aboutsummaryrefslogtreecommitdiffstats
path: root/src/lib/pubkey/cecpq1
diff options
context:
space:
mode:
authorJack Lloyd <[email protected]>2017-06-04 05:17:54 -0400
committerJack Lloyd <[email protected]>2017-06-04 05:17:54 -0400
commitd6e7c9ea7f029026d84ce2828a26310dd9882679 (patch)
tree0304f0cda9c683f160e626f274deb00b5a2e6966 /src/lib/pubkey/cecpq1
parent41b1e738dbcbf2c33b418d2da235a56ad11feb9a (diff)
Correct failure when renegotiating with old server
When renegotiating the client checks that the server hasn't changed its mind about supporting the renegotiation extension (this is a likely indicator of an attack). However due to a typo the client was actually comparing the value in the client hello of the first handshake against the server hello in the renegotiation handshake. Since Botan always sends the renegotiation extension, this would cause the check to fail when renegotiating with an old server that doesn't support the renegotiation extension. Reported on mailing list by Falko Strenzke. Tested patch against OpenSSL 0.9.8k
Diffstat (limited to 'src/lib/pubkey/cecpq1')
0 files changed, 0 insertions, 0 deletions