Skip to content

Commit 6193a7c

Browse files
Rev up testssl (microsoft#6801)
Co-authored-by: Amaury Chamayou <[email protected]>
1 parent 66a93ab commit 6193a7c

File tree

2 files changed

+47
-28
lines changed

2 files changed

+47
-28
lines changed

CMakeLists.txt

+1-1
Original file line numberDiff line numberDiff line change
@@ -1124,7 +1124,7 @@ if(BUILD_TESTS)
11241124
OUTPUT ${CMAKE_CURRENT_BINARY_DIR}/testssl/testssl.sh
11251125
COMMAND
11261126
rm -rf ${CMAKE_CURRENT_BINARY_DIR}/testssl && git clone --depth 1
1127-
--branch v3.0.7 --single-branch
1127+
--branch v3.2rc4 --single-branch -c advice.detachedHead=false
11281128
https://github.com/drwetter/testssl.sh
11291129
${CMAKE_CURRENT_BINARY_DIR}/testssl
11301130
)

tests/tls_report.csv

+46-27
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,17 @@
11
"ALPN","","INFO","http/1.1","",""
22
"BEAST","","OK","not vulnerable, no SSL3 or TLS1","CVE-2011-3389","CWE-20"
3-
"BREACH","","OK","not vulnerable, no HTTP compression - only supplied '/' tested","CVE-2013-3587","CWE-310"
3+
"BREACH","","OK","not vulnerable, no gzip/deflate/compress/br HTTP compression - only supplied '/' tested","CVE-2013-3587","CWE-310"
44
"CCS","","OK","not vulnerable","CVE-2014-0224","CWE-310"
55
"CRIME_TLS","","OK","not vulnerable","CVE-2012-4929","CWE-310"
66
"DNS_CAArecord","","LOW","--","",""
77
"DROWN","","OK","not vulnerable on this host and port","CVE-2016-0800 CVE-2016-0703","CWE-310"
88
"DROWN_hint","","INFO","no RSA certificate, can't be used with SSLv2 elsewhere","CVE-2016-0800 CVE-2016-0703","CWE-310"
99
"FREAK","","OK","not vulnerable","CVE-2015-0204","CWE-310"
10+
"FS","","OK","offered","",""
11+
"FS_ECDHE_curves","","OK","prime256v1 secp384r1 secp521r1","",""
12+
"FS_TLS12_sig_algs","","INFO","ECDSA+SHA256 ECDSA+SHA384 ECDSA+SHA512 ECDSA-BRAINPOOL+SHA256 ECDSA-BRAINPOOL+SHA384 ECDSA-BRAINPOOL+SHA512 ECDSA+SHA224","",""
13+
"FS_TLS13_sig_algs","","INFO","ECDSA+SHA384","",""
14+
"FS_ciphers","","INFO","TLS_AES_256_GCM_SHA384 ECDHE-ECDSA-AES256-GCM-SHA384 TLS_AES_128_GCM_SHA256 ECDHE-ECDSA-AES128-GCM-SHA256","",""
1015
"HPKP","","INFO","No support for HTTP Public Key Pinning","",""
1116
"HSTS","","LOW","not offered","",""
1217
"HTTP_clock_skew","","INFO","Got no HTTP time, maybe try different URL?","",""
@@ -16,9 +21,6 @@
1621
"LUCKY13","","OK","not vulnerable","CVE-2013-0169","CWE-310"
1722
"NPN","","INFO","not offered","",""
1823
"OCSP_stapling","","INFO","not offered","",""
19-
"PFS","","OK","offered","",""
20-
"PFS_ECDHE_curves","","OK","prime256v1 secp384r1 secp521r1","",""
21-
"PFS_ciphers","","INFO","TLS_AES_256_GCM_SHA384 ECDHE-ECDSA-AES256-GCM-SHA384 TLS_AES_128_GCM_SHA256 ECDHE-ECDSA-AES128-GCM-SHA256","",""
2224
"POODLE_SSL","","OK","not vulnerable, no SSLv3","CVE-2014-3566","CWE-310"
2325
"RC4","","OK","not vulnerable","CVE-2013-2566 CVE-2015-2808","CWE-310"
2426
"ROBOT","","OK","not vulnerable, no RSA key transport cipher","CVE-2017-17382 CVE-2017-17427 CVE-2017-17428 CVE-2017-13098 CVE-2017-1000385 CVE-2017-13099 CVE-2016-6883 CVE-2012-5081 CVE-2017-6168","CWE-203"
@@ -46,9 +48,10 @@
4648
"cert_eTLS","","INFO","not present","",""
4749
"cert_expirationStatus","","HIGH","expires < 30 days (0)","",""
4850
"cert_extKeyUsage","","INFO","No server extended key usage information","",""
51+
"cert_extlifeSpan","","OK","certificate has no extended life time according to browser forum","",""
4952
"cert_fingerprintSHA1","","INFO","","",""
5053
"cert_fingerprintSHA256","","INFO","","",""
51-
"cert_keySize","","OK","EC 384 bits","",""
54+
"cert_keySize","","OK","EC 384 bits (curve P-384)","",""
5255
"cert_keyUsage","","INFO","No server key usage information","",""
5356
"cert_mustStapleExtension","","INFO","--","",""
5457
"cert_notAfter","","HIGH","","",""
@@ -61,39 +64,46 @@
6164
"cert_signatureAlgorithm","","OK","ECDSA with SHA384","",""
6265
"cert_subjectAltName","","INFO","","",""
6366
"cert_trust","","OK","Ok via SAN","",""
64-
"cert_validityPeriod","","INFO","No finding","",""
67+
"certificate_compression","","INFO","none","",""
6568
"certificate_transparency","","INFO","--","",""
6669
"certs_countServer","","INFO","1","",""
