]> git.ipfire.org Git - thirdparty/openssl.git/commitdiff
Increase PSK_MAX_IDENTITY_LEN from 128 to 256
authorEric Curtin <ericcurtin17@gmail.com>
Wed, 2 Sep 2020 09:49:47 +0000 (10:49 +0100)
committerMatt Caswell <matt@openssl.org>
Mon, 21 Sep 2020 08:32:22 +0000 (09:32 +0100)
We are considering using the format "host-nqn controller-nqn" for
psk-id in the NVMe-oF/TCP over TLS spec, it's in the current version,
but openssl's limit was 128 upto now, we need a little longer than that.

Reviewed-by: Shane Lontis <shane.lontis@oracle.com>
Reviewed-by: Matt Caswell <matt@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/12771)

include/openssl/ssl.h.in

index ac7c521e95f1e441c064127e182449424cf74a12..1d7996ed614896c278f5699b948c09ea0113406a 100644 (file)
@@ -849,7 +849,7 @@ void SSL_get0_alpn_selected(const SSL *ssl, const unsigned char **data,
  * the maximum length of the buffer given to callbacks containing the
  * resulting identity/psk
  */
-#  define PSK_MAX_IDENTITY_LEN 128
+#  define PSK_MAX_IDENTITY_LEN 256
 #  define PSK_MAX_PSK_LEN 512
 typedef unsigned int (*SSL_psk_client_cb_func)(SSL *ssl,
                                                const char *hint,