Feature #262
closedkeyword 'ssl_version'
Description
unknown rule keyword 'ssl_version'
Example:
[9838] 20/12/2010 -- 11:50:19 - (detect-parse.c:655) <Error> (SigParseOptions) -- [ERRCODE: SC_ERR_RULE_KEYWORD_UNKNOWN(100)] - unknown rule keyword 'ssl_version'.
[9838] 20/12/2010 -- 11:50:19 - (detect.c:526) <Error> (DetectLoadSigFile) -- [ERRCODE: SC_ERR_INVALID_SIGNATURE(39)] - Error parsing signature "alert tcp $EXTERNAL_NET any -> $HOME_NET 443 (msg:"WEB-MISC TLSv1 Client_Certificate handshake"; flow:established, to_server; ssl_version:tls1.0; content:"|16 03 01|"; depth:3; content:"|0B|"; depth:1; offset:5; flowbits:set,tlsv1.client_hello.certificate; flowbits:noalert; metadata:service http; classtype:protocol-command-decode; sid:17748; rev:1;)" from file /etc/suricata/rules/web-misc.rules at line 619
Updated by Victor Julien almost 14 years ago
- Due date set to 01/07/2011
- Status changed from New to Assigned
- Assignee set to Gurvinder Singh
- Target version set to 1.1beta2
- Estimated time set to 6.00 h
Gurvinder, you should be able to add support for this based on the existing tls.version keyword. Can you do so?
Updated by Victor Julien over 13 years ago
- Status changed from Assigned to Closed
This made it into our git tree.