Stop skipping stray HelloRequests.

This makes sense to do if we are a client and initiate a renegotiation
at the same time as the server requesting one. Since we will never
initiate a renegotiation, this should not be necessary.

Change-Id: I5835944291fdb8dfcc4fed2ebf1064e91ccdbe6a
Reviewed-on: https://boringssl-review.googlesource.com/13825
Reviewed-by: Steven Valdez <svaldez@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
CQ-Verified: CQ bot account: commit-bot@chromium.org <commit-bot@chromium.org>
This commit is contained in:
David Benjamin
2017-02-13 19:44:22 +00:00
committed by CQ bot account: commit-bot@chromium.org
parent 040bc4944b
commit 07ab5d44d9
2 changed files with 5 additions and 12 deletions
-11
View File
@@ -678,7 +678,6 @@ static int read_v2_client_hello(SSL *ssl) {
}
int ssl3_get_message(SSL *ssl) {
again:
/* Re-create the handshake buffer if needed. */
if (ssl->init_buf == NULL) {
ssl->init_buf = BUF_MEM_new();
@@ -733,16 +732,6 @@ again:
ssl->s3->tmp.message_type = ((const uint8_t *)ssl->init_buf->data)[0];
ssl->init_msg = (uint8_t*)ssl->init_buf->data + SSL3_HM_HEADER_LENGTH;
ssl->init_num = ssl->init_buf->length - SSL3_HM_HEADER_LENGTH;
/* Ignore stray HelloRequest messages in the handshake before TLS 1.3. Per RFC
* 5246, section 7.4.1.1, the server may send HelloRequest at any time. */
if (!ssl->server && SSL_in_init(ssl) &&
(!ssl->s3->have_version || ssl3_protocol_version(ssl) < TLS1_3_VERSION) &&
ssl->s3->tmp.message_type == SSL3_MT_HELLO_REQUEST &&
ssl->init_num == 0) {
goto again;
}
return 1;
}
+5 -1
View File
@@ -6395,7 +6395,7 @@ func addRenegotiationTests() {
// this case. https://crbug.com/boringssl/130
})
// Stray HelloRequests during the handshake are ignored in TLS 1.2.
// We reject stray HelloRequests during the handshake in TLS 1.2.
testCases = append(testCases, testCase{
name: "StrayHelloRequest",
config: Config{
@@ -6404,6 +6404,8 @@ func addRenegotiationTests() {
SendHelloRequestBeforeEveryHandshakeMessage: true,
},
},
shouldFail: true,
expectedError: ":UNEXPECTED_MESSAGE:",
})
testCases = append(testCases, testCase{
name: "StrayHelloRequest-Packed",
@@ -6414,6 +6416,8 @@ func addRenegotiationTests() {
SendHelloRequestBeforeEveryHandshakeMessage: true,
},
},
shouldFail: true,
expectedError: ":UNEXPECTED_MESSAGE:",
})
// Test renegotiation works if HelloRequest and server Finished come in