6770
"certs_list_ordering_problem","","INFO","no","",""
68-
"cipher_negotiated","","OK","TLS_AES_256_GCM_SHA384, 256 bit ECDH (P-256)","",""
71+
"cipher-tls1_2_xc02b","","OK","TLSv1.2 xc02b ECDHE-ECDSA-AES128-GCM-SHA256 ECDH 521 AESGCM 128 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256","",""
72+
"cipher-tls1_2_xc02c","","OK","TLSv1.2 xc02c ECDHE-ECDSA-AES256-GCM-SHA384 ECDH 521 AESGCM 256 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384","",""
73+
"cipher-tls1_3_x1301","","OK","TLSv1.3 x1301 TLS_AES_128_GCM_SHA256 ECDH 256 AESGCM 128 TLS_AES_128_GCM_SHA256","",""
74+
"cipher-tls1_3_x1302","","OK","TLSv1.3 x1302 TLS_AES_256_GCM_SHA384 ECDH 256 AESGCM 256 TLS_AES_256_GCM_SHA384","",""
6975
"cipher_order","","OK","server","",""
70-
"cipher_x1301","","INFO","x1301 TLS_AES_128_GCM_SHA256 ECDH 256 AESGCM 128 TLS_AES_128_GCM_SHA256","",""
71-
"cipher_x1302","","INFO","x1302 TLS_AES_256_GCM_SHA384 ECDH 256 AESGCM 256 TLS_AES_256_GCM_SHA384","",""
72-
"cipher_xc02b","","INFO","xc02b ECDHE-ECDSA-AES128-GCM-SHA256 ECDH 521 AESGCM 128 TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256","",""
73-
"cipher_xc02c","","INFO","xc02c ECDHE-ECDSA-AES256-GCM-SHA384 ECDH 521 AESGCM 256 TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384","",""
76+
"cipher_order-tls1_2","","OK","server","",""
77+
"cipher_order-tls1_3","","OK","server","",""
78+
"cipher_strength_score","","INFO","0","",""
79+
"cipher_strength_score_weighted","","INFO","0","",""
7480
"cipherlist_3DES_IDEA","","INFO","not offered","","CWE-310"
75-
"cipherlist_AVERAGE","","INFO","not offered","","CWE-310"
7681
"cipherlist_EXPORT","","OK","not offered","","CWE-327"
7782
"cipherlist_LOW","","OK","not offered","","CWE-327"
7883
"cipherlist_NULL","","OK","not offered","","CWE-327"
79-
"cipherlist_STRONG","","OK","offered","",""
84+
"cipherlist_OBSOLETED","","INFO","not offered","","CWE-310"
85+
"cipherlist_STRONG_FS","","OK","offered","",""
86+
"cipherlist_STRONG_NOFS","","INFO","not offered","",""
8087
"cipherlist_aNULL","","OK","not offered","","CWE-327"
8188
"cipherorder_TLSv1_2","","INFO","ECDHE-ECDSA-AES256-GCM-SHA384 ECDHE-ECDSA-AES128-GCM-SHA256","",""
8289
"cipherorder_TLSv1_3","","INFO","TLS_AES_256_GCM_SHA384 TLS_AES_128_GCM_SHA256","",""
83-
"clientsimulation-android_442","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
84-
"clientsimulation-android_500","","INFO","TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256","",""
90+
"clientAuth","","INFO","optional","",""
91+
"clientAuth_CA_list","","INFO","empty","",""
92+
"clientsimulation-android_11","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
93+
"clientsimulation-android_12","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
8594
"clientsimulation-android_60","","INFO","TLSv1.2 ECDHE-ECDSA-AES128-GCM-SHA256","",""
8695
"clientsimulation-android_70","","INFO","No connection","",""
8796
"clientsimulation-android_81","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
8897
"clientsimulation-android_90","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
8998
"clientsimulation-android_X","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
90-
"clientsimulation-apple_ats_9_ios9","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
91-
"clientsimulation-chrome_74_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
99+
"clientsimulation-apple_mail_16_0","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
100+
"clientsimulation-chrome_101_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
92101
"clientsimulation-chrome_79_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
102+
"clientsimulation-edge_101_win10_21h2","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
93103
"clientsimulation-edge_15_win10","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
94-
"clientsimulation-edge_17_win10","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
104+
"clientsimulation-firefox_100_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
95105
"clientsimulation-firefox_66_win81","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
96-
"clientsimulation-firefox_71_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
