Dirk Wetter and GitHub
7c85b44a9f
Merge pull request #1482 from dcooper16/shellcheck_SC2178
...
Suppress shellcheck issue SC2178
2020-01-31 09:23:06 +01:00
Dirk Wetter and GitHub
e8b7a04e53
Merge pull request #1487 from simondeziel/dup-cipher
...
Remove (harmless) AESGCM dup in the strong ciphers list
2020-01-31 09:22:03 +01:00
Dirk Wetter and GitHub
2f54613d6d
Merge pull request #1484 from dcooper16/tls13_post_handshake
...
TLS 1.3 post-handshake messages
2020-01-31 08:55:08 +01:00
Dirk Wetter and GitHub
7443a532cf
Merge pull request #1486 from drwetter/fix_ids_friendly
...
Fix --ids-friendly
2020-01-31 08:48:01 +01:00
Dirk Wetter and GitHub
89fd902b18
Merge pull request #1483 from dcooper16/minor_code_cleanup
...
Minor code cleanup
2020-01-31 08:41:43 +01:00
Dirk Wetter
c4920f61e4
rename query_globals() --> count_do_variables()
...
.. and fix one problem instroduced with last patch (testssl.sh
din't work correclty if only an URI was supplied)
2020-01-30 22:25:10 +01:00
Dirk Wetter
073d383f76
Fix switch --ids-friendly
...
This switch had no effect. There was probably a regression
problem as it worked before.
Besides fixing that the large case statement in parse_cmd_line()
was simplified, in a sense that banner and help functions were
moved to a separate case statement.
2020-01-30 21:49:56 +01:00
Dirk Wetter and GitHub
3a73a97b67
Merge pull request #1480 from drwetter/readme-patch1
...
Status update / mir rephrasing of key features
2020-01-30 18:14:43 +01:00
Dirk Wetter and GitHub
16907cf77e
Status update / mir rephrasing of key features
2020-01-30 18:14:20 +01:00
Dirk Wetter and GitHub
ef21f3f9bf
Merge pull request #1476 from dcooper16/tls13_finished_messages
...
TLS 1.3 Finished messages
2020-01-30 10:26:27 +01:00
Dirk Wetter and GitHub
5e9767a17c
Merge pull request #1477 from dcooper16/faster_gcm
...
Speedup AES-GCM
2020-01-30 10:22:02 +01:00
Dirk Wetter and GitHub
3da67437f3
Merge pull request #1475 from dcooper16/reorganize_key_derivation
...
Reorganize TLS 1.3 key derivation
2020-01-27 21:52:24 +01:00
Dirk Wetter and GitHub
c3bab98b92
Merge pull request #1474 from drwetter/backport_4b573dd
...
Suppress displaying an error in maketempf()
2020-01-26 01:30:58 +01:00
Dirk
c63547ca7b
Suppress displaying an error in maketempf()
2020-01-26 01:29:18 +01:00
Dirk
4b573dd833
Suppress displaying an error in maketempf()
2020-01-26 01:24:11 +01:00
Dirk Wetter and GitHub
51ca429b48
Merge pull request #1473 from dcooper16/aead
...
Full AEAD cipher implementations
2020-01-25 12:37:28 +01:00
Dirk Wetter and GitHub
1ad7a65adf
Merge pull request #1472 from drwetter/reorder
...
Reorder functions and some variables
2020-01-24 14:46:18 +01:00
Dirk Wetter
d44a643fab
Reorder functions and some variables
...
For a fresh start it seemed a good idea to cleanup
the order of functions and some variables so that
those with the same functionality are somewhat grouped.
Some of the functions have now a header and a foooter
to make it easier to spot and use then. Also for added future
functions the hope is that they will be put where they better
fit
2020-01-24 13:58:05 +01:00
Dirk
67598e824f
Start next release
2020-01-23 22:24:33 +01:00
Dirk Wetter and GitHub
b0b084dcda
Merge pull request #1442 from drwetter/bump_version
...
bump version to final
2020-01-23 18:08:23 +01:00
Dirk Wetter and GitHub
a11a060acb
Merge pull request #1456 from drwetter/changes_etc
...
