DTLS version negotiation doesn't happen at HelloVerifyRequest.

RFC 6347 changed the meaning of server_version in HelloVerifyRequest. It should
now always be 1.0 with version negotiation not happening until ServerHello. Fix
runner.go logic and remove #if-0'd code in dtls1_get_hello_verify.

Enforce this in the runner for when we get DTLS 1.2 tests.

Change-Id: Ice83628798a231df6bf268f66b4c47b14a519386
Reviewed-on: https://boringssl-review.googlesource.com/1552
Reviewed-by: Adam Langley <agl@google.com>
This commit is contained in:
David Benjamin
2014-08-18 18:07:43 +00:00
committed by Adam Langley
parent f2fedefdca
commit 8bc38f556a
3 changed files with 15 additions and 18 deletions
-10
View File
@@ -622,16 +622,6 @@ static int dtls1_get_hello_verify(SSL *s)
goto f_err;
}
#if 0
if (s->method->version != DTLS_ANY_VERSION && server_version != s->version)
{
OPENSSL_PUT_ERROR(SSL, dtls1_get_hello_verify, SSL_R_WRONG_SSL_VERSION);
s->version=(s->version&0xff00)|data[1];
al = SSL_AD_PROTOCOL_VERSION;
goto f_err;
}
#endif
if (CBS_len(&cookie) > sizeof(s->d1->cookie))
{
al=SSL_AD_ILLEGAL_PARAMETER;
+7
View File
@@ -166,6 +166,13 @@ NextCipherSuite:
if c.isDTLS {
helloVerifyRequest, ok := msg.(*helloVerifyRequestMsg)
if ok {
if helloVerifyRequest.vers != VersionTLS10 {
// Per RFC 6347, the version field in
// HelloVerifyRequest SHOULD be always DTLS
// 1.0. Enforce this for testing purposes.
return errors.New("dtls: bad HelloVerifyRequest version")
}
hello.raw = nil
hello.cookie = helloVerifyRequest.cookie
helloBytes = hello.marshal()
+8 -8
View File
@@ -113,15 +113,12 @@ func (hs *serverHandshakeState) readClientHello() (isResume bool, err error) {
c.sendAlert(alertUnexpectedMessage)
return false, unexpectedMessageError(hs.clientHello, msg)
}
c.vers, ok = config.mutualVersion(hs.clientHello.vers)
if !ok {
c.sendAlert(alertProtocolVersion)
return false, fmt.Errorf("tls: client offered an unsupported, maximum protocol version of %x", hs.clientHello.vers)
}
if c.isDTLS && !config.Bugs.SkipHelloVerifyRequest {
// Per RFC 6347, the version field in HelloVerifyRequest SHOULD
// be always DTLS 1.0
helloVerifyRequest := &helloVerifyRequestMsg{
vers: c.vers,
vers: VersionTLS10,
cookie: make([]byte, 32),
}
if _, err := io.ReadFull(c.config.rand(), helloVerifyRequest.cookie); err != nil {
@@ -158,8 +155,11 @@ func (hs *serverHandshakeState) readClientHello() (isResume bool, err error) {
hs.clientHello = newClientHello
}
// Do not set c.haveVers until after HelloVerifyRequest; the
// retransmitted ClientHello may not have the final version.
c.vers, ok = config.mutualVersion(hs.clientHello.vers)
if !ok {
c.sendAlert(alertProtocolVersion)
return false, fmt.Errorf("tls: client offered an unsupported, maximum protocol version of %x", hs.clientHello.vers)
}
c.haveVers = true
hs.hello = new(serverHelloMsg)