Project

General

Profile

Actions

Optimization #7353

open

files: remove deprecated force-md5 config option

Added by Philippe Antoine 5 months ago. Updated 18 days ago.

Status:
New
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:
Beginner, Good First Issue, Outreachy

Description

in util-file.c

Actions #1

Updated by Victor Julien 21 days ago

  • Subject changed from Remove deprecated force-md5 config option to files: remove deprecated force-md5 config option
  • Target version changed from 8.0.0-beta1 to TBD

This is something we'd only do if we remove md5 tracking, matching and logging.

Actions #2

Updated by Jason Ish 21 days ago

I'm curious what is the reason to deprecate md5? Besides not being cryptographically secure, it still seems to be in wide use for identifying files.

Actions #3

Updated by Philippe Antoine 19 days ago

        SCLogWarning("deprecated 'force-md5' option " 
                     "found. Please use 'force-hash: [md5]' instead");
Actions #4

Updated by Philippe Antoine 19 days ago

Victor Julien wrote in #note-1:

This is something we'd only do if we remove md5 tracking, matching and logging.

No, we do md5 tracking, matching and logging with force-hash: [md5] instead of force-md5 in suricata.yaml

Do not we want to have this for 8 ?

Actions #5

Updated by Philippe Antoine 19 days ago

git grep deprecated shows other stuff like legacy.uricontent ...

Actions #6

Updated by Jason Ish 18 days ago

Philippe Antoine wrote in #note-4:

Victor Julien wrote in #note-1:

This is something we'd only do if we remove md5 tracking, matching and logging.

No, we do md5 tracking, matching and logging with force-hash: [md5] instead of force-md5 in suricata.yaml

Do not we want to have this for 8 ?

I think this makes sense then. The ticket didn't have enough context to reason about it properly.

Actions #7

Updated by Philippe Antoine 18 days ago

  • Target version changed from TBD to 8.0.0-beta1
Actions

Also available in: Atom PDF