Update attributions and changes for release
2020-01-23 18:05:50 +01:00
Dirk Wetter and GitHub
a9e5bcc30c
Merge pull request #1470 from drwetter/1xmsg_squash
...
Squash the last futile -msg for $OPENSSL
2020-01-23 11:03:46 +01:00
Dirk
ace4098693
Squash the last futile -msg for $OPENSSL
...
... see also https://github.com/drwetter/testssl.sh/pull/1468#discussion_r369786007
2020-01-23 09:46:33 +01:00
Dirk Wetter and GitHub
631755ceb1
Merge pull request #1464 from drwetter/further_handshakes
...
Further handshakes / minor changes
2020-01-22 22:30:16 +01:00
Dirk Wetter and GitHub
fa4f1e4366
Merge pull request #1468 from nosnilmot/fix-xmpp-starttls
...
Fix XMPP starttls
2020-01-22 21:09:51 +01:00
Dirk
5083e950d2
Move debugging remainders detection to t/00_testssl_help.t
2020-01-22 21:04:23 +01:00
Dirk Wetter and GitHub
ec722e0e9c
Merge pull request #1469 from dcooper16/simplify_draft_tls13_version_determination
...
Simplify code to determine draft TLS 1.3 version
2020-01-22 20:39:10 +01:00
Dirk Wetter and GitHub
f7ab5a0821
Move quotes...
...
as David suggested.
2020-01-22 20:34:00 +01:00
Dirk Wetter and GitHub
7619e430f2
Merge pull request #1466 from dcooper16/fix_run_ssl_poodle
...
Fix run_ssl_poodle()
2020-01-22 18:05:08 +01:00
Dirk Wetter and GitHub
2602e14191
Merge pull request #1465 from dcooper16/undo_copy_paste_error
...
Undo copy and paste error
2020-01-22 17:25:33 +01:00
Dirk Wetter and GitHub
2181061c6e
Merge pull request #1463 from drwetter/shortcurt_vulns
...
Shortcuts for vulnerability tests for TLS 1.3 only servers
2020-01-22 15:37:11 +01:00
Dirk Wetter
eeb1acd749
Android 9 still has 2 signature hash algos: x0201 + x0203
2020-01-22 11:41:42 +01:00
Dirk
d4d5a61a0b
Hopefully make Travis shut up now
...
picked a TLS 1.2 host
2020-01-22 11:30:21 +01:00
Dirk
cae052cfab
Address some HTML check failures in travis
...
(shouldn't work too late)
2020-01-22 11:29:04 +01:00
Dirk Wetter
7c66ed47c0
All self retrieved Android handshakes modified to service ANY
2020-01-22 10:58:00 +01:00
Dirk Wetter
a50a660d6c
Add Android 10 client simulation
2020-01-22 10:54:50 +01:00
Dirk Wetter
ca8054184b
remove also leading colon in helper script bc of GREASE
2020-01-22 10:52:07 +01:00
Dirk
39abb27dd9
cloudflare seems not good for html travis checks
2020-01-22 00:28:59 +01:00
Dirk
80530aa34c
remove fast as it makes problems especially with Travis+testssl.net
2020-01-21 23:53:52 +01:00
Dirk
e0f8c8d43e
Relax misunderstanding of DEBUG statemement
...
There's a check for >825 days certificate lifetime. That
check emits a debug statement when the lifetime is within
this limit. It does that also when the certificate expired.
This commit adds now the word "total"
DEBUG: all is fine with total certificate life time
to make sure the life time left not is what should be understood.
2020-01-21 22:47:53 +01:00
Dirk
26a8f23ec1
Shutup Travis
...
... by adding the formerly intruoced "DEBUG" statement as a filter.
Note: "DEBUG" can now / should now be taken preferably for extra
output on debug level 1.
Replacing badssl.com by testssl.net. The former needed almost 5 min
for a run, whereas one IP of testssl.net needs ~80 secs. With --fast
even less.
2020-01-21 22:41:50 +01:00
Dirk
952231dd94
Shortcuts for vulnerability tests
...
Several vulnerability checks add a time penalty when the server
side only support TLS 1.3 as The TLS 1.3 RFC 8446 and implementations
known so far don't support the flaws being checked for.
This PR adds "shortcut" checks for all TLS 1.3, assuming that the
TLS 1.3 implementation is correct which seems at this time a valid
assumpution. That either saves a TCP connect or at least some logic to
be executed. Also in some cases a TLS 1.3 only server emitted unnecessary
warnings, see #1444 .
If $DEBUG -eq 1 then it outputs information that a shortcut was
used. It doesn't do that in other cases because the screen output
seems too obtrusive.
It also adds a shortcut for beast when SSL 3 or TLS 1.0 is is known
not to be supported.
This commit radds 747fb039ed which
was accidenially reverted in 45f28d8166 .
It fixes #1462 .
See also #1459 .
2020-01-20 21:37:02 +01:00
Dirk
431f4fbe5f
last walk through the changelog
2020-01-20 12:50:31 +01:00
Dirk
3e8d1983b3
reorder / rephrase some points
2020-01-20 12:49:49 +01:00
Dirk Wetter and GitHub
c08250d1bb
Merge pull request #1461 from drwetter/ci_setx
...
add check for forgotten "set -x" + provide defined start conditions
2020-01-20 12:20:07 +01:00
Dirk
45f28d8166
Revert "Shortcuts for TLS13 only servers in renegotiation checks"
...
This reverts commit 747fb039ed .
2020-01-18 21:55:35 +01:00
Dirk
44d1139e99
Revert "Complete shortcut checks (Renegotiation and CRIME)"
...
This reverts commit 8c24d1a6f2 .
2020-01-18 21:54:42 +01:00
Dirk
f109d3bbd6
add unlink / start with a clean state
...
... good when running "prove -v" locally and previously
the run was interrrupted by e.g. ^C
2020-01-18 21:47:44 +01:00
Dirk
cb6677e2d3
removed comment
2020-01-18 21:45:32 +01:00
Dirk
bec9ebdda8
only one ip
2020-01-18 21:44:24 +01:00
Dirk
2563dfb5e5
add set -x
2020-01-18 21:36:19 +01:00
Dirk
8c24d1a6f2
Complete shortcut checks (Renegotiation and CRIME)
...
This also makes a short exit when the server side
supports TLS 1.3 only as this protocol doesn't support
TLS renegotiation or compression.
Also it fixes the logic flaw from the previous
commit that "-no_tls1_3" has to be supplied.
Furthermore, it unifies the output presented to the user.
2020-01-18 12:31:38 +01:00
Dirk Wetter and GitHub
155824214b
Merge pull request #1460 from drwetter/drwetter-patch-1
...
add also here -z
2020-01-17 15:26:09 +01:00
Dirk Wetter and GitHub
adfa411e24
add also here -z
2020-01-17 15:24:36 +01:00
Dirk
747fb039ed
Shortcuts for TLS13 only servers in renegotiation checks
...
As noted in #1444 a few vulnerability checks don't make sense
or aren't working. This commit addresses the renegotiation checks.
Also a few redundant quotes in parse_tls_serverhello() and
run_crime() were removed.
2020-01-17 15:16:26 +01:00
Dirk Wetter and GitHub
71b6305e00
Merge pull request #1458 from drwetter/drwetter-patch-2
...
fix language
2020-01-17 11:59:50 +01:00
Dirk Wetter and GitHub
ddc7a56ab0
fix language
2020-01-17 11:59:41 +01:00
Dirk Wetter and GitHub
a094ebc981
Merge pull request #1457 from drwetter/drwetter-patch-2
...
fix missing -z
2020-01-17 11:57:36 +01:00
Dirk Wetter and GitHub
1fb2db02a7
Update docker-debian10.tls13only.start.sh
2020-01-17 11:57:13 +01:00
Dirk
2ea57f0701
Update attributions and Changes for release
...
If anything is missing or wrong please let us know or do a PR.
(This is until from earlier time to ~2018. >2019 need to follow)
2020-01-17 11:01:41 +01:00
Dirk Wetter and GitHub
03fb04a9f9
Merge pull request #1455 from drwetter/drwetter-patch-1
...
