Dirk Wetter and GitHub
3bf31e2f87
Merge pull request #2802 from testssl/update_clientsim_3.0
...
Update client simulation 3.0
2025-06-14 17:35:35 +02:00
Dirk
5e23dae8c7
Update client simulation
...
from 3.2 .
2025-06-14 16:43:49 +02:00
Dirk Wetter and GitHub
cdbeb91765
Merge pull request #2800 from testssl/update_CAstores_3.0
...
Update CA hashes for 3.0
2025-06-14 16:09:06 +02:00
Dirk
adb611ca2c
Update certificate store for 3.0
2025-06-14 15:15:12 +02:00
Dirk Wetter and GitHub
7bdc26cdd5
Merge pull request #2791 from testssl/FixServerHeaderParser_3.0
...
Fix parser for server header (3.0)
2025-06-10 23:18:50 +02:00
Dirk Wetter
e9b06335e1
Fix parser for server header (3.0)
...
Do word matching and exclude minus sign
This fixes #2787 for 3.0.
2025-06-10 22:05:29 +02:00
Dirk Wetter and GitHub
f5da039c86
Merge pull request #2781 from testssl/ccsInjectionFix_3.0
...
Fix CCS injection
2025-05-21 15:08:45 +02:00
Dirk
04e174b3af
Fix CCS injection
...
The rhs of the pattern was off by one byte and it worked in practise until recent PR #2658 .
This fixes #2691 for 3.0 .
2025-05-21 13:58:13 +02:00
Dirk Wetter and GitHub
4beed531be
Merge pull request #2741 from testssl/update_CAs_3.0
...
Update CA stores (3.0)
2025-04-18 13:29:48 +02:00
Dirk
4a9cee0717
Update CA stores (3.0)
...
This is tha same update as #2740 (for 3.2).
Despite using ``./utils/create_ca_hashes.sh`` git claims ``ca_hashes.txt`` hasn't changed here too.
This fixes #2739 .
2025-04-18 13:25:46 +02:00
Dirk Wetter and GitHub
84c1cdca1b
Clarify GHCR
2025-04-06 20:31:21 +02:00
Dirk Wetter and GitHub
56908d3a94
Merge pull request #2730 from testssl/ghcr.io-doc-3.0
...
Add minimal doc for GHCR
2025-04-06 18:38:13 +02:00
Dirk Wetter
ab15338dfc
Add minimal doc for GHCR
2025-04-06 18:37:04 +02:00
Dirk Wetter and GitHub
e101be3ff2
Merge pull request #2717 from dcooper16/has_sigalgs
...
Check for -sigalgs support
2025-03-24 11:52:21 +01:00
Dirk Wetter and GitHub
6a4a96c342
Merge pull request #2715 from testssl/sanitze_better_http_header.3.0
...
Remove inherited double line
2025-03-20 14:23:00 +01:00
Dirk Wetter
8063982891
fix typo
2025-03-20 13:28:31 +01:00
Dirk Wetter
c825a70eeb
Remove inherited double line
...
.. and update the comment
2025-03-20 13:22:55 +01:00
Dirk Wetter and GitHub
cbe896d685
Merge pull request #2713 from testssl/sanitze_better_http_header.3.0
...
Sanitze HTTP header early and better
2025-03-20 12:10:15 +01:00
Dirk Wetter and GitHub
5a320df081
Merge pull request #2711 from testssl/fix_2708_TLS_FALLBACK_SCSV_3.0
...
Set POODLE var when exiting run_ssl_poodle()
2025-03-20 12:09:19 +01:00
Dirk Wetter
520604df2e
Sanitze HTTP header early and better
...
On MacOS run_http_header() hiccuped when in any place of the web site unprintable chars were
returned, see https://github.com/testssl/testssl.sh/issues/2708#issuecomment-2738347784 .
This PR fixes that by moving the sanitization to a separate function and run it earlier before
any processing of the returned content (header plus body) takes place.
Output was:
``
'HTTP Status Code awk: towc: multibyte conversion failure on: '� disabilitato");
input record number 36, file /tmp/testssl.FHu8E0/AAA.BBB.CCC.DDD.http_header.txt
source line number 1
'wk: towc: multibyte conversion failure on: '� disabilitato");
input record number 36, file /tmp/testssl.FHu8E0/AAA.BBB.CCC.DDD.http_header.txt
source line number 1
200 OK
``
2025-03-20 11:19:29 +01:00
Dirk Wetter
95d39fdeab
Set POODLE var when exiting run_ssl_poodle()
...
