As noted in #3154 there was an unused variable `waitsleep` in `starttls_io`
which was filled with argument passed \#3. The loop search for the pattern
in `$2` however was the filled with another variable `nr_waits` which was
pre-set to 10 (`STARTTLS_SLEEP`)
This PR for 3.2 fixes that by
- removing STARTTLS_SLEEP from this function
- passing a value of 4 to this function when called
For ~1200 xmpp tests 2 was the maximum in less than 10% of the cases, so
4 should be really safe. `starttls_postgres_dialog()` uses also `starttls_io`
but it should be a safe bet when searching for the pattern `S`
... which warns also via file output when not recommended command line options are used.
This function named issue_cmdline_warnings() is being called in lets roll after all fileout() functions has been initialized. It needs to make use of fileout_insert_warning() though because otherwise the JSON output is not correct.
Besides the previoulsy introduced warning when scanning IP addresses, warnings of usage of '--fast' and '--ssl-native' will end up also in a file now which gives ther tools using the machine readable output to detect bad scan conditions.
Also warnings when scanning the most known IPv4 addresses from Cloudflare, Google and Quad9, are avoided.
See also #3043 (3.3dev) .
This is an update of the CA certificate stores, same as #3125 .
- jdk-25.0.4.1
- Mozilla from Aug 13
- Apple via git repo from Aug 24
Note: The MS store still contained the DST Root CA X3 and has been
removed manually.
This fixes#3121 , a bug which was introduced in ceb24740a3 because
`prepare_logging()` expected an argument to pass the time stamp.
This PR adds "${FNAME_DATE}" as it has been in 3.3dev when creating this backport.
Starting with a few simple patterns, like for checking for non-variables at left hand side like [[ LHS == $value ]]. The file is supposed be amended in the future.
This fixes#3074 for 3.2
This fixes#3003 for 3.2 .
The conversion to proper UTF-8 should have taken place by just using -nameopt RFC2253, see manpage openssl-namedisplay-options(1ssl).
As @dcooper16 suggested removing esc_msb should help. This may look counterintuitive but works.
The trailing error messages were swapped in the paragraphs / description for MAX_SOCKET_FAIL + MAX_OSSL_FAIL .
This fixes the confusion for 3.2 , see #3028 .
When checking early for date flavors, there might be an edge case when a directory with a referred file (for the date command) isn't readable which might cause testssl.sh not to detect the date flavor correctly.
This fixes that (#3009) by cd'ing to / in a subshell which should be cd'able and readable under every platform.
The commit 6753a95c939359f9e06fb9f3dd199a0 changed some variables however for consistency
MAX_WAITSOCK should have been completely changed to ROBOT_TIMEOUT .
This PR suggests that. Moreover it changes the local variable robottimeout to robot_timeout.
This fixes#2983 for 3.2 .
As reported a longer while back in #2083 there were trailing bytes when receiving a TLS alert by the ROBOT check.
This PR corrects and thus normalizes the length of the TLS alert message to the correct value, supposed the length in the TLS alert is two bytes and it is an TLS alert. PR for 3.3dev was #2969 .
Also this PR now uses a separate variable for the timeout. Using a separate global variable may offer some possibility for tuning the check when the latency to the target is high. This is still subject of research.
The variable is 10 seconds here to be in line with MAX_WAITSOCK which (name) was used previously.
We missed somehow to add in the big while loop to add the fact that ROBOT is a vulnerability which became
apparent with #2967 (3.3dev).
This PR adds that for 3.2 also. See #2968.
`grep -w` matches also `string1-whatsoever` so that entries like
```
192.168.0.10 anystring anystring-apache
192.168.0.11 anystring-tomcat
```
matched 3 entries over 2 lines.
This PR fixes#2937 for 3.2 by improving the pattern, so that `string1` needs a trailing whitespace or an EOL -- besides a leading whitespace..
The new block making sure that rust coreutils work properly (PR #2913)
introduced a new check in order to determine which date functions
to use.
The function however parsed only for English error messages ("No such file").
This PR fixes#2929 that for 3.2 by setting LC_ALL to C.
Ubuntu 25.10 has transitionned from GNU Core-utils to Rust Core-utils. That changes the testing
results which date version to use for displaying / conversion of dates like in certificates.
Probably more Linux distriutions will follow. See also #2909 .
For maintenance reasons it is advised also the stable version will get this patched. For
3.3dev, see #2913 .
This PR ist similar to #2905 for 3.3dev . However for the stable brnach it's
important to note that this is a breaking change as it modifies the output.
That happens only tough when `ciphers_by_strength()` is being used --equivalent
to the command line `./testssl.sh -E` = `./testssl.sh --cipher-per-proto`. As
this is seldom used and was basically succeeded by `-P, --server-preference`
this looks acceptable as it provides consistency which was overdue.
Details:
* keys now always with `v`, like `supportedciphers_TLSv1_2` and also ciphers
(e.g. `TLSv1.2 x35 AES256-SHA`)
* add word "server" to file output so that it reads "NOT a server cipher order configured"
Fixes#2884 for 3.2 .
... to avoid repeated failures because of heise.de . Looks like there are
server side measures which made some tests fail. Often the MacOS CI runner
is slower and seems to run into that.
See also 56c1e585