Project

General

Profile

Actions

Bug #8158

closed

Bug #3220: tls: ssl_version keyword negation (!) not working

tls: ssl_version keyword negation (!) not working (7.0.x backport)

Added by OISF Ticketbot about 2 months ago. Updated 22 days ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Effort:
Difficulty:
Label:
Actions #1

Updated by Philippe Antoine about 2 months ago

  • Assignee changed from Philippe Antoine to OISF Dev

I do not think this needs to be backported to 7 : nothing critical, an undocumented feature never worked, and this is just syntax sugar, not adding more expressivity to the rules language

Actions #2

Updated by Jason Ish about 2 months ago

Philippe Antoine wrote in #note-1:

I do not think this needs to be backported to 7 : nothing critical, an undocumented feature never worked, and this is just syntax sugar, not adding more expressivity to the rules language

How does it fail. Does 7.0 silently accept the negation leading the user to think that it should work? Then a backport is fine.

Or does it error out as an invalid rule? Then probably not, its more of a feature then.

Actions #3

Updated by Philippe Antoine about 2 months ago

How does it fail. Does 7.0 silently accept the negation leading the user to think that it should work?

yes

There are other cases where we use the opposite rule like https://redmine.openinfosecfoundation.org/issues/8010
Suricata8 silently accepts fragbits:M+D; leading the user to think that it should work, but it does not : it is handled as just M with trailing garbage ignored, and we do not want to backport it as existing ruleset will fail to load

Actions #4

Updated by Philippe Antoine about 2 months ago

  • Status changed from Assigned to In Review
Actions #5

Updated by Philippe Antoine about 2 months ago

  • Status changed from In Review to Closed
Actions #6

Updated by Shivani Bhardwaj 22 days ago

  • Subject changed from ssl_version keyword negation (!) not working (7.0.x backport) to tls: ssl_version keyword negation (!) not working (7.0.x backport)
  • Assignee changed from OISF Dev to Philippe Antoine
Actions

Also available in: Atom PDF