mirror of
https://github.com/zeek/zeek.git
synced 2025-10-02 22:58:20 +00:00

This change adds compression methods to the ssl_client_hello event. It not being included was an oversight from a long time ago. This change means that the signature of ssl_client_hello changes slightly and scripts will have to be adjusted; since this is a commonly used event, the impact of it might be higher than usually for event changes.
9 lines
362 B
Text
9 lines
362 B
Text
# @TEST-EXEC: bro -r $TRACES/tls/tls1.2.trace %INPUT
|
|
# @TEST-EXEC: btest-diff .stdout
|
|
|
|
event ssl_client_hello(c: connection, version: count, possible_ts: time, client_random: string, session_id: string, ciphers: index_vec, comp_methods: index_vec)
|
|
{
|
|
print fmt("Got %d cipher suites", |ciphers|);
|
|
for ( i in ciphers )
|
|
print SSL::cipher_desc[ciphers[i]];
|
|
}
|