Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
OpenHarmony
Third Party Openssl
提交
64abf5e6
T
Third Party Openssl
项目概览
OpenHarmony
/
Third Party Openssl
大约 1 年 前同步成功
通知
9
Star
18
Fork
1
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
T
Third Party Openssl
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
提交
Issue看板
体验新版 GitCode,发现更多精彩内容 >>
提交
64abf5e6
编写于
11月 18, 2009
作者:
D
Dr. Stephen Henson
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
Include a more meaningful error message when rejecting legacy renegotiation
上级
446a6a8a
变更
3
显示空白变更内容
内联
并排
Showing
3 changed file
with
10 addition
and
0 deletion
+10
-0
ssl/ssl.h
ssl/ssl.h
+3
-0
ssl/ssl_err.c
ssl/ssl_err.c
+3
-0
ssl/t1_lib.c
ssl/t1_lib.c
+4
-0
未找到文件。
ssl/ssl.h
浏览文件 @
64abf5e6
...
...
@@ -1954,7 +1954,9 @@ void ERR_load_SSL_strings(void);
#define SSL_F_SSL_LOAD_CLIENT_CA_FILE 185
#define SSL_F_SSL_NEW 186
#define SSL_F_SSL_PARSE_CLIENTHELLO_RENEGOTIATE_EXT 300
#define SSL_F_SSL_PARSE_CLIENTHELLO_TLSEXT 302
#define SSL_F_SSL_PARSE_SERVERHELLO_RENEGOTIATE_EXT 301
#define SSL_F_SSL_PARSE_SERVERHELLO_TLSEXT 303
#define SSL_F_SSL_PEEK 270
#define SSL_F_SSL_PREPARE_CLIENTHELLO_TLSEXT 281
#define SSL_F_SSL_PREPARE_SERVERHELLO_TLSEXT 282
...
...
@@ -2251,6 +2253,7 @@ void ERR_load_SSL_strings(void);
#define SSL_R_UNKNOWN_REMOTE_ERROR_TYPE 253
#define SSL_R_UNKNOWN_SSL_VERSION 254
#define SSL_R_UNKNOWN_STATE 255
#define SSL_R_UNSAFE_LEGACY_RENEGOTIATION_DISABLED 338
#define SSL_R_UNSUPPORTED_CIPHER 256
#define SSL_R_UNSUPPORTED_COMPRESSION_ALGORITHM 257
#define SSL_R_UNSUPPORTED_DIGEST_TYPE 326
...
...
ssl/ssl_err.c
浏览文件 @
64abf5e6
...
...
@@ -226,7 +226,9 @@ static ERR_STRING_DATA SSL_str_functs[]=
{
ERR_FUNC
(
SSL_F_SSL_LOAD_CLIENT_CA_FILE
),
"SSL_load_client_CA_file"
},
{
ERR_FUNC
(
SSL_F_SSL_NEW
),
"SSL_new"
},
{
ERR_FUNC
(
SSL_F_SSL_PARSE_CLIENTHELLO_RENEGOTIATE_EXT
),
"SSL_PARSE_CLIENTHELLO_RENEGOTIATE_EXT"
},
{
ERR_FUNC
(
SSL_F_SSL_PARSE_CLIENTHELLO_TLSEXT
),
"SSL_PARSE_CLIENTHELLO_TLSEXT"
},
{
ERR_FUNC
(
SSL_F_SSL_PARSE_SERVERHELLO_RENEGOTIATE_EXT
),
"SSL_PARSE_SERVERHELLO_RENEGOTIATE_EXT"
},
{
ERR_FUNC
(
SSL_F_SSL_PARSE_SERVERHELLO_TLSEXT
),
"SSL_PARSE_SERVERHELLO_TLSEXT"
},
{
ERR_FUNC
(
SSL_F_SSL_PEEK
),
"SSL_peek"
},
{
ERR_FUNC
(
SSL_F_SSL_PREPARE_CLIENTHELLO_TLSEXT
),
"SSL_PREPARE_CLIENTHELLO_TLSEXT"
},
{
ERR_FUNC
(
SSL_F_SSL_PREPARE_SERVERHELLO_TLSEXT
),
"SSL_PREPARE_SERVERHELLO_TLSEXT"
},
...
...
@@ -526,6 +528,7 @@ static ERR_STRING_DATA SSL_str_reasons[]=
{
ERR_REASON
(
SSL_R_UNKNOWN_REMOTE_ERROR_TYPE
),
"unknown remote error type"
},
{
ERR_REASON
(
SSL_R_UNKNOWN_SSL_VERSION
)
,
"unknown ssl version"
},
{
ERR_REASON
(
SSL_R_UNKNOWN_STATE
)
,
"unknown state"
},
{
ERR_REASON
(
SSL_R_UNSAFE_LEGACY_RENEGOTIATION_DISABLED
),
"unsafe legacy renegotiation disabled"
},
{
ERR_REASON
(
SSL_R_UNSUPPORTED_CIPHER
)
,
"unsupported cipher"
},
{
ERR_REASON
(
SSL_R_UNSUPPORTED_COMPRESSION_ALGORITHM
),
"unsupported compression algorithm"
},
{
ERR_REASON
(
SSL_R_UNSUPPORTED_DIGEST_TYPE
),
"unsupported digest type"
},
...
...
ssl/t1_lib.c
浏览文件 @
64abf5e6
...
...
@@ -636,6 +636,7 @@ int ssl_parse_clienthello_tlsext(SSL *s, unsigned char **p, unsigned char *d, in
{
/* We should always see one extension: the renegotiate extension */
*
al
=
SSL_AD_ILLEGAL_PARAMETER
;
/* is this the right alert? */
SSLerr
(
SSL_F_SSL_PARSE_CLIENTHELLO_TLSEXT
,
SSL_R_UNSAFE_LEGACY_RENEGOTIATION_DISABLED
);
return
0
;
}
return
1
;
...
...
@@ -965,6 +966,7 @@ int ssl_parse_clienthello_tlsext(SSL *s, unsigned char **p, unsigned char *d, in
if
(
s
->
new_session
&&
!
renegotiate_seen
&&
!
(
s
->
ctx
->
options
&
SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION
))
{
SSLerr
(
SSL_F_SSL_PARSE_CLIENTHELLO_TLSEXT
,
SSL_R_UNSAFE_LEGACY_RENEGOTIATION_DISABLED
);
*
al
=
SSL_AD_ILLEGAL_PARAMETER
;
/* is this the right alert? */
return
0
;
}
...
...
@@ -992,6 +994,7 @@ int ssl_parse_serverhello_tlsext(SSL *s, unsigned char **p, unsigned char *d, in
{
/* We should always see one extension: the renegotiate extension */
*
al
=
SSL_AD_ILLEGAL_PARAMETER
;
/* is this the right alert? */
SSLerr
(
SSL_F_SSL_PARSE_SERVERHELLO_TLSEXT
,
SSL_R_UNSAFE_LEGACY_RENEGOTIATION_DISABLED
);
return
0
;
}
return
1
;
...
...
@@ -1130,6 +1133,7 @@ int ssl_parse_serverhello_tlsext(SSL *s, unsigned char **p, unsigned char *d, in
&&
!
(
s
->
ctx
->
options
&
SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION
))
{
*
al
=
SSL_AD_ILLEGAL_PARAMETER
;
/* is this the right alert? */
SSLerr
(
SSL_F_SSL_PARSE_SERVERHELLO_TLSEXT
,
SSL_R_UNSAFE_LEGACY_RENEGOTIATION_DISABLED
);
return
0
;
}
...
...
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录