[crypto] Ignore any data digested before TLS key schedule is started

The initial ClientHello is sent and digested before the key schedule
has been started (since the digest algorithm is not known until the
ServerHello arrives).

A server that sends a premature ServerHello with an all-zero nonce
before the ClientHello is sent can currently cause the key schedule's
"nonced" flag to become set.  The flag will be reset when the key
schedule is started and so this is unclean but harmless.

Fix by ignoring any data that arrives before the digest algorithm has
been set (i.e. before the key schedule has been started), since the
null digest algorithm cannot meaningfully incorporate anything into a
running transcript digest.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
Michael Brown
2026-09-21 18:16:19 +01:00
parent ed4a9b2e67
commit 194306d457
+4
View File
@@ -424,6 +424,10 @@ void tlskey_digest ( struct tls_key_schedule *tlskey, const void *data,
uint8_t ctx[ctxsize];
} tmp;
/* Do nothing if key schedule is stopped */
if ( ! digestsize )
return;
/* Append to running transcript digest */
digest_update ( digest, transcript->ctx, data, len );