Dirk Wetter and GitHub
a43261fc6f
Merge pull request #2703 from dcooper16/ocsp_check_rev_ossl_ver
...
OpenSSL version check in check_revocation_ocsp()
2025-03-18 13:04:23 +01:00
Dirk Wetter and GitHub
0c64e09203
Merge pull request #2702 from testssl/dependabot/github_actions/docker/login-action-3.4.0
...
Bump docker/login-action from 3.3.0 to 3.4.0
2025-03-17 10:26:57 +01:00
Dirk Wetter and GitHub
87d57bbf2f
Merge pull request #2700 from testssl/unitttest_revocation
...
Unit test revocation
2025-03-15 21:38:57 +01:00
Dirk
52476b8a46
Fix finger confusion ;-)
2025-03-15 17:27:28 +01:00
Dirk
c7e095305f
Add unit test for certificate revocation
...
One positive, one negative
This should detect failures in the future like in #2667 , #2516
and #1275 .
2025-03-15 17:24:22 +01:00
Dirk Wetter and GitHub
2090bdc849
Merge pull request #2698 from testssl/fixDockerOcspCall
...
Fix --phone-out + ocsp, also in docker container
2025-03-15 17:11:52 +01:00
Dirk
633503cd17
Fix complaint wrt Lowercase "as"
2025-03-15 16:02:32 +01:00
Dirk
430c5c8d09
Fix --phone-out + ocsp, also in docker container
...
Previously in 4f1a91f92e there was a
double header sent to the server to check whether the certificate
was revoked.
This PR addresses that and fixes #2667 .
2025-03-15 15:58:28 +01:00
Dirk Wetter and GitHub
098aa4ad8b
Merge pull request #2697 from dcooper16/fix_ossl_version_check
...
Fix OpenSSL version check
2025-03-15 09:22:26 +01:00
Dirk Wetter and GitHub
73be4f7381
Merge pull request #2695 from testssl/fix_segfault_error4
...
Fix segfault with error 4 in check_revocation_ocsp() when using --phone-out
2025-03-14 19:19:38 +01:00
Dirk
4f1a91f92e
Fix segfault with error 4 in check_revocation_ocsp() when using --phone-out
...
As `--phone-out` sometimes doesn't work with our binary we switch transparently/automagically
to the vendor support openssl binary -- if available.
This fixes at least #2516 where the issue has been explained/debugged in detail.
See also #2667 and #1275 .
2025-03-14 17:06:42 +01:00
Dirk Wetter and GitHub
c53f4a3e44
Merge pull request #2682 from testssl/speedup_curvetests
...
Speed up startup checks for supported curves and more
2025-03-13 10:59:42 +01:00
Dirk Wetter and GitHub
31a09ec593
Merge pull request #2692 from testssl/more_extension_numbers
...
Add a few extension numbers in the server hello
2025-03-12 10:29:15 +01:00
Dirk Wetter and GitHub
cab5bd7b13
Merge pull request #2694 from dcooper16/changes_update
...
Update CHANGELOG.md and CREDITS.md
2025-03-12 10:27:31 +01:00
Dirk Wetter and GitHub
1e63bd296d
Merge pull request #2693 from testssl/drwetter-patch-1
...
Update pull_request_template.md
2025-03-11 16:25:19 +01:00
Dirk Wetter and GitHub
011bcc7223
Update pull_request_template.md
2025-03-11 16:21:24 +01:00
Dirk Wetter and GitHub
bad917f193
Update pull_request_template.md
2025-03-11 16:20:25 +01:00
Dirk
8b00ab4c47
Add a few extension numbers in the server hello
...
Issue #2686 showed a server which listed an unknown extension number from
RFC 8446. THis PR adds this number and a few (later) ones.
It just lists them when detected in `parse_tls_serverhello()`
See also https://www.iana.org/assignments/tls-extensiontype-values/tls-extensiontype-values.xhtml
2025-03-11 15:57:25 +01:00
Dirk Wetter and GitHub
830af44953
Merge pull request #2690 from dcooper16/mlkem
...
