Match DPD TLS signature on one-sided connections.

This commit changes DPD matching for TLS connections. A one-sided match
is enough to enable DPD now.

This commit also removes DPD for SSLv2 connections. SSLv2 connections do
basically no longer happen in the wild. SSLv2 is also really finnicky to
identify correctly - there is very little data required to match it, and
basically all matches today will be false positives. If DPD for SSLv2 is
still desired, the optional signature in policy/protocols/ssl/dpd-v2.sig
can be loaded.

Fixes GH-1952
This commit is contained in:
Johanna Amann 2022-02-01 16:48:57 +00:00
parent 0793a38cc5
commit 95f1565498
4 changed files with 27 additions and 9 deletions

View file

@ -1 +1 @@
7c40cc2c3709fc54e5c75c119d1d01ed8a3ceb93
76b3112a06ff6c1b25c2aedcfe1828bf0b82d7bf