... so that run_tls_fallback_scsv() doesn't exit with a warning.
This fixes #2708 .
This is for 3.0 . For 3.2 see #2710
2025-03-19 23:45:28 +01:00
Dirk Wetter and GitHub
8e555768fb
Merge pull request #2704 from dcooper16/ocsp_check_rev_ossl_ver_30
...
OpenSSL version check in check_revocation_ocsp()
2025-03-18 17:40:12 +01:00
Dirk Wetter and GitHub
dd188c1daf
Merge pull request #2699 from testssl/fixDockerOcspCall_3.0
...
Fix --phone-out + ocsp, also in docker container (3.0)
2025-03-15 21:39:24 +01:00
Dirk
3485606bc0
Fix --phone-out + ocsp, also in docker container (3.0)
...
Previously in 4f1a91f92e there was a
double header sent to the server to check whether the certificate
was revoked.
This corrects the problem.
2025-03-15 17:20:14 +01:00
Dirk Wetter and GitHub
7937c0b845
Merge pull request #2696 from testssl/fix_segfault_error4-3.0
...
Fix segfault with error 4 in check_revocation_ocsp() when using --phone-out (3.0)
2025-03-14 19:19:16 +01:00
Dirk
8d019855a3
Fix segfault with error 4 in check_revocation_ocsp() when using --phone-out (3.0)
...
As `--phone-out` sometimes doesn't work with our binary we switch transparently/automagically
to the vendor support openssl binary -- if available. This is the PR for 3.0, for 3.2 see #2695 .
This fixes at least #2516 where the issue has been explained/debugged in detail.
See also #2667 and #1275 .
2025-03-14 17:15:40 +01:00
Dirk Wetter and GitHub
ab0b829d36
Merge pull request #2668 from krufab/fix/fix-typo-in-help-message
...
Corrected typo in help message
2025-02-23 14:29:45 +01:00
Dirk Wetter and GitHub
d2550395a7
Merge pull request #2663 from dcooper16/fix_ossl_supported_curve_check_30
...
Fix check for OpenSSL supported curves
2025-02-20 11:31:45 +01:00
Dirk Wetter and GitHub
94b590f0af
Merge pull request #2658 from dcooper16/fix_pattern_match_30
...
Fix pattern matches
2025-02-15 14:15:32 +01:00
Dirk Wetter and GitHub
c49d9f67fa
Merge pull request #2654 from testssl/drwetter-patch-1
...
Update workflows to Ubuntu 24.04
2025-02-12 16:22:28 +01:00
Dirk Wetter and GitHub
65200f4a7e
Update test.yml
2025-02-12 16:21:33 +01:00
Dirk Wetter and GitHub
bd88c844db
Update docker-3.0.yml
2025-02-12 16:21:04 +01:00
Dirk Wetter and GitHub
7174521b3d
Update test.yml to Ububutu 22.04
...
Warning from Github that this will be out of service in April 1st.
2025-02-12 16:17:23 +01:00
Dirk Wetter and GitHub
01dd7a4bd4
Merge pull request #2651 from testssl/readme_update_3.0
...
Update Readme drwetter --> testssl
2025-02-07 12:29:36 +01:00
Dirk Wetter and GitHub
5d2d9f2c00
Merge pull request #2652 from testssl/address_addCA_issue_3.0
...
Address CA file parsing problem
2025-02-07 12:28:47 +01:00
Dirk Wetter
b0c026ecc3
Address CA file parsing problem
...
.... by forbidding spaces in supplied CA files/directories
Also now we're sanitizing the cmd line parameter better `using safe_echo()`
See also #2647 .
2025-02-07 11:23:13 +01:00
Dirk Wetter
305ce18931
Update Readme drwetter --> testssl
...
and some links in testssl.sh
2025-02-07 10:58:41 +01:00
Dirk Wetter and GitHub
e69a29ca0c
Merge pull request #2637 from testssl/fix_2633_3.0
...
Fix bug when legacy NPN is tested against a TLS 1.3 host
2025-01-24 20:40:05 +01:00
Dirk
7597360775
fix typo
2025-01-24 19:38:44 +01:00
Dirk
f321bcf1ed
Fix bug when legacy NPN is tested against a TLS 1.3 host (3.0)
...
