Skip to content

Commit caeb03f

Browse files
committed
Merge cipher_order into master
2 parents f107061 + 7d0dd32 commit caeb03f

File tree

4 files changed

+334
-526
lines changed

4 files changed

+334
-526
lines changed

Changelog

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,20 @@
11
Changelog
22
=========
33

4+
Version: 1.11.0
5+
Date : 24/09/2015
6+
Author : rbsec <robin@rbsec.net>
7+
Changes: The following are a list of changes
8+
> Rewrote ciphersuite scanning engine to be much faster
9+
> Ciphers are now output in order of server preference
10+
> Most secure protocols are scanned first (TLSv1.2 -> SSLv2)
11+
> All protocols are tried when trying to obtain the certificate
12+
> Obselete --failed and --no-preferred-ciphers options removed
13+
> Flag TLSv1.0 ciphers in output
14+
> Flag 56 bit ciphers as red, not yellow
15+
> Fix building on OpenBSD (credit Stuart Henderson)
16+
> Fix incorrect output when server prefers NULL ciphers
17+
418
Version: 1.10.6
519
Date : 06/08/2015
620
Author : rbsec <robin@rbsec.net>

sslscan.1

Lines changed: 1 addition & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -57,10 +57,6 @@ Don't flag certificates signed with weak algorithms (MD5 and SHA-1) or short (<2
5757
.B \-\-show\-client\-cas
5858
Show a list of CAs that the server allows for client authentication. Will be blank for IIS/Schannel servers.
5959
.TP
60-
.B \-\-failed
61-
Show rejected ciphers
62-
(default is to listing only accepted ciphers)
63-
.TP
6460
.B \-\-ssl2
6561
.br
6662
Only check SSLv2 ciphers
@@ -106,7 +102,7 @@ The password for the private key or PKCS#12 file
106102
A file containing PEM/ASN1 formatted client certificates
107103
.TP
108104
.B \-\-no\-ciphersuites
109-
Only check for supported SSL/TLS versions, not ciphersuites
105+
Do not scan for supported ciphersuites.
110106
.TP
111107
.B \-\-no\-renegotiation
112108
Do not check for secure TLS renegotiation
@@ -117,9 +113,6 @@ Do not check for TLS compression (CRIME)
117113
.B \-\-no\-heartbleed
118114
Do not check for OpenSSL Heartbleed (CVE-2014-0160)
119115
.TP
120-
.B \-\-no\-preferred
121-
Do not check for preferred ciphersuites
122-
.TP
123116
.B \-\-starttls\-ftp
124117
STARTTLS setup for FTP
125118
.TP

0 commit comments

Comments
 (0)