tls-server: Determine supported/configured suites and versions early

If we don't do this, we might negotiate a TLS version for which we don't
have any suites configured, so that the cipher suite negotiation
subsequently fails.
This commit is contained in:
Tobias Brunner
2021-02-12 14:35:23 +01:00
parent 8a6edc08a4
commit 06424efa17
3 changed files with 9 additions and 7 deletions
+4 -6
View File
@@ -1228,7 +1228,10 @@ METHOD(tls_crypto_t, get_cipher_suites, int,
{ {
build_cipher_suite_list(this); build_cipher_suite_list(this);
} }
*suites = this->suites; if (suites)
{
*suites = this->suites;
}
return this->suite_count; return this->suite_count;
} }
@@ -1376,11 +1379,6 @@ METHOD(tls_crypto_t, select_cipher_suite, tls_cipher_suite_t,
suite_algs_t *algs; suite_algs_t *algs;
int i, j; int i, j;
if (!this->suites)
{
build_cipher_suite_list(this);
}
for (i = 0; i < this->suite_count; i++) for (i = 0; i < this->suite_count; i++)
{ {
for (j = 0; j < count; j++) for (j = 0; j < count; j++)
+1 -1
View File
@@ -436,7 +436,7 @@ struct tls_crypto_t {
/** /**
* Get a list of supported TLS cipher suites. * Get a list of supported TLS cipher suites.
* *
* @param suites list of suites, points to internal data * @param suites optional list of suites, points to internal data
* @return number of suites returned * @return number of suites returned
*/ */
int (*get_cipher_suites)(tls_crypto_t *this, tls_cipher_suite_t **suites); int (*get_cipher_suites)(tls_crypto_t *this, tls_cipher_suite_t **suites);
+4
View File
@@ -235,6 +235,10 @@ static status_t process_client_hello(private_tls_server_t *this,
return NEED_MORE; return NEED_MORE;
} }
/* before we do anything version-related, determine our supported suites
* as that might change the min./max. versions */
this->crypto->get_cipher_suites(this->crypto, NULL);
if (ext.len) if (ext.len)
{ {
extensions = bio_reader_create(ext); extensions = bio_reader_create(ext);