Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

X509 folder move, table improvement, update for v1.4.0 #104

Merged
merged 12 commits into from
Mar 26, 2025

Conversation

JW-Corelight
Copy link
Contributor

Move x509 folder under version folder and reorg README table structure for consistency with other logs.

@mavam
Copy link
Contributor

mavam commented Jan 29, 2025

How did you figure out the TLS extensions to map to?

@JW-Corelight
Copy link
Contributor Author

I think you're talking about the type values i gave the ones with type_id="99".
https://schema.ocsf.io/1.4.0-dev/objects/tls_extension

I gave them the exact name of the field they're coming from, assuming that's how they work.

If I'm misuderstanding this, i'm happy to realign.

@mavam
Copy link
Contributor

mavam commented Jan 29, 2025

My understanding was that the TLS extension names comes from the RFC: https://datatracker.ietf.org/doc/html/rfc8446#page-35. At least that's where the schema links.

@JW-Corelight
Copy link
Contributor Author

After reviewing this again, I think I'm seeing what you're saying here @mavam

The TLS Extensions are used by the TLS protocol while the connection is set up, while the 'other' Zeek fields I'm attempting to fit into there are really just details about the cert itself. They seem to belong in the tls.certificate object instead of tls.tls_extension_list

@JW-Corelight JW-Corelight merged commit 666f251 into ocsf:main Mar 26, 2025
@JW-Corelight JW-Corelight deleted the x509 branch March 26, 2025 18:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants