mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2025-08-07 06:42:56 +03:00
TLS 1.3: Fix selected key exchange mode check
ECDHE operations have to be done in ephemeral and PSK-ephemeral key exchange mode, not just ephemeral key exhange mode. Signed-off-by: Ronald Cron <ronald.cron@arm.com>
This commit is contained in:
@@ -1237,7 +1237,7 @@ int mbedtls_ssl_tls13_key_schedule_stage_handshake( mbedtls_ssl_context *ssl )
|
|||||||
* client_handshake_traffic_secret and server_handshake_traffic_secret
|
* client_handshake_traffic_secret and server_handshake_traffic_secret
|
||||||
* are derived in the handshake secret derivation stage.
|
* are derived in the handshake secret derivation stage.
|
||||||
*/
|
*/
|
||||||
if( mbedtls_ssl_tls13_ephemeral_enabled( ssl ) )
|
if( mbedtls_ssl_tls13_some_ephemeral_enabled( ssl ) )
|
||||||
{
|
{
|
||||||
if( mbedtls_ssl_tls13_named_group_is_ecdhe( handshake->offered_group_id ) )
|
if( mbedtls_ssl_tls13_named_group_is_ecdhe( handshake->offered_group_id ) )
|
||||||
{
|
{
|
||||||
|
Reference in New Issue
Block a user