Deprecate extract-certs-pem.zeek and add log-certs-base64.zeek

Extract-certs-pem writes pem files to a dedicated file; since it does
not really work in cluster-environments it was never super helpful.

This commit deprecates this file and, instead, adds
log-certs-base64.zeek, which adds the base64-encoded certificate (which
is basically equivalent with a PEM) to the log-file. Since, nowadays,
the log-files are deduplicates this should not add a huge overhead.
This commit is contained in:
Johanna Amann 2021-06-28 16:09:27 +01:00
parent dde1e2e77e
commit 279a060fae
7 changed files with 44 additions and 1 deletions

View file

@ -7,6 +7,7 @@
@load frameworks/files/extract-all-files.zeek
@load policy/misc/dump-events.zeek
@load policy/protocols/conn/speculative-service.zeek
@load policy/protocols/ssl/extract-certs-pem.zeek
@load ./example.zeek