_ciphers]=""
|
||||||
else
|
ossl_supported[nr_ciphers]=true
|
||||||
$OPENSSL s_client -cipher "${ciphers_to_test:1}" $proto $STARTTLS $BUGS -connect $NODEIP:$PORT $PROXY $SNI >$TMPFILE 2>$ERRFILE </dev/null
|
nr_ciphers+=1
|
||||||
fi
|
fi
|
||||||
sclient_connect_successful "$?" "$TMPFILE"
|
done < <($OPENSSL ciphers $ossl_ciphers_proto -V 'ALL:COMPLEMENTOFALL:@STRENGTH' 2>>$ERRFILE)
|
||||||
[[ "$?" -eq 0 ]] && ciphers_found[child]=true
|
fi
|
||||||
else
|
|
||||||
# No need to test, since test of parent demonstrated none of these ciphers work.
|
|
||||||
ciphers_found[child]=false
|
|
||||||
fi
|
|
||||||
|
|
||||||
# If this is a "leaf" of the test tree, then print out the results.
|
if [[ "$proto" == "-ssl2" ]] && "$using_sockets"; then
|
||||||
if [[ $bundle_size -eq 1 ]] && ( ${ciphers_found[child]} || "$SHOW_EACH_C"); then
|
sslv2_sockets "${sslv2_ciphers:2}" "true"
|
||||||
export=${export2[i]}
|
if [[ $? -eq 3 ]] && [[ "$V2_HELLO_CIPHERSPEC_LENGTH" -ne 0 ]]; then
|
||||||
normalize_ciphercode "${hexcode[i]}"
|
supported_sslv2_ciphers="$(grep "Supported cipher: " "$TEMPDIR/$NODEIP.parse_sslv2_serverhello.txt")"
|
||||||
if [[ ${kx[i]} == "Kx=ECDH" ]] || [[ ${kx[i]} == "Kx=DH" ]] || [[ ${kx[i]} == "Kx=EDH" ]]; then
|
"$SHOW_SIGALGO" && s="$($OPENSSL x509 -noout -text -in "$HOSTCERT" | awk -F':' '/Signature Algorithm/ { print $2 }' | head -1)"
|
||||||
if ${ciphers_found[child]}; then
|
for (( i=0 ; i<nr_ciphers; i++ )); do
|
||||||
dhlen=$(read_dhbits_from_file "$TMPFILE" quiet)
|
if [[ "$supported_sslv2_ciphers" =~ "${normalized_hexcode[i]}" ]]; then
|
||||||
kx[i]="${kx[i]} $dhlen"
|
ciphers_found[i]=true
|
||||||
fi
|
"$SHOW_SIGALGO" && sigalg[i]="$s"
|
||||||
fi
|
fi
|
||||||
neat_list "$HEXC" "${ciph[i]}" "${kx[i]}" "${enc[i]}"
|
done
|
||||||
if "$SHOW_EACH_C"; then
|
fi
|
||||||
if ${ciphers_found[child]}; then
|
elif [[ "$proto" == "-ssl2" ]]; then
|
||||||
|
$OPENSSL s_client $STARTTLS $BUGS -connect $NODEIP:$PORT $PROXY -ssl2 >$TMPFILE 2>$ERRFILE </dev/null
|
||||||
|
sclient_connect_successful "$?" "$TMPFILE"
|
||||||
|
if [[ "$?" -eq 0 ]]; then
|
||||||
|
supported_sslv2_ciphers="$(grep -A 4 "Ciphers common between both SSL endpoints:" $TMPFILE)"
|
||||||
|
"$SHOW_SIGALGO" && s="$($OPENSSL x509 -noout -text -in $TMPFILE | awk -F':' '/Signature Algorithm/ { print $2 }' | head -1)"
|
||||||
|
for (( i=0 ; i<nr_ciphers; i++ )); do
|
||||||
|
if [[ "$supported_sslv2_ciphers" =~ "${ciph[i]}" ]]; then
|
||||||
|
ciphers_found[i]=true
|
||||||
|
"$SHOW_SIGALGO" && sigalg[i]="$s"
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
nr_ossl_ciphers=0
|
||||||
|
for (( i=0; i < nr_ciphers; i++ )); do
|
||||||
|
if "${ossl_supported[i]}"; then
|
||||||
|
ciphers_found2[nr_ossl_ciphers]=false
|
||||||
|
ciph2[nr_ossl_ciphers]="${ciph[i]}"
