]> git.ipfire.org Git - thirdparty/openssl.git/commit
Correct alert when extended master secret support is dropped
authorTomas Mraz <tomas@openssl.org>
Wed, 21 Jan 2026 17:50:07 +0000 (18:50 +0100)
committerNorbert Pocs <norbertp@openssl.org>
Fri, 23 Jan 2026 10:32:58 +0000 (11:32 +0100)
commitcf29b4194e7eb486fccabd56e3e4c84fd318516c
tree4ab246700b070010e8691f93fcb07f7dccc5bf3e
parentf5f85711192bddfabeec278ab4bec6c1de688ec5
Correct alert when extended master secret support is dropped

When resuming session with the extended master secret support
dropped we should use SSL_AD_HANDSHAKE_FAILURE instead of
SSL_AD_ILLEGAL_PARAMETER according to the RFC7627 section 5.

Fixes #9791

Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Matt Caswell <matt@openssl.org>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
MergeDate: Fri Jan 23 10:33:12 2026
(Merged from https://github.com/openssl/openssl/pull/29706)
ssl/ssl_sess.c