Re: TLS 1.3 non compliance with current draft

Matt Caswell <[email protected]> Mon, 4 Sep 2017 07:51:19 +0100
Newsgroups gmane.comp.encryption.openssl.devel
Message-ID <[email protected]>

On 01/09/17 18:05, Hubert Kario wrote:
> When openssl sends a second Client Hello message, it modifies it quite 
> extensively, not only client_random is changed but also advertised cipher 
> suites.
> 
> see https://github.com/openssl/openssl/issues/4292
> 
> That makes it non-compliant with the current draft (-21):

Yes, I've seen the github issue on this. I will take a look at this at
some point this week.

Matt

> 
>    When a client first connects to a server, it is REQUIRED to send the
>    ClientHello as its first message.  The client will also send a
>    ClientHello when the server has responded to its ClientHello with a
>    HelloRetryRequest.  In that case, the client *MUST send the same*
>    *ClientHello* (without modification) except:
> 
>    -  If a "key_share" extension was supplied in the HelloRetryRequest,
>       replacing the list of shares with a list containing a single
>       KeyShareEntry from the indicated group.
> 
>    -  Removing the "early_data" extension (Section 4.2.9) if one was
>       present.  Early data is not permitted after HelloRetryRequest.
> 
>    -  Including a "cookie" extension if one was provided in the
>       HelloRetryRequest.
> 
>    -  Updating the "pre_shared_key" extension if present by recomputing
>       the "obfuscated_ticket_age" and binder values and (optionally)
>       removing any PSKs which are incompatible with the server's
>       indicated cipher suite.
> 
> 
> 
>

-- 
openssl-dev mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev
signature.asc (application/pgp-signature, 480 B)
-----BEGIN PGP SIGNATURE-----

iQEuBAEBCAAYBQJZrPfnERxtYXR0QG9wZW5zc2wub3JnAAoJENnE0m0OYESRMYkH
/192YKuqvdACZ5bzmtZABrJePE6rwsxoaJ9tK5hp5ZWwetcAaD8Bzlk9eJtyKyN3
9NvDY0ulSzj1uZqLErZtp48qPaT42n6D8BFPWgz3hvLJuVdmFX8WugrhxZWukfg/
escN8Oo8kK+AeGJE2t26p3/gVACOG+RIHfMISr87lGc6cswf0LaYnJcE+tjCIfVX
ZRDvdXJ9V+y78UsGxsUEXVJdcjs1KH5YOCe98fFUhuVu1f8cptKzywZKmYDoYvpu
ykQpq3kT7wD+tf/EogTfq/qlv4m9bGp+6vwXMtMf4J9kaVpFxtH4jlisEohIUAwU
W0Lc0FAQK80+0opJJNfte38=
=ftld
-----END PGP SIGNATURE-----