Dirk
d19675136a
Deprecating $FAST / --fast
...
As this option shows inconsistencies / wrong results and a fix would require
too much work at this moment this option is being hidden from the help. It
wasn't in the ~/doc .
See #849 , #2382 , #1732 etc.
2023-08-28 15:53:02 +02:00
Dirk Wetter and GitHub
1e7219f344
Merge pull request #2383 from ghen2/grep-3.8
...
Fix another grep-3.8 warning on needlessly escaped exclamation mark.
2023-08-28 14:38:18 +02:00
Dirk Wetter and GitHub
27c77071eb
Merge pull request #2380 from WtfJoke/removeOutdatedDockerImageRefere
...
Remove reference to outdated docker image
2023-08-12 13:12:35 +02:00
Dirk Wetter and GitHub
c888475b2c
Merge pull request #2377 from drwetter/3.1dev_to_3.2_references
...
change references from 3.1dev to 3.2
2023-07-31 17:15:15 +02:00
Dirk
2067ac8123
Fall back to heise.de
...
.. to scan.
It worked in a few examples locally. Other hosts I tried so far weren't
available anymore (like scanme.nmap.org). In order to reduce the burden
we scan now only during PRs.
2023-07-31 16:34:56 +02:00
Dirk
15b7f7b403
Stop using deprecated OS
2023-07-31 14:03:57 +02:00
Dirk
fc14a02035
Changed heise.de to example.com as sometimes we're blocked
2023-07-31 13:44:35 +02:00
Dirk
9e76b1e9ce
Change content here too
2023-07-31 12:51:29 +02:00
Dirk
6669af2fc5
remove this one (3.2 see previous commit)
2023-07-31 12:46:50 +02:00
Dirk
5246194bee
further files which contained 3.1dev
2023-07-31 12:46:04 +02:00
Dirk
b6143e1fb9
Change references from 3.1dev to 3.2
2023-07-31 12:40:56 +02:00
Dirk Wetter and GitHub
3c0ae4663f
Merge pull request #2375 from dcooper16/line_endings
...
Fix line endings in etc/curves-mapping.txt
2023-07-03 19:56:22 +02:00
Dirk Wetter and GitHub
3a80a13d66
Merge pull request #2372 from drwetter/dependabot/github_actions/docker/build-push-action-4.1.1
...
Bump docker/build-push-action from 4.1.0 to 4.1.1
2023-06-15 13:27:40 +02:00
Dirk Wetter and GitHub
864877df0e
Merge pull request #2370 from drwetter/dependabot/github_actions/docker/setup-qemu-action-2.2.0
...
Bump docker/setup-qemu-action from 2.1.0 to 2.2.0
2023-06-12 10:20:44 +02:00
Dirk Wetter and GitHub
69549d815f
Merge pull request #2369 from drwetter/dependabot/github_actions/docker/login-action-2.2.0
...
Bump docker/login-action from 2.1.0 to 2.2.0
2023-06-12 10:20:21 +02:00
Dirk Wetter and GitHub
35590baa5a
Merge pull request #2371 from drwetter/dependabot/github_actions/docker/build-push-action-4.1.0
...
Bump docker/build-push-action from 4.0.0 to 4.1.0
2023-06-12 10:19:54 +02:00
Dirk Wetter and GitHub
7f49af1100
Merge pull request #2367 from drwetter/Improve_ServerHello_ErrorMessage
...
Make clear where the parsing error comes from: SSL or TLS
2023-06-05 12:45:28 +02:00
Dirk
858f00304c
tiny clarification in debug mode
2023-06-02 16:57:47 +02:00
Dirk
6e2b9ae1c6
Make clear where the parsing error comes from: SSL or TLS
2023-06-02 16:43:27 +02:00
Dirk Wetter and GitHub
00b510d08c
Merge pull request #2364 from drwetter/lineending_lf
...
try to fix the line ending problem using .gitattributes .
2023-05-23 18:39:29 +02:00
Dirk Wetter and GitHub
947b2565e6
Merge pull request #2363 from teki69/patch-1
...
Fix CRL conversion issue when already in PEM format
2023-05-23 18:38:46 +02:00
Dirk
33211c0cf1
add file types to be interpreted w lf line endings
2023-05-23 16:18:42 +02:00
Dirk
e6abc5fedc
Try to fix the line ending problem
...
