From 0937bd9c01fd4c56fdee688e887958dc72a9b03b Mon Sep 17 00:00:00 2001 From: Stefan Schantl Date: Tue, 27 Oct 2020 10:49:31 +0100 Subject: [PATCH] suricata: Automatically enable JA3 fingerprinting. Enable JA3 fingerprinting if any rules are enabled which are using this kind of feature. Fixes #12507. Signed-off-by: Stefan Schantl Signed-off-by: Michael Tremer --- config/suricata/suricata.yaml | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/config/suricata/suricata.yaml b/config/suricata/suricata.yaml index 743a4716cd..4e9e399675 100644 --- a/config/suricata/suricata.yaml +++ b/config/suricata/suricata.yaml @@ -387,9 +387,7 @@ app-layer: # Generate JA3 fingerprint from client hello. If not specified it # will be disabled by default, but enabled if rules require it. - #ja3-fingerprints: auto - # Generate JA3 fingerprint from client hello - ja3-fingerprints: no + ja3-fingerprints: auto # Completely stop processing TLS/SSL session after the handshake # completed. If bypass is enabled this will also trigger flow -- 2.39.5