Blame SOURCES/openssl-1.1.1-tls-compliance.patch
|
|
3a273b |
diff -up openssl-1.1.1c/ssl/record/ssl3_record.c.compliance openssl-1.1.1c/ssl/record/ssl3_record.c
|
|
|
3a273b |
--- openssl-1.1.1c/ssl/record/ssl3_record.c.compliance 2019-05-28 15:12:21.000000000 +0200
|
|
|
3a273b |
+++ openssl-1.1.1c/ssl/record/ssl3_record.c 2019-11-25 13:10:53.890637381 +0100
|
|
|
3a273b |
@@ -559,7 +559,7 @@ int ssl3_get_record(SSL *s)
|
|
|
3a273b |
RECORD_LAYER_reset_read_sequence(&s->rlayer);
|
|
|
3a273b |
return 1;
|
|
|
3a273b |
}
|
|
|
3a273b |
- SSLfatal(s, SSL_AD_DECRYPTION_FAILED, SSL_F_SSL3_GET_RECORD,
|
|
|
3a273b |
+ SSLfatal(s, SSL_AD_BAD_RECORD_MAC, SSL_F_SSL3_GET_RECORD,
|
|
|
3a273b |
SSL_R_BLOCK_CIPHER_PAD_IS_WRONG);
|
|
|
3a273b |
return -1;
|
|
|
3a273b |
}
|
|
|
3a273b |
diff -up openssl-1.1.1c/ssl/statem/extensions_srvr.c.compliance openssl-1.1.1c/ssl/statem/extensions_srvr.c
|
|
|
3a273b |
--- openssl-1.1.1c/ssl/statem/extensions_srvr.c.compliance 2019-05-28 15:12:21.000000000 +0200
|
|
|
3a273b |
+++ openssl-1.1.1c/ssl/statem/extensions_srvr.c 2019-11-25 13:12:59.329459528 +0100
|
|
|
3a273b |
@@ -1487,6 +1487,10 @@ EXT_RETURN tls_construct_stoc_status_req
|
|
|
3a273b |
unsigned int context, X509 *x,
|
|
|
3a273b |
size_t chainidx)
|
|
|
3a273b |
{
|
|
|
3a273b |
+ /* We don't currently support this extension inside a CertificateRequest */
|
|
|
3a273b |
+ if (context == SSL_EXT_TLS1_3_CERTIFICATE_REQUEST)
|
|
|
3a273b |
+ return EXT_RETURN_NOT_SENT;
|
|
|
3a273b |
+
|
|
|
3a273b |
if (!s->ext.status_expected)
|
|
|
3a273b |
return EXT_RETURN_NOT_SENT;
|
|
|
3a273b |
|