Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What:
Add support for TLSv1.3
Why:
GnuTLS 3.6.5+ has enabled TLS 1.3 by default.
How:
create certs
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes
start web server forcing the usage of tls1_3 only
openssl s_server -tls1_3 -key key.pem -cert cert.pem -accept 44330 -www
The new TLSv1.3 has the transport value 8 internally in openvas. So, for testing, both values will be used: 7 -> TLS_12 and 8 -> TLS_13
tls_13_test.nasl:
Execute the script twice, first with transport: 7 and then with transport:8 as argument in soclet_negotiate_ssl()
With transport 7, the communication fails.
With transport 8, an answer is received from the openssl s_server.