mirror of
https://gitlab.com/openconnect/ocserv.git
synced 2026-10-12 01:26:48 +08:00
Do not use renegotiation in old clients.
This commit is contained in:
+1
-23
@@ -548,17 +548,11 @@ struct key_cb_data * cdata;
|
||||
return 0;
|
||||
}
|
||||
|
||||
/* Allow clients to rehandshake even if they don't support safe
|
||||
* renegotiation */
|
||||
#define ADDITIONAL_FLAGS ":%UNSAFE_RENEGOTIATION"
|
||||
|
||||
/* reload key files etc. */
|
||||
void tls_global_init_certs(main_server_st* s)
|
||||
{
|
||||
int ret;
|
||||
const char* perr;
|
||||
char *tmp;
|
||||
unsigned len;
|
||||
|
||||
if (s->config->debug >= DEBUG_TLS) {
|
||||
gnutls_global_set_log_function(tls_log_func);
|
||||
@@ -607,27 +601,11 @@ unsigned len;
|
||||
verify_certificate_cb);
|
||||
}
|
||||
|
||||
if (s->config->cisco_client_compat) {
|
||||
len = strlen(s->config->priorities);
|
||||
tmp = malloc(len+sizeof(ADDITIONAL_FLAGS));
|
||||
if (tmp == NULL) {
|
||||
mslog(s, NULL, LOG_ERR, "memory error");
|
||||
exit(1);
|
||||
}
|
||||
|
||||
memcpy(tmp, s->config->priorities, len);
|
||||
memcpy(&tmp[len], ADDITIONAL_FLAGS, sizeof(ADDITIONAL_FLAGS)); /* includes terminating zero */
|
||||
} else {
|
||||
tmp = strdup(s->config->priorities);
|
||||
}
|
||||
|
||||
ret = gnutls_priority_init(&s->creds.cprio, tmp, &perr);
|
||||
ret = gnutls_priority_init(&s->creds.cprio, s->config->priorities, &perr);
|
||||
if (ret == GNUTLS_E_PARSING_ERROR)
|
||||
mslog(s, NULL, LOG_ERR, "error in TLS priority string: %s", perr);
|
||||
GNUTLS_FATAL_ERR(ret);
|
||||
|
||||
free(tmp);
|
||||
|
||||
if (s->config->ocsp_response != NULL) {
|
||||
ret = gnutls_certificate_set_ocsp_status_request_file(s->creds.xcred,
|
||||
s->config->ocsp_response, 0);
|
||||
|
||||
+8
-2
@@ -1544,14 +1544,20 @@ static int connect_handler(worker_st * ws)
|
||||
SEND_ERR(ret);
|
||||
|
||||
if (ws->config->rekey_time > 0) {
|
||||
unsigned method;
|
||||
|
||||
ret =
|
||||
tls_printf(ws->session, "X-CSTP-Rekey-Time: %u\r\n",
|
||||
(unsigned)(ws->config->rekey_time));
|
||||
SEND_ERR(ret);
|
||||
|
||||
if (gnutls_safe_renegotiation_status(ws->session) != 0)
|
||||
method = ws->config->rekey_method;
|
||||
else
|
||||
method = REKEY_METHOD_NEW_TUNNEL;
|
||||
|
||||
ret = tls_printf(ws->session, "X-CSTP-Rekey-Method: %s\r\n",
|
||||
(ws->config->rekey_method ==
|
||||
REKEY_METHOD_SSL) ? "ssl" : "new-tunnel");
|
||||
(method == REKEY_METHOD_SSL) ? "ssl" : "new-tunnel");
|
||||
SEND_ERR(ret);
|
||||
} else {
|
||||
ret = tls_puts(ws->session, "X-CSTP-Rekey-Method: none\r\n");
|
||||
|
||||
Reference in New Issue
Block a user