From: Victor Julien Date: Sat, 25 May 2024 18:45:00 +0000 (+0200) Subject: tests: add tls client cert match test X-Git-Tag: suricata-6.0.20~29 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=refs%2Fpull%2F1866%2Fhead;p=thirdparty%2Fsuricata-verify.git tests: add tls client cert match test --- diff --git a/tests/tls/tls-client-cert-01/test.yaml b/tests/tls/tls-client-cert-01/test.yaml new file mode 100644 index 000000000..f6188f1a0 --- /dev/null +++ b/tests/tls/tls-client-cert-01/test.yaml @@ -0,0 +1,19 @@ +requires: + min-version: 7 + +args: + - -k none + +pcap: ../tls-store-02/tls-client-auth.pcap + +checks: + - filter: + count: 1 + match: + event_type: alert + app_proto: tls + alert.signature_id: 1 + - filter: + count: 1 + match: + event_type: tls diff --git a/tests/tls/tls-client-cert-01/tls.rules b/tests/tls/tls-client-cert-01/tls.rules new file mode 100644 index 000000000..7b46c4603 --- /dev/null +++ b/tests/tls/tls-client-cert-01/tls.rules @@ -0,0 +1,5 @@ +alert tls any any -> any any ( \ + tls.cert_subject; content:"O=TLSClientAuthSampleClient"; \ + tls.cert_issuer; content:"O=TLSClientAuthSampleCA"; \ + tls.cert_fingerprint; content:"32:56:41:d0:6a:ff:47:cb:21:e4:89:c5:ae:2a:a2:d8:1b:c9:70:0c"; \ + sid:1; rev:1;)