LibreSSL 4.3.0 added support for X25519MLKEM768, but did not add a "-decap" option to pkeyutl.
This commit allows for X25519MLKEM768 to be included in $OSSL_SUPPORTED_CURVES when LibreSSL 4.3.x is used. It also changes the method for determining whether $OPENSSL supports decapsulating ML-KEM ciphertexts, since only checking whether $OPENSSL supports a curve with MLKEM is no longer reliable.
As noted in #3154 there was an unused variable `waitsleep` in `starttls_io`
which was filled with argument passed \#3. The loop search for the pattern
in `$2` however was the filled with another variable `nr_waits` which was
pre-set to 10 (`STARTTLS_SLEEP`)
This PR fixes that by
- removing STARTTLS_SLEEP from this function
- passing a value of 4 to this function when called *)
For ~1200 xmpp tests 2 was the maximum in less than 10% of the cases, so
4 should be really safe. `starttls_postgres_dialog()` uses also `starttls_io`
but it should be a safe bet when searching for the pattern `S`
Improve emphasize_stuff_in_headers() by matching more than one digit at a time.
The primary benefit of this change is in the HTML, since it does not result in each digit being wrapped by <span style="color:#8a7237;">...</span>
testssl.sh shouldn't issue command line warnings about the target not being a server name (or the use of "--fast" or "--ssl-native") when the command line includes the "--local" option.
This commit adds missing declarations for local variables, so that they are not mistakenly treated as globals. It also changes one global variable (single_cipher) to uppercase and deletes two lines in run_cipher_match() that were not doing anything.
run_freak() and run_logjam() were using the color functions $magenta and $off (from set_color_functions()) in the sting $addtl_warning. This worked okay for the terminal output, but not for the HTML output or fileout().
This commit fixes run_freak() and run_logjam() by using pr_warning() for the terminal and HTML output and plaintext for fileout().
This commit also deletes the unused color functions from set_color_functions() and adds a note discouraging the use of the color functions that are still defined there.
Rewrite so that the function does not make use of $yellow, $brown, or $off. This avoids the need to repeat all of the headers for terminal and HTML output, and it also allows for case insensitive matching.
This commit fixes Shellcheck issue SC2076 by not quoting the right-hand-side of "=~" expressions. In the case of lines 22812 and 22939, this commit fixes a bug as the right-hand-side needs to be evaluated as a regular expression.