Skip to content

fix: [circl_passivessl] don't fail the whole expansion when a certificate can't be fetched - #909

Open
ikrksglobal wants to merge 1 commit into
MISP:mainfrom
ikrksglobal:fix-circl-passivessl-missing-cert
Open

ikrksglobal wants to merge 1 commit into
MISP:mainfrom
ikrksglobal:fix-circl-passivessl-missing-cert

Conversation

@ikrksglobal

Copy link
Copy Markdown

Problem

circl_passivessl fails whenever the Passive SSL API can't fetch one of the certificates it lists for an IP. The module calls fetch_cert() for every fingerprint returned by /v2pssl/query/<ip>. If /v2pssl/cfetch/<sha1> responds with Not existing certificate or a 500, pypssl raises. That exception aborts the handler, so the whole expansion fails with Something went wrong, look in the server logs for details.

To reproduce, query an IP such as 8.8.8.8 or 1.1.1.1 on current main:

Exception: Unable to decode JSON object: Not existing certificate
  File ".../circl_passivessl.py", line 86, in _handle_certificate
    cert_details = self.pssl.fetch_cert(certificate)

Fix

If fetch_cert() fails, the module keeps the x509 object with just the SHA-1 fingerprint and the seen-by reference, then continues with the next certificate. It also skips fields missing from info. Nothing changes when every certificate can be fetched.

With the fix, 8.8.8.8 returns 6 x509 objects: 4 with full details and 2 with the fingerprint only.

🤖 Generated with Claude Code

…cate can't be fetched

The Passive SSL API lists certificates for an IP that it then refuses to
return from /v2pssl/cfetch/<sha1> ("Not existing certificate", or a bare
500). fetch_cert() raises on that, and the exception aborts the handler, so
MISP only sees "Something went wrong" for common IPs like 8.8.8.8 or
1.1.1.1. Keep the fingerprint-only x509 object and continue.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant