Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It feels like ssldump has been abandoned and is horribly out-of-date. Is anybody maintaining it these days?


I use ssldump all the time; I don't think it's actively maintained, but it's not like it's broken. (The author of ssldump is one of the chairs of the TLS WG).


Last time I used it (quite a few months ago) it wasn't recognizing about half the fields in the SSL negotiation. It wasn't useless, but aside from its decryption-capabilities[1] wireshark had it beat because it could recognize and parse nearly all the fields.

[1] Wireshark might have that, but I haven't checked. I like to keep diversity in the tools I use.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: