Request contexts are now illegal during the handshake.

One less thing to keep track of.
https://github.com/tlswg/tls13-spec/pull/549 got merged.

Change-Id: Ide66e547140f8122a3b8013281be5215c11b6de0
Reviewed-on: https://boringssl-review.googlesource.com/10482
Reviewed-by: Steven Valdez <svaldez@google.com>
Reviewed-by: David Benjamin <davidben@google.com>
Commit-Queue: Steven Valdez <svaldez@google.com>
Commit-Queue: David Benjamin <davidben@google.com>
CQ-Verified: CQ bot account: commit-bot@chromium.org <commit-bot@chromium.org>
This commit is contained in:
David Benjamin
2016-08-18 15:40:40 +00:00
committed by CQ bot account: commit-bot@chromium.org
parent e73c7f4281
commit 8a8349b53e
7 changed files with 34 additions and 12 deletions
-3
View File
@@ -906,9 +906,6 @@ struct ssl_handshake_st {
uint8_t *public_key;
size_t public_key_len;
uint8_t *cert_context;
size_t cert_context_len;
uint8_t session_tickets_sent;
} /* SSL_HANDSHAKE */;
+4
View File
@@ -1049,6 +1049,10 @@ type ProtocolBugs struct {
// SendExtraFinished, if true, causes an extra Finished message to be
// sent.
SendExtraFinished bool
// SendRequestContext, if not empty, is the request context to send in
// a TLS 1.3 CertificateRequest.
SendRequestContext []byte
}
func (c *Config) serverInit() {
+4
View File
@@ -673,6 +673,10 @@ func (hs *clientHandshakeState) doTLS13Handshake() error {
var ok bool
certReq, ok = msg.(*certificateRequestMsg)
if ok {
if len(certReq.requestContext) != 0 {
return errors.New("tls: non-empty certificate request context sent in handshake")
}
if c.config.Bugs.IgnorePeerSignatureAlgorithmPreferences {
certReq.signatureAlgorithms = c.config.signSignatureAlgorithms()
}
+1
View File
@@ -596,6 +596,7 @@ Curves:
certReq := &certificateRequestMsg{
hasSignatureAlgorithm: true,
hasRequestContext: true,
requestContext: config.Bugs.SendRequestContext,
}
if !config.Bugs.NoSignatureAlgorithms {
certReq.signatureAlgorithms = config.verifySignatureAlgorithms()
+20 -2
View File
@@ -3125,7 +3125,7 @@ func addStateMachineCoverageTests(config stateMachineTestConfig) {
MaxVersion: VersionTLS13,
MinVersion: VersionTLS13,
},
resumeSession: true,
resumeSession: true,
})
tests = append(tests, testCase{
@@ -3135,7 +3135,7 @@ func addStateMachineCoverageTests(config stateMachineTestConfig) {
MaxVersion: VersionTLS13,
MinVersion: VersionTLS13,
},
resumeSession: true,
resumeSession: true,
})
tests = append(tests, testCase{
@@ -8007,6 +8007,24 @@ func addTLS13HandshakeTests() {
shouldFail: true,
expectedError: ":WRONG_CURVE:",
})
testCases = append(testCases, testCase{
name: "TLS13-RequestContextInHandshake",
config: Config{
MaxVersion: VersionTLS13,
MinVersion: VersionTLS13,
ClientAuth: RequireAnyClientCert,
Bugs: ProtocolBugs{
SendRequestContext: []byte("request context"),
},
},
flags: []string{
"-cert-file", path.Join(*resourceDir, rsaCertificateFile),
"-key-file", path.Join(*resourceDir, rsaKeyFile),
},
shouldFail: true,
expectedError: ":DECODE_ERROR:",
})
}
func worker(statusChan chan statusMsg, c chan *testCase, shimPath string, wg *sync.WaitGroup) {
+3 -5
View File
@@ -63,7 +63,6 @@ void ssl_handshake_free(SSL_HANDSHAKE *hs) {
ssl_handshake_clear_groups(hs);
OPENSSL_free(hs->key_share_bytes);
OPENSSL_free(hs->public_key);
OPENSSL_free(hs->cert_context);
OPENSSL_free(hs);
}
@@ -329,11 +328,10 @@ int tls13_process_finished(SSL *ssl) {
}
int tls13_prepare_certificate(SSL *ssl) {
CBB cbb, body, context;
CBB cbb, body;
if (!ssl->method->init_message(ssl, &cbb, &body, SSL3_MT_CERTIFICATE) ||
!CBB_add_u8_length_prefixed(&body, &context) ||
!CBB_add_bytes(&context, ssl->s3->hs->cert_context,
ssl->s3->hs->cert_context_len) ||
/* The request context is always empty in the handshake. */
!CBB_add_u8(&body, 0) ||
!ssl_add_cert_chain(ssl, &body) ||
!ssl->method->finish_message(ssl, &cbb)) {
CBB_cleanup(&cbb);
+2 -2
View File
@@ -394,8 +394,8 @@ static enum ssl_hs_wait_t do_process_certificate_request(SSL *ssl,
CBS cbs, context, supported_signature_algorithms;
CBS_init(&cbs, ssl->init_msg, ssl->init_num);
if (!CBS_get_u8_length_prefixed(&cbs, &context) ||
!CBS_stow(&context, &ssl->s3->hs->cert_context,
&ssl->s3->hs->cert_context_len) ||
/* The request context is always empty during the handshake. */
CBS_len(&context) != 0 ||
!CBS_get_u16_length_prefixed(&cbs, &supported_signature_algorithms) ||
CBS_len(&supported_signature_algorithms) == 0 ||
!tls1_parse_peer_sigalgs(ssl, &supported_signature_algorithms)) {