Omitting the extension means we'll never issue tickets, but if the client were to offer a ticket anyway, RFC8446 4.2.9 says we MUST reject the ClientHello. It's not clear on what alert to use, but missing_extension is probably appropriate. Thanks to Ben Kaduk for pointing this out. Change-Id: Ie5c720eac9dd2e1a27ba8a13c59b707c109eaa4e Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/46464 Commit-Queue: David Benjamin <davidben@google.com> Commit-Queue: Adam Langley <agl@google.com> Reviewed-by: Adam Langley <agl@google.com>grpc-202302
parent
4aef687fcf
commit
3af62269df
4 changed files with 33 additions and 3 deletions
Loading…
Reference in new issue