I have stumbled across this a while ago and it slipped my mind. Since some people in our community noticed missing JA3 support as well - which is required for some rather new rulesets, particularly those provided by abuse.ch - I create this ticket as a reminder for myself. See also: https://community.ipfire.org/t/suricata-service-fails-errcode-sc-warn-ja3-disabled-309/3470
Patch has been sent to the development mailing list: https://patchwork.ipfire.org/patch/3612/
@Stefan: Thanks for taking care of this. :-)
https://git.ipfire.org/?p=ipfire-2.x.git;a=commit;h=0937bd9c01fd4c56fdee688e887958dc72a9b03b
Does not work, see bug 12536.
I think we can close this because JA3 require NSS which we won't package for IPFire. Future versions of suricata will replace this part and use Rust, so the dependency on nss will go away eventually.