Skip to content

Commit 8a5d534

Browse files
authored
Update testssl.sh
Fix to be consistent in reporting (Not Ok) for ClientHello/ServerHello errors.
1 parent f3f6dae commit 8a5d534

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

testssl.sh

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5639,7 +5639,7 @@ run_protocols() {
56395639
fileout "$jsonID" "MEDIUM" "not offered, and downgraded to SSL"
56405640
elif [[ "$DETECTED_TLS_VERSION" == 03* ]]; then
56415641
detected_version_string="TLSv1.$((0x$DETECTED_TLS_VERSION-0x0301))"
5642-
prln_svrty_critical " -- server responded with higher version number ($detected_version_string) than requested by client"
5642+
prln_svrty_critical " -- server responded with higher version number ($detected_version_string) than requested by client (NOT ok)"
56435643
fileout "$jsonID" "CRITICAL" "server responded with higher version number ($detected_version_string) than requested by client"
56445644
else
56455645
if [[ ${#DETECTED_TLS_VERSION} -eq 4 ]]; then
@@ -5851,7 +5851,7 @@ run_protocols() {
58515851
prln_svrty_critical " -- server supports $latest_supported_string, but downgraded to $detected_version_string"
58525852
fileout "$jsonID" "CRITICAL" "not offered, and downgraded to $detected_version_string rather than $latest_supported_string"
58535853
elif [[ "$tls12_detected_version" == 03* ]] && [[ 0x$tls12_detected_version -gt 0x0303 ]]; then
5854-
prln_svrty_critical " -- server responded with higher version number ($detected_version_string) than requested by client"
5854+
prln_svrty_critical " -- server responded with higher version number ($detected_version_string) than requested by client (NOT ok)"
58555855
fileout "$jsonID" "CRITICAL" "not offered, server responded with higher version number ($detected_version_string) than requested by client"
58565856
else
58575857
if [[ ${#tls12_detected_version} -eq 4 ]]; then
@@ -5999,7 +5999,7 @@ run_protocols() {
59995999
fileout "$jsonID" "CRITICAL" "not offered, and downgraded to $detected_version_string rather than $latest_supported_string"
60006000
elif [[ "$DETECTED_TLS_VERSION" == 03* ]] && [[ 0x$DETECTED_TLS_VERSION -gt 0x0304 ]]; then
60016001
out "not offered"
6002-
prln_svrty_critical " -- server responded with higher version number ($detected_version_string) than requested by client"
6002+
prln_svrty_critical " -- server responded with higher version number ($detected_version_string) than requested by client (NOT ok)"
60036003
fileout "$jsonID" "CRITICAL" "not offered, server responded with higher version number ($detected_version_string) than requested by client"
60046004
else
60056005
out "not offered"

0 commit comments

Comments
 (0)