diff options
Diffstat (limited to 'src')
| -rw-r--r-- | src/lib/libssl/tls13_handshake.c | 9 | ||||
| -rw-r--r-- | src/lib/libssl/tls13_internal.h | 3 | ||||
| -rw-r--r-- | src/lib/libssl/tls13_server.c | 25 |
3 files changed, 3 insertions, 34 deletions
diff --git a/src/lib/libssl/tls13_handshake.c b/src/lib/libssl/tls13_handshake.c index 1825bfbf6c..d3333a2e4a 100644 --- a/src/lib/libssl/tls13_handshake.c +++ b/src/lib/libssl/tls13_handshake.c | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: tls13_handshake.c,v 1.58 2020/05/09 16:43:05 tb Exp $ */ | 1 | /* $OpenBSD: tls13_handshake.c,v 1.59 2020/05/09 20:38:19 tb Exp $ */ |
| 2 | /* | 2 | /* |
| 3 | * Copyright (c) 2018-2019 Theo Buehler <tb@openbsd.org> | 3 | * Copyright (c) 2018-2019 Theo Buehler <tb@openbsd.org> |
| 4 | * Copyright (c) 2019 Joel Sing <jsing@openbsd.org> | 4 | * Copyright (c) 2019 Joel Sing <jsing@openbsd.org> |
| @@ -102,7 +102,6 @@ static const struct tls13_handshake_action state_machine[] = { | |||
| 102 | .sender = TLS13_HS_SERVER, | 102 | .sender = TLS13_HS_SERVER, |
| 103 | .send = tls13_server_hello_retry_request_send, | 103 | .send = tls13_server_hello_retry_request_send, |
| 104 | .recv = tls13_server_hello_retry_request_recv, | 104 | .recv = tls13_server_hello_retry_request_recv, |
| 105 | .sent = tls13_server_hello_retry_request_sent, | ||
| 106 | }, | 105 | }, |
| 107 | [SERVER_ENCRYPTED_EXTENSIONS] = { | 106 | [SERVER_ENCRYPTED_EXTENSIONS] = { |
| 108 | .handshake_type = TLS13_MT_ENCRYPTED_EXTENSIONS, | 107 | .handshake_type = TLS13_MT_ENCRYPTED_EXTENSIONS, |
| @@ -374,12 +373,6 @@ tls13_handshake_send_action(struct tls13_ctx *ctx, | |||
| 374 | if (action->sent != NULL && !action->sent(ctx)) | 373 | if (action->sent != NULL && !action->sent(ctx)) |
| 375 | return TLS13_IO_FAILURE; | 374 | return TLS13_IO_FAILURE; |
| 376 | 375 | ||
| 377 | if (ctx->send_dummy_ccs) { | ||
| 378 | if ((ret = tls13_send_dummy_ccs(ctx->rl)) != TLS13_IO_SUCCESS) | ||
| 379 | return ret; | ||
| 380 | ctx->send_dummy_ccs = 0; | ||
| 381 | } | ||
| 382 | |||
| 383 | return TLS13_IO_SUCCESS; | 376 | return TLS13_IO_SUCCESS; |
| 384 | } | 377 | } |
| 385 | 378 | ||
diff --git a/src/lib/libssl/tls13_internal.h b/src/lib/libssl/tls13_internal.h index e3aaf634c3..050ad15df8 100644 --- a/src/lib/libssl/tls13_internal.h +++ b/src/lib/libssl/tls13_internal.h | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: tls13_internal.h,v 1.71 2020/05/09 16:43:05 tb Exp $ */ | 1 | /* $OpenBSD: tls13_internal.h,v 1.72 2020/05/09 20:38:19 tb Exp $ */ |
| 2 | /* | 2 | /* |
| 3 | * Copyright (c) 2018 Bob Beck <beck@openbsd.org> | 3 | * Copyright (c) 2018 Bob Beck <beck@openbsd.org> |
| 4 | * Copyright (c) 2018 Theo Buehler <tb@openbsd.org> | 4 | * Copyright (c) 2018 Theo Buehler <tb@openbsd.org> |
| @@ -323,7 +323,6 @@ int tls13_server_hello_send(struct tls13_ctx *ctx, CBB *cbb); | |||
| 323 | int tls13_server_hello_sent(struct tls13_ctx *ctx); | 323 | int tls13_server_hello_sent(struct tls13_ctx *ctx); |
| 324 | int tls13_server_hello_retry_request_recv(struct tls13_ctx *ctx, CBS *cbs); | 324 | int tls13_server_hello_retry_request_recv(struct tls13_ctx *ctx, CBS *cbs); |