... at github when using the browser for a PR.
It seems that the web interface inserts an additional CR
and doesn't stick to the LF line endings.
Not sure it helps though. It can't hurt though.
2023-05-23 16:12:11 +02:00
Dirk Wetter and GitHub
f71619326d
Merge pull request #2362 from drwetter/fix_2361_dnsminimal
...
Fix misleading output
2023-05-16 10:44:56 +02:00
Dirk Wetter
9b8dc3a07e
Fix misleading output
...
... when instructed to do no DNS queries at all
2023-05-16 09:05:04 +02:00
Dirk Wetter and GitHub
be987d17a0
Merge pull request #2360 from mum-viadee/run_renego_sni_patch
...
Secure renegotiations tests need servername for servers that use SNI
2023-05-15 15:26:37 +02:00
Dirk Wetter and GitHub
e33e0bc204
Update testssl.sh
...
clarify comment
2023-05-15 15:04:59 +02:00
Dirk Wetter and GitHub
aa5235e658
Merge pull request #2346 from Odinmylord/3.1dev
...
Add information to RSA-PSS report
2023-04-01 09:51:27 +02:00
Dirk Wetter and GitHub
a04291fdb1
Merge pull request #2352 from dcooper16/pss_cert_tls13
...
Find RSASSA-PSS certificates with TLS 1.3
2023-03-31 16:38:14 +02:00
Dirk Wetter and GitHub
13b42069d5
Merge pull request #2353 from dcooper16/brainpooltls13
...
Add support for brainpool curves with TLS 1.3
2023-03-31 16:36:33 +02:00
Dirk Wetter and GitHub
82fbd8076e
Merge pull request #2347 from drwetter/suse_docker
...
Switching from Alpine Image to multistaged opensuse/leap
2023-03-24 09:23:26 +01:00
Dirk
91f3d9716b
amending previous commit
2023-03-23 15:05:15 +01:00
Dirk
90aa86ce6b
add another contributor and change
...
(not related to this PR but it'll be forgotten otherwise)
2023-03-23 14:45:51 +01:00
Dirk Wetter and GitHub
f95d0dd09a
Merge pull request #2328 from drwetter/w4ntun-merge
...
fixed DNS via Proxy
2023-03-23 14:31:17 +01:00
Dirk
bad5dedf42
correcting Brennan's name
2023-03-23 14:22:05 +01:00
Dirk
48a597e19d
don't forget the kudos ;-)
2023-03-23 09:11:14 +01:00
Dirk Wetter and GitHub
37c17a5e09
Merge pull request #2344 from polarathene/refactor/dockerfile-to-opensuse
...
refactor(dockerfile): Change base Alpine (3.17) => openSUSE Leap (15.4)
2023-03-22 11:10:21 +01:00
Dirk
d001bba86b
Finalize DNS via Proxy
...
See #2328 , original PR #2295 from @w4ntun .
Formally testssl.sh returned an error when it wasn't not possible to determine IP
addresses through DNS resolution, even if --proxy and --ip=proxy flags are set.
The main function always tried to determine IP addresses via DNS and exits with
a fatal error if it cannot do it. Although the client cannot get the IP, the
proxy could, so the SSL/TLS analysis is still possible.
This PR allows the analysis for an HTTP service via a proxy server and the DNS
traffic can be sent directly or through the proxy using the flag --ip=proxy.
ATTENTION: This may be a breaking change for those who don't have a local resolver.
They now have to add --ip=proxy.
In addition:
* help() was amended to add --ip=proxy (was only in the ~i/doc dir before)
* amending ~/doc dir to document it's better to add --nodns=min when there's
no local resolver
2023-03-21 19:40:40 +01:00
Dirk Wetter and GitHub
cb451777d2
Merge pull request #2338 from drwetter/CAstores_update
...
CA astores update
2023-03-18 20:19:03 +01:00
Dirk Wetter
aac696b0a0
Updated root CA stores
2023-03-17 18:06:57 +01:00
Dirk Wetter
6106887fdd
Update DST CA
2023-03-17 18:06:03 +01:00
Dirk Wetter
419aae3c98
updates docu to reflekt actual status
2023-03-17 18:05:24 +01:00
Dirk Wetter and GitHub
2659a13086
Merge pull request #2336 from drwetter/drwetter-patch-4
...
