diff options
Diffstat (limited to 'src/lib')
| -rw-r--r-- | src/lib/libssl/ssl_tlsext.c | 23 |
1 files changed, 17 insertions, 6 deletions
diff --git a/src/lib/libssl/ssl_tlsext.c b/src/lib/libssl/ssl_tlsext.c index 22c5e7d1b1..2755cbc92d 100644 --- a/src/lib/libssl/ssl_tlsext.c +++ b/src/lib/libssl/ssl_tlsext.c | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: ssl_tlsext.c,v 1.162 2026/06/08 12:05:25 tb Exp $ */ | 1 | /* $OpenBSD: ssl_tlsext.c,v 1.163 2026/06/14 15:47:49 jsing Exp $ */ |
| 2 | /* | 2 | /* |
| 3 | * Copyright (c) 2016, 2017, 2019 Joel Sing <jsing@openbsd.org> | 3 | * Copyright (c) 2016, 2017, 2019 Joel Sing <jsing@openbsd.org> |
| 4 | * Copyright (c) 2017 Doug Hogan <doug@openbsd.org> | 4 | * Copyright (c) 2017 Doug Hogan <doug@openbsd.org> |
| @@ -1501,7 +1501,7 @@ tlsext_keyshare_server_process(SSL *s, uint16_t msg_type, CBS *cbs, int *alert) | |||
| 1501 | const uint16_t *client_groups = NULL, *server_groups = NULL; | 1501 | const uint16_t *client_groups = NULL, *server_groups = NULL; |
| 1502 | size_t client_groups_len = 0, server_groups_len = 0; | 1502 | size_t client_groups_len = 0, server_groups_len = 0; |
| 1503 | size_t i, j, client_groups_index; | 1503 | size_t i, j, client_groups_index; |
| 1504 | int preferred_group_found = 0; | 1504 | int shared_group_found = 0; |
| 1505 | int decode_error; | 1505 | int decode_error; |
| 1506 | uint16_t client_preferred_group = 0; | 1506 | uint16_t client_preferred_group = 0; |
| 1507 | uint16_t group; | 1507 | uint16_t group; |
| @@ -1577,21 +1577,32 @@ tlsext_keyshare_server_process(SSL *s, uint16_t msg_type, CBS *cbs, int *alert) | |||
| 1577 | 1577 | ||
| 1578 | /* | 1578 | /* |
| 1579 | * Find the group that is most preferred by the client that | 1579 | * Find the group that is most preferred by the client that |
| 1580 | * we also support. | 1580 | * is also supported by the server. |
| 1581 | */ | 1581 | */ |
| 1582 | for (i = 0; i < client_groups_len && !preferred_group_found; i++) { | 1582 | for (i = 0; i < client_groups_len && !shared_group_found; i++) { |
| 1583 | if (!ssl_security_supported_group(s, client_groups[i])) | 1583 | if (!ssl_security_supported_group(s, client_groups[i])) |
| 1584 | continue; | 1584 | continue; |
| 1585 | for (j = 0; j < server_groups_len; j++) { | 1585 | for (j = 0; j < server_groups_len; j++) { |
| 1586 | if (server_groups[j] == client_groups[i]) { | 1586 | if (server_groups[j] == client_groups[i]) { |
| 1587 | /* XXX - this should be equivalent to tls1_check_group() */ | ||
| 1587 | client_preferred_group = client_groups[i]; | 1588 | client_preferred_group = client_groups[i]; |
| 1588 | s->s3->hs.tls13.server_group = client_preferred_group; | 1589 | s->s3->hs.tls13.server_group = client_preferred_group; |
| 1589 | preferred_group_found = 1; | 1590 | shared_group_found = 1; |
| 1590 | break; | 1591 | break; |
| 1591 | } | 1592 | } |
| 1592 | } | 1593 | } |
| 1593 | } | 1594 | } |
| 1594 | 1595 | ||
| 1596 | if (!shared_group_found) { | ||
| 1597 | /* | ||
| 1598 | * There are no supported groups that are shared between the | ||
| 1599 | * client and server - this is treated as a handshake failure | ||
| 1600 | * or as insufficient security - see RFC 8446 section 4.1.1. | ||
| 1601 | */ | ||
| 1602 | *alert = TLS13_ALERT_HANDSHAKE_FAILURE; | ||
| 1603 | return 0; | ||
| 1604 | } | ||
| 1605 | |||
| 1595 | if (!CBS_get_u16_length_prefixed(cbs, &client_shares)) | 1606 | if (!CBS_get_u16_length_prefixed(cbs, &client_shares)) |
| 1596 | return 0; | 1607 | return 0; |
| 1597 | 1608 | ||
| @@ -1637,7 +1648,7 @@ tlsext_keyshare_server_process(SSL *s, uint16_t msg_type, CBS *cbs, int *alert) | |||
| 1637 | * less preferred, and we choose to to use it instead of | 1648 | * less preferred, and we choose to to use it instead of |
| 1638 | * requesting the more preferred group. | 1649 | * requesting the more preferred group. |
| 1639 | */ | 1650 | */ |
| 1640 | if (!preferred_group_found || group != client_preferred_group) | 1651 | if (group != client_preferred_group) |
| 1641 | continue; | 1652 | continue; |
| 1642 | 1653 | ||
| 1643 | /* Decode and store the selected key share. */ | 1654 | /* Decode and store the selected key share. */ |
