Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Scan with no SNI #690

Open
nettnikl opened this issue Jan 19, 2025 · 0 comments
Open

Scan with no SNI #690

nettnikl opened this issue Jan 19, 2025 · 0 comments

Comments

@nettnikl
Copy link

Is your feature request related to a problem? Please describe.
With the sparse availability of IPv4, shared IPs and SNI are a must have, that is included in sslyze.
In the wild, some servers also send a different certificate for SNI-less requests, which acts as a default.
Some old clients (w/o SNI support) therefore might receive this other certificate.

Describe the solution you'd like
This scan could be included in the scan, to discover a broader range of leaf certificates that are served by/for the given host.

Describe alternatives you've considered
I can also just resolve the IP of the host and start a scan with the SNI set to the IP instead of the host name, which often coincides with the "default cert" - but does not really have to, as i understand.

Additional context
The functionality is mostly implemented already.
#202

Further changes/complexity will be brought to SNI anyways.
#452

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant