mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2025-07-30 22:43:08 +03:00
tls13: srv: Fix return value
Fix the value returned by ssl_tls13_offered_psks_check_identity_match_ticket() when there is no ticket parser function defined or no time. Signed-off-by: Ronald Cron <ronald.cron@arm.com>
This commit is contained in:
@ -123,7 +123,7 @@ static int ssl_tls13_offered_psks_check_identity_match_ticket(
|
|||||||
|
|
||||||
/* Ticket parser is not configured, Skip */
|
/* Ticket parser is not configured, Skip */
|
||||||
if (ssl->conf->f_ticket_parse == NULL || identity_len == 0) {
|
if (ssl->conf->f_ticket_parse == NULL || identity_len == 0) {
|
||||||
return 0;
|
return SSL_TLS1_3_OFFERED_PSK_NOT_MATCH;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* We create a copy of the encrypted ticket since the ticket parsing
|
/* We create a copy of the encrypted ticket since the ticket parsing
|
||||||
@ -171,7 +171,6 @@ static int ssl_tls13_offered_psks_check_identity_match_ticket(
|
|||||||
*
|
*
|
||||||
* We regard the ticket with incompatible key exchange modes as not match.
|
* We regard the ticket with incompatible key exchange modes as not match.
|
||||||
*/
|
*/
|
||||||
ret = MBEDTLS_ERR_ERROR_GENERIC_ERROR;
|
|
||||||
MBEDTLS_SSL_PRINT_TICKET_FLAGS(4, session->ticket_flags);
|
MBEDTLS_SSL_PRINT_TICKET_FLAGS(4, session->ticket_flags);
|
||||||
|
|
||||||
key_exchanges = 0;
|
key_exchanges = 0;
|
||||||
@ -186,11 +185,12 @@ static int ssl_tls13_offered_psks_check_identity_match_ticket(
|
|||||||
|
|
||||||
if (key_exchanges == 0) {
|
if (key_exchanges == 0) {
|
||||||
MBEDTLS_SSL_DEBUG_MSG(3, ("No suitable key exchange mode"));
|
MBEDTLS_SSL_DEBUG_MSG(3, ("No suitable key exchange mode"));
|
||||||
|
ret = MBEDTLS_ERR_ERROR_GENERIC_ERROR;
|
||||||
goto exit;
|
goto exit;
|
||||||
}
|
}
|
||||||
|
|
||||||
ret = MBEDTLS_ERR_SSL_SESSION_TICKET_EXPIRED;
|
|
||||||
#if defined(MBEDTLS_HAVE_TIME)
|
#if defined(MBEDTLS_HAVE_TIME)
|
||||||
|
ret = MBEDTLS_ERR_SSL_SESSION_TICKET_EXPIRED;
|
||||||
now = mbedtls_ms_time();
|
now = mbedtls_ms_time();
|
||||||
|
|
||||||
if (now < session->ticket_creation_time) {
|
if (now < session->ticket_creation_time) {
|
||||||
@ -244,7 +244,6 @@ static int ssl_tls13_offered_psks_check_identity_match_ticket(
|
|||||||
}
|
}
|
||||||
|
|
||||||
ret = 0;
|
ret = 0;
|
||||||
|
|
||||||
#endif /* MBEDTLS_HAVE_TIME */
|
#endif /* MBEDTLS_HAVE_TIME */
|
||||||
|
|
||||||
exit:
|
exit:
|
||||||
|
Reference in New Issue
Block a user