Closed Bug 1444050 Opened 6 years ago Closed 6 years ago

Abort if the server picks TLS 1.2 but SH.session_id_echo equals the fake SID

Categories

(NSS :: Libraries, enhancement, P2)

enhancement

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: ttaubert, Assigned: ttaubert)

Details

Attachments

(1 file)

This is for BoGo test EchoTLS13CompatibilitySessionID:

The client wants to establish a connection with max_version=1.3 in compat mode and sends a fake SID. The server picks 1.2 but echos the fake SID.
Summary: Abort if the server picks TLS 1.2 but SH.legacy_session_id_echo equals the fake SID → Abort if the server picks TLS 1.2 but SH.session_id_echo equals the fake SID
Priority: -- → P2
Comment on attachment 8957107 [details]
Bug 1444050 - Abort if the server picks TLS 1.2 but SH.session_id equals the fake SID r=ekr

Martin Thomson [:mt:] has approved the revision.

https://phabricator.services.mozilla.com/D698
Attachment #8957107 - Flags: review+
https://hg.mozilla.org/projects/nss/rev/c329a8089a7c
Status: ASSIGNED → RESOLVED
Closed: 6 years ago
Resolution: --- → FIXED
Target Milestone: --- → 3.37
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: