Dirk
1c1eaa53d8
- fix for renamed http_header function
2015-09-29 18:47:49 +02:00
Dirk
cac49cb1f1
- "--file" implicitly does "--warnings=batch"
...
- "--file" works now fine with equal sign
- fixed load balancer issue where header request stalled and testssl.sh consequently too
- http_date needed to be changed too because of that
- needed to estimate then the http_date when request was killed (HAD_SLEPT)
will Mr. Spock like this??
- fixed load balancer issue where header request for breach test stalled and thus an error was displayed
- code improvements
2015-09-28 22:54:00 +02:00
Dirk
feaef680aa
- IPv6 #11 is 80% working (whohoo!). Needed is an openssl capable IPv6 and HAS_IPv6=true in the environment
...
- FIX #191
2015-09-26 22:44:33 +02:00
Dirk Wetter
cc81642ee3
- #FIX 202 (EV detection from TERENA/Digicert)
2015-09-25 14:35:42 +02:00
Dirk
a2efc201b7
- added a failure condition for trust check
2015-09-24 09:10:43 +02:00
Dirk
06466cca92
- proxy in determine_trust was missing
2015-09-23 09:03:47 +02:00
Dirk
0b1e573fc9
- FIX #190 : Server temp key backport for RH-ish systems works now automagically
...
- just to be sure there's a cmd line flag --has-dhbit / env HAS_DH_BITS
- some reordering
2015-09-22 20:09:26 +02:00
Dirk
4b57a22f6e
- FIX #198 (date env problem under BSD and maybe others)
2015-09-22 17:14:36 +02:00
Dirk
1668daa04e
- NEW: chain of trust -- for openssl 1.0.2 only
...
- FIX #97
2015-09-22 15:05:59 +02:00
Dirk
3eeb1f9d9d
- check whether dig, host or nslookup is there. The error message is now describing the cause
2015-09-21 16:43:47 +02:00
Dirk
23802e219d
- #FIX 197
...
- renamed a variable
2015-09-21 14:03:48 +02:00
Dirk
6406e1828d
- minor polish of output
2015-09-19 15:03:40 +02:00
Dirk
413b64c44a
- fixed proxy name resolution and make it more robust
...
- additional line if a proxy is used above rDNS
2015-09-18 15:12:01 +02:00
Dirk
945d26d222
- changed version number
...
- retabed to five spaces
2015-09-17 15:30:15 +02:00
Dirk
58096d6633
2.6 release
2015-09-15 08:49:00 +02:00
Dirk
467988fb0a
- improved resilience in cipher order check
...
- improved also there compatibility with intolerant IIS6 servers
2015-09-14 12:54:54 +02:00
Dirk
a2ba43ec78
- litemagenta should be used for not fatal conditions / magenta for fatal conditions (prg terminates then)
2015-09-14 11:12:37 +02:00
Dirk
9b08cb7584
- FIX /workaround for #188 ( https://github.com/drwetter/testssl.sh/issues/188 )
...
- bumped up version to rc4
2015-09-14 11:03:10 +02:00
Dirk
a9f231b3ff
- fix where an $PID"ERRFILE" was written
2015-09-09 16:41:32 +02:00
Dirk
d28317f2d0
- exit code always 0 unless an error occured
...
- enable devel feaure of SSLv2 via socket
2015-09-08 19:30:03 +02:00
Dirk
566a059250
- fix for issue when a non-HTTP service indicates a misleading non-match of certificate
...
- wildcard check
2015-09-06 18:21:08 +02:00
Dirk Wetter
b9bfa2355a
fix for scott helme's multiple keys ( https://scotthelme.co.uk/hpkp-toolset )
2015-09-04 14:19:06 +02:00
Dirk Wetter
422b4d511a
minor cleanups for finding openssl binaries
2015-09-04 10:04:56 +02:00
Dirk Wetter
6a036cd7d4
removed hardcoded obsolete paths for binaries
2015-09-03 13:26:02 +02:00
Dirk
1c5870e3e3
typo, fix from Stefan Stidl (thx!)
2015-09-03 12:17:32 +02:00
Dirk
489baa1299
unitize programming styles: ${var} --> $var, double square brackets instead of single
2015-09-03 12:14:47 +02:00
anoma
6b22851104
Typo. Inconsistent CVE string format
...
Trivial typo. All other CVE outputs are in the form CVE-XXXX-YYYY
2015-09-03 09:10:06 +01:00
Dirk Wetter
90930a2f78
- changed return code if someone dares to use dash as it hiccups
...
