]> git.ipfire.org Git - ipfire-2.x.git/commitdiff
suricata: Automatically enable JA3 fingerprinting.
authorStefan Schantl <stefan.schantl@ipfire.org>
Tue, 27 Oct 2020 09:49:31 +0000 (10:49 +0100)
committerMichael Tremer <michael.tremer@ipfire.org>
Tue, 27 Oct 2020 11:51:00 +0000 (11:51 +0000)
Enable JA3 fingerprinting if any rules are enabled which are using this
kind of feature.

Fixes #12507.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
config/suricata/suricata.yaml

index 743a4716cd89bada64f645e9c36a49944aafdb88..4e9e399675551c8a5bfd81568da622b2f3767576 100644 (file)
@@ -387,9 +387,7 @@ app-layer:
 
       # Generate JA3 fingerprint from client hello. If not specified it
       # will be disabled by default, but enabled if rules require it.
-      #ja3-fingerprints: auto
-      # Generate JA3 fingerprint from client hello
-      ja3-fingerprints: no
+      ja3-fingerprints: auto
 
       # Completely stop processing TLS/SSL session after the handshake
       # completed. If bypass is enabled this will also trigger flow