JA3 rules in 171

Thank you @mfischer and everyone for upgrading Suricata to 6.X

While, I am aware of the JA3 issues in 5.x
https://bugzilla.ipfire.org/show_bug.cgi?id=12536

just wondering if JA3 is still not enabled in IPFire CU 171?

Looking at the documentation for suricata 6.0.x series it still mentions that to use JA3 you have to build suricate with libnss support so it looks like the problem still exists for the suricata 6.x family.

Looking at the documentation for suricata 7.x beta libnss is not mentioned at all. This might indicate that suricata 7.x will be using rust-crypto integrated in as the libnss reference must have been deliberately removed from the 7.x documentation.

1 Like