mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 14:48:21 +00:00
Bug fix and style updates.
This commit is contained in:
parent
5a45c246e5
commit
a649be6d9e
1 changed files with 6 additions and 6 deletions
|
@ -1,7 +1,6 @@
|
||||||
##! This script can be used to generate notices when X.509 certificates over
|
##! This script can be used to generate notices when X.509 certificates over
|
||||||
##! SSL/TLS are expired or going to expire based on the date and time values
|
##! SSL/TLS are expired or going to expire based on the date and time values
|
||||||
##! stored within the certificate. Notices will be suppressed for 1 day
|
##! stored within the certificate.
|
||||||
##! by default.
|
|
||||||
|
|
||||||
@load base/protocols/ssl
|
@load base/protocols/ssl
|
||||||
@load base/frameworks/notice
|
@load base/frameworks/notice
|
||||||
|
@ -23,17 +22,18 @@ export {
|
||||||
Certificate_Not_Valid_Yet,
|
Certificate_Not_Valid_Yet,
|
||||||
};
|
};
|
||||||
|
|
||||||
## Which hosts you would like to be notified about which have certificates
|
## The category of hosts you would like to be notified about which have
|
||||||
## that are going to be expiring soon.
|
## certificates that are going to be expiring soon. By default, these
|
||||||
|
## notices will be suppressed by the notice framework for 1 day.
|
||||||
## Choices are: LOCAL_HOSTS, REMOTE_HOSTS, ALL_HOSTS, NO_HOSTS
|
## Choices are: LOCAL_HOSTS, REMOTE_HOSTS, ALL_HOSTS, NO_HOSTS
|
||||||
const notify_certs_expiration = LOCAL_HOSTS &redef;
|
const notify_certs_expiration = LOCAL_HOSTS &redef;
|
||||||
|
|
||||||
## The time before a certificate is going to expire that you would like to
|
## The time before a certificate is going to expire that you would like to
|
||||||
## start receiving notices.
|
## start receiving :bro:enum:`Certificate_Expires_Soon` notices.
|
||||||
const notify_when_cert_expiring_in = 30days &redef;
|
const notify_when_cert_expiring_in = 30days &redef;
|
||||||
}
|
}
|
||||||
|
|
||||||
event x509_certificate(c: connection, cert: X509, is_server: bool, chain_idx: count, chain_len: count, der_cert: string) &priority=5
|
event x509_certificate(c: connection, cert: X509, is_server: bool, chain_idx: count, chain_len: count, der_cert: string) &priority=3
|
||||||
{
|
{
|
||||||
# If this isn't the host cert or we aren't interested in the server, just return.
|
# If this isn't the host cert or we aren't interested in the server, just return.
|
||||||
if ( chain_idx != 0 || ! addr_matches_host(c$id$resp_h, notify_certs_expiration) )
|
if ( chain_idx != 0 || ! addr_matches_host(c$id$resp_h, notify_certs_expiration) )
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue