# validate-certs.bro error

**URL:** <https://community.zeek.org/t/validate-certs-bro-error/2004>\
**Category:** Development\
**Tags:** development\
**Created:** [August 31, 2011, 3:40pm UTC](https://community.zeek.org/t/validate-certs-bro-error/2004 "2011-08-31T15:40:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Martin\_Holste](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@Martin\_Holste](https://community.zeek.org/u/Martin_Holste)\
**Post date:** [August 31, 2011, 3:40pm UTC](https://community.zeek.org/t/validate-certs-bro-error/2004/1 "2011-08-31T15:40:39Z")

</div>

Fatal from git rev 005b150:  
1314803689.614709 internal error in  
/usr/local/bro-005b150/share/bro/policy/protocols/ssl/validate-certs.bro,  
line 20: field value missing (SSL::c$ssl)  
Aborted

Looks like a basic case where a sub-hash key is being accessed without  
verify the parent hash key exists. I think I fixed with:  
if ( !c?$ssl || !c$ssl?$cert || !c$ssl?$cert\_chain )

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [August 31, 2011, 3:54pm UTC](https://community.zeek.org/t/validate-certs-bro-error/2004/2 "2011-08-31T15:54:22Z")

</div>

Sorry about that, I've had it fixed locally for a few days but I'm trying to finish up some automatic notice deduplication code before I commit it because I'm modifying some other SSL scripts to use the notice dedup-ing.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![Martin\_Holste](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@Martin\_Holste](https://community.zeek.org/u/Martin_Holste)\
**Post date:** [September 7, 2011, 5:06pm UTC](https://community.zeek.org/t/validate-certs-bro-error/2004/3 "2011-09-07T17:06:13Z")

</div>

Looks like this fix didn't make it into the current trunk:

1315414623.768835 internal error in  
/usr/local/bro-eds2245/share/bro/policy/protocols/ssl/validate-certs.bro,  
line 20: field value missing (SSL::c$ssl)

Line 20: if ( !c$ssl?$cert || !c$ssl?$cert\_chain )

---

<div class="post-metadata">

**Author:** ![Seth\_Hall3](https://avatars.discourse-cdn.com/v4/letter/s/d6d6ee/32.png) [@Seth\_Hall3](https://community.zeek.org/u/Seth_Hall3)\
**Post date:** [September 7, 2011, 5:52pm UTC](https://community.zeek.org/t/validate-certs-bro-error/2004/4 "2011-09-07T17:52:48Z")

</div>

I implemented it as part of a larger change that hasn't been committed yet. I'll commit it separately right now.

&nbsp;&nbsp;.Seth

---

<div class="post-metadata">

**Author:** ![system](https://canada1.discourse-cdn.com/flex011/uploads/zeek/original/1X/f09d732bc2cc7c7cc7e35db67cf4e1d5233ce7a7.png) [@system](https://community.zeek.org/u/system)\
**Post date:** [May 6, 2022, 3:39pm UTC](https://community.zeek.org/t/validate-certs-bro-error/2004/5 "2022-05-06T15:39:48Z")

</div>


