From 6f881dc70b7ce55c26d830e3bc8bc369ad5f10b0 Mon Sep 17 00:00:00 2001 From: Dirk Wetter Date: Sun, 5 Feb 2023 19:32:08 +0100 Subject: [PATCH 1/2] Rename 3 jsonIDs in run_cipherlists(): breaking change see #2316 / #2320 AVERAGE --> OBSOLETED GOOD --> STRONG_NOFS STRONG --> STRONG_FS --- testssl.sh | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/testssl.sh b/testssl.sh index 58a1c23..be14b90 100755 --- a/testssl.sh +++ b/testssl.sh @@ -6254,11 +6254,11 @@ run_cipherlists() { ret=$((ret + $?)) sub_cipherlists "$ossl_tdes_ciphers" "" " Triple DES Ciphers / IDEA " 3 "3DES_IDEA" "$tdes_ciphers" "$sslv2_tdes_ciphers" "$using_sockets" "$cve" "$cwe2" ret=$((ret + $?)) - sub_cipherlists "$ossl_obsoleted_ciphers" "" " Obsoleted CBC ciphers (AES, ARIA etc.) " 4 "AVERAGE" "$obsoleted_ciphers" "" "$using_sockets" "$cve" "$cwe2" + sub_cipherlists "$ossl_obsoleted_ciphers" "" " Obsoleted CBC ciphers (AES, ARIA etc.) " 4 "OBSOLETED" "$obsoleted_ciphers" "" "$using_sockets" "$cve" "$cwe2" ret=$((ret + $?)) - sub_cipherlists "$ossl_good_ciphers" "" " Strong encryption (AEAD ciphers) with no FS " 6 "GOOD" "$good_ciphers" "" "$using_sockets" "" "" + sub_cipherlists "$ossl_good_ciphers" "" " Strong encryption (AEAD ciphers) with no FS " 6 "STRONG_NOFS" "$good_ciphers" "" "$using_sockets" "" "" ret=$((ret + $?)) - sub_cipherlists "$ossl_strong_ciphers" 'ALL' " Forward Secrecy strong encryption (AEAD ciphers)" 7 "STRONG" "$strong_ciphers" "" "$using_sockets" "" "" + sub_cipherlists "$ossl_strong_ciphers" 'ALL' " Forward Secrecy strong encryption (AEAD ciphers)" 7 "STRONG_FS" "$strong_ciphers" "" "$using_sockets" "" "" ret=$((ret + $?)) outln From 66ebfb2f585624c9c5e1d7b94e0f69dfd2d9f021 Mon Sep 17 00:00:00 2001 From: Dirk Wetter Date: Mon, 6 Feb 2023 21:56:54 +0100 Subject: [PATCH 2/2] Add changes to CSV baseline --- t/baseline_data/default_testssl.csvfile | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/t/baseline_data/default_testssl.csvfile b/t/baseline_data/default_testssl.csvfile index a265981..4a0866b 100644 --- a/t/baseline_data/default_testssl.csvfile +++ b/t/baseline_data/default_testssl.csvfile @@ -15,9 +15,9 @@ "cipherlist_EXPORT","testssl.sh/81.169.166.184","443","OK","not offered","","CWE-327" "cipherlist_LOW","testssl.sh/81.169.166.184","443","OK","not offered","","CWE-327" "cipherlist_3DES_IDEA","testssl.sh/81.169.166.184","443","INFO","not offered","","CWE-310" -"cipherlist_AVERAGE","testssl.sh/81.169.166.184","443","LOW","offered","","CWE-310" -"cipherlist_GOOD","testssl.sh/81.169.166.184","443","OK","offered","","" -"cipherlist_STRONG","testssl.sh/81.169.166.184","443","OK","offered","","" +"cipherlist_OBSOLETED","testssl.sh/81.169.166.184","443","LOW","offered","","CWE-310" +"cipherlist_STRONG_NOFS","testssl.sh/81.169.166.184","443","OK","offered","","" +"cipherlist_STRONG_FS","testssl.sh/81.169.166.184","443","OK","offered","","" "cipher_order-tls1","testssl.sh/81.169.166.184","443","OK","server","","" "cipher-tls1_xc014","testssl.sh/81.169.166.184","443","LOW","TLSv1 xc014 ECDHE-RSA-AES256-SHA ECDH 256 AES 256 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA","","" "cipher-tls1_xc013","testssl.sh/81.169.166.184","443","LOW","TLSv1 xc013 ECDHE-RSA-AES128-SHA ECDH 256 AES 128 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA","",""