Page MenuHomeFreeBSD

ktls: Fix assertion for TLS 1.0 CBC when using non-zero starting seqno.
ClosedPublic

Authored by jhb on Oct 26 2021, 11:31 PM.
Tags
None
Referenced Files
F147487127: D32676.id97509.diff
Wed, Mar 11, 9:16 AM
Unknown Object (File)
Tue, Mar 3, 4:20 AM
Unknown Object (File)
Feb 9 2026, 1:25 AM
Unknown Object (File)
Jan 6 2026, 12:11 PM
Unknown Object (File)
Dec 20 2025, 12:44 AM
Unknown Object (File)
Nov 24 2025, 1:47 AM
Unknown Object (File)
Nov 10 2025, 8:38 PM
Unknown Object (File)
Nov 9 2025, 12:57 AM
Subscribers

Details

Summary

The starting sequence number used to verify that TLS 1.0 CBC records
are encrypted in-order in the OCF layer was always set to 0 and not to
the initial sequence number from the struct tls_enable.

In practice, OpenSSL always starts TLS transmit offload with a
sequence number of zero, so this only matters for tests that use a
random starting sequence number.

Sponsored by: Netflix

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable