Send an alert if we fail to pick a signature algorithm.

Change-Id: Id7f5ef9932c4c491bd15085e3c604ebfcf259b7c
Reviewed-on: https://boringssl-review.googlesource.com/29665
Commit-Queue: David Benjamin <davidben@google.com>
CQ-Verified: CQ bot account: commit-bot@chromium.org <commit-bot@chromium.org>
Reviewed-by: David Benjamin <davidben@google.com>
This commit is contained in:
Adam Langley
2018-07-10 15:38:12 +00:00
committed by CQ bot account: commit-bot@chromium.org
parent 428fb3ad52
commit e0afc85719
4 changed files with 17 additions and 8 deletions
+1
View File
@@ -1350,6 +1350,7 @@ static enum ssl_hs_wait_t do_send_client_certificate_verify(SSL_HANDSHAKE *hs) {
uint16_t signature_algorithm;
if (!tls1_choose_signature_algorithm(hs, &signature_algorithm)) {
ssl_send_alert(ssl, SSL3_AL_FATAL, SSL_AD_HANDSHAKE_FAILURE);
return ssl_hs_error;
}
if (ssl_protocol_version(ssl) >= TLS1_2_VERSION) {
+1
View File
@@ -861,6 +861,7 @@ static enum ssl_hs_wait_t do_send_server_key_exchange(SSL_HANDSHAKE *hs) {
// Determine the signature algorithm.
uint16_t signature_algorithm;
if (!tls1_choose_signature_algorithm(hs, &signature_algorithm)) {
ssl_send_alert(ssl, SSL3_AL_FATAL, SSL_AD_HANDSHAKE_FAILURE);
return ssl_hs_error;
}
if (ssl_protocol_version(ssl) >= TLS1_2_VERSION) {
+14 -8
View File
@@ -2812,7 +2812,7 @@ read alert 1 0
messageCount: 5,
keyUpdateRequest: keyUpdateRequested,
readWithUnfinishedWrite: true,
flags: []string{"-async"},
flags: []string{"-async"},
},
{
name: "SendSNIWarningAlert",
@@ -8644,12 +8644,14 @@ func addSignatureAlgorithmTests() {
shouldVerifyFail = true
}
var signError, verifyError string
var signError, signLocalError, verifyError, verifyLocalError string
if shouldSignFail {
signError = ":NO_COMMON_SIGNATURE_ALGORITHMS:"
signLocalError = "remote error: handshake failure"
}
if shouldVerifyFail {
verifyError = ":WRONG_SIGNATURE_TYPE:"
verifyLocalError = "remote error"
}
suffix := "-" + alg.name + "-" + ver.name
@@ -8674,6 +8676,7 @@ func addSignatureAlgorithmTests() {
tls13Variant: ver.tls13Variant,
shouldFail: shouldSignFail,
expectedError: signError,
expectedLocalError: signLocalError,
expectedPeerSignatureAlgorithm: alg.id,
})
@@ -8702,9 +8705,10 @@ func addSignatureAlgorithmTests() {
},
// Resume the session to assert the peer signature
// algorithm is reported on both handshakes.
resumeSession: !shouldVerifyFail,
shouldFail: shouldVerifyFail,
expectedError: verifyError,
resumeSession: !shouldVerifyFail,
shouldFail: shouldVerifyFail,
expectedError: verifyError,
expectedLocalError: verifyLocalError,
})
testCases = append(testCases, testCase{
@@ -8728,6 +8732,7 @@ func addSignatureAlgorithmTests() {
},
shouldFail: shouldSignFail,
expectedError: signError,
expectedLocalError: signLocalError,
expectedPeerSignatureAlgorithm: alg.id,
})
@@ -8755,9 +8760,10 @@ func addSignatureAlgorithmTests() {
},
// Resume the session to assert the peer signature
// algorithm is reported on both handshakes.
resumeSession: !shouldVerifyFail,
shouldFail: shouldVerifyFail,
expectedError: verifyError,
resumeSession: !shouldVerifyFail,
shouldFail: shouldVerifyFail,
expectedError: verifyError,
expectedLocalError: verifyLocalError,
})
if !shouldVerifyFail {
+1
View File
@@ -537,6 +537,7 @@ enum ssl_private_key_result_t tls13_add_certificate_verify(SSL_HANDSHAKE *hs) {
SSL *const ssl = hs->ssl;
uint16_t signature_algorithm;
if (!tls1_choose_signature_algorithm(hs, &signature_algorithm)) {
ssl_send_alert(ssl, SSL3_AL_FATAL, SSL_AD_HANDSHAKE_FAILURE);
return ssl_private_key_failure;
}