Script to verify that server doesn't mask ciphersuite bits #59
Labels
good first issue
relatively simple changes, good for first time contributors
help wanted
new test script
will require creation of a new connection script
Projects
Some old servers (SSLv2 era) don't check the first byte of ciphersuite ID advertised by client in SSLv3 and later Client Hello messages.
Write a test script that goes over all possible ciphersuite IDs and verifies that server either negotiates the single one advertised by client or aborts connection with an Alert message.
The text was updated successfully, but these errors were encountered: