diff --git a/CHANGES b/CHANGES index e34e89295f..c552bbb2d3 100644 --- a/CHANGES +++ b/CHANGES @@ -1,4 +1,8 @@ +2.6-110 | 2019-01-29 14:49:10 -0800 + + * Add fuid to SSL:Invalid_Server_Cert notice (Stephen Hosom) + 2.6-108 | 2019-01-28 14:11:19 -0600 * GH-210: improve call stack tracking w/ argument info (Jon Siwek, Corelight) diff --git a/VERSION b/VERSION index 0eb1f86e83..a65d034b05 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -2.6-108 +2.6-110 diff --git a/scripts/policy/protocols/ssl/validate-certs.bro b/scripts/policy/protocols/ssl/validate-certs.bro index 3f0d18a1c5..bd76daeceb 100644 --- a/scripts/policy/protocols/ssl/validate-certs.bro +++ b/scripts/policy/protocols/ssl/validate-certs.bro @@ -191,6 +191,7 @@ hook ssl_finishing(c: connection) &priority=20 local message = fmt("SSL certificate validation failed with (%s)", c$ssl$validation_status); NOTICE([$note=Invalid_Server_Cert, $msg=message, $sub=c$ssl$cert_chain[0]$x509$certificate$subject, $conn=c, + $fuid=c$ssl$cert_chain[0]$fuid, $identifier=cat(c$id$resp_h,c$id$resp_p,hash,c$ssl$validation_code)]); } }