Support draft-connolly-tls-mlkem-key-agreement
2025-03-11 15:33:22 +01:00
Dirk Wetter and GitHub
70e1c4d693
Merge pull request #2689 from dcooper16/sort_tls_extns
...
Sort TLS extensions
2025-03-11 15:20:36 +01:00
Dirk Wetter and GitHub
6ed6db500b
Merge pull request #2688 from dcooper16/ossl4_compat
...
OpenSSL 4 compatibility
2025-03-11 15:16:45 +01:00
Dirk Wetter and GitHub
ac83b79680
Merge pull request #2687 from dcooper16/ossl35_compat
...
OpenSSL 3.5 compatibility
2025-03-11 15:13:44 +01:00
Dirk Wetter and GitHub
f34b81ed8f
Merge pull request #2683 from testssl/drwetter-patch-1
...
Update pull_request_template.md
2025-03-06 11:16:01 +01:00
Dirk Wetter and GitHub
b25038e248
Update pull_request_template.md
2025-03-06 11:14:54 +01:00
Dirk
4a8377a396
Conflicts resolved
2025-03-06 11:01:00 +01:00
Dirk Wetter and GitHub
08d8039813
Merge pull request #2681 from testssl/date_not_available
...
Fix regex for openssl banner
2025-03-05 22:20:42 +01:00
Dirk
7bb04e020e
Fix regex for openssl banner
...
,,, and also update the warning when runing in SSL native mode to check the ciphers
before and include OpenSSL also
2025-03-05 17:52:34 +01:00
Dirk
f03440bc28
Speed up startup checks for supported curves and more
...
In order to avoid delays due to lookups of the hostname "invalid." we
just avoid to use "invalid." whenever possible. :-)
Therefore we just do a test before whether `$OPENSSL s_client 2>&1 </dev/null`
does a connect, except when a WSL system is discovered. If that succeeds
we omit the part `-connect invalid.` to check whether the curve is supported.
In some quick testing this in fact improved the startup time.
This seemed to work under Linux with several openssl and one LibreSSL binary.
More testing would be required, especially e.g. under WSL / WSL2.
Also in `sclient_supported()` the `$OPENSSL s_client` statement was changed
in a similar fashion. That worked so far but would need to be observed more
closely.
2025-03-05 17:22:01 +01:00
Dirk Wetter and GitHub
9807bc327a
Merge pull request #2679 from testssl/banner_change
...
Banner change
2025-03-05 16:28:29 +01:00
Dirk
e6cfe8c3b0
Resolve merge conflict by incorporating both suggestions
2025-03-05 15:35:18 +01:00
Dirk
e2ee8b24b4
fix typo in comment
2025-03-05 15:06:41 +01:00
Dirk
5ffcd086eb
Add missing local vars
2025-03-05 15:02:15 +01:00
Dirk
3152cdf864
Banner change + minor fix for curve detection
...
In order to tell openssl binaries better apart the short banner below the
hash tag signs contain now also the date. That is the short version of the
build date unless it is not supplied which is the case of opensuse. Then
the name contains the date and it's taken from there.
The start and end banner lines have the same length now.
"sieve" was added in a comment and the sequence where sieve appears in
a pattern was trying to match other occurences (i.e. after nntp)
While testing the banners it appeared under Linux that a) the vendor
supplied openssl sometimes hangs during startup when determining the
supported curves using -connect b) a pattern was missing to detect
whether the curve was not supported which falsely labeled all supplied curves
as supported when using /usr/bin/openssl . The pattern for the latter
was added (b). For a) there needs to be a follow up PR to avoid the
long delays.
2025-03-05 14:41:12 +01:00
Dirk Wetter and GitHub
f555fb050e
Merge pull request #2678 from dcooper16/fix_typo
...
Fix typo
2025-03-05 09:13:12 +01:00
Dirk Wetter and GitHub
3ae276497d
Merge pull request #2677 from testssl/dependabot/github_actions/docker/setup-qemu-action-3.6.0
...