Update codespell.yml
2023-03-12 18:12:29 +01:00
Dirk Wetter and GitHub
6cea273a68
Update codespell.yml
...
add exception for aNULL which should work now
2023-03-12 17:55:10 +01:00
Dirk Wetter and GitHub
b84e182ca2
Merge pull request #2332 from drwetter/sanitize_fileout
...
Make sure control chars from HTTP header don't end up in html,csv,json
2023-03-12 16:18:20 +01:00
Dirk Wetter and GitHub
83f67b4fb7
Merge pull request #2333 from drwetter/drwetter-patch-4
...
Update .gitignore
2023-03-12 16:00:11 +01:00
Dirk Wetter and GitHub
8643ed4c72
Update .gitignore
2023-03-12 15:57:01 +01:00
Dirk Wetter
cacd8c57b1
Add variable htmlfile + filter GOST message
...
... which is needed for newer LibreSSL/OpenSSL versions
2023-03-12 15:09:24 +01:00
Dirk Wetter
2e33c483dd
remove comma in tr as it was interpreted as such
2023-03-12 14:52:11 +01:00
Dirk Wetter
fab67d0cca
Remove CR in server banner
...
... which caused a problem in t/32_isHTML_valid.t.
Also the test for an empty server banner was simplified
2023-03-12 14:00:55 +01:00
Dirk Wetter
d298b41d2c
add aNULL exception to codespell
2023-03-11 14:06:47 +01:00
Dirk Wetter
06506b371e
Make sure control chars from HTTP header don't end up in html,csv,json
...
This addresses the bug #2330 by implementing a function which removes
control characters from the file output format html,csv,json at the
output.
In every instance called there's a check before whether the string
contains control chars, hoping it'll save a few milli seconds.
A tr function is used, omitting LF.
It doesn't filter the terminal output and the log file output.
2023-03-11 13:38:28 +01:00
Dirk
9afa277c02
another indent correction
2023-03-03 12:50:02 +01:00
Dirk
2b6bd2f1dd
fix indentation
2023-03-03 12:47:12 +01:00
Dirk
581788ff39
Merge branch '3.1dev' of https://github.com/w4ntun/testssl.sh into w4ntun-3.1dev
2023-03-03 12:31:26 +01:00
Dirk Wetter and GitHub
88763f47a8
Merge pull request #2326 from drwetter/fix_mime-type
...
Fix Accept Header
2023-02-20 20:29:14 +01:00
Dirk
a14fc5bdcf
Fix Accept header
...
see #2325 .
"whenever HTTP/1.1 is used then the Accept header uses "text/*" as a MIME type.
This causes some minor issues with some of the checks we are doing"
2023-02-20 15:01:40 +01:00
Dirk Wetter and GitHub
e57527f3ec
Merge pull request #2321 from drwetter/align_json+terminal@run_cipherlists
...
Rename 3 jsonIDs in run_cipherlists(): breaking change
2023-02-08 17:07:42 +01:00
Dirk Wetter and GitHub
8260ca16e2
Merge pull request #2309 from polarathene/chore/dockerfile-improved-copy
...
chore: Use a single `COPY` by better leveraging `.dockerignore` patterns
2023-02-07 12:23:04 +01:00
Dirk Wetter and GitHub
363c0d0a69
Merge pull request #2323 from drwetter/drwetter-patch-4
...
