summaryrefslogtreecommitdiff
path: root/plugin/business/ssl-policy/src/ssl_policy.cpp
AgeCommit message (Collapse)Author
2024-10-16TSG-22707 Adaptation of DB indicates changes, fixes self-check process ↵fengweihao
testing issues
2024-10-15TSG-22752 Delete SSL Fingerprints, use is_app_not_pinning to determine ↵luwenpeng
Certificate Not Installed or Certificate Pinning
2024-10-10Fix the issue of loading JSON files in Maat within tfefengweihao
2024-09-26change maat_plugin_table_get_ex_data() key type from uuid_t to uuid stringluwenpeng
2024-09-26fix compile errors for adapting maatluwenpeng
2024-09-25feature(adapt maat): PXY_PROFILE_DECRYPTION adapt uuidluwenpeng
2024-07-19feature: TSG-21853 Refactoring TFE Kafka infrastructureluwenpeng
2023-06-08TSG-15381 TFE适配MAAT4的maat_plugin_table_get_ex_data()接口变更luwenpeng
2023-04-23TFE适配MAAT4,编译表只注册一次luwenpeng
2023-04-21TSG-14628 TFE适配TCP Option Profile库表的变更luwenpeng
2023-04-21TSG-14627 TFE适配Decryption Profile库表的变更luwenpeng
2023-03-30TSG-14484 Pxoxy支持Maat4fengweihao
2022-11-08TSG-12548 TFE适配拦截策略的keyring_for_untrusted字段luwenpeng
* keyring拆分为keyring_for_trusted与keyring_for_untrusted
2022-01-28TSG-4030 Security Event Logs 中的 SSL.Intercept State 为 Passthrough ↵v4.5.34-20220128luwenpeng
时,并未说明引起 Passthrough 的原因 (当命中 tcp passthrough 时,将 ssl_intercept_status 设置为 passthrough)
2021-01-06TSG-4965 功能端通过界面下发的 JA3 Fingerprint 识别 Pinning APP ↵luwenpeng
和未装根证书的 APP
2020-07-06TSG-1531 TFE 新增 DOH 插件luwenpeng
1.DOH 协议解析 2.DOH 协议还原 3.DOH POST请求 early response 4.DOH 策略扫描 5.tfe plugin 支持多个 bussiness 插件调用 6.Maat_feather 的创建从 pangu 剥离(涉及pangu/doh/ssl-policy) 7.增加 kafka 日志 8.增加测试用例
2020-05-25TSG-1719 功能端增加 dynamic bypass 选项 ↵v4.3.3-20200528luwenpeng
trusted_root_cert_is_not_installed_on_client && TSG-1687 pinning 功能优化
2020-04-28TSG-1280 修改 debug logluwenpeng
2020-04-27TSG-1280 修改 decryption profile 功能的接口luwenpeng
2020-04-26TSG-1280 修改 debuglogluwenpeng
2020-04-26TSG-1280 Proxy TFE使用Decryption Profile获得部分拦截参数luwenpeng
2019-11-25* 修改策略编译配置表关于协议字段处理fengweihao
2019-11-19TSG-91fengweihao
* 修改策略编译配置表名称 * 增加对用户自定域协议字段处理 * 修改配置文件,json文件
2019-10-23修改拦截策略拦截动作时user_region表的json参数变更:v4.3.20-202011v4.2.0-20191206release-4.2luwenpeng
1)exclusions修正为dynamic_bypass; 2)pinning修正为cert_pinning; 3)client_cert_req修正为mutual_authentication; 4)cert_verify修正为certificate_checks; 5)fail_method修正为fail_action; 6)ssl_ver修正为protocol_version。
2019-09-02设置 UNUSED,修复编译警告luwenpeng
2019-06-21修复ssl policy日志打印乱码的bug。zhengchao
2019-06-21ssl policy使用gcc __sync_add_and_fetch操作引用计数,fix #150zhengchao
2019-06-15兼容拦截策略中字符串格式的keyringzhengchao
2019-06-14ssl policy增加调试输出。zhengchao
2019-06-11在处理pxy_ctrl_policy回调时,仅对manipulate和block动作解析json。zhengchao
2019-06-11未完成:在ssl_stream_free中检测pinning。zhengchao
2019-06-06处理自定义域异常的拦截策略。zhengchao
2019-06-04修正在SSLPOLICY在获取ProfileID失败打印日志时的段错误luqiuwen
2019-06-02修正stream_proto从cmsg读出的方式luqiuwen
2019-06-02ssl stream和ssl policy对接tfe_cmsg_xx。zhengchao
2019-05-27拦截策略支持allow_http2的开关;恢复cmakelist漏掉的HTTP2的编 ↵zhengchao
译开关。
2019-05-24支持通过拦截策略指定ssl最大和最小版本号。zhengchao
2019-05-24证书校验选项及校验失败动作自测通过。zhengchao
2019-05-241. ↵zhengchao
客户端报SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN错误时,不作为maybe pinning; 2. ssl policy中增加protocol_errors的bypass开关。
2019-05-24在ssl policy中处理keyring。zhengchao
2019-05-241. 暴露ssl_stream.h给业务层;2. 将ssl ↵zhengchao
policy功能放到业务层插件目录。