TLS Extensions: add more extensions and improve current - #11362
Conversation
81d6404 to
e16541a
Compare
|
646253f to
55ec736
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11362
Scan targets checked: wolfcrypt-rs-bugs, wolfssl-bugs, wolfssl-src
Findings: 3
3 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
55ec736 to
72e8586
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11362
Scan targets checked: wolfcrypt-rs-bugs, wolfssl-bugs, wolfssl-src
Findings: 3
3 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
72e8586 to
f512027
Compare
f512027 to
de17187
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11362
Scan targets checked: wolfcrypt-rs-bugs, wolfssl-bugs, wolfssl-src
Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
de17187 to
1882e64
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11362
Scan targets checked: wolfcrypt-rs-bugs, wolfssl-bugs, wolfssl-src
Findings: 1
1 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
Added support for record_size_limit in TLS 1.3 and TLS 1.2. Added compress_certificate support for TLS 1.3. Added signed_certificate_timestamp TLS 1.2 send and TLS 1.2 and 1.3 receive. Accepts server_name in CertificateRequest. Added API for setting signature algorithms for signature_algorithms_cert. Tests added and interop performed where possible.
1882e64 to
3557bfd
Compare
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11362
Scan targets checked: wolfcrypt-rs-bugs, wolfssl-bugs, wolfssl-src
Findings: 2
2 finding(s) posted as inline comments (see file-level comments below)
This review was generated automatically by Fenrir. Reported findings require changes before merge.
| * must not shrink its own records either - otherwise any client could | ||
| * push a server that never opted in down to 64-byte records and pay | ||
| * it in per-record overhead. */ | ||
| if (ssl->recordSizeLimit == 0) |
There was a problem hiding this comment.
Server discards peer's record_size_limit when its own limit is 0 · TLS protocol issues
On client_hello the parser returns before ssl->peerRecordSizeLimit = limit when ssl->recordSizeLimit == 0. RFC 8449 limits are per-direction, so a server configured with wolfSSL_CTX_UseRecordSizeLimit(ctx, 0) keeps sending full 2^14 records to a peer that advertised a smaller limit.
Related known finding #7004 (similar but distinct): Both concern RFC 8449 record_size_limit handling, but #7004 was the absence of extension registration and parsing in TLSX_Parse, while this is an existing parser in TLSX_RecordSizeLimit_Parse failing to retain the peer's limit under a local-limit condition. The faulting operations and root causes differ, and separate patches are required.
Fix: Skip only the TLSX_Push/TLSX_SetResponse when ssl->recordSizeLimit == 0, and always assign ssl->peerRecordSizeLimit.
| * default, into one that never compresses. */ | ||
| if (ssl->options.side == WOLFSSL_SERVER_END) { | ||
| #ifdef HAVE_CERTIFICATE_STATUS_REQUEST | ||
| if (ssl->status_request != 0) |
There was a problem hiding this comment.
Compressed Certificate silently drops the signed_certificate_timestamp response · Cryptographic correctness
The cached ctx->certComp body is built by BuildTls13CertificateBody() with hardcoded empty per-certificate extensions. UseCompressedCertificate() opts out for status_request/status_request_v2 but not for a pending SCT response, so a server with both features enabled sends a CompressedCertificate carrying no SCT list even though it marked the extension as a response.
Fix: Add a HAVE_SIGNED_CERT_TIMESTAMP guard returning 0 when ssl->sctListSz > 0 (or ssl->sctRequested) alongside the existing status_request checks.
Description
Added support for record_size_limit in TLS 1.3 and TLS 1.2. Added compress_certificate support for TLS 1.3.
Added signed_certificate_timestamp TLS 1.2 send and TLS 1.2 and 1.3 receive. Accepts server_name in CertificateRequest.
Added API for setting signature algorithms for signature_algorithms_cert.
Tests added and interop performed where possible.
Testing
Regression tested TLS.