Remove mkdir in Dockerfile
2023-02-07 10:29:08 +01:00
Dirk Wetter and GitHub
f914423978
Remove mkdir in Dockerfile
...
see https://github.com/drwetter/testssl.sh/pull/2312#pullrequestreview-1286620850
2023-02-07 10:28:26 +01:00
Dirk Wetter and GitHub
1ee21b7f22
Merge pull request #2312 from polarathene/chore/dockerfile-simplify-user
...
chore(Dockerfile): Simplify `testssl` user creation
2023-02-07 09:03:23 +01:00
Dirk Wetter and GitHub
64ae161218
Merge branch '3.1dev' into chore/dockerfile-simplify-user
2023-02-07 09:03:15 +01:00
Dirk Wetter
66ebfb2f58
Add changes to CSV baseline
2023-02-06 21:56:54 +01:00
Dirk Wetter
6f881dc70b
Rename 3 jsonIDs in run_cipherlists(): breaking change
...
see #2316 / #2320
AVERAGE --> OBSOLETED
GOOD --> STRONG_NOFS
STRONG --> STRONG_FS
2023-02-05 19:32:08 +01:00
Dirk Wetter and GitHub
e87b745c93
Merge pull request #2316 from dcooper16/cipherlists_doc
...
Update documentation for cipherlists tests
2023-02-05 19:25:02 +01:00
Dirk Wetter and GitHub
05b4cdcc0d
Merge pull request #2317 from dcooper16/fix_html
...
Fix HTML output in Bash 5.2 and newer
2023-02-04 09:22:03 +01:00
Dirk Wetter and GitHub
70237b2328
Merge pull request #2313 from polarathene/chore/dockerfile-remove-mkdir
...
chore: Remove redundant `mkdir`
2023-02-03 19:54:51 +01:00
Dirk Wetter and GitHub
6c2663aeb6
Merge pull request #2311 from SSLbrain/3.1dev
...
Feature Trustcor certificates being removed/disabled from root stores #2293
2023-02-02 13:55:07 +01:00
Dirk Wetter and GitHub
e02e8be19f
Merge pull request #2306 from drwetter/upgrade_alpine_perf-fix
...
Upgrade Alpine version for both Dockerfiles
2023-02-01 19:45:57 +01:00
Dirk Wetter
beb94d9efc
Upgrade Alpine version for both Dockerfiles
...
... to improve/mitigate performance problems, see #2299 .
(musl libc vs. glibc)
2023-02-01 19:40:40 +01:00
Dirk Wetter and GitHub
5a1a114adc
Merge pull request #2300 from drwetter/dependabot/github_actions/docker/build-push-action-4.0.0
...
Bump docker/build-push-action from 3.3.0 to 4.0.0
2023-01-31 09:37:28 +01:00
Dirk Wetter and GitHub
0b5c414970
Merge pull request #2303 from drwetter/nntp_ci_remove
...
Remove NNTP from CI tests
2023-01-31 09:37:06 +01:00
Dirk Wetter
2e0898c9ef
Remove NNTP from CI tests
...
Maybe for the future we should check whether host is available and
if so then run the test
2023-01-31 09:34:18 +01:00
Dirk Wetter and GitHub
8099dc0106
Merge pull request #2297 from drwetter/ldap_starttls_improvements
...
Add logic for STARTTLS enabled AD servers
2023-01-17 14:27:01 +01:00
Dirk Wetter
fdd72d2785
Cleanup code, clarfy comments for AD/LDAP + STARTTLS
2023-01-17 14:23:53 +01:00
Dirk Wetter
fc2a020294
Add logic for STARTTLS enabled AD servers
...
There are two different scenarios. x0C is the buffsize reply from openldap-like servers
whereas AD servers probably have x84 and return also the OID. The following is kind of
hackish as ldap_ExtendedResponse_parse() in apps/s_client.c of openssl is kind of hard
to understand. It was deducted from a number of hosts.
Bottom line: We'll look at the 9th byte or at the 17th when retrieving the result code
AD:
30 84 00 00 00 7d 02 01 01 78 84 00 00 00 74 0a 01 34 04 00 04 55 30 30 30 30 30 30 30 30 3a 20 [ failed AD .. LdapErr + OID..]
30 84 00 00 00 28 02 01 01 78 84 00 00 00 1F 0A 01 00 04 00 04 00 8A 16 [.. OID ..]
^^ bufflen ^^ resultcode
30 0C 02 01 01 78 07 0A 01 00 04 00 04 00
^^ bufflen ^^ result code
2023-01-17 11:16:05 +01:00
Dirk Wetter and GitHub
ce3bd4764f
Merge pull request #2296 from drwetter/dependabot/github_actions/docker/build-push-action-3.3.0
...
