Example values: "1.0", "1.1", "1.2"
-Support added in Suricata version 1.3.
-
tls.subject
-----------
tls.subject:"CN=*.googleusercontent.com"
-Support added in Suricata version 1.3.
-
Case sensitve, can't use 'nocase'.
Legacy keyword. ``tls_cert_subject`` is the replacement.
tls.issuerdn:!"CN=Google-Internet-Authority"
-Support added in Suricata version 1.3.
-
Case sensitve, can't use 'nocase'.
Legacy keyword. ``tls_cert_issuer`` is the replacement.
tls.fingerprint:!"f3:40:21:48:70:2c:31:bc:b5:aa:22:ad:63:d6:bc:2e:b3:46:e2:5a"
-Support added in Suricata version 1.4.
-
Case sensitive, can't use 'nocase'.
The tls.fingerprint buffer is lower case so you must use lower case letters for this to match.
store TLS/SSL certificate on disk
-Support added in Suricata version 1.4.
-
ssl_state
---------