Make tls_session_secret_cb work with CVE-2014-0224 fix.
authorDr. Stephen Henson <steve@openssl.org>
Sat, 7 Jun 2014 14:21:13 +0000 (15:21 +0100)
committerDr. Stephen Henson <steve@openssl.org>
Sat, 7 Jun 2014 14:27:21 +0000 (15:27 +0100)
If application uses tls_session_secret_cb for session resumption
set the CCS_OK flag.
(cherry picked from commit 953c592572e8811b7956cc09fbd8e98037068b58)

ssl/s3_clnt.c

index 83d6ede3f7752e9f8018810696202100a5f9345a..2b1d2b8c5720f35fb43b8454ae660edc2ece42bd 100644 (file)
@@ -815,6 +815,7 @@ int ssl3_get_server_hello(SSL *s)
                        {
                        s->session->cipher = pref_cipher ?
                                pref_cipher : ssl_get_cipher_by_char(s, p+j);
+                       s->s3->flags |= SSL3_FLAGS_CCS_OK;
                        }
                }
 #endif /* OPENSSL_NO_TLSEXT */