4 ms·
SSLPing was a tool that was designed to test SSL/TLS/PKI server configuration. According to the author's message, it was built on top of OpenSSL. There have bee
by ivanr 4y ago
SSLPing was a tool that was designed to test SSL/TLS/PKI server configuration. According to the author's message, it was built on top of OpenSSL. There have been significant changes made to OpenSSL since 2016, many focused on improving security by removing very old cryptographic primitives that are obsolete and insecure. Think RC4, 3DES, SHA1, and so on. If you're relying on OpenSSL to detect presence of such primitives on a server, upgrading your own (client) OpenSSL version breaks the functionality.
This is a problem for all testing tools that rely on OpenSSL. If you follow this direction, you typically need to use at least two OpenSSL versions, one new to test modern features and one very old to test obsolete features.
- weddpros 4y agoHi Ivan, I know you appreciate the issue to its fullest like no one else! Cheers