Bump docker/setup-qemu-action from 3.5.0 to 3.6.0
2025-03-03 09:49:25 +01:00
Dirk Wetter and GitHub
4fde2e7e49
Merge pull request #2674 from testssl/dependabot/github_actions/docker/build-push-action-6.15.0
...
Bump docker/build-push-action from 6.14.0 to 6.15.0
2025-02-27 10:32:27 +01:00
Dirk Wetter and GitHub
105c19e4ef
Merge pull request #2675 from testssl/dependabot/github_actions/docker/setup-qemu-action-3.5.0
...
Bump docker/setup-qemu-action from 3.4.0 to 3.5.0
2025-02-27 10:32:03 +01:00
Dirk Wetter and GitHub
c9d1ba4fcc
Merge pull request #2673 from dcooper16/avoid_subshell
...
Avoid subshell overhead
2025-02-27 10:31:04 +01:00
Dirk Wetter and GitHub
78dd0a13c9
Merge pull request #2671 from javabrett/javabrett/improve-ev-detection
...
Improved (experimental) Extended Validation (EV) certificate identification
2025-02-26 22:56:21 +01:00
Dirk Wetter and GitHub
04e5bc4be9
Merge pull request #2672 from javabrett/patch-1
...
Update CONTRIBUTING.md
2025-02-26 10:23:26 +01:00
Dirk Wetter and GitHub
ff41cbbb89
Merge pull request #2669 from magnuslarsen/3.1dev
...
fix(rating): explicit enable rating if required vuln-checks are enabled
2025-02-23 14:29:18 +01:00
Dirk Wetter and GitHub
69e2067b99
Merge pull request #2666 from krufab/fix/fix-typo-in-help-message
...
Corrected typo in the help message
2025-02-22 16:00:31 +01:00
Dirk Wetter and GitHub
ffa3e19764
Merge pull request #2662 from dcooper16/fix_ossl_supported_curve_check
...
Fix check for OpenSSL supported curves
2025-02-20 11:30:10 +01:00
Dirk Wetter and GitHub
94ff89671f
Merge pull request #2664 from testssl/dependabot/github_actions/docker/build-push-action-6.14.0
...
Bump docker/build-push-action from 6.13.0 to 6.14.0
2025-02-20 11:29:28 +01:00
Dirk Wetter and GitHub
74209e05de
Merge pull request #2660 from testssl/rm_comment
...
Remove obsolete comment that SNI is not needed for ticketbleed
2025-02-17 15:39:26 +01:00
Dirk Wetter and GitHub
2baaf61cc5
Merge pull request #2657 from dcooper16/fix_pattern_match
...
Fix pattern matches
2025-02-15 14:14:38 +01:00
Dirk Wetter and GitHub
f085fd1880
Merge pull request #2659 from dcooper16/npn_sockets
...
Enable run_npn() to use tls_sockets()
2025-02-15 13:47:13 +01:00
Dirk
e79dc8161e
Remove obsolete comment that SNI is not needed for ticketbleed
...
See also https://github.com/testssl/testssl.sh/pull/2656/files/aa5d4917cfc04f5fb2f6b57c3726237cca6735b9#r1954824502
2025-02-15 13:33:52 +01:00
Dirk Wetter and GitHub
4b57f4c9f9
Merge pull request #2656 from dcooper16/ticketbleed
...
Enhance ticketbleed testing
2025-02-15 13:31:15 +01:00
Dirk Wetter and GitHub
4b4260831e
Merge pull request #2653 from testssl/address_addCA_issue
...
Address CA file parsing problem (3.2)
2025-02-07 14:18:51 +01:00
Dirk Wetter
ebc43ddafe
Add previously added line from 3.0 in change log
...
for consistency reasons
2025-02-07 12:40:06 +01:00
Dirk Wetter
5e1db5f0a1
Address CA file parsing problem (3.2)
...
.... by forbidding spaces in supplied CA files/directories
Also now we're sanitizing the cmd line parameter better using `safe_echo()`
See also #2647 .
2025-02-07 12:30:41 +01:00
Dirk Wetter and GitHub
21a89e40e8
Merge pull request #2650 from testssl/drwetter-patch-1
...
