Latest update.
This commit is contained in:
+10
-3
@@ -348,10 +348,12 @@ static const EXTENSION_DEFINITION ext_defs[] = {
|
||||
{
|
||||
/*
|
||||
* Special unsolicited ServerHello extension only used when
|
||||
* SSL_OP_CRYPTOPRO_TLSEXT_BUG is set
|
||||
* SSL_OP_CRYPTOPRO_TLSEXT_BUG is set. We allow it in a ClientHello but
|
||||
* ignore it.
|
||||
*/
|
||||
TLSEXT_TYPE_cryptopro_bug,
|
||||
SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_2_AND_BELOW_ONLY,
|
||||
SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO
|
||||
| SSL_EXT_TLS1_2_AND_BELOW_ONLY,
|
||||
NULL, NULL, NULL, tls_construct_stoc_cryptopro_bug, NULL, NULL
|
||||
},
|
||||
{
|
||||
@@ -623,7 +625,12 @@ int tls_collect_extensions(SSL *s, PACKET *packet, unsigned int context,
|
||||
&& type != TLSEXT_TYPE_cookie
|
||||
&& type != TLSEXT_TYPE_renegotiate
|
||||
&& type != TLSEXT_TYPE_signed_certificate_timestamp
|
||||
&& (s->ext.extflags[idx] & SSL_EXT_FLAG_SENT) == 0) {
|
||||
&& (s->ext.extflags[idx] & SSL_EXT_FLAG_SENT) == 0
|
||||
#ifndef OPENSSL_NO_GOST
|
||||
&& !((context & SSL_EXT_TLS1_2_SERVER_HELLO) != 0
|
||||
&& type == TLSEXT_TYPE_cryptopro_bug)
|
||||
#endif
|
||||
) {
|
||||
SSLfatal(s, SSL_AD_UNSUPPORTED_EXTENSION,
|
||||
SSL_F_TLS_COLLECT_EXTENSIONS, SSL_R_UNSOLICITED_EXTENSION);
|
||||
goto err;
|
||||
|
||||
@@ -1112,13 +1112,6 @@ int tls_construct_client_hello(SSL *s, WPACKET *pkt)
|
||||
SSL_SESSION *sess = s->session;
|
||||
unsigned char *session_id;
|
||||
|
||||
if (!WPACKET_set_max_size(pkt, SSL3_RT_MAX_PLAIN_LENGTH)) {
|
||||
/* Should not happen */
|
||||
SSLfatal(s, SSL_AD_INTERNAL_ERROR,
|
||||
SSL_F_TLS_CONSTRUCT_CLIENT_HELLO, ERR_R_INTERNAL_ERROR);
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Work out what SSL/TLS/DTLS version to use */
|
||||
protverr = ssl_set_client_hello_version(s);
|
||||
if (protverr != 0) {
|
||||
|
||||
Reference in New Issue
Block a user