SSLCAUDIT
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
sslcaudit is a tool for automating testing of SSL/TLS clients. It acts as an SSL/TLS server presenting various certificates (self-signed, wrong CN, expired) to test how clients handle certificate validation errors.
BASIC USAGE#
sslcaudit # Start with defaults (port 8443) sslcaudit -l <listen_addr> # Listen on specific address
OPTIONS#
sslcaudit -l <addr:port> # Listen address:port sslcaudit -m <module> # Select test module sslcaudit --user-cert <cert> # Use specific certificate sslcaudit --user-key <key> # Use specific private key sslcaudit --user-ca-cert <ca> # Use specific CA certificate sslcaudit --user-ca-key <key> # Use specific CA key sslcaudit -N <cn> # Set server Common Name sslcaudit -T <timeout> # Connection timeout (seconds) sslcaudit -o <file> # Output results to file
TEST MODULES#
sslcaudit -m sslcert # SSL certificate tests sslcaudit -m sslproto # SSL/TLS protocol tests
CERTIFICATE TESTS#
# sslcaudit automatically tests clients with: # - Self-signed certificates # - Certificates with wrong Common Name # - Expired certificates # - Untrusted CA certificates # - Certificates matching target domain (generated) # - Valid certificates (baseline test)
EXAMPLES#
# Start on default port sslcaudit # Listen on specific port sslcaudit -l 0.0.0.0:4443 # Test with custom Common Name sslcaudit -N www.example.com # Use specific certificate sslcaudit --user-cert server.crt --user-key server.key # Save results sslcaudit -o /tmp/sslcaudit_results.txt # Custom timeout sslcaudit -l 0.0.0.0:8443 -T 10
WORKFLOW#
# 1. Start sslcaudit on a port # 2. Configure client to connect to sslcaudit # 3. sslcaudit presents various bad certificates # 4. Observe if client accepts or rejects each certificate # 5. Review results to identify certificate validation issues # Clients that accept bad certificates are vulnerable to: # - Man-in-the-middle attacks # - SSL/TLS interception # - Certificate spoofing
INTERPRETING RESULTS#
# PASS = Client properly rejected bad certificate # FAIL = Client accepted bad certificate (vulnerability!) # # Test scenarios: # self-signed - Should be rejected # wrong-CN - Should be rejected # expired - Should be rejected # untrusted-CA - Should be rejected # matching-cert - Depends on CA trust
NOTES#
- Useful for testing custom SSL/TLS client implementations - Identifies certificate validation weaknesses - Can test mobile apps, API clients, IoT devices - Requires configuring client to connect to sslcaudit - Python-based tool - Helps identify MITM vulnerability in SSL clients - Complements sslscan and sslyze (which test servers)