This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Projects/O-Saft"
From OWASP
(current_release_details commented aout) |
(purpose improved) |
||
| Line 8: | Line 8: | ||
| project_home_page =O-Saft | | project_home_page =O-Saft | ||
| project_description =This tools lists information about remote target's SSL certificate and tests the remote target's SSL connection according given list of ciphers and various SSL configurations. | | project_description =This tools lists information about remote target's SSL certificate and tests the remote target's SSL connection according given list of ciphers and various SSL configurations. | ||
| + | ;O-Saft - OWASP SSL audit for testers | ||
| + | :The main idea is to have a tool which works on common platforms and can simply be automated. | ||
| + | ;In a Nutshell: | ||
| + | :* show SSL connection details | ||
| + | :* show certificate details | ||
| + | :* check for supported ciphers | ||
| + | :* check for ciphers provided in your own libssl.so and libcrypt.so | ||
| + | :* check for special HTTP(S) support (like SNI, HSTS, certificate pinning) | ||
| + | :* may check for a single attribute | ||
| + | :* may check multiple targets at once | ||
| + | :* can be scripted (headless or as CGI) | ||
| + | :* should work on any platform (just needs perl, openssl optional) | ||
| + | :* scoring for all checks (still to be improved in many ways ;-) | ||
| + | :* output format can be cutomized | ||
| + | :* various trace and debug options to hunt unusual connection problems | ||
| + | |||
| project_license = GPL v2 | | project_license = GPL v2 | ||
| leader_name1 = [[User:Achim|Achim]] | | leader_name1 = [[User:Achim|Achim]] | ||
Revision as of 20:23, 5 June 2013
| |
This project is part of the OWASP Defenders community. Feel free to browse other projects within the Defenders, Builders, and Breakers communities. |
| PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
| |||||||||||||||||||||||||||||||||||||
| current release | |
|---|---|
| O-Saft 13.03.13 - 03/2013 - (download)
Release details: N/A : Rating:
| |