tls-server: Check if peer sent hash and signature algorithms
It is mandatory to receive the `signature_algorithms` extension when a server is authenticating with a certificate, which is always the case.
This commit is contained in:
committed by
Tobias Brunner
parent
91c9e4d576
commit
e731396280
@@ -412,6 +412,14 @@ static status_t process_client_hello(private_tls_server_t *this,
|
|||||||
}
|
}
|
||||||
extensions->destroy(extensions);
|
extensions->destroy(extensions);
|
||||||
|
|
||||||
|
if (this->tls->get_version_max(this->tls) >= TLS_1_3 && !this->hashsig.len)
|
||||||
|
{
|
||||||
|
DBG1(DBG_TLS, "no %N extension received", tls_extension_names,
|
||||||
|
TLS_MISSING_EXTENSION);
|
||||||
|
this->alert->add(this->alert, TLS_FATAL, TLS_MISSING_EXTENSION);
|
||||||
|
return NEED_MORE;
|
||||||
|
}
|
||||||
|
|
||||||
memcpy(this->client_random, random.ptr, sizeof(this->client_random));
|
memcpy(this->client_random, random.ptr, sizeof(this->client_random));
|
||||||
|
|
||||||
htoun32(&this->server_random, time(NULL));
|
htoun32(&this->server_random, time(NULL));
|
||||||
|
|||||||
Reference in New Issue
Block a user