SSL Server Hello Extensions are missed by Bro

Description

When I run this against any TLS pcap:

event ssl_extension(c: connection, is_orig: bool, code: count, val: string)
{
if ( is_orig=F ) {
print cat(code);
}
}

event ssl_extension_ec_point_formats(c: connection, is_orig: bool, point_formats: index_vec)
{
if (is_orig=F ) {
for ( i in point_formats ) {
print cat(point_formats[i]);
}
}
}

I'm not getting any results. When I switch the is_orig to T (looking at the client hello packet) I get all of the expected results for the client. It doesn't look like these events are working for the extensions within server hello packets.

Environment

None

Assignee

Unassigned

Reporter

John Althouse

Labels

External issue ID

None

Components

Affects versions

Priority

Normal
Configure