From 7ed30e59af0e8378901a0d458ac94c58a9c1da04 Mon Sep 17 00:00:00 2001 From: Xiaokang Qian Date: Fri, 16 Dec 2022 08:32:02 +0000 Subject: [PATCH] Fix the issue that gnutls server doesn't support packet Signed-off-by: Xiaokang Qian --- library/ssl_tls13_client.c | 10 ++++++---- tests/opt-testcases/tls13-misc.sh | 4 ++-- 2 files changed, 8 insertions(+), 6 deletions(-) diff --git a/library/ssl_tls13_client.c b/library/ssl_tls13_client.c index 4c07a64bbc..3219425c28 100644 --- a/library/ssl_tls13_client.c +++ b/library/ssl_tls13_client.c @@ -2153,12 +2153,14 @@ MBEDTLS_CHECK_RETURN_CRITICAL static int ssl_tls13_finalize_write_end_of_early_data( mbedtls_ssl_context *ssl) { -#if defined(MBEDTLS_SSL_TLS1_3_COMPATIBILITY_MODE) +#if defined(MBEDTLS_SSL_EARLY_DATA) || \ + !defined(MBEDTLS_SSL_TLS1_3_COMPATIBILITY_MODE) + mbedtls_ssl_handshake_set_state(ssl, MBEDTLS_SSL_CLIENT_CERTIFICATE); +#else mbedtls_ssl_handshake_set_state( ssl, MBEDTLS_SSL_CLIENT_CCS_AFTER_SERVER_FINISHED); -#else - mbedtls_ssl_handshake_set_state(ssl, MBEDTLS_SSL_CLIENT_CERTIFICATE); -#endif /* MBEDTLS_SSL_TLS1_3_COMPATIBILITY_MODE */ +#endif /* MBEDTLS_SSL_EARLY_DATA || + !MBEDTLS_SSL_TLS1_3_COMPATIBILITY_MODE */ return 0; } diff --git a/tests/opt-testcases/tls13-misc.sh b/tests/opt-testcases/tls13-misc.sh index 5428e3c38b..0b01e50a50 100755 --- a/tests/opt-testcases/tls13-misc.sh +++ b/tests/opt-testcases/tls13-misc.sh @@ -274,8 +274,8 @@ requires_any_configs_enabled MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_PSK_EPHEMERAL_ MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_PSK_ENABLED run_test "TLS 1.3 m->G: EarlyData: basic check, good" \ "$G_NEXT_SRV -d 10 --priority=NORMAL:-VERS-ALL:+VERS-TLS1.3:+CIPHER-ALL:+ECDHE-PSK:+PSK --earlydata --disable-client-cert" \ - "$P_CLI debug_level=4 early_data=1 reco_mode=1 reconnect=1 reco_delay=900" \ - 1 \ + "$P_CLI debug_level=4 early_data=1 reco_mode=1 reconnect=1 reco_delay=2" \ + 0 \ -c "Reconnecting with saved session" \ -c "NewSessionTicket: early_data(42) extension received." \ -c "ClientHello: early_data(42) extension exists." \