summaryrefslogtreecommitdiff
path: root/src/lib/libssl/ssl_clnt.c
diff options
context:
space:
mode:
authorjsing <>2021-06-27 18:15:35 +0000
committerjsing <>2021-06-27 18:15:35 +0000
commitb109677d03c0eb1062f19ab300b485b90c0c2ad7 (patch)
tree42013562216a12affa5986c4c490d1a5738f1bee /src/lib/libssl/ssl_clnt.c
parentca8c2e09b0f4c1b2fe04fdd1a80b941378a2290f (diff)
downloadopenbsd-b109677d03c0eb1062f19ab300b485b90c0c2ad7.tar.gz
openbsd-b109677d03c0eb1062f19ab300b485b90c0c2ad7.tar.bz2
openbsd-b109677d03c0eb1062f19ab300b485b90c0c2ad7.zip
Change ssl_sigalgs_from_value() to perform sigalg list selection.
Rather that passing in a sigalg list at every call site, pass in the appropriate TLS version and have ssl_sigalgs_from_value() perform the sigalg list selection itself. This allows the sigalg lists to be made internal to the sigalgs code. ok tb@
Diffstat (limited to 'src/lib/libssl/ssl_clnt.c')
-rw-r--r--src/lib/libssl/ssl_clnt.c7
1 files changed, 4 insertions, 3 deletions
diff --git a/src/lib/libssl/ssl_clnt.c b/src/lib/libssl/ssl_clnt.c
index c092fe4c89..fac30b26aa 100644
--- a/src/lib/libssl/ssl_clnt.c
+++ b/src/lib/libssl/ssl_clnt.c
@@ -1,4 +1,4 @@
1/* $OpenBSD: ssl_clnt.c,v 1.100 2021/06/27 18:09:07 jsing Exp $ */ 1/* $OpenBSD: ssl_clnt.c,v 1.101 2021/06/27 18:15:35 jsing Exp $ */
2/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) 2/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
3 * All rights reserved. 3 * All rights reserved.
4 * 4 *
@@ -1550,8 +1550,9 @@ ssl3_get_server_key_exchange(SSL *s)
1550 1550
1551 if (!CBS_get_u16(&cbs, &sigalg_value)) 1551 if (!CBS_get_u16(&cbs, &sigalg_value))
1552 goto decode_err; 1552 goto decode_err;
1553 if ((sigalg = ssl_sigalg_from_value(sigalg_value, 1553 if ((sigalg = ssl_sigalg_from_value(
1554 tls12_sigalgs, tls12_sigalgs_len)) == NULL) { 1554 S3I(s)->hs.negotiated_tls_version,
1555 sigalg_value)) == NULL) {
1555 SSLerror(s, SSL_R_UNKNOWN_DIGEST); 1556 SSLerror(s, SSL_R_UNKNOWN_DIGEST);
1556 al = SSL_AD_DECODE_ERROR; 1557 al = SSL_AD_DECODE_ERROR;
1557 goto fatal_err; 1558 goto fatal_err;