mirror of
https://github.com/ipxe/ipxe
synced 2026-10-07 15:05:42 +03:00
[tls] Exclude sequence number from authentication for TLS version 1.3
The authentication header used for TLS version 1.3 no longer includes the sequence number, since the use of sequential initialisation vectors renders it redundant. Skip authenticating this portion of the authentication header for TLS version 1.3 or later. Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
+15
-4
@@ -3559,8 +3559,14 @@ static int tls_send_record ( struct tls_connection *tls, unsigned int type,
|
||||
record_len, mac );
|
||||
}
|
||||
if ( is_auth_cipher ( cipher ) ) {
|
||||
cipher_encrypt ( cipher, pipe->ctx, &authhdr, NULL,
|
||||
sizeof ( authhdr ) );
|
||||
if ( tls_version ( tls, TLS_VERSION_TLS_1_3 ) ) {
|
||||
cipher_encrypt ( cipher, pipe->ctx,
|
||||
&authhdr.header, NULL,
|
||||
sizeof ( authhdr.header ) );
|
||||
} else {
|
||||
cipher_encrypt ( cipher, pipe->ctx, &authhdr,
|
||||
NULL, sizeof ( authhdr ) );
|
||||
}
|
||||
}
|
||||
|
||||
/* Calculate encryption length */
|
||||
@@ -3780,8 +3786,13 @@ static int tls_new_ciphertext ( struct tls_connection *tls,
|
||||
/* Process authentication data, if applicable */
|
||||
authhdr.header.length = htons ( len );
|
||||
if ( is_auth_cipher ( cipher ) ) {
|
||||
cipher_decrypt ( cipher, pipe->ctx, &authhdr,
|
||||
NULL, sizeof ( authhdr ) );
|
||||
if ( tls_version ( tls, TLS_VERSION_TLS_1_3 ) ) {
|
||||
cipher_decrypt ( cipher, pipe->ctx, &authhdr.header,
|
||||
NULL, sizeof ( authhdr.header ) );
|
||||
} else {
|
||||
cipher_decrypt ( cipher, pipe->ctx, &authhdr,
|
||||
NULL, sizeof ( authhdr ) );
|
||||
}
|
||||
}
|
||||
|
||||
/* Decrypt the received data */
|
||||
|
||||
Reference in New Issue
Block a user