From: Norbert Pocs Date: Sun, 11 May 2025 15:36:05 +0000 (+0200) Subject: s3_lib.c: Handle weak x keys as illegal_parameter alert X-Git-Tag: openssl-3.5.1~108 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=cc347063046ea244394c24b5fcb5372c97cb7628;p=thirdparty%2Fopenssl.git s3_lib.c: Handle weak x keys as illegal_parameter alert Reviewed-by: Saša Nedvědický Reviewed-by: Tomas Mraz (Merged from https://github.com/openssl/openssl/pull/27597) (cherry picked from commit 5da4ea10be8cf8ca66dff95c9997966f21c82029) --- diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c index 22095fbf232..e6177950c92 100644 --- a/ssl/s3_lib.c +++ b/ssl/s3_lib.c @@ -5036,7 +5036,10 @@ int ssl_derive(SSL_CONNECTION *s, EVP_PKEY *privkey, EVP_PKEY *pubkey, int gense } if (EVP_PKEY_derive(pctx, pms, &pmslen) <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + /* + * the public key was probably a weak key + */ + SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_KEY_SHARE); goto err; }