Page MenuHomeFreeBSD

ktls: Reject attempts to enable AES-CBC with TLS 1.3.
ClosedPublic

Authored by jhb on Oct 9 2021, 3:13 PM.
Tags
None
Referenced Files
Unknown Object (File)
Feb 9 2024, 8:40 PM
Unknown Object (File)
Jan 12 2024, 8:44 AM
Unknown Object (File)
Dec 23 2023, 10:47 AM
Unknown Object (File)
Dec 15 2023, 12:17 PM
Unknown Object (File)
Dec 12 2023, 1:33 PM
Unknown Object (File)
Dec 11 2023, 2:41 PM
Unknown Object (File)
Dec 8 2023, 5:55 PM
Unknown Object (File)
Nov 7 2023, 10:07 AM
Subscribers

Details

Summary

AES-CBC cipher suites are not supported in TLS 1.3.

Reported by: syzbot+ab501c50033ec01d53c6@syzkaller.appspotmail.com

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 42044
Build 38932: arc lint + arc unit

Event Timeline

jhb requested review of this revision.Oct 9 2021, 3:13 PM

I haven't tested this yet. I can try to do that this week unless one of y'all want to beat me to it.

In D32404#731030, @jhb wrote:

I haven't tested this yet. I can try to do that this week unless one of y'all want to beat me to it.

I verified that the repro works and that this patch causes it to return EINVAL instead.

This revision is now accepted and ready to land.Oct 9 2021, 3:30 PM

I've tested that all the expected cipher suites and versions still work.