From: Matt Caswell Date: Mon, 7 Nov 2016 13:49:18 +0000 (+0000) Subject: Ignore the record version in TLS1.3 X-Git-Tag: OpenSSL_1_1_1-pre1~3172 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=3c9539d294b931bc430a01510753e10b7a201f11;p=oweals%2Fopenssl.git Ignore the record version in TLS1.3 The record layer version field must be ignored in TLSv1.3, so we remove the check when using that version. Reviewed-by: Rich Salz --- diff --git a/ssl/record/ssl3_record.c b/ssl/record/ssl3_record.c index f160c06746..181ebbbfb8 100644 --- a/ssl/record/ssl3_record.c +++ b/ssl/record/ssl3_record.c @@ -204,8 +204,9 @@ int ssl3_get_record(SSL *s) rr[num_recs].rec_version = version; n2s(p, rr[num_recs].length); - /* Lets check version */ - if (!s->first_packet && version != s->version) { + /* Lets check version. In TLSv1.3 we ignore this field */ + if (!s->first_packet && s->version != TLS1_3_VERSION + && version != s->version) { SSLerr(SSL_F_SSL3_GET_RECORD, SSL_R_WRONG_VERSION_NUMBER); if ((s->version & 0xFF00) == (version & 0xFF00) && !s->enc_write_ctx && !s->write_hash) {