Do not use renegotiation in old clients.

This commit is contained in:
Nikos Mavrogiannopoulos
2014-04-15 11:22:27 +02:00
parent e6364e8e52
commit 392c6a0178
2 changed files with 9 additions and 25 deletions
+1 -23
View File
@@ -548,17 +548,11 @@ struct key_cb_data * cdata;
return 0;
}
/* Allow clients to rehandshake even if they don't support safe
* renegotiation */
#define ADDITIONAL_FLAGS ":%UNSAFE_RENEGOTIATION"
/* reload key files etc. */
void tls_global_init_certs(main_server_st* s)
{
int ret;
const char* perr;
char *tmp;
unsigned len;
if (s->config->debug >= DEBUG_TLS) {
gnutls_global_set_log_function(tls_log_func);
@@ -607,27 +601,11 @@ unsigned len;
verify_certificate_cb);
}
if (s->config->cisco_client_compat) {
len = strlen(s->config->priorities);
tmp = malloc(len+sizeof(ADDITIONAL_FLAGS));
if (tmp == NULL) {
mslog(s, NULL, LOG_ERR, "memory error");
exit(1);
}
memcpy(tmp, s->config->priorities, len);
memcpy(&tmp[len], ADDITIONAL_FLAGS, sizeof(ADDITIONAL_FLAGS)); /* includes terminating zero */
} else {
tmp = strdup(s->config->priorities);
}
ret = gnutls_priority_init(&s->creds.cprio, tmp, &perr);
ret = gnutls_priority_init(&s->creds.cprio, s->config->priorities, &perr);
if (ret == GNUTLS_E_PARSING_ERROR)
mslog(s, NULL, LOG_ERR, "error in TLS priority string: %s", perr);
GNUTLS_FATAL_ERR(ret);
free(tmp);
if (s->config->ocsp_response != NULL) {
ret = gnutls_certificate_set_ocsp_status_request_file(s->creds.xcred,
s->config->ocsp_response, 0);
+8 -2
View File
@@ -1544,14 +1544,20 @@ static int connect_handler(worker_st * ws)
SEND_ERR(ret);
if (ws->config->rekey_time > 0) {
unsigned method;
ret =
tls_printf(ws->session, "X-CSTP-Rekey-Time: %u\r\n",
(unsigned)(ws->config->rekey_time));
SEND_ERR(ret);
if (gnutls_safe_renegotiation_status(ws->session) != 0)
method = ws->config->rekey_method;
else
method = REKEY_METHOD_NEW_TUNNEL;
ret = tls_printf(ws->session, "X-CSTP-Rekey-Method: %s\r\n",
(ws->config->rekey_method ==
REKEY_METHOD_SSL) ? "ssl" : "new-tunnel");
(method == REKEY_METHOD_SSL) ? "ssl" : "new-tunnel");
SEND_ERR(ret);
} else {
ret = tls_puts(ws->session, "X-CSTP-Rekey-Method: none\r\n");