- catch users try to use sh instead of real bash (#184 ), see http://www.gnu.org/software/bash/manual/bashref.html#Bash-POSIX-Mode )
2015-09-02 12:56:03 +02:00
Dirk Wetter
45eb3ed662
better phrasing for LOGJAM, see #181
2015-08-28 17:43:38 +02:00
Dirk Wetter
90ead7a301
FIX #183
2015-08-28 17:06:07 +02:00
Dirk Wetter
412fb6fb05
FIX #182
2015-08-28 16:46:28 +02:00
Dirk Wetter
9b718d39d0
- removed VERBERR (is now DEBUG=2)
...
- hex2dec uses now internal echo instead of printf (which has problems with some chars if unexpected content if not properly used)
2015-08-28 14:59:04 +02:00
Dirk
b5818f6034
- FIX $177
...
- some by-catches whle shellchecking
- minor cleanups
2015-08-28 00:15:51 +02:00
Dirk
c102bb6712
micro fix for the ESC code orgination fron tput test
2015-08-27 20:39:20 +02:00
Dirk
0d9370237c
- FIX #172
...
- labeled TLS_FALLBACK_SCSV as experimental, to be improved in next release (remarks in code)
- removed experimental from FREAK check
- separated headerfile from errorfile, TLS handshake oids were sometimes misinterpreted as IPv4 addreses in header
- bumped up rc version
- linefeeds
2015-08-27 11:25:12 +02:00
Dirk Wetter
c93dc01b41
better service detection, dedicated line for NNTP and certificate stuff redirected to ERRFILE
2015-08-26 20:06:53 +02:00
Dirk Wetter
838112e6d2
- LibreSSL compatibility: recent pull spits out an error if cnf file isn't found (oh well) ==> introduction of #ERRFILE, good idea anyway
...
- commented what I wanted to achieve with the colors
- code cleanups
2015-08-24 23:50:03 +02:00
Dirk
aa91990fb3
- fix bug where a host name like AAA.BBB.CCC.DDD.in-addr.arpa.DOMAIN.TLS was taken as an ipv4 address
...
- freebsd 9 supports now also colors with setaf, Darwin?
- correct indentation of help
- improved parsing in command line so that where a distinct option is required it is also tested in the 1st place
- removed -q in help (deprecated as we might want to use it for other things in the future)
- fix: if $PWD/openssl was a dir it bailed out
- cleanup of fatal errors ==> provide ONE function
2015-08-24 22:17:35 +02:00
Dirk
83bf9067aa
FIX #167 (# of certificates provided)
2015-08-23 21:16:34 +02:00
Dirk Wetter
6baf5e377c
- sanitize '%' in general output function, avoids hiccups in url encoded strings
...
- FIX #178 (Security headers only key in green, not value)
- CSP rule for facebook hast 127.0.0.1 which is labeled as IP address
2015-08-21 18:10:45 +02:00
Dirk Wetter
87cef93b6c
- more solid parsing for HPKP header ( FIX #163 )
...
- X-UA-Compatible is now an "other" flag and key won't be swallowed
2015-08-21 12:43:10 +02:00
Dirk Wetter
394bde8ff5
output FIX for multiple CRLs ( #165 )
2015-08-21 10:47:29 +02:00
Peter Mosmans
cd4ba60f16
Fixes #174
...
Thanks to Ligushka
2015-08-18 16:07:24 +02:00
Jonathon Rossi
e8cbf1a699
Fix subject alternative name on darwin
2015-08-18 17:15:17 +10:00
Dirk
9afab04012
FIX #162 (leading space for rp banner and missing lf)
2015-08-17 20:13:52 +02:00
Dirk
405b0f10bf
FIX #161 + small improvemnet on rengotiation
2015-08-15 21:33:17 +02:00
Dirk
e3fcd786f7
- FIX #160 -- removed code from #27
...
- bumped up version to 2.6rc2
2015-08-15 18:48:49 +02:00
Dirk Wetter
58a1c1c1da
- expiration variables tunable via ENV
...
- cleanups expire section
2015-08-13 16:56:12 +02:00
Thomas Kähn
8963916b3b
Fix certificate expiration check
2015-08-12 18:28:50 +02:00
Dirk Wetter
719536a44e
FIX: Dilyans bug where a STARTTLS servive runs on a different port
2015-08-12 13:58:45 +02:00