← All cheat sheets

SSLCAUDIT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

sslcaudit is a tool for automating testing of SSL/TLS clients. It
acts as an SSL/TLS server presenting various certificates (self-signed,
wrong CN, expired) to test how clients handle certificate validation
errors.

BASIC USAGE#

sslcaudit                        # Start with defaults (port 8443)
sslcaudit -l <listen_addr>       # Listen on specific address

OPTIONS#

sslcaudit -l <addr:port>         # Listen address:port
sslcaudit -m <module>            # Select test module
sslcaudit --user-cert <cert>     # Use specific certificate
sslcaudit --user-key <key>       # Use specific private key
sslcaudit --user-ca-cert <ca>    # Use specific CA certificate
sslcaudit --user-ca-key <key>    # Use specific CA key
sslcaudit -N <cn>                # Set server Common Name
sslcaudit -T <timeout>           # Connection timeout (seconds)
sslcaudit -o <file>              # Output results to file

TEST MODULES#

sslcaudit -m sslcert             # SSL certificate tests
sslcaudit -m sslproto            # SSL/TLS protocol tests

CERTIFICATE TESTS#

# sslcaudit automatically tests clients with:
# - Self-signed certificates
# - Certificates with wrong Common Name
# - Expired certificates
# - Untrusted CA certificates
# - Certificates matching target domain (generated)
# - Valid certificates (baseline test)

EXAMPLES#

# Start on default port
sslcaudit

# Listen on specific port
sslcaudit -l 0.0.0.0:4443

# Test with custom Common Name
sslcaudit -N www.example.com

# Use specific certificate
sslcaudit --user-cert server.crt --user-key server.key

# Save results
sslcaudit -o /tmp/sslcaudit_results.txt

# Custom timeout
sslcaudit -l 0.0.0.0:8443 -T 10

WORKFLOW#

# 1. Start sslcaudit on a port
# 2. Configure client to connect to sslcaudit
# 3. sslcaudit presents various bad certificates
# 4. Observe if client accepts or rejects each certificate
# 5. Review results to identify certificate validation issues

# Clients that accept bad certificates are vulnerable to:
# - Man-in-the-middle attacks
# - SSL/TLS interception
# - Certificate spoofing

INTERPRETING RESULTS#

# PASS = Client properly rejected bad certificate
# FAIL = Client accepted bad certificate (vulnerability!)
#
# Test scenarios:
# self-signed       - Should be rejected
# wrong-CN          - Should be rejected
# expired           - Should be rejected
# untrusted-CA      - Should be rejected
# matching-cert     - Depends on CA trust

NOTES#

- Useful for testing custom SSL/TLS client implementations
- Identifies certificate validation weaknesses
- Can test mobile apps, API clients, IoT devices
- Requires configuring client to connect to sslcaudit
- Python-based tool
- Helps identify MITM vulnerability in SSL clients
- Complements sslscan and sslyze (which test servers)