tls-server: Determine supported/configured suites and versions early

If we don't do this, we might negotiate a TLS version for which we don't
have any suites configured, so that the cipher suite negotiation
subsequently fails.
This commit is contained in:
Tobias Brunner
2021-02-12 14:35:23 +01:00
parent 8a6edc08a4
commit 06424efa17
3 changed files with 9 additions and 7 deletions
+4 -6
View File
@@ -1228,7 +1228,10 @@ METHOD(tls_crypto_t, get_cipher_suites, int,
{
build_cipher_suite_list(this);
}
*suites = this->suites;
if (suites)
{
*suites = this->suites;
}
return this->suite_count;
}
@@ -1376,11 +1379,6 @@ METHOD(tls_crypto_t, select_cipher_suite, tls_cipher_suite_t,
suite_algs_t *algs;
int i, j;
if (!this->suites)
{
build_cipher_suite_list(this);
}
for (i = 0; i < this->suite_count; i++)
{
for (j = 0; j < count; j++)
+1 -1
View File
@@ -436,7 +436,7 @@ struct tls_crypto_t {
/**
* Get a list of supported TLS cipher suites.
*
* @param suites list of suites, points to internal data
* @param suites optional list of suites, points to internal data
* @return number of suites returned
*/
int (*get_cipher_suites)(tls_crypto_t *this, tls_cipher_suite_t **suites);
+4
View File
@@ -235,6 +235,10 @@ static status_t process_client_hello(private_tls_server_t *this,
return NEED_MORE;
}
/* before we do anything version-related, determine our supported suites
* as that might change the min./max. versions */
this->crypto->get_cipher_suites(this->crypto, NULL);
if (ext.len)
{
extensions = bio_reader_create(ext);