[tls] Transition to handshake traffic keys after receiving ServerHello

The ServerHello provides the earliest point at which the handshake
traffic keys can be generated, and the defined point at which the
receive cipher must transition to using the handshake traffic key.

We do not intend to support sending early data, and so this also
provides a convenient point at which to transition the tranmit cipher
to using the handshake traffic key.

Signed-off-by: Michael Brown <mcb30@ipxe.org>
This commit is contained in:
Michael Brown
2026-09-14 22:26:03 +01:00
parent 9077d45852
commit 8087d6ac22
+6
View File
@@ -2817,6 +2817,12 @@ static int tls_new_server_hello ( struct tls_connection *tls,
return rc;
}
/* Schedule change to handshake traffic keys, if applicable */
if ( tls_version ( tls, TLS_VERSION_TLS_1_3 ) ) {
tls->tx.cipherspec.pending = &tls_handshake;
tls->rx.cipherspec.pending = &tls_handshake;
}
return 0;
}