• D
    Unauthenticated DH client certificate fix. · 1421e0c5
    Dr. Stephen Henson 提交于
    Fix to prevent use of DH client certificates without sending
    certificate verify message.
    
    If we've used a client certificate to generate the premaster secret
    ssl3_get_client_key_exchange returns 2 and ssl3_get_cert_verify is
    never called.
    
    We can only skip the certificate verify message in
    ssl3_get_cert_verify if the client didn't send a certificate.
    
    Thanks to Karthikeyan Bhargavan for reporting this issue.
    CVE-2015-0205
    Reviewed-by: NMatt Caswell <matt@openssl.org>
    1421e0c5
s3_srvr.c 93.9 KB