Accept TLS records with zero-length plaintext
This commit is contained in:
@@ -168,7 +168,7 @@ METHOD(tls_protection_t, process, status_t,
|
|||||||
u_int8_t bs;
|
u_int8_t bs;
|
||||||
|
|
||||||
bs = this->signer_in->get_block_size(this->signer_in);
|
bs = this->signer_in->get_block_size(this->signer_in);
|
||||||
if (data.len <= bs)
|
if (data.len < bs)
|
||||||
{
|
{
|
||||||
DBG1(DBG_TLS, "TLS record too short to verify MAC");
|
DBG1(DBG_TLS, "TLS record too short to verify MAC");
|
||||||
this->alert->add(this->alert, TLS_FATAL, TLS_BAD_RECORD_MAC);
|
this->alert->add(this->alert, TLS_FATAL, TLS_BAD_RECORD_MAC);
|
||||||
|
|||||||
Reference in New Issue
Block a user