openssl/ssl
Tomas Mraz 11d3235e2b Do not allow dropping Extended Master Secret extension on renegotiaton
Abort renegotiation if server receives client hello with Extended Master
Secret extension dropped in comparison to the initial session.

Fixes #9754

Reviewed-by: Matt Caswell <matt@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/12045)
2020-06-09 14:11:19 +02:00
..
record TLSv13: add kTLS support 2020-06-08 11:13:53 +01:00
statem Do not allow dropping Extended Master Secret extension on renegotiaton 2020-06-09 14:11:19 +02:00
bio_ssl.c Update copyright year 2020-05-15 14:09:49 +01:00
build.info If we are multiblock capable make sure we use it 2019-08-14 11:04:09 +01:00
d1_lib.c Reorganize local header files 2019-09-28 20:26:35 +02:00
d1_msg.c Reorganize local header files 2019-09-28 20:26:35 +02:00
d1_srtp.c Update copyright year 2020-05-15 14:09:49 +01:00
methods.c Update some inclusions of <openssl/macros.h> 2019-11-07 11:37:25 +01:00
pqueue.c Reorganize local header files 2019-09-28 20:26:35 +02:00
s3_cbc.c Update copyright year 2020-04-23 13:55:52 +01:00
s3_enc.c Update copyright year 2020-04-23 13:55:52 +01:00
s3_lib.c New Russian TLS 1.2 implementation 2020-05-19 13:02:43 +03:00
s3_msg.c Reorganize local header files 2019-09-28 20:26:35 +02:00
ssl_asn1.c Explicitly test against NULL; do not use !p or similar 2019-10-09 21:32:15 +02:00
ssl_cert.c SSL: refactor ssl_cert_lookup_by_pkey() to work with provider side keys 2020-05-15 16:43:31 +02:00
ssl_cert_table.h Following the license change, modify the boilerplates in ssl/ 2018-12-06 14:20:59 +01:00
ssl_ciph.c Add cipher list ciphersuites which using encryption algorithm in mode CBC. 2020-06-04 17:45:00 +03:00
ssl_conf.c SSL_OP_DISABLE_TLSEXT_CA_NAMES option implementation 2020-05-07 16:14:47 +03:00
ssl_err.c New Russian TLS 1.2 implementation 2020-05-19 13:02:43 +03:00
ssl_init.c Update copyright year 2020-04-23 13:55:52 +01:00
ssl_lib.c TLSv1.3: additional checks in SSL_set_record_padding_callback 2020-06-08 11:13:53 +01:00
ssl_local.h Check that Signature Algorithms are available before using them 2020-06-05 10:31:06 +01:00
ssl_mcnf.c Reorganize local header files 2019-09-28 20:26:35 +02:00
ssl_rsa.c Rename EVP_PKEY_cmp() to EVP_PKEY_eq() and EVP_PKEY_cmp_parameters() to EVP_PKEY_parameters_eq() 2020-05-27 14:36:13 +02:00
ssl_sess.c In OpenSSL builds, declare STACK for datatypes ... 2020-04-24 16:42:46 +02:00
ssl_stat.c Reorganize local header files 2019-09-28 20:26:35 +02:00
ssl_txt.c Update copyright year 2020-04-23 13:55:52 +01:00
ssl_utst.c Reorganize local header files 2019-09-28 20:26:35 +02:00
t1_enc.c kTLS: add support for AES_CCM128 and AES_GCM256 2020-06-08 11:13:52 +01:00
t1_lib.c use safe primes in ssl_get_auto_dh() 2020-06-09 12:15:48 +02:00
t1_trce.c t1_trce: Fix remaining places where the 24 bit shift overflow happens 2020-05-20 17:31:56 +02:00
tls13_enc.c TLSv13: add kTLS support 2020-06-08 11:13:53 +01:00
tls_srp.c Update copyright year 2020-04-23 13:55:52 +01:00