106+
"clientsimulation-go_1178","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
97107
"clientsimulation-ie_11_win10","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
98108
"clientsimulation-ie_11_win7","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
99109
"clientsimulation-ie_11_win81","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
@@ -102,30 +112,39 @@
102112
"clientsimulation-ie_8_win7","","INFO","No connection","",""
103113
"clientsimulation-ie_8_xp","","INFO","No connection","",""
104114
"clientsimulation-java1102","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
105-
"clientsimulation-java1201","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
106-
"clientsimulation-java_6u45","","INFO","No connection","",""
115+
"clientsimulation-java1703","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
107116
"clientsimulation-java_7u25","","INFO","No connection","",""
108117
"clientsimulation-java_8u161","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
118+
"clientsimulation-libressl_283","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
109119
"clientsimulation-openssl_102e","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
110120
"clientsimulation-openssl_110l","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
111121
"clientsimulation-openssl_111d","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
112-
"clientsimulation-opera_66_win10","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
113-
"clientsimulation-safari_10_osx1012","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
122+
"clientsimulation-openssl_303","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
114123
"clientsimulation-safari_121_ios_122","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
115124
"clientsimulation-safari_130_osx_10146","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
116-
"clientsimulation-safari_9_ios9","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
117-
"clientsimulation-safari_9_osx1011","","INFO","TLSv1.2 ECDHE-ECDSA-AES256-GCM-SHA384","",""
118-
"clientsimulation-thunderbird_68_3_1","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
125+
"clientsimulation-safari_154_osx_1231","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
126+
"clientsimulation-thunderbird_91_9","","INFO","TLSv1.3 TLS_AES_256_GCM_SHA384","",""
119127
"cookie_count","","INFO","0 at '/' (30x detected, better try target URL of 30x)","",""
120128
"fallback_SCSV","","OK","no protocol below TLS 1.2 offered","",""
129+
"final_score","","INFO","0","",""
130+
"grade_cap_reason_1","","INFO","Grade capped to T. Issues with the chain of trust (chain incomplete)","",""
131+
"grade_cap_reason_2","","INFO","Grade capped to A. HSTS is not offered","",""
121132
"heartbleed","","OK","not vulnerable, no heartbeat extension","CVE-2014-0160","CWE-119"
122133
"id","fqdn/ip","port","severity","finding","cve","cwe"
134+
"intermediate_cert_badOCSP","","OK","intermediate certificate(s) is/are ok","",""
135+
"key_exchange_score","","INFO","0","",""
136+
"key_exchange_score_weighted","","INFO","0","",""
137+
"overall_grade","","CRITICAL","T","",""
123138
"pre_128cipher","","INFO","No 128 cipher limit bug","",""
124-
"protocol_negotiated","","OK","Default protocol TLS1.3","",""
139+
"protocol_support_score","","INFO","0","",""
140+
"protocol_support_score_weighted","","INFO","0","",""
141+
"rating_doc","","INFO","https://github.com/ssllabs/research/wiki/SSL-Server-Rating-Guide","",""
142+
"rating_spec","","INFO","SSL Labs's 'SSL Server Rating Guide' (version 2009q from 2020-01-30)","",""
125143
"secure_client_renego","","OK","not vulnerable","CVE-2011-1473","CWE-310"
126144
"secure_renego","","OK","supported","","CWE-310"
127145
"security_headers","","MEDIUM","--","",""
128146
"service","","INFO","HTTP","",""
129147
"sessionresumption_ID","","INFO","not supported","",""
130148
"sessionresumption_ticket","","INFO","not supported","",""
131149
"ticketbleed","","OK","not vulnerable","CVE-2016-9244","CWE-200"
150+
"winshock","","OK","not vulnerable","CVE-2014-6321","CWE-94"

0 commit comments

Comments
 (0)