From b3ad72ce1de399322c4362acc2d4d792f7f14893 Mon Sep 17 00:00:00 2001 From: Matt Caswell Date: Thu, 19 Jan 2017 10:07:50 +0000 Subject: [PATCH] Set the kex modes on the client too. Reviewed-by: Rich Salz (Merged from https://github.com/openssl/openssl/pull/2259) --- ssl/statem/extensions_clnt.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/ssl/statem/extensions_clnt.c b/ssl/statem/extensions_clnt.c index 8c663320e1..1e6eddf373 100644 --- a/ssl/statem/extensions_clnt.c +++ b/ssl/statem/extensions_clnt.c @@ -516,6 +516,8 @@ int tls_construct_ctos_psk_kex_modes(SSL *s, WPACKET *pkt, X509 *x, SSLerr(SSL_F_TLS_CONSTRUCT_CTOS_PSK_KEX_MODES, ERR_R_INTERNAL_ERROR); return 0; } + + s->ext.psk_kex_mode = TLSEXT_KEX_MODE_FLAG_KE | TLSEXT_KEX_MODE_FLAG_KE_DHE; #endif return 1; -- 2.25.1