Skip to content

Fix #2959#2963

Merged
drwetter merged 1 commit intotestssl:3.3devfrom
dcooper16:fix2959
Dec 13, 2025
Merged

Fix #2959#2963
drwetter merged 1 commit intotestssl:3.3devfrom
dcooper16:fix2959

Conversation

@dcooper16
Copy link
Collaborator

@dcooper16 dcooper16 commented Dec 11, 2025

Describe your changes

This PR fixes #2959 by modifying TLS12_CIPHER, TLS12_CIPHER_2ND_TRY, and TLS12_CIPHER_3RD_TRY so that they each have 118 ciphers (including "00,ff"). It also modifies run_cipherlists(), run_server_defaults(), and run_beast() so that, when $SERVER_SIZE_LIMIT_BUG is true, no more than 125 ciphers are sent.

What is your pull request about?

  • Bug fix
  • Improvement
  • New feature (adds functionality)
  • Breaking change (bug fix, feature or improvement that would cause existing functionality to not work as expected)
  • Typo fix
  • Documentation update
  • Update of other files

If it's a code change please check the boxes which are applicable

  • For the main program: My edits contain no tabs, indentation is five spaces and any line endings do not contain any blank chars
  • I've read CONTRIBUTING.md and Coding_Convention.md
  • I have tested this fix or improvement against >=2 hosts and I couldn't spot a problem
  • I have tested this new feature against >=2 hosts which show this feature and >=2 host which does not (in order to avoid side effects) . I couldn't spot a problem
  • For the new feature I have made corresponding changes to the documentation and / or to help()
  • If it's a bigger change: I added myself to CREDITS.md (alphabetical order) and the change to CHANGELOG.md

This commit fixes testssl#2959 by modifying TLS12_CIPHER, TLS12_CIPHER_2ND_TRY, and TLS12_CIPHER_3RD_TRY so that they each have 118 ciphers (including "00,ff"). It also modifies run_cipherlists(), run_server_defaults(), and run_beast() so that, when $SERVER_SIZE_LIMIT_BUG is true, no more than 125 ciphers are sent.
@drwetter drwetter merged commit 651ddc1 into testssl:3.3dev Dec 13, 2025
4 checks passed
@drwetter
Copy link
Collaborator

drwetter commented Dec 13, 2025

Thanks a lot @dcooper16 ! Works like a charm ;-)

@dcooper16 dcooper16 deleted the fix2959 branch December 13, 2025 16:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[possible BUG] Testing usgodae.org:443 only succeeded using testssl.sh-3.2.2/bin/openssl.Linux.x86_64 / bash sockets needed

2 participants