Warning for handshake retrieved by Google apps
2020-01-16 22:48:07 +01:00
Dirk Wetter and GitHub
ac7a20f018
Update client-simulation.wiresharked.md
2020-01-16 22:46:43 +01:00
Dirk Wetter and GitHub
86afeabf8f
Merge pull request #1438 from drwetter/update_clienthandshakes
...
Update clienthandshakes
2020-01-16 22:26:21 +01:00
Dirk Wetter and GitHub
c2060c08f3
Merge pull request #1454 from dcooper16/basic_auth_polishing
...
More polishing of http basic auth
2020-01-16 20:24:39 +01:00
Dirk Wetter and GitHub
91e14a3840
Merge pull request #1452 from drwetter/add_1451
...
Last fine tuning for http basic auth
2020-01-16 16:34:09 +01:00
Dirk Wetter and GitHub
0691dc1bf8
Merge pull request #1453 from mkauschi/add-cache-control-header-check
...
Check for the Cache-Control and Pragma header
2020-01-16 16:25:18 +01:00
Dirk Wetter
4603d924be
Last fine tuning for http basic auth
...
* create roff file and HTML
* add hint to $ENV
Avoid 1x subshell
See #1451 .
2020-01-16 14:29:53 +01:00
Dirk Wetter and GitHub
700a727f3f
Merge pull request #1451 from mkauschi/http-basic-auth-support
...
Add support for HTTP Basic Auth
2020-01-16 14:13:59 +01:00
Dirk Wetter and GitHub
787e575085
Merge pull request #1450 from drwetter/826days_towarn
...
Add one second for 825 day validity test
2020-01-15 15:38:26 +01:00
Dirk Wetter
38a00f7170
Add one second for 825 day validity test
...
The CA browser form agreed on a validity period of 825 days or less
(https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-1.5.3-redlined.pdf ,
p4).
PR #1427 addressed that. However when an issuer signed/issued a certificate
with exactly 825 days, the check reported incorrectly that the life time
is too long.
This commit addressed that by adding a second to the calulation. Also the
output takes into account that it must be over ('>') 825 days, not '>='.
2020-01-15 15:32:32 +01:00
Dirk Wetter and GitHub
520a4fbf75
Merge pull request #1449 from drwetter/pr_1070
...
Reimplement mitigation check (renegotiation->node.js)
2020-01-15 13:09:39 +01:00
Dirk Wetter
2ed317441f
Reimplement mitigation check (renegotiation->node.js)
...
See #1070 , kudos @poupas.
In addition it checks whether the first result was positive (in
terms of a finding). If so it does 4 rounds and checks the
result. So that other servers won't be penalized with 4 seconds.
2020-01-15 12:11:57 +01:00
Dirk Wetter and GitHub
2a87f7505d
Merge pull request #1445 from drwetter/alternative_temppath
...
Try temp file creation in a different location
2020-01-15 09:59:12 +01:00
Dirk Wetter
50ea6b1891
$PWD check : negate pattern + add $BASH_REMATCH
2020-01-14 22:52:47 +01:00
Dirk Wetter
50c9075ba8
Provide whitelist for $PWD
...
see #1445
2020-01-14 20:41:08 +01:00
Dirk Wetter and GitHub
e75ed94573
Merge pull request #1446 from dcooper16/add_missing_declarations
...
Add missing variable declarations
2020-01-14 20:17:07 +01:00
Dirk Wetter
f0f8f3a318
Remove TEMPPATH, make sure PWD doesn't contain a blank
2020-01-14 20:09:46 +01:00
Dirk Wetter
8518284795
Try temp file creation in a different location
...
... if the standard directory /tmp is not allowed to write to.
As noted in #1273 this might be the case for Termux on Android.
2020-01-14 18:55:09 +01:00
Dirk Wetter
8d864aba2e
Output adjustments closer to a more common format
2020-01-14 18:44:11 +01:00
Dirk Wetter
13aa6aa433
Readd TLS 1.0 and TLS 1.1 to openssl 1.1.1d (Debian)
...
... see previous commit
2020-01-14 18:17:44 +01:00
Dirk Wetter
09eda2aa97
Update openssl handshakes
...
to 1.1.0l and 1.1.1d. Seems that for the latter TLS 1.0 and 1.1
are disabled now, looking at the supported version extension.
However on the command line an s_client connect works. So
this commit need to be amended.
2020-01-14 18:02:43 +01:00
Dirk Wetter and GitHub
6378371baa
Merge pull request #1443 from dcooper16/no_stdout
...
Don't write to /dev/stdout
2020-01-14 17:59:32 +01:00
Dirk Wetter
331b5cb750
Output changes
...
* add TLS_EMPTY_RENEGOTIATION_INFO_SCSV in screen output
* remove trailing ":" to be sure no one copies it, see also #1440
2020-01-14 17:38:02 +01:00
Dirk Wetter
58498583c9
Modified LFs
2020-01-13 23:50:14 +01:00
Dirk
ee11ea408e
bump version to final
2020-01-13 23:27:00 +01:00
Dirk Wetter
56e6fa4bb7
Remove FTP as a "service" from Firefox' client simulation
...
... as firefox never supported FTP over TLS or SSL, see
https://bugzilla.mozilla.org/show_bug.cgi?id=85464
In general browsers tend to remove noaways cleartext FTP from
browsers.
2020-01-13 23:11:59 +01:00
Dirk Wetter
89275f7ea9
Redefine numbering scheme
2020-01-13 23:00:10 +01:00
Dirk Wetter
8cc3a5f514
Add firefox 71
...
... and
* deprecate openssl 1.0.1
* enable Chrome 74 instead of Chrome 65
2020-01-13 22:57:10 +01:00
Dirk Wetter and GitHub
be5a258383
Merge pull request #1441 from dcooper16/fix_run_server_preference
...
Fix run_server_preference() in --ssl-native mode
2020-01-13 17:41:02 +01:00
Dirk Wetter
91f8f33a6c
add new basic checks, rename ca_hashes_up_to_date
2020-01-13 17:36:40 +01:00
Dirk Wetter and GitHub
ddbfe2d79d
Merge pull request #1440 from dcooper16/fix_client_sim
...
Fix Safari 13.0 Client Simulation
2020-01-13 17:14:43 +01:00
Dirk Wetter
a7b0a04480
remove redundant lines
2020-01-13 16:26:05 +01:00
Dirk Wetter
88ec92d622
Add recent Chrome and Opera handshakes
...
Chrome 78 and 79, Opera 65 and 66
Remove FTP from Chrome
2020-01-13 16:02:39 +01:00
Dirk Wetter
a714aec912
Clarify / correct a few bits
2020-01-13 16:01:27 +01:00
Dirk Wetter
69acd00731
Add file to check whether ~/etc/client-simulation.txt is parsable
2020-01-13 15:52:17 +01:00
Dirk Wetter and GitHub
b8e2b35165
Merge pull request #1437 from drwetter/avoid_1435
...
Avoid conflict of parallel mass scanning + connect timeouts
2020-01-13 11:50:02 +01:00
Dirk Wetter
cf8cb541d5
Update Thunderbird simulation to v68.3
2020-01-13 11:35:58 +01:00
Dirk Wetter
0911d1ae31
For better recognition put readme in a separate file
2020-01-13 11:34:25 +01:00
Dirk Wetter
5c2a9772ea
Avoid conflict of parallel mass scanning + connect timeouts
...
As stated in #1435 when specifying ``-connect-timeout=20`` AND
``--parallel`` there asa problem with the file handles of child
processes (__testssl.sh: line 10454: 5: Bad file descriptor__).
This commit mitigates that in a sense that both switches can't
be used together. There's a check now in parse_cmd_line().
In addition it addresses a problem when fatal() is called and
e.g. JSON files haven't been created yet (error message ~
__testssl.sh: line 825: : No such file or directory__). It
introduces a global CMDLINE_PARSED which remembers the state
whether ``parse_cmd_line()`` has been fully executed or
not. Only when the former is the case it allows writing to files.
That implies that in main parse_cmd_line() has to be followed
by json_header() and similar.
2020-01-13 10:58:25 +01:00
Dirk Wetter and GitHub
c375403482
Merge pull request #1436 from drwetter/update_CAstores
...
Update CA stores
2020-01-11 16:00:16 +01:00