Bump docker/build-push-action from 3.2.0 to 3.3.0
2023-01-16 10:20:13 +01:00
Dirk Wetter and GitHub
7670275e59
Merge pull request #2292 from drwetter/ldap_starttls_improvements
...
make starttls_ldap_dialog() more readable...
2022-12-27 22:06:12 +01:00
Dirk Wetter
c67cefaf8e
add info about error handling
2022-12-26 19:15:49 +01:00
Dirk Wetter
336d3c947a
better use safe_echo()
2022-12-26 16:14:26 +01:00
Dirk Wetter
b633efae69
make starttls_ldap_dialog() more readable...
...
... add references + better debugging output
2022-12-26 16:10:31 +01:00
Dirk Wetter and GitHub
198bb09d51
Merge pull request #2282 from drwetter/drwetter-patch-2
...
Reflect past update for docker hub's Dockerfile
2022-11-28 17:09:04 +01:00
Dirk Wetter and GitHub
0c807bea5b
Reflect past update for docker hub's Dockerfile
...
... using alpine 3.16
2022-11-28 14:10:13 +01:00
Dirk Wetter and GitHub
9304bb80b8
Merge pull request #2281 from dcooper16/fix_whitespace
...
Fix whitespace issues
2022-11-25 18:23:58 +01:00
Dirk Wetter and GitHub
6ba21a937a
Merge pull request #2278 from dcooper16/fix_extract_calist
...
Fix extract_calist()
2022-11-24 11:15:10 +01:00
Dirk Wetter and GitHub
a4666087e8
Merge pull request #2265 from dcooper16/server_sig_algs
...
Show server supported signature algorithms
2022-11-23 11:11:02 +01:00
Dirk Wetter and GitHub
462a602625
Merge pull request #2276 from dcooper16/pem_fileout
...
Fix #1747
2022-11-18 11:06:26 +01:00
Dirk Wetter and GitHub
827782cd58
Merge pull request #2275 from drwetter/remove_negotiated
...
Remove Negotiated cipher / protocol in server preferences
2022-11-15 09:28:38 +01:00
Dirk Wetter
e918a2c31f
remove negotiated cipher / protocol also in baseline file
2022-11-14 20:25:56 +01:00
Dirk Wetter
1842b9eefb
Remove Negotiated cipher / protocol in server preferences
...
As a first cleanup action I removed in run_server_preference()
the line with Negotiated Protocol and Negotiated Cipher as
the don't have any real information, see #2235 , comment below:
https://github.com/drwetter/testssl.sh/pull/2235
2022-11-14 17:23:13 +01:00
Dirk Wetter and GitHub
0dac50c830
Merge pull request #2272 from dcooper16/fix2271
...
Fix #2271
2022-11-11 16:27:18 +01:00
Dirk Wetter and GitHub
92a80f7f86
Merge pull request #2268 from drwetter/mastodon
...
Hint for mastodon
2022-11-10 15:11:41 +01:00
Dirk Wetter and GitHub
c403249678
Hint for mastodon
...
... and to a separate account
2022-11-10 15:09:03 +01:00
Dirk Wetter and GitHub
6716dc7465
Merge pull request #2261 from osown/3.1dev
...
if PROXY variable is set there is no need to do a direct connection attempt
2022-11-10 10:52:14 +01:00
Dirk Wetter and GitHub
2b0fdfdf64
Merge pull request #2262 from dcooper16/run_fs_infnite_loop
...
Fix infinite loop in run_fs()
2022-11-10 09:43:29 +01:00
Dirk Wetter and GitHub
a4419fa9c9
Merge pull request #2264 from dcooper16/padding
...
Clean up adding padding
2022-11-10 09:37:42 +01:00
Dirk Wetter and GitHub
dda579cdf2
Merge pull request #2266 from dcooper16/fix2249
...
Fix #2249
2022-11-10 09:22:35 +01:00
Dirk Wetter and GitHub
f5d41ff26f
Merge pull request #2258 from drwetter/minor
...
Fix indentation + clarify openssl warning
2022-10-21 15:44:55 +02:00
Dirk Wetter and GitHub
7c38cc7290
Merge pull request #2235 from dcooper16/fix1311
...
Fix #1311
2022-10-21 15:41:24 +02:00