When testing a TLS 1.3 host s_client_options used TLS 1.3 ciphers to test for NPN. As that is not implemented we nee dto make sure any other version is used.
This PR ensures that --after testing whether it's a TLS 1.3-only host where this test doesn't make any sense in the first place.
Fix for #2633
2025-01-24 19:38:02 +01:00
Dirk Wetter and GitHub
439937feb9
Merge pull request #2630 from testssl/fix_roundbracket_in_header
...
Fix place for round bracket for header and remove obsolete comment
2025-01-23 12:43:55 +01:00
Dirk Wetter
7a6efd9483
Remove +-sign from c&p'ed diff
2025-01-23 11:32:53 +01:00
Dirk Wetter
c482df82bd
Fix place for round bracket and remove obsolete header
...
This was done in 3.2 previously, see commit 4efe324ef7 .
As everything was sanitized, the comment was removed.
2025-01-23 10:51:55 +01:00
Dirk Wetter and GitHub
b1f279f6af
Merge pull request #2627 from dcooper16/fix_x25519_and_x448_check_30
...
Fix checks for whether X25519 and X448 are supported
2025-01-22 17:49:26 +01:00
Dirk Wetter and GitHub
b4274e8d65
Merge pull request #2603 from dcooper16/fix2599_30
...
Fix #2599
2024-11-27 11:36:22 +01:00
Dirk Wetter and GitHub
6570c20798
Merge pull request #2581 from drwetter/fix_2575-3.0
...
Fix json/csv output when STARTTLS problem is passed back (3.0)
2024-10-14 17:06:41 +02:00
Dirk
c2ed4d55da
Fix json/csv output when STARTTLS problem is passed back (3.0)
...
In rare cases testssl.sh writes to the terminal output "likely not offered" but misses the "likely" in the json/csv output.
This fixes #2575 for the 3.0 branch by adding that word and amending the return value 4 with a comment.
2024-10-14 16:26:23 +02:00
Dirk Wetter and GitHub
d248451340
Merge pull request #2578 from drwetter/fix_f5_short_rfc1918.3.0
...
Fix F5 cookie in 10.x.x.x. (3.0)
2024-10-13 10:50:19 +02:00
Dirk Wetter
968e5509ad
Fix F5 cookie in 10.x.x.x. (3.0)
...
The F5 cookie decoder doesn't detect IPs in the 10.x.x.x space for non-encrypted cookies. This fixes the regex pattern, see also
https://github.com/drwetter/F5-BIGIP-Decoder/pull/4 and https://github.com/drwetter/testssl.sh/pull/2577
2024-10-12 21:06:21 +02:00
Dirk Wetter and GitHub
eee26817c5
Merge pull request #2560 from drwetter/fix_docker_3.0
...
Fix the Dockerfile (3.0) env (hopefully)
2024-09-05 17:59:26 +02:00
Dirk
73fa5607d8
restrict CI run to pull
2024-09-05 17:55:44 +02:00
Dirk
cebb52f698
Fix the Dockerfile env (hopefully)
...
* Upgrade both GHCR and Docker hub foile to alpine 3.2
* uses openssl version 3.3 as a alternative to option (default is still "ours"
* docker 3.0 yml hast now ubuntu-22.04 (not EOL) + "latest" omitted
2024-09-05 17:44:33 +02:00
Dirk Wetter and GitHub
1296279fa9
Merge pull request #2554 from drwetter/noCtrlCharInHeader_3.0
...
No ctrl char in header (3.0)
2024-09-03 20:50:00 +02:00
Dirk
27f996d99f
Remove crtl chars from HTTP header (3.0)
...
... which fixes #2337
2024-09-03 19:33:09 +02:00
Dirk Wetter and GitHub
6ce7b643ed
Merge pull request #2550 from drwetter/banner_3.0
...
Improve banner (3.0)
2024-09-03 19:13:36 +02:00
Dirk
196cd53dd5
Fix CI
2024-09-03 18:25:32 +02:00
Dirk
ac81c182b1
Fix CI
2024-09-03 18:24:51 +02:00
Dirk
52374e552e
handle spell errors
2024-09-03 15:27:42 +02:00
Dirk
44a60ff80b
Improve banner (3.0)
...
... for readablity and bugs to be filed (see #2506 )
This PR defines a short string for the OpenSSL banner as some suppliers have
makde them (unnecessarily) long so that it won't fit in the banner.
The banner also now omits the built line nad bash version when scanning
as for the user it is normally not important.
