From a8c21ff90a9bb9017f47efc93d3448c770af053e Mon Sep 17 00:00:00 2001 From: Igor Kolchinskii Date: Mon, 28 Sep 2026 18:05:00 +0200 Subject: [PATCH] fix: [circl_passivessl] don't fail the whole expansion when a certificate can't be fetched The Passive SSL API lists certificates for an IP that it then refuses to return from /v2pssl/cfetch/ ("Not existing certificate", or a bare 500). fetch_cert() raises on that, and the exception aborts the handler, so MISP only sees "Something went wrong" for common IPs like 8.8.8.8 or 1.1.1.1. Keep the fingerprint-only x509 object and continue. Co-Authored-By: Claude Opus 5.5 (1M context) --- misp_modules/modules/expansion/circl_passivessl.py | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/misp_modules/modules/expansion/circl_passivessl.py b/misp_modules/modules/expansion/circl_passivessl.py index 3ceb6b996..42de21822 100755 --- a/misp_modules/modules/expansion/circl_passivessl.py +++ b/misp_modules/modules/expansion/circl_passivessl.py @@ -83,12 +83,20 @@ def parse(self): def _handle_certificate(self, certificate, ip_uuid): x509 = MISPObject("x509") x509.add_attribute(self.cert_hash, type=self.cert_hash, value=certificate) - cert_details = self.pssl.fetch_cert(certificate) - info = cert_details["info"] + # A certificate listed for an IP is not always fetchable: the API answers + # "Not existing certificate" or a bare 500. Keep the fingerprint and move on + # instead of failing the whole expansion. + try: + info = self.pssl.fetch_cert(certificate).get("info") or {} + except Exception: + info = {} for feature, mapping in self.mapping.items(): + if info.get(feature) is None: + continue attribute_type, object_relation = mapping x509.add_attribute(object_relation, type=attribute_type, value=info[feature]) - x509.add_attribute(self.cert_type, type="text", value=self.cert_type) + if info: + x509.add_attribute(self.cert_type, type="text", value=self.cert_type) x509.add_reference(ip_uuid, "seen-by") self.misp_event.add_object(**x509)