Ever wonder if any of your users connect to sites with bad SSL certificates? I ran into this issue recently when debugging some SSL issues, and ended up with this quick tshark and shell script trick to extract the necessary information from a packet capture here......https://isc.sans.edu/forums/diary/Who+got+the+bad+SSL+Certificate+Using+tshark+to+analyze+the+SSL+handshake/19455/
↧