mirror of
https://github.com/mozilla/cipherscan.git
synced 2024-11-22 14:23:41 +01:00
verify server side ordering is used in analyze.py
This commit is contained in:
parent
1c9d52c94c
commit
0da92f25b7
@ -114,6 +114,8 @@ def is_old(results):
|
|||||||
old = False
|
old = False
|
||||||
if not has_ocsp:
|
if not has_ocsp:
|
||||||
failures[lvl].append("consider enabling OCSP Stapling")
|
failures[lvl].append("consider enabling OCSP Stapling")
|
||||||
|
if results['serverside'] != 'True':
|
||||||
|
failures[lvl].append("enforce server side ordering")
|
||||||
return old
|
return old
|
||||||
|
|
||||||
# is_intermediate is similar to is_old but for intermediate configuration from
|
# is_intermediate is similar to is_old but for intermediate configuration from
|
||||||
@ -174,6 +176,8 @@ def is_intermediate(results):
|
|||||||
inter = False
|
inter = False
|
||||||
if not has_ocsp:
|
if not has_ocsp:
|
||||||
failures[lvl].append("consider enabling OCSP Stapling")
|
failures[lvl].append("consider enabling OCSP Stapling")
|
||||||
|
if results['serverside'] != 'True':
|
||||||
|
failures[lvl].append("enforce server side ordering")
|
||||||
return inter
|
return inter
|
||||||
|
|
||||||
# is_modern is similar to is_old but for modern configuration from
|
# is_modern is similar to is_old but for modern configuration from
|
||||||
@ -221,6 +225,8 @@ def is_modern(results):
|
|||||||
modern = False
|
modern = False
|
||||||
if not has_ocsp:
|
if not has_ocsp:
|
||||||
failures[lvl].append("consider enabling OCSP Stapling")
|
failures[lvl].append("consider enabling OCSP Stapling")
|
||||||
|
if results['serverside'] != 'True':
|
||||||
|
failures[lvl].append("enforce server side ordering")
|
||||||
return modern
|
return modern
|
||||||
|
|
||||||
def is_ordered(results, ref_ciphersuite, lvl):
|
def is_ordered(results, ref_ciphersuite, lvl):
|
||||||
|
Loading…
Reference in New Issue
Block a user