aboutsummaryrefslogtreecommitdiff
path: root/ssl
diff options
context:
space:
mode:
Diffstat (limited to 'ssl')
-rw-r--r--ssl/statem/extensions.c8
-rw-r--r--ssl/statem/statem_lib.c4
-rw-r--r--ssl/t1_lib.c25
3 files changed, 31 insertions, 6 deletions
diff --git a/ssl/statem/extensions.c b/ssl/statem/extensions.c
index 8c9c16ec2120..1518ca7f4e72 100644
--- a/ssl/statem/extensions.c
+++ b/ssl/statem/extensions.c
@@ -1,5 +1,5 @@
/*
- * Copyright 2016-2022 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2023 The OpenSSL Project Authors. All Rights Reserved.
*
* Licensed under the Apache License 2.0 (the "License"). You may not use
* this file except in compliance with the License. You can obtain a copy
@@ -1392,7 +1392,11 @@ static int final_key_share(SSL *s, unsigned int context, int sent)
group_id = pgroups[i];
if (check_in_list(s, group_id, clntgroups, clnt_num_groups,
- 1))
+ 1)
+ && tls_group_allowed(s, group_id,
+ SSL_SECOP_CURVE_SUPPORTED)
+ && tls_valid_group(s, group_id, TLS1_3_VERSION,
+ TLS1_3_VERSION, 0, NULL))
break;
}
diff --git a/ssl/statem/statem_lib.c b/ssl/statem/statem_lib.c
index bcce73bcdc3e..b1ee38b9e5bc 100644
--- a/ssl/statem/statem_lib.c
+++ b/ssl/statem/statem_lib.c
@@ -1,5 +1,5 @@
/*
- * Copyright 1995-2022 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
* Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved
*
* Licensed under the Apache License 2.0 (the "License"). You may not use
@@ -47,7 +47,7 @@ int ssl3_do_write(SSL *s, int type)
ret = ssl3_write_bytes(s, type, &s->init_buf->data[s->init_off],
s->init_num, &written);
- if (ret < 0)
+ if (ret <= 0)
return -1;
if (type == SSL3_RT_HANDSHAKE)
/*
diff --git a/ssl/t1_lib.c b/ssl/t1_lib.c
index e6f4bcc04533..8be00a4f3405 100644
--- a/ssl/t1_lib.c
+++ b/ssl/t1_lib.c
@@ -23,6 +23,7 @@
#include "internal/nelem.h"
#include "internal/sizes.h"
#include "internal/tlsgroups.h"
+#include "internal/cryptlib.h"
#include "ssl_local.h"
#include <openssl/ct.h>
@@ -600,6 +601,7 @@ uint16_t tls1_shared_group(SSL *s, int nmatch)
const uint16_t *pref, *supp;
size_t num_pref, num_supp, i;
int k;
+ SSL_CTX *ctx = s->ctx;
/* Can't do anything on client side */
if (s->server == 0)
@@ -636,10 +638,29 @@ uint16_t tls1_shared_group(SSL *s, int nmatch)
for (k = 0, i = 0; i < num_pref; i++) {
uint16_t id = pref[i];
+ const TLS_GROUP_INFO *inf;
if (!tls1_in_list(id, supp, num_supp)
- || !tls_group_allowed(s, id, SSL_SECOP_CURVE_SHARED))
- continue;
+ || !tls_group_allowed(s, id, SSL_SECOP_CURVE_SHARED))
+ continue;
+ inf = tls1_group_id_lookup(ctx, id);
+ if (!ossl_assert(inf != NULL))
+ return 0;
+ if (SSL_IS_DTLS(s)) {
+ if (inf->maxdtls == -1)
+ continue;
+ if ((inf->mindtls != 0 && DTLS_VERSION_LT(s->version, inf->mindtls))
+ || (inf->maxdtls != 0
+ && DTLS_VERSION_GT(s->version, inf->maxdtls)))
+ continue;
+ } else {
+ if (inf->maxtls == -1)
+ continue;
+ if ((inf->mintls != 0 && s->version < inf->mintls)
+ || (inf->maxtls != 0 && s->version > inf->maxtls))
+ continue;
+ }
+
if (nmatch == k)
return id;
k++;