From 2d31f3fc1b1c88739e5babbd6a9e8cb3b80263de Mon Sep 17 00:00:00 2001 From: lloyd Date: Fri, 27 Jan 2012 15:38:53 +0000 Subject: Add client-side support for PSK kex. Tested against OpenSSL. --- src/tls/s_kex.cpp | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) (limited to 'src/tls/s_kex.cpp') diff --git a/src/tls/s_kex.cpp b/src/tls/s_kex.cpp index 3ebdc3027..b8aba344c 100644 --- a/src/tls/s_kex.cpp +++ b/src/tls/s_kex.cpp @@ -116,7 +116,12 @@ Server_Key_Exchange::Server_Key_Exchange(const MemoryRegion& buf, * to be able to parse the whole thing anyway. */ - if(kex_algo == "DH") + if(kex_algo == "PSK") + { + std::string identity_hint = reader.get_string(2, 1, 65535); + append_tls_length_value(m_params, identity_hint, 2); + } + else if(kex_algo == "DH") { // 3 bigints, DH p, g, Y @@ -149,8 +154,7 @@ Server_Key_Exchange::Server_Key_Exchange(const MemoryRegion& buf, append_tls_length_value(m_params, ecdh_key, 1); } else - throw Decoding_Error("Server_Key_Exchange: Unsupported server key exchange type " + - kex_algo); + throw Decoding_Error("Server_Key_Exchange: Unsupported kex type " + kex_algo); if(sig_algo != "") { -- cgit v1.2.3