|
||||||
|
index[nr_ossl_ciphers]=$i
|
||||||
|
nr_ossl_ciphers+=1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
if [[ $nr_ossl_ciphers -eq 0 ]]; then
|
||||||
|
num_bundles=0
|
||||||
|
else
|
||||||
|
# Some servers can't handle a handshake with >= 128 ciphers. So,
|
||||||
|
# test cipher suites in bundles of 128 or less.
|
||||||
|
num_bundles=$nr_ossl_ciphers/128
|
||||||
|
mod_check=$nr_ossl_ciphers%128
|
||||||
|
[[ $mod_check -ne 0 ]] && num_bundles=$num_bundles+1
|
||||||
|
|
||||||
|
bundle_size=$nr_ossl_ciphers/$num_bundles
|
||||||
|
mod_check=$nr_ossl_ciphers%$num_bundles
|
||||||
|
[[ $mod_check -ne 0 ]] && bundle_size+=1
|
||||||
|
fi
|
||||||
|
|
||||||
|
sni=""
|
||||||
|
[[ ! "$proto" =~ ssl ]] && sni="$SNI"
|
||||||
|
for (( bundle=0; bundle < num_bundles; bundle++ )); do
|
||||||
|
end_of_bundle=$bundle*$bundle_size+$bundle_size
|
||||||
|
[[ $end_of_bundle -gt $nr_ossl_ciphers ]] && end_of_bundle=$nr_ossl_ciphers
|
||||||
|
for (( success=0; success==0 ; 1 )); do
|
||||||
|
ciphers_to_test=""
|
||||||
|
for (( i=bundle*bundle_size; i < end_of_bundle; i++ )); do
|
||||||
|
! "${ciphers_found2[i]}" && ciphers_to_test+=":${ciph2[i]}"
|
||||||
|
done
|
||||||
|
success=1
|
||||||
|
if [[ -n "$ciphers_to_test" ]]; then
|
||||||
|
$OPENSSL s_client -cipher "${ciphers_to_test:1}" $proto $STARTTLS $BUGS -connect $NODEIP:$PORT $PROXY $sni >$TMPFILE 2>$ERRFILE </dev/null
|
||||||
|
sclient_connect_successful "$?" "$TMPFILE"
|
||||||
|
if [[ "$?" -eq 0 ]]; then
|
||||||
|
cipher=$(awk '/Cipher *:/ { print $3 }' $TMPFILE)
|
||||||
|
if [[ -n "$cipher" ]]; then
|
||||||
|
success=0
|
||||||
|
for (( i=bundle*bundle_size; i < end_of_bundle; i++ )); do
|
||||||
|
[[ "$cipher" == "${ciph2[i]}" ]] && ciphers_found2[i]=true && break
|
||||||
|
done
|
||||||
|
i=${index[i]}
|
||||||
|
ciphers_found[i]=true
|
||||||
|
if [[ ${kx[i]} == "Kx=ECDH" ]] || [[ ${kx[i]} == "Kx=DH" ]] || [[ ${kx[i]} == "Kx=EDH" ]]; then
|
||||||
|
dhlen=$(read_dhbits_from_file "$TMPFILE" quiet)
|
||||||
|
kx[i]="${kx[i]} $dhlen"
|
||||||
|
fi
|
||||||
|
"$SHOW_SIGALGO" && grep -q "\-\-\-\-\-BEGIN CERTIFICATE\-\-\-\-\-" $TMPFILE && \
|
||||||
|
sigalg[i]="$($OPENSSL x509 -noout -text -in $TMPFILE | awk -F':' '/Signature Algorithm/ { print $2 }' | head -1)"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
done
|
||||||
|
|
||||||
|
if "$using_sockets"; then
|
||||||
|
nr_nonossl_ciphers=0
|
||||||
|
for (( i=0; i < nr_ciphers; i++ )); do
|
||||||
|
if ! "${ciphers_found[i]}"; then
|
||||||
|
ciphers_found2[nr_nonossl_ciphers]=false
|
||||||
|
hexcode2[nr_nonossl_ciphers]="${hexcode[i]}"
|
||||||
|
rfc_ciph2[nr_nonossl_ciphers]="${rfc_ciph[i]}"
|
||||||
|
index[nr_nonossl_ciphers]=$i
|
||||||
|
nr_nonossl_ciphers+=1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ $nr_nonossl_ciphers -eq 0 ]]; then
