Send an alert if we fail to pick a signature algorithm.
Change-Id: Id7f5ef9932c4c491bd15085e3c604ebfcf259b7c Reviewed-on: https://boringssl-review.googlesource.com/29665 Commit-Queue: David Benjamin <davidben@google.com> CQ-Verified: CQ bot account: commit-bot@chromium.org <commit-bot@chromium.org> Reviewed-by: David Benjamin <davidben@google.com>
This commit is contained in:
committed by
CQ bot account: commit-bot@chromium.org
parent
428fb3ad52
commit
e0afc85719
@@ -1350,6 +1350,7 @@ static enum ssl_hs_wait_t do_send_client_certificate_verify(SSL_HANDSHAKE *hs) {
|
||||
|
||||
uint16_t signature_algorithm;
|
||||
if (!tls1_choose_signature_algorithm(hs, &signature_algorithm)) {
|
||||
ssl_send_alert(ssl, SSL3_AL_FATAL, SSL_AD_HANDSHAKE_FAILURE);
|
||||
return ssl_hs_error;
|
||||
}
|
||||
if (ssl_protocol_version(ssl) >= TLS1_2_VERSION) {
|
||||
|
||||
@@ -861,6 +861,7 @@ static enum ssl_hs_wait_t do_send_server_key_exchange(SSL_HANDSHAKE *hs) {
|
||||
// Determine the signature algorithm.
|
||||
uint16_t signature_algorithm;
|
||||
if (!tls1_choose_signature_algorithm(hs, &signature_algorithm)) {
|
||||
ssl_send_alert(ssl, SSL3_AL_FATAL, SSL_AD_HANDSHAKE_FAILURE);
|
||||
return ssl_hs_error;
|
||||
}
|
||||
if (ssl_protocol_version(ssl) >= TLS1_2_VERSION) {
|
||||
|
||||
@@ -2812,7 +2812,7 @@ read alert 1 0
|
||||
messageCount: 5,
|
||||
keyUpdateRequest: keyUpdateRequested,
|
||||
readWithUnfinishedWrite: true,
|
||||
flags: []string{"-async"},
|
||||
flags: []string{"-async"},
|
||||
},
|
||||
{
|
||||
name: "SendSNIWarningAlert",
|
||||
@@ -8644,12 +8644,14 @@ func addSignatureAlgorithmTests() {
|
||||
shouldVerifyFail = true
|
||||
}
|
||||
|
||||
var signError, verifyError string
|
||||
var signError, signLocalError, verifyError, verifyLocalError string
|
||||
if shouldSignFail {
|
||||
signError = ":NO_COMMON_SIGNATURE_ALGORITHMS:"
|
||||
signLocalError = "remote error: handshake failure"
|
||||
}
|
||||
if shouldVerifyFail {
|
||||
verifyError = ":WRONG_SIGNATURE_TYPE:"
|
||||
verifyLocalError = "remote error"
|
||||
}
|
||||
|
||||
suffix := "-" + alg.name + "-" + ver.name
|
||||
@@ -8674,6 +8676,7 @@ func addSignatureAlgorithmTests() {
|
||||
tls13Variant: ver.tls13Variant,
|
||||
shouldFail: shouldSignFail,
|
||||
expectedError: signError,
|
||||
expectedLocalError: signLocalError,
|
||||
expectedPeerSignatureAlgorithm: alg.id,
|
||||
})
|
||||
|
||||
@@ -8702,9 +8705,10 @@ func addSignatureAlgorithmTests() {
|
||||
},
|
||||
// Resume the session to assert the peer signature
|
||||
// algorithm is reported on both handshakes.
|
||||
resumeSession: !shouldVerifyFail,
|
||||
shouldFail: shouldVerifyFail,
|
||||
expectedError: verifyError,
|
||||
resumeSession: !shouldVerifyFail,
|
||||
shouldFail: shouldVerifyFail,
|
||||
expectedError: verifyError,
|
||||
expectedLocalError: verifyLocalError,
|
||||
})
|
||||
|
||||
testCases = append(testCases, testCase{
|
||||
@@ -8728,6 +8732,7 @@ func addSignatureAlgorithmTests() {
|
||||
},
|
||||
shouldFail: shouldSignFail,
|
||||
expectedError: signError,
|
||||
expectedLocalError: signLocalError,
|
||||
expectedPeerSignatureAlgorithm: alg.id,
|
||||
})
|
||||
|
||||
@@ -8755,9 +8760,10 @@ func addSignatureAlgorithmTests() {
|
||||
},
|
||||
// Resume the session to assert the peer signature
|
||||
// algorithm is reported on both handshakes.
|
||||
resumeSession: !shouldVerifyFail,
|
||||
shouldFail: shouldVerifyFail,
|
||||
expectedError: verifyError,
|
||||
resumeSession: !shouldVerifyFail,
|
||||
shouldFail: shouldVerifyFail,
|
||||
expectedError: verifyError,
|
||||
expectedLocalError: verifyLocalError,
|
||||
})
|
||||
|
||||
if !shouldVerifyFail {
|
||||
|
||||
@@ -537,6 +537,7 @@ enum ssl_private_key_result_t tls13_add_certificate_verify(SSL_HANDSHAKE *hs) {
|
||||
SSL *const ssl = hs->ssl;
|
||||
uint16_t signature_algorithm;
|
||||
if (!tls1_choose_signature_algorithm(hs, &signature_algorithm)) {
|
||||
ssl_send_alert(ssl, SSL3_AL_FATAL, SSL_AD_HANDSHAKE_FAILURE);
|
||||
return ssl_private_key_failure;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user