2024-09-03 15:17:23 +02:00
Dirk Wetter and GitHub
6d714d6b99
Merge pull request #2546 from drwetter/fix_2542_3.0
...
fix typo
2024-08-26 10:44:30 +02:00
Dirk Wetter
69d3cff51c
fix typo
2024-08-26 10:42:34 +02:00
Dirk Wetter and GitHub
7db944e584
Merge pull request #2536 from drwetter/update_CAstores-3.0
...
Update Truststores (3.0)
2024-07-24 09:28:39 +02:00
Dirk
887f21609a
Update Truststores (3.0)
...
Same as #2528 , only for the 3.0 branch.
- Mozilla: 2024-7-02
- Debian 12, ca-certificates from 20230311
- JDK 21.04
- Apple via https://github.com/apple-oss-distributions/security_certificates (according to git log latest change Fri Dec 15 00:44:35 2023)
- Microsoft via CertUtil (date of this PR)
Modified Readme to reflect that the Apple CA certificates are better to retrieve from GH and clarified minor things.
This also fixes #2525 (for 3.0), where >=2 certificates were missing.
2024-07-23 12:20:09 +02:00
Dirk Wetter and GitHub
08a430e01a
Merge pull request #2531 from drwetter/fix_ipv6_ula_and_more-3.0
...
Fix IPv6 addresses (3.0)
2024-07-22 23:31:55 +02:00
Dirk
33993d4174
Fix IPv6 addresses (3.0)
...
Local and ULA and other IPv6 adresses were incorrectly filtered by ``awk '/^[0-9]/ { print $1 }'`` which searches in the first term for numeric values only.
This PR adds a-f and fixes #2529 for the 3.0 branch.
2024-07-22 21:17:16 +02:00
Dirk Wetter and GitHub
4f9bfbc47c
Merge pull request #2508 from drwetter/make_rel3.0
...
Prepare for release 3.0
2024-06-13 18:32:28 +02:00
Dirk
3cb2371744
Make ready for release
...
* bump version
* modify banner and issue template to address #2506
Needed to modify the banner a bit for space reasons. Looks catchier
though.
2024-06-13 17:28:46 +02:00
Dirk Wetter and GitHub
05fb5f97bf
Merge pull request #2507 from drwetter/codespell_2502
...
Fix spelling issues in #2503
2024-06-13 15:39:17 +02:00
Dirk
54d1784203
add file, previously forgotten
2024-06-13 15:21:13 +02:00
Dirk
3beeedcaf0
Fix spelling issues in #2502
2024-06-13 15:19:10 +02:00
Dirk Wetter and GitHub
9c2bfff1bf
Merge pull request #2505 from dcooper16/fix2502_30
...
Fix #2502 in 3.0 branch
2024-06-13 15:12:57 +02:00
Dirk Wetter and GitHub
212bdbb78e
Merge pull request #2485 from drwetter/fix_CAARRquery_noDNS_30
...
Fix CAA query when nodns set
2024-05-26 17:40:10 +02:00
Dirk
83059ca5ee
Fixes DNS CAA query when no query option set
2024-03-30 17:33:55 +01:00
Dirk Wetter and GitHub
30c0359bdd
Merge pull request #2471 from Tazmaniac/mongodb-detection-fix-backport
...
MongoDB identification fix
2024-02-13 18:42:33 +01:00
Dirk Wetter and GitHub
208efdc68a
Merge pull request #2452 from drwetter/update_hashes_3.0
...
Update hashes for HPKP
2023-12-24 15:33:28 +01:00
Dirk
0de86283e9
Update hashes for HPKP
2023-12-24 13:57:48 +01:00
Dirk Wetter and GitHub
0de609da8c
Merge pull request #2451 from drwetter/fix_stupid_umaskerror_3.0
...
Bail out if user error bc of umask (3.0 branch)
2023-12-24 11:12:29 +01:00
Dirk Wetter
02220d2fc4
Bail out if user error bc of umask (3.0 branch)
...
Implemnation for 3.0, 3.2 see #2450
If a user chose a broken umask testssl.sh will start but emits subsequent errors.
This patch adds two sanity checks whether it is allowed to create and read files in the temp directory.
Fixes #2449
2023-12-24 10:21:11 +01:00
Dirk Wetter and GitHub
68dec54cc5
Merge pull request #2435 from drwetter/fix_2431_grepProb
...