Update Readme.md
2025-02-07 10:01:31 +01:00
Dirk Wetter and GitHub
72d9168389
add that pentest2xlsx is python
2025-02-07 10:00:50 +01:00
Dirk Wetter and GitHub
d38e6ef6a7
Update Readme.md
2025-02-07 09:57:20 +01:00
Dirk Wetter and GitHub
5b58771040
Merge pull request #2649 from testssl/dependabot/github_actions/docker/setup-qemu-action-3.4.0
...
Bump docker/setup-qemu-action from 3.3.0 to 3.4.0
2025-02-07 09:50:49 +01:00
Dirk Wetter and GitHub
6e72c9b81d
Merge pull request #2646 from testssl/fix_feature2098
...
Feature: Detection STARTTLS throtteling via code 421/SMTP
2025-01-31 12:26:44 +01:00
Dirk
4b928108ec
Add trotteling feature
...
* reorder points
* add sieve also
2025-01-31 11:39:45 +01:00
Dirk
e73a2a9d53
Feature: Detection STARTTLS throtteling via code 421/SMTP
...
For this anotehr variable needed to be passed to starttls_full_read()
via starttls_smtp_dialog, where the variable is defined.
Handling of the connection problem will occur at the calling level, fd_socket(),
so that in the future this can be extended if another STARTTLS problem signals
that we're too fast.
Fixes #2098 .
2025-01-31 11:26:44 +01:00
Dirk Wetter and GitHub
abd0170fc4
Merge pull request #2645 from teunvink/3.2
...
fix missing semicolon in docs
2025-01-30 10:59:06 +01:00
Dirk Wetter and GitHub
65c18bed99
Merge pull request #2644 from testssl/fix_2642
...
Fix error when hostname w trailing dot supplied
2025-01-29 22:51:35 +01:00
Dirk Wetter
61cf7fe0e7
Fix error when hostname w trailing dot supplied
2025-01-29 20:47:13 +01:00
Dirk Wetter and GitHub
aa4e9a4d41
Merge pull request #2641 from testssl/sieve_fix
...
two sieve fixes to make it work
2025-01-29 16:29:38 +01:00
Dirk
b054b5d687
two sieve fixes
...
* one logical error
* removing check for trailing space for OK
2025-01-28 22:15:17 +01:00
Dirk Wetter and GitHub
f95ff7ab3e
Merge pull request #2640 from forced-request/3.2
...
Readme: Misformatted Markdown
2025-01-28 20:57:53 +01:00
Dirk Wetter and GitHub
8339a730f5
Merge pull request #2638 from testssl/dependabot/github_actions/docker/build-push-action-6.13.0
...
Bump docker/build-push-action from 6.12.0 to 6.13.0
2025-01-27 21:15:22 +01:00
Dirk Wetter and GitHub
e068c52e28
Merge pull request #2639 from testssl/fix_ci_runs
...
Fix ci runs
2025-01-27 20:54:29 +01:00
Dirk Wetter
e41b488172
Merge branch 'fix_ci_runs' into dependabot/github_actions/docker/build-push-action-6.13.0
2025-01-27 20:36:49 +01:00
Dirk Wetter
d93549e327
fix match expr
2025-01-27 20:08:11 +01:00
Dirk Wetter
cdf5cf7b97
remove + @ beginning of line
2025-01-27 17:20:39 +01:00
Dirk Wetter
e17bbfd8c6
Merge branch 'fix_ci_runs' into dependabot/github_actions/docker/build-push-action-6.13.0
2025-01-27 16:42:15 +01:00
Dirk Wetter
ef13122f4f
fix typo
2025-01-27 16:39:02 +01:00
Dirk Wetter
b984ae5ea2
minor stuff
2025-01-27 16:37:04 +01:00
Dirk Wetter
8e39d161a8
cleaner code
2025-01-27 16:36:42 +01:00
Dirk Wetter
0640eb9004
Several CI fixes
...
- don't output stdin on terminal
- adapt to different google.com ip addresses
- cleaner code
2025-01-27 16:33:58 +01:00
Dirk Wetter and GitHub
04c98d93ab
Merge pull request #2628 from testssl/diffing_openssls
...
