What's the issue?
The WSTG-CRYP-01 is old and too verbose, too unusable from a testing perspective
How do we solve it?
Clearly section it to test for the weaknesses in the protocol implementations. A full re-write
@rbsec would you be able to lend a hand in this? I can definitely work alongside you on this.
Wow, that guide is.....definitely in need of a rewrite. My thoughts would be to try and align it with the transport layer security cheat sheet, so a structure something like:
Thoughts?
In the server config I'd add in the "other stuff" the redirections issues from HTTP to HTTPS.
I like it. It covers everything in terms of ensuring TLS security.
I thought about that - but then the main recommendation there is going to be around implementing HSTS - and that's already a separate check (WSTG-CONF-07).
Should these checks be included here as well, or does it make more sense for it to be somewhere else?
We can directly link to it, instead of explaining it.
@ThunderSon this issue can be closed now that #555 has been merged.
Most helpful comment
@ThunderSon this issue can be closed now that #555 has been merged.