Re: Framing and control-frame continuations

On Thu, Feb 07, 2013 at 12:47:08AM +1300, Amos Jeffries wrote:

> Magic" below.  I've been holding this off while I try to figure out
> what bit ranges the TLS handshakes are detectible with. It seems
> 32-bits is required if we merge TLS port 443 traffic into this
> magic, but I'm not yet completely certain of that.

AFAIK, the first bytes from client in current TLS connections are:

0x16 (Handshake packet)
0x03 (SSLv3 or TLS v1.x)
0x00-0x03 (At least until TLSv1.3 appears, that would use 0x04).

Then there's the SSLv2 compatiblity handshake. Hope nothing uses
that anymore.

-Ilari

Received on Wednesday, 6 February 2013 17:06:52 UTC