| 325 | int tls13_server_hello_retry_request_send(struct tls13_ctx *ctx, CBB *cbb); | 325 | int tls13_server_hello_retry_request_send(struct tls13_ctx *ctx, CBB *cbb); |
| 326 | int tls13_server_hello_retry_request_sent(struct tls13_ctx *ctx); | ||
| 327 | int tls13_server_encrypted_extensions_recv(struct tls13_ctx *ctx, CBS *cbs); | 326 | int tls13_server_encrypted_extensions_recv(struct tls13_ctx *ctx, CBS *cbs); |
| 328 | int tls13_server_encrypted_extensions_send(struct tls13_ctx *ctx, CBB *cbb); | 327 | int tls13_server_encrypted_extensions_send(struct tls13_ctx *ctx, CBB *cbb); |
| 329 | int tls13_server_certificate_recv(struct tls13_ctx *ctx, CBS *cbs); | 328 | int tls13_server_certificate_recv(struct tls13_ctx *ctx, CBS *cbs); |
diff --git a/src/lib/libssl/tls13_server.c b/src/lib/libssl/tls13_server.c index 5e2711d4d4..0b040fb51d 100644 --- a/src/lib/libssl/tls13_server.c +++ b/src/lib/libssl/tls13_server.c | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: tls13_server.c,v 1.39 2020/05/09 16:43:05 tb Exp $ */ | 1 | /* $OpenBSD: tls13_server.c,v 1.40 2020/05/09 20:38:19 tb Exp $ */ |
| 2 | /* | 2 | /* |
| 3 | * Copyright (c) 2019, 2020 Joel Sing <jsing@openbsd.org> | 3 | * Copyright (c) 2019, 2020 Joel Sing <jsing@openbsd.org> |
| 4 | * Copyright (c) 2020 Bob Beck <beck@openbsd.org> | 4 | * Copyright (c) 2020 Bob Beck <beck@openbsd.org> |
| @@ -335,20 +335,6 @@ tls13_server_hello_retry_request_send(struct tls13_ctx *ctx, CBB *cbb) | |||
| 335 | } | 335 | } |
| 336 | 336 | ||
| 337 | int | 337 | int |
| 338 | tls13_server_hello_retry_request_sent(struct tls13_ctx *ctx) | ||
| 339 | { | ||
| 340 | /* | ||
| 341 | * If the client has requested middlebox compatibility mode, | ||
| 342 | * we MUST send a dummy CCS following our first handshake message. | ||
| 343 | * See RFC 8446 Appendix D.4. | ||
| 344 | */ | ||
| 345 | if (ctx->hs->legacy_session_id_len > 0) | ||
| 346 | ctx->send_dummy_ccs = 1; | ||
| 347 | |||
| 348 | return 1; | ||
| 349 | } | ||
| 350 | |||
| 351 | int | ||
| 352 | tls13_client_hello_retry_recv(struct tls13_ctx *ctx, CBS *cbs) | 338 | tls13_client_hello_retry_recv(struct tls13_ctx *ctx, CBS *cbs) |
| 353 | { | 339 | { |
| 354 | SSL *s = ctx->ssl; | 340 | SSL *s = ctx->ssl; |
| @@ -382,15 +368,6 @@ tls13_server_hello_send(struct tls13_ctx *ctx, CBB *cbb) | |||
| 382 | int | 368 | int |
| 383 | tls13_server_hello_sent(struct tls13_ctx *ctx) | 369 | tls13_server_hello_sent(struct tls13_ctx *ctx) |
| 384 | { | 370 | { |
| 385 | /* | ||
| 386 | * If the client has requested middlebox compatibility mode, | ||
| 387 | * we MUST send a dummy CCS following our first handshake message. | ||
| 388 | * See RFC 8446 Appendix D.4. | ||
| 389 | */ | ||
| 390 | if ((ctx->handshake_stage.hs_type & WITHOUT_HRR) && | ||
| 391 | ctx->hs->legacy_session_id_len > 0) | ||
| 392 | ctx->send_dummy_ccs = 1; | ||
| 393 | |||
| 394 | return tls13_server_engage_record_protection(ctx); | 371 | return tls13_server_engage_record_protection(ctx); |
| 395 | } | 372 | } |
| 396 | 373 | ||
