eap-tls: Fix server implementation with TLS 1.2 and earlier
With5401a74d36("eap-tls: Add support for TLS 1.3") a TLS application was added to implement TLS 1.3's protected success indication. For earlier TLS versions, its build() method simply returned SUCCESS as there was nothing to send. However, that had the unintended side-effect of also not sending the final TLS handshake messages (ChangeCipherSpec and Finished). The reason is that the TLS stack first checks for remaining handshake messages but then also asks the registered application for data to piggyback to that response (before the commit there was no application, so that step was skipped). The problem is that the status returned by the application is directly forwarded through the TLS stack. So not returning INVALID_STATE caused the session to get concluded immediately instead of resulting in ALREADY_DONE that would trigger sending the final EAP message instead of an EAP-Success. Fixes:5401a74d36("eap-tls: Add support for TLS 1.3")
This commit is contained in:
@@ -179,11 +179,12 @@ METHOD(tls_application_t, server_process, status_t,
|
|||||||
METHOD(tls_application_t, server_build, status_t,
|
METHOD(tls_application_t, server_build, status_t,
|
||||||
eap_tls_app_t *app, bio_writer_t *writer)
|
eap_tls_app_t *app, bio_writer_t *writer)
|
||||||
{
|
{
|
||||||
if (app->this->tls->get_version_max(app->this->tls) < TLS_1_3 ||
|
if (app->this->indication_sent_received)
|
||||||
app->this->indication_sent_received)
|
|
||||||
{
|
{
|
||||||
return SUCCESS;
|
return SUCCESS;
|
||||||
}
|
}
|
||||||
|
if (app->this->tls->get_version_max(app->this->tls) >= TLS_1_3)
|
||||||
|
{
|
||||||
/* build() is called twice when sending the indication, return the same
|
/* build() is called twice when sending the indication, return the same
|
||||||
* status but data only once */
|
* status but data only once */
|
||||||
if (app->indication_sent)
|
if (app->indication_sent)
|
||||||
@@ -196,6 +197,14 @@ METHOD(tls_application_t, server_build, status_t,
|
|||||||
writer->write_uint8(writer, 0);
|
writer->write_uint8(writer, 0);
|
||||||
app->indication_sent = TRUE;
|
app->indication_sent = TRUE;
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
/* with earlier TLS versions, return INVALID_STATE without data to send
|
||||||
|
* the final handshake messages (returning SUCCESS immediately would
|
||||||
|
* prevent that) */
|
||||||
|
app->this->indication_sent_received = TRUE;
|
||||||
|
}
|
||||||
return INVALID_STATE;
|
return INVALID_STATE;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user