Project

General

Profile

Actions

Feature #4123

open

Task #4122: tracking: handle various TLS decrypt headers in proxies and decryption tools

Research: handle different flow tuples in TLS decrypt

Added by Victor Julien almost 5 years ago. Updated 9 days ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:

Description

Decrypted TLS traffic with special headers indicating the original tuple (see for example #2513) poses a challenge wrt tuple handling.

Rules looking at IP addresses might not work as expected, ip and port vars may be off.

This could perhaps be handled similar to how encapsulation on the IP level is handled: by tracking both tuples separately.

Actions #1

Updated by Philippe Antoine over 1 year ago

  • Assignee set to OISF Ticketbot
  • Target version set to TBD
Actions #2

Updated by Jason Ish 9 days ago

  • Assignee changed from OISF Ticketbot to OISF Dev

I don't think assigning to the ticket bot makes much sense.

Actions

Also available in: Atom PDF