mysql: Recognize when client/server negotiate SSL

This instantiates the SSL analyzer when the client requests SSL
so that Zeek now has a bit more visibility into encrypted MySQL
connections.

The pattern used is the same as in the IMAP, POP or XMPP analyzer.
This commit is contained in:
Arne Welzel 2023-01-27 11:15:23 +01:00
parent e9caea9694
commit fa48c88533
16 changed files with 144 additions and 13 deletions

View file

@ -7,12 +7,12 @@
# @TEST-EXEC: mkdir tls-13 && mv *log tls-13
#
# @TEST-EXEC: btest-diff tls-12/conn.log
# #TEST-EXEC: btest-diff tls-12/ssl.log
# #TEST-EXEC: btest-diff tls-12/x509.log
# @TEST-EXEC: btest-diff tls-12/ssl.log
# @TEST-EXEC: btest-diff tls-12/x509.log
#
# @TEST-EXEC: btest-diff tls-13/conn.log
# #TEST-EXEC: btest-diff tls-13/ssl.log
# #TEST-EXEC: ! test -f tls-13/x509.log
# @TEST-EXEC: btest-diff tls-13/ssl.log
# @TEST-EXEC: ! test -f tls-13/x509.log
@load base/protocols/conn
@load base/protocols/mysql

View file

@ -5,5 +5,12 @@
# @TEST-EXEC: touch mysql.log
# @TEST-EXEC: zeek -b -r $TRACES/mysql/encrypted.trace %INPUT
# @TEST-EXEC: btest-diff mysql.log
#
# Ensure the connection was handed off by peaking into some other logs.
# @TEST-EXEC: btest-diff conn.log
# @TEST-EXEC: btest-diff ssl.log
# @TEST-EXEC: btest-diff x509.log
@load base/protocols/conn
@load base/protocols/mysql
@load base/protocols/ssl