Repository navigation
fix: [circl_passivessl] don't fail the whole expansion when a certificate can't be fetched - #909
Open
ikrksglobal wants to merge 1 commit into
Open
ikrksglobal wants to merge 1 commit into
ikrksglobal wants to merge 1 commit into
Conversation
…cate can't be fetched
The Passive SSL API lists certificates for an IP that it then refuses to
return from /v2pssl/cfetch/<sha1> ("Not existing certificate", or a bare
500). fetch_cert() raises on that, and the exception aborts the handler, so
MISP only sees "Something went wrong" for common IPs like 8.8.8.8 or
1.1.1.1. Keep the fingerprint-only x509 object and continue.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
circl_passivesslfails whenever the Passive SSL API can't fetch one of the certificates it lists for an IP. The module callsfetch_cert()for every fingerprint returned by/v2pssl/query/<ip>. If/v2pssl/cfetch/<sha1>responds withNot existing certificateor a500, pypssl raises. That exception aborts the handler, so the whole expansion fails withSomething went wrong, look in the server logs for details.To reproduce, query an IP such as
8.8.8.8or1.1.1.1on currentmain:Fix
If
fetch_cert()fails, the module keeps thex509object with just the SHA-1 fingerprint and theseen-byreference, then continues with the next certificate. It also skips fields missing frominfo. Nothing changes when every certificate can be fetched.With the fix,
8.8.8.8returns 6 x509 objects: 4 with full details and 2 with the fingerprint only.🤖 Generated with Claude Code