From ae803c8b51dec9e31e99cb37cd64bd968b314669 Mon Sep 17 00:00:00 2001 From: Luca Deri Date: Sun, 10 May 2020 21:40:35 +0200 Subject: Added detection of self-signed TLS certificates --- src/lib/protocols/tls.c | 5 +++++ 1 file changed, 5 insertions(+) (limited to 'src/lib/protocols/tls.c') diff --git a/src/lib/protocols/tls.c b/src/lib/protocols/tls.c index 171d7c489..655d61ed6 100644 --- a/src/lib/protocols/tls.c +++ b/src/lib/protocols/tls.c @@ -450,6 +450,11 @@ static void processCertificateElements(struct ndpi_detection_module_struct *ndpi } if(rdn_len) flow->protos.stun_ssl.ssl.subjectDN = strdup(rdnSeqBuf); + + if(flow->protos.stun_ssl.ssl.subjectDN && flow->protos.stun_ssl.ssl.subjectDN + && (!strcmp(flow->protos.stun_ssl.ssl.subjectDN, flow->protos.stun_ssl.ssl.issuerDN))) + NDPI_SET_BIT_16(flow->risk, NDPI_TLS_SELFSIGNED_CERTIFICATE); + #if DEBUG_TLS printf("[TLS] %s() SubjectDN [%s]\n", __FUNCTION__, rdnSeqBuf); #endif -- cgit v1.2.3