DTLS version negotiation doesn't happen at HelloVerifyRequest.
RFC 6347 changed the meaning of server_version in HelloVerifyRequest. It should now always be 1.0 with version negotiation not happening until ServerHello. Fix runner.go logic and remove #if-0'd code in dtls1_get_hello_verify. Enforce this in the runner for when we get DTLS 1.2 tests. Change-Id: Ice83628798a231df6bf268f66b4c47b14a519386 Reviewed-on: https://boringssl-review.googlesource.com/1552 Reviewed-by: Adam Langley <agl@google.com>
This commit is contained in:
committed by
Adam Langley
parent
f2fedefdca
commit
8bc38f556a
@@ -622,16 +622,6 @@ static int dtls1_get_hello_verify(SSL *s)
|
||||
goto f_err;
|
||||
}
|
||||
|
||||
#if 0
|
||||
if (s->method->version != DTLS_ANY_VERSION && server_version != s->version)
|
||||
{
|
||||
OPENSSL_PUT_ERROR(SSL, dtls1_get_hello_verify, SSL_R_WRONG_SSL_VERSION);
|
||||
s->version=(s->version&0xff00)|data[1];
|
||||
al = SSL_AD_PROTOCOL_VERSION;
|
||||
goto f_err;
|
||||
}
|
||||
#endif
|
||||
|
||||
if (CBS_len(&cookie) > sizeof(s->d1->cookie))
|
||||
{
|
||||
al=SSL_AD_ILLEGAL_PARAMETER;
|
||||
|
||||
@@ -166,6 +166,13 @@ NextCipherSuite:
|
||||
if c.isDTLS {
|
||||
helloVerifyRequest, ok := msg.(*helloVerifyRequestMsg)
|
||||
if ok {
|
||||
if helloVerifyRequest.vers != VersionTLS10 {
|
||||
// Per RFC 6347, the version field in
|
||||
// HelloVerifyRequest SHOULD be always DTLS
|
||||
// 1.0. Enforce this for testing purposes.
|
||||
return errors.New("dtls: bad HelloVerifyRequest version")
|
||||
}
|
||||
|
||||
hello.raw = nil
|
||||
hello.cookie = helloVerifyRequest.cookie
|
||||
helloBytes = hello.marshal()
|
||||
|
||||
@@ -113,15 +113,12 @@ func (hs *serverHandshakeState) readClientHello() (isResume bool, err error) {
|
||||
c.sendAlert(alertUnexpectedMessage)
|
||||
return false, unexpectedMessageError(hs.clientHello, msg)
|
||||
}
|
||||
c.vers, ok = config.mutualVersion(hs.clientHello.vers)
|
||||
if !ok {
|
||||
c.sendAlert(alertProtocolVersion)
|
||||
return false, fmt.Errorf("tls: client offered an unsupported, maximum protocol version of %x", hs.clientHello.vers)
|
||||
}
|
||||
|
||||
if c.isDTLS && !config.Bugs.SkipHelloVerifyRequest {
|
||||
// Per RFC 6347, the version field in HelloVerifyRequest SHOULD
|
||||
// be always DTLS 1.0
|
||||
helloVerifyRequest := &helloVerifyRequestMsg{
|
||||
vers: c.vers,
|
||||
vers: VersionTLS10,
|
||||
cookie: make([]byte, 32),
|
||||
}
|
||||
if _, err := io.ReadFull(c.config.rand(), helloVerifyRequest.cookie); err != nil {
|
||||
@@ -158,8 +155,11 @@ func (hs *serverHandshakeState) readClientHello() (isResume bool, err error) {
|
||||
hs.clientHello = newClientHello
|
||||
}
|
||||
|
||||
// Do not set c.haveVers until after HelloVerifyRequest; the
|
||||
// retransmitted ClientHello may not have the final version.
|
||||
c.vers, ok = config.mutualVersion(hs.clientHello.vers)
|
||||
if !ok {
|
||||
c.sendAlert(alertProtocolVersion)
|
||||
return false, fmt.Errorf("tls: client offered an unsupported, maximum protocol version of %x", hs.clientHello.vers)
|
||||
}
|
||||
c.haveVers = true
|
||||
|
||||
hs.hello = new(serverHelloMsg)
|
||||
|
||||
Reference in New Issue
Block a user