Amend fix for newer grep versions
2023-10-30 20:29:59 +01:00
Dirk
a0c0c73b66
Amend fix for newer grep versions
...
See also PR #2243 , issue #2241
Removes unneeded escape for exclamation mark. This is for 3.0.
3.2 has the fix already.
2023-10-30 19:07:06 +01:00
Dirk Wetter and GitHub
40c6be790b
Merge pull request #2434 from drwetter/fix_2429_3.0
...
Fix weird bash globbing (3.0)
2023-10-30 17:53:19 +01:00
Dirk
41c697f232
put the redirection in the right spot
2023-10-30 15:25:38 +01:00
Dirk
775ed60437
Fix weird bash globbing (3.0)
...
What was problematic was the error message when the certificate stores were missing. This fixes it by redirecting the error message to /dev/null so that if the sub function detects the missing file it returns with an error by the program and not by executing "basename"
As for 3.2 this is for the 3.0 branch.
2023-10-30 15:20:37 +01:00
Dirk Wetter and GitHub
7df05511da
Merge pull request #2426 from drwetter/drwetter-patch-2
...
Sync GHCR with Dockerfile
2023-10-30 14:41:12 +01:00
Dirk Wetter and GitHub
382c1530cb
Sync GHCR with Dockerfile
2023-10-13 17:38:09 +02:00
Dirk Wetter and GitHub
3eb3994d39
Merge pull request #2421 from drwetter/alpine_3.18
...
Update Dockerfile to Alpine 3.18
2023-10-13 10:43:56 +02:00
Dirk Wetter and GitHub
cd6659c7ad
Update Dockerfile to Alpine 3.18
...
for an extension of life time:
https://endoflife.date/alpine
2023-10-12 09:59:25 +02:00
Dirk Wetter and GitHub
ece9447ac4
Merge pull request #2412 from drwetter/fix_extended_regexp3.0
...
Fix regexp in STARTTLS detection
2023-10-07 17:21:25 +02:00
Dirk
c09e1587b7
fix spell errors
2023-10-07 15:15:04 +02:00
Dirk
c31b9492ce
Fix regexp in STARTTLS detection
...
see also #2411 , kudo to Geert!
2023-10-07 15:06:36 +02:00
Dirk Wetter and GitHub
e9cd8c3afd
Merge pull request #2391 from Tazmaniac/Renego-backport-patch
...
Backport pull request #2360 to fix #2389
2023-09-08 19:20:38 +02:00
Dirk Wetter and GitHub
5cb30aa510
Merge pull request #2342 from drwetter/openssl_link_docker_3.0
...
make openssl 1.1 available via /usr/bin/openssl
2023-03-20 14:29:14 +01:00
Dirk
f65b81837c
make openssl 1.1 available via /usr/bin/openssl
2023-03-20 14:19:35 +01:00
Dirk Wetter and GitHub
4c54464ab8
Merge pull request #2341 from drwetter/fix_nss_dns_3.0
...
Modify Dockerfile.git also, amending #2340
2023-03-20 13:42:59 +01:00
Dirk Wetter
bf88b8b443
Modify Dockerfile.git also, amending #2340
2023-03-19 22:57:58 +01:00
Dirk Wetter and GitHub
6454f656db
Merge pull request #2340 from drwetter/fix_nss_dns_3.0
...
Add openssl, offer to query OCSP responder (3.0)
2023-03-19 22:52:33 +01:00
Dirk Wetter
8759ac61af
Add openssl, offer to query OCSP responder
...
This PR includes two tweaks:
* it helps avoiding the bug querying OCSP responder #2329 by adding
openssl. The openssl supplied has a mimor DNS lookup problem due
to glibc / musl libc compatibilty issues
* by adding openssl also it helps a bit for some performance problems
related to other projects, see #2314
Also the git binary is removed (#2315 ).
Thanks to @polarathene for the discussions
2023-03-19 22:41:17 +01:00
Dirk Wetter and GitHub
30022ea697
Merge pull request #2339 from drwetter/CAstores_update_3.0
...
Update CA root stores
2023-03-19 22:27:36 +01:00
Dirk Wetter
ad44f7d53e
Update CA root stores
2023-03-18 22:57:52 +01:00
Dirk Wetter and GitHub
e9c0beb3f7
Merge pull request #2335 from drwetter/sanitize_fileout_3.0
...
Backport: Make sure control chars from HTTP header don't end up in …
2023-03-12 18:19:09 +01:00