|
||||||
|
num_bundles=0
|
||||||
|
else
|
||||||
|
# Some servers can't handle a handshake with >= 128 ciphers. So,
|
||||||
|
# test cipher suites in bundles of 128 or less.
|
||||||
|
num_bundles=$nr_nonossl_ciphers/128
|
||||||
|
mod_check=$nr_nonossl_ciphers%128
|
||||||
|
[[ $mod_check -ne 0 ]] && num_bundles=$num_bundles+1
|
||||||
|
|
||||||
|
bundle_size=$nr_nonossl_ciphers/$num_bundles
|
||||||
|
mod_check=$nr_nonossl_ciphers%$num_bundles
|
||||||
|
[[ $mod_check -ne 0 ]] && bundle_size+=1
|
||||||
|
fi
|
||||||
|
|
||||||
|
for (( bundle=0; bundle < num_bundles; bundle++ )); do
|
||||||
|
end_of_bundle=$bundle*$bundle_size+$bundle_size
|
||||||
|
[[ $end_of_bundle -gt $nr_nonossl_ciphers ]] && end_of_bundle=$nr_nonossl_ciphers
|
||||||
|
for (( success=0; success==0 ; 1 )); do
|
||||||
|
ciphers_to_test=""
|
||||||
|
for (( i=bundle*bundle_size; i < end_of_bundle; i++ )); do
|
||||||
|
! "${ciphers_found2[i]}" && ciphers_to_test+=", ${hexcode2[i]}"
|
||||||
|
done
|
||||||
|
success=1
|
||||||
|
if [[ -n "$ciphers_to_test" ]]; then
|
||||||
|
if "$SHOW_SIGALGO"; then
|
||||||
|
tls_sockets "$proto_hex" "${ciphers_to_test:2}, 00,ff" "all"
|
||||||
|
else
|
||||||
|
tls_sockets "$proto_hex" "${ciphers_to_test:2}, 00,ff" "ephemeralkey"
|
||||||
|
fi
|
||||||
|
if [[ $? -eq 0 ]]; then
|
||||||
|
success=0
|
||||||
|
cipher=$(awk '/Cipher *:/ { print $3 }' "$TEMPDIR/$NODEIP.parse_tls_serverhello.txt")
|
||||||
|
for (( i=bundle*bundle_size; i < end_of_bundle; i++ )); do
|
||||||
|
[[ "$cipher" == "${rfc_ciph2[i]}" ]] && ciphers_found2[i]=true && break
|
||||||
|
done
|
||||||
|
i=${index[i]}
|
||||||
|
ciphers_found[i]=true
|
||||||
|
if [[ "$proto_text" == "TLS 1.3" ]]; then
|
||||||
|
temp=$(awk -F': ' '/^Server Temp Key/ { print $2 }' "$TEMPDIR/$NODEIP.parse_tls_serverhello.txt") # extract line
|
||||||
|
kx[i]="Kx=$(awk -F',' '{ print $1 }' <<< $temp)"
|
||||||
|
fi
|
||||||
|
if [[ ${kx[i]} == "Kx=ECDH" ]] || [[ ${kx[i]} == "Kx=DH" ]] || [[ ${kx[i]} == "Kx=EDH" ]]; then
|
||||||
|
dhlen=$(read_dhbits_from_file "$TEMPDIR/$NODEIP.parse_tls_serverhello.txt" quiet)
|
||||||
|
kx[i]="${kx[i]} $dhlen"
|
||||||
|
fi
|
||||||
|
"$SHOW_SIGALGO" && [[ -r "$HOSTCERT" ]] && \
|
||||||
|
sigalg[i]="$($OPENSSL x509 -noout -text -in "$HOSTCERT" | awk -F':' '/Signature Algorithm/ { print $2 }' | head -1)"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
|
||||||
|
for (( i=0 ; i<nr_ciphers; i++ )); do
|
||||||
|
if "${ciphers_found[i]}" || "$SHOW_EACH_C"; then
|
||||||
|
export=${export2[i]}
|
||||||
|
normalized_hexcode[i]="$(tolower "${normalized_hexcode[i]}")"
|
||||||
|
neat_list "${normalized_hexcode[i]}" "${ciph[i]}" "${kx[i]}" "${enc[i]}"
|
||||||
|
available=""
|
||||||
|
if "$SHOW_EACH_C"; then
|
||||||
|
if "${ciphers_found[i]}"; then
|
||||||
available="available"
|
available="available"
|
||||||
pr_cyan "$available"
|
pr_cyan "$available"
|
||||||
else
|
else
|
||||||
available="not a/v"
|
available="not a/v"
|
||||||
out "$available"
|
out "$available"
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
if "$SHOW_SIGALGO" && ${ciphers_found[child]}; then
|
outln "${sigalg[i]}"
|
||||||
$OPENSSL x509 -noout -text -in $TMPFILE | awk -F':' '/Signature Algorithm/ { print $2 }' | head -1
|
id="cipher$proto"
|
||||||
else
|
id+="_${normalized_hexcode[i]}"
|
||||||
outln
|
fileout "$id" "INFO" "$proto_text $(neat_list "${normalized_hexcode[i]}" "${ciph[i]}" "${kx[i]}" "${enc[i]}") $available"
|
||||||
fi
|
fi
|
||||||
id="cipher$proto"
|
|
||||||
id+="_$HEXC"
|
|
||||||
fileout "$id" "INFO" "$proto_text $(neat_list "$HEXC" "${ciph[i]}" "${kx[i]}" "${enc[i]}") $available"
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
round_num=round_num+1
|
|
||||||
done
|
done
|
||||||
done
|
done
|
||||||
|
"$using_sockets" && HAS_DH_BITS="$has_dh_bits"
|
||||||
tmpfile_handle $FUNCNAME.txt
|
tmpfile_handle $FUNCNAME.txt
|
||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user