This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Projects/O-Saft/Roadmap
From OWASP
- review the code (technically, note that it is a testing and not a security tool)
- add check for certificate chains
- add proper metric for risks rating
- implement client certificates
- encourage other admins and developers to fix their SSL issues ;-)"
Done
- implement other protocols (STARTTLS, IMAPS, POPS, ...) (Nov 2014)
- check target for any possible/existing cipher (May 2014)