HomeFreeBSD

OpenSSL: KTLS: Handle TLS 1.3 in ssl3_get_record.

Description

OpenSSL: KTLS: Handle TLS 1.3 in ssl3_get_record.

  • Don't unpad records, check the outer record type, or extract the inner record type from TLS 1.3 records handled by the kernel. KTLS performs all of these steps and returns the inner record type in the TLS header.
  • When checking the length of a received TLS 1.3 record don't allow for the extra byte for the nested record type when KTLS is used.
  • Pass a pointer to the record type in the TLS header to the SSL3_RT_INNER_CONTENT_TYPE message callback. For KTLS, the old pointer pointed to the last byte of payload rather than the record type. For the non-KTLS case, the TLS header has been updated with the inner type before this callback is invoked.

Approved by: jkim
Obtained from: OpenSSL commit a5fb9605329fb939abb536c1604d44a511741624
MFC after: 1 week
Sponsored by: Netflix
Differential Revision: https://reviews.freebsd.org/D34975

Details

Provenance
jhbAuthored on May 4 2022, 8:08 PM
Differential Revision
D34975: OpenSSL: KTLS: Handle TLS 1.3 in ssl3_get_record.
Parents
rG4f1f9c550227: OpenSSL: KTLS: Add using_ktls helper variable in ssl3_get_record().
Branches
Unknown
Tags
Unknown