Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
OpenHarmony
Third Party Openssl
提交
0ebc965b
T
Third Party Openssl
项目概览
OpenHarmony
/
Third Party Openssl
1 年多 前同步成功
通知
10
Star
18
Fork
1
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
T
Third Party Openssl
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
提交
Issue看板
提交
0ebc965b
编写于
1月 25, 2014
作者:
D
Dr. Stephen Henson
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
Support retries in certificate callback
上级
ba168244
变更
3
隐藏空白更改
内联
并排
Showing
3 changed file
with
36 addition
and
14 deletion
+36
-14
ssl/s3_clnt.c
ssl/s3_clnt.c
+13
-4
ssl/s3_srvr.c
ssl/s3_srvr.c
+22
-10
ssl/ssl3.h
ssl/ssl3.h
+1
-0
未找到文件。
ssl/s3_clnt.c
浏览文件 @
0ebc965b
...
...
@@ -3307,11 +3307,20 @@ int ssl3_send_client_certificate(SSL *s)
if
(
s
->
state
==
SSL3_ST_CW_CERT_A
)
{
/* Let cert callback update client certificates if required */
if
(
s
->
cert
->
cert_cb
&&
s
->
cert
->
cert_cb
(
s
,
s
->
cert
->
cert_cb_arg
)
<=
0
)
if
(
s
->
cert
->
cert_cb
)
{
ssl3_send_alert
(
s
,
SSL3_AL_FATAL
,
SSL_AD_INTERNAL_ERROR
);
return
0
;
i
=
s
->
cert
->
cert_cb
(
s
,
s
->
cert
->
cert_cb_arg
);
if
(
i
<
0
)
{
s
->
rwstate
=
SSL_X509_LOOKUP
;
return
-
1
;
}
if
(
i
==
0
)
{
ssl3_send_alert
(
s
,
SSL3_AL_FATAL
,
SSL_AD_INTERNAL_ERROR
);
return
0
;
}
s
->
rwstate
=
SSL_NOTHING
;
}
if
(
ssl3_check_client_certificate
(
s
))
s
->
state
=
SSL3_ST_CW_CERT_C
;
...
...
ssl/s3_srvr.c
浏览文件 @
0ebc965b
...
...
@@ -352,12 +352,11 @@ int ssl3_accept(SSL *s)
case
SSL3_ST_SR_CLNT_HELLO_B
:
case
SSL3_ST_SR_CLNT_HELLO_C
:
if
(
s
->
rwstate
!=
SSL_X509_LOOKUP
)
{
ret
=
ssl3_get_client_hello
(
s
);
if
(
ret
<=
0
)
goto
end
;
}
ret
=
ssl3_get_client_hello
(
s
);
if
(
ret
<=
0
)
goto
end
;
#ifndef OPENSSL_NO_SRP
s
->
state
=
SSL3_ST_SR_CLNT_HELLO_D
;
case
SSL3_ST_SR_CLNT_HELLO_D
:
{
int
al
;
if
((
ret
=
ssl_check_srp_ext_ClientHello
(
s
,
&
al
))
<
0
)
...
...
@@ -950,6 +949,9 @@ int ssl3_get_client_hello(SSL *s)
#endif
STACK_OF
(
SSL_CIPHER
)
*
ciphers
=
NULL
;
if
(
s
->
state
==
SSL3_ST_SR_CLNT_HELLO_C
)
goto
retry_cert
;
/* We do this so that we will respond with our native type.
* If we are TLSv1 and we get SSLv3, we will respond with TLSv1,
* This down switching should be handled by a different method.
...
...
@@ -1394,12 +1396,22 @@ int ssl3_get_client_hello(SSL *s)
}
ciphers
=
NULL
;
/* Let cert callback update server certificates if required */
if
(
s
->
cert
->
cert_cb
&&
s
->
cert
->
cert_cb
(
s
,
s
->
cert
->
cert_cb_arg
)
<=
0
)
retry_cert:
if
(
s
->
cert
->
cert_cb
)
{
al
=
SSL_AD_INTERNAL_ERROR
;
SSLerr
(
SSL_F_SSL3_GET_CLIENT_HELLO
,
SSL_R_CERT_CB_ERROR
);
goto
f_err
;
int
rv
=
s
->
cert
->
cert_cb
(
s
,
s
->
cert
->
cert_cb_arg
);
if
(
rv
==
0
)
{
al
=
SSL_AD_INTERNAL_ERROR
;
SSLerr
(
SSL_F_SSL3_GET_CLIENT_HELLO
,
SSL_R_CERT_CB_ERROR
);
goto
f_err
;
}
if
(
rv
<
0
)
{
s
->
rwstate
=
SSL_X509_LOOKUP
;
return
-
1
;
}
s
->
rwstate
=
SSL_NOTHING
;
}
c
=
ssl3_choose_cipher
(
s
,
s
->
session
->
ciphers
,
SSL_get_ciphers
(
s
));
...
...
ssl/ssl3.h
浏览文件 @
0ebc965b
...
...
@@ -685,6 +685,7 @@ typedef struct ssl3_state_st
#define SSL3_ST_SR_CLNT_HELLO_A (0x110|SSL_ST_ACCEPT)
#define SSL3_ST_SR_CLNT_HELLO_B (0x111|SSL_ST_ACCEPT)
#define SSL3_ST_SR_CLNT_HELLO_C (0x112|SSL_ST_ACCEPT)
#define SSL3_ST_SR_CLNT_HELLO_D (0x115|SSL_ST_ACCEPT)
#ifndef OPENSSL_NO_TLSEXT
#define SSL3_ST_SR_SUPPLEMENTAL_DATA_A (0x212|SSL_ST_ACCEPT)
#define SSL3_ST_SR_SUPPLEMENTAL_DATA_B (0x213|SSL_ST_ACCEPT)
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录