update main-with-bazel from master branch
This commit is contained in:
@@ -2779,7 +2779,6 @@ static bool ext_delegated_credential_parse_clienthello(SSL_HANDSHAKE *hs,
|
||||
return false;
|
||||
}
|
||||
|
||||
hs->delegated_credential_requested = true;
|
||||
return true;
|
||||
}
|
||||
|
||||
|
||||
@@ -134,7 +134,6 @@ SSL_HANDSHAKE::SSL_HANDSHAKE(SSL *ssl_arg)
|
||||
cert_request(false),
|
||||
certificate_status_expected(false),
|
||||
ocsp_stapling_requested(false),
|
||||
delegated_credential_requested(false),
|
||||
should_ack_sni(false),
|
||||
in_false_start(false),
|
||||
in_early_data(false),
|
||||
|
||||
+2
-5
@@ -1925,7 +1925,8 @@ struct SSL_HANDSHAKE {
|
||||
Array<uint16_t> peer_supported_group_list;
|
||||
|
||||
// peer_delegated_credential_sigalgs are the signature algorithms the peer
|
||||
// supports with delegated credentials.
|
||||
// supports with delegated credentials, or empty if the peer does not support
|
||||
// delegated credentials.
|
||||
Array<uint16_t> peer_delegated_credential_sigalgs;
|
||||
|
||||
// peer_key is the peer's ECDH key for a TLS 1.2 client.
|
||||
@@ -2035,10 +2036,6 @@ struct SSL_HANDSHAKE {
|
||||
// ocsp_stapling_requested is true if a client requested OCSP stapling.
|
||||
bool ocsp_stapling_requested : 1;
|
||||
|
||||
// delegated_credential_requested is true if the peer indicated support for
|
||||
// the delegated credential extension.
|
||||
bool delegated_credential_requested : 1;
|
||||
|
||||
// should_ack_sni is used by a server and indicates that the SNI extension
|
||||
// should be echoed in the ServerHello.
|
||||
bool should_ack_sni : 1;
|
||||
|
||||
+1
-3
@@ -810,9 +810,7 @@ static bool ssl_can_serve_dc(const SSL_HANDSHAKE *hs) {
|
||||
|
||||
bool ssl_signing_with_dc(const SSL_HANDSHAKE *hs) {
|
||||
// We only support delegated credentials as a server.
|
||||
return hs->ssl->server &&
|
||||
hs->delegated_credential_requested &&
|
||||
ssl_can_serve_dc(hs);
|
||||
return hs->ssl->server && ssl_can_serve_dc(hs);
|
||||
}
|
||||
|
||||
static int cert_set_dc(CERT *cert, CRYPTO_BUFFER *const raw, EVP_PKEY *privkey,
|
||||
|
||||
Reference in New Issue
Block a user