Add unittest for different openssl versions
2025-01-24 21:38:26 +01:00
Dirk
ce8984706e
Finalize unit test
...
* pattern search + replace for tls_sockets() vs. openssl
* better error handling for invocations with perl functions system + die
2025-01-24 20:36:59 +01:00
Dirk
cbaa813a40
Merge branch '3.2' into diffing_openssls
2025-01-24 19:47:40 +01:00
Dirk Wetter and GitHub
d115b2ebbf
Merge pull request #2635 from testssl/fix_2633
...
Fix bug when legacy NPN is tested against a TLS 1.3 host
2025-01-24 19:44:49 +01:00
Dirk
d9b293f6c7
fix typo
2025-01-24 18:51:11 +01:00
Dirk
43a0099fbc
Fix bug when legacy NPN is tested against a TLS 1.3 host
...
When testing a TLS 1.3 host s_client_options used TLS 1.3 ciphers to test
for NPN. As that is not implemented we nee dto make sure any other version
is used.
This PR ensures that --after testing whether it's a TLS 1.3-only host
where this test doesn't make any sense in the first place.
Fix for #2633
2025-01-24 18:46:07 +01:00
Dirk Wetter and GitHub
5c1232b9dc
Merge pull request #2566 from testssl/bump_version
...
Bump version to 3.2rc4
2025-01-24 15:47:11 +01:00
Dirk
76cdf3166a
fix typo
2025-01-24 14:53:52 +01:00
Dirk
bf75a91bc7
Merge branch '3.2' into bump_version
2025-01-24 14:41:21 +01:00
Dirk Wetter and GitHub
5eeab6484f
Merge pull request #2632 from testssl/Tazmaniac-client-renego-refactoring
...
Tazmaniac client renego refactoring
2025-01-24 14:24:43 +01:00
Dirk
002b91192c
fix spelling
2025-01-24 13:50:35 +01:00
Dirk
49db77e63a
Conflicts resolved
2025-01-24 13:44:19 +01:00
Dirk Wetter
163d744c13
Add recent and bigger changes
...
From today back to 1f37a8406f
2025-01-24 11:32:41 +01:00
Dirk Wetter
0042b6313e
s/drwetter/testssl
...
For the remaining occurences. Except dockerhub which needs to be solved.
2025-01-24 11:15:55 +01:00
Dirk Wetter
69d6a50696
Merge branch '3.2' into bump_version
2025-01-24 11:05:00 +01:00
Dirk Wetter and GitHub
0539688c06
Merge pull request #2631 from testssl/corydalis10-3.2
...
Improve CONTRIBUTING.md
2025-01-23 17:42:29 +01:00
Dirk
b185b1bea9
Fix typo
2025-01-23 17:41:36 +01:00
Dirk
90f1e59e9f
Merge #2618 and doing some overdue amendments
2025-01-23 17:37:32 +01:00
Dirk
8f054c6f12
Merge branch '3.2' of https://github.com/corydalis10/testssl.sh into corydalis10-3.2
2025-01-23 16:49:12 +01:00
Dirk Wetter and GitHub
9e9334f3c8
Merge pull request #2619 from testssl/co_header
...
Add more security headers
2025-01-23 11:47:34 +01:00
Dirk Wetter
4efe324ef7
Fix round bracket and remove obsolete comment
2025-01-23 10:45:15 +01:00
Dirk Wetter and GitHub
7d919d494c
Merge pull request #2629 from testssl/misc
...
Remove --nsa in help() and add --forward-secrecy instead
2025-01-22 23:37:28 +01:00
Dirk
d7da22d598
Finalize check
...
* use system with @args so that we can query the return value
* code style improved for readability
* diff shows the filtered difference
* ok instead of cmp_ok to show not the whole content of vars
2025-01-22 23:33:35 +01:00
Dirk
4df0d9e4c3
Re-added the ) to make the action word (why??)
2025-01-22 23:32:39 +01:00
Dirk
207b902109
Merge branch '3.2' into co_header
2025-01-22 22:50:00 +01:00