diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c index eb2865661..fbed5482b 100644 --- a/ssl/ssl_ciph.c +++ b/ssl/ssl_ciph.c @@ -761,20 +761,8 @@ static int ssl_cipher_process_rulestr(const char *rule_str, { rule = CIPHER_DEL; l++; } else if (ch == '+') { rule = CIPHER_ORD; l++; } - else if (ch == '!' && has_group) - { - OPENSSL_PUT_ERROR(SSL, ssl_cipher_process_rulestr, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS); - retval = found = in_group = 0; - break; - } else if (ch == '!') { rule = CIPHER_KILL; l++; } - else if (ch == '@' && has_group) - { - OPENSSL_PUT_ERROR(SSL, ssl_cipher_process_rulestr, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS); - retval = found = in_group = 0; - break; - } else if (ch == '@') { rule = CIPHER_SPECIAL; l++; } else if (ch == '[') @@ -793,6 +781,16 @@ static int ssl_cipher_process_rulestr(const char *rule_str, else { rule = CIPHER_ADD; } + /* If preference groups are enabled, the only legal + * operator is +. Otherwise the in_group bits will get + * mixed up. */ + if (has_group && rule != CIPHER_ADD) + { + OPENSSL_PUT_ERROR(SSL, ssl_cipher_process_rulestr, SSL_R_MIXED_SPECIAL_OPERATOR_WITH_GROUPS); + retval = found = in_group = 0; + break; + } + if (ITEM_SEP(ch)) { l++; diff --git a/ssl/ssl_test.c b/ssl/ssl_test.c index 19f7efd70..68889a0a2 100644 --- a/ssl/ssl_test.c +++ b/ssl/ssl_test.c @@ -179,6 +179,11 @@ static const char *kBadRules[] = { "BOGUS", /* Invalid command. */ "?BAR", + /* Special operators are not allowed if groups are used. */ + "[ECDHE-RSA-CHACHA20-POLY1305|ECDHE-RSA-AES128-GCM-SHA256]:+FOO", + "[ECDHE-RSA-CHACHA20-POLY1305|ECDHE-RSA-AES128-GCM-SHA256]:!FOO", + "[ECDHE-RSA-CHACHA20-POLY1305|ECDHE-RSA-AES128-GCM-SHA256]:-FOO", + "[ECDHE-RSA-CHACHA20-POLY1305|ECDHE-RSA-AES128-GCM-SHA256]:@STRENGTH", NULL, };