diff --git a/ssl/t1_lib.c b/ssl/t1_lib.c index 5975f7006..39627eb40 100644 --- a/ssl/t1_lib.c +++ b/ssl/t1_lib.c @@ -954,7 +954,7 @@ uint8_t *ssl_add_clienthello_tlsext(SSL *s, uint8_t *buf, uint8_t *limit, } } - if (SSL_USE_SIGALGS(s)) { + if (ssl3_version_from_wire(s, s->client_version) >= TLS1_2_VERSION) { size_t salglen; const uint8_t *salg; salglen = tls12_get_psigalgs(s, &salg); diff --git a/ssl/test/runner/handshake_server.go b/ssl/test/runner/handshake_server.go index 284f31437..2b1b552f9 100644 --- a/ssl/test/runner/handshake_server.go +++ b/ssl/test/runner/handshake_server.go @@ -172,6 +172,11 @@ func (hs *serverHandshakeState) readClientHello() (isResume bool, err error) { } c.clientVersion = hs.clientHello.vers + // Reject < 1.2 ClientHellos with signature_algorithms. + if c.clientVersion < VersionTLS12 && len(hs.clientHello.signatureAndHashes) > 0 { + return false, fmt.Errorf("tls: client included signature_algorithms before TLS 1.2") + } + c.vers, ok = config.mutualVersion(hs.clientHello.vers) if !ok { c.sendAlert(alertProtocolVersion)