mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-25 09:57:32 +09:00
Update NSS to 3.48 while keeping vc2013 hackfix and no-sslkeylogfile intact.
This commit is contained in:
parent
0b9855b841
commit
171849c8e5
351 changed files with 115185 additions and 57946 deletions
|
|
@ -14,6 +14,7 @@
|
|||
#include "ssl3exthandle.h"
|
||||
#include "tls13esni.h"
|
||||
#include "tls13exthandle.h"
|
||||
#include "tls13subcerts.h"
|
||||
|
||||
SECStatus
|
||||
tls13_ServerSendStatusRequestXtn(const sslSocket *ss, TLSExtensionData *xtnData,
|
||||
|
|
@ -448,7 +449,7 @@ tls13_ClientSendPreSharedKeyXtn(const sslSocket *ss, TLSExtensionData *xtnData,
|
|||
goto loser;
|
||||
|
||||
/* Obfuscated age. */
|
||||
age = ssl_TimeUsec() - session_ticket->received_timestamp;
|
||||
age = ssl_Time(ss) - session_ticket->received_timestamp;
|
||||
age /= PR_USEC_PER_MSEC;
|
||||
age += session_ticket->ticket_age_add;
|
||||
rv = sslBuffer_AppendNumber(buf, age, 4);
|
||||
|
|
@ -1400,3 +1401,94 @@ tls13_ClientCheckEsniXtn(sslSocket *ss)
|
|||
|
||||
return SECSuccess;
|
||||
}
|
||||
|
||||
/* Indicates support for the delegated credentials extension. This should be
|
||||
* hooked while processing the ClientHello.
|
||||
*/
|
||||
SECStatus
|
||||
tls13_ClientSendDelegatedCredentialsXtn(const sslSocket *ss,
|
||||
TLSExtensionData *xtnData,
|
||||
sslBuffer *buf, PRBool *added)
|
||||
{
|
||||
/* Only send the extension if support is enabled and the client can
|
||||
* negotiate TLS 1.3.
|
||||
*/
|
||||
if (ss->vrange.max < SSL_LIBRARY_VERSION_TLS_1_3 ||
|
||||
!ss->opt.enableDelegatedCredentials) {
|
||||
return SECSuccess;
|
||||
}
|
||||
|
||||
*added = PR_TRUE;
|
||||
return SECSuccess;
|
||||
}
|
||||
|
||||
/* Parses the delegated credential (DC) offered by the server. This should be
|
||||
* hooked while processing the server's CertificateVerify.
|
||||
*
|
||||
* Only the DC sent with the end-entity certificate is to be parsed. This is
|
||||
* ensured by |tls13_HandleCertificateEntry|, which only processes extensions
|
||||
* for the first certificate in the chain.
|
||||
*/
|
||||
SECStatus
|
||||
tls13_ClientHandleDelegatedCredentialsXtn(const sslSocket *ss,
|
||||
TLSExtensionData *xtnData,
|
||||
SECItem *data)
|
||||
{
|
||||
if (!ss->opt.enableDelegatedCredentials ||
|
||||
ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
|
||||
ssl3_ExtSendAlert(ss, alert_fatal, illegal_parameter);
|
||||
PORT_SetError(SSL_ERROR_RX_UNEXPECTED_EXTENSION);
|
||||
return SECFailure;
|
||||
}
|
||||
|
||||
SECStatus rv = tls13_ReadDelegatedCredential(data->data, data->len,
|
||||
&xtnData->peerDelegCred);
|
||||
if (rv != SECSuccess) {
|
||||
return SECFailure; /* code already set */
|
||||
}
|
||||
|
||||
xtnData->negotiated[xtnData->numNegotiated++] =
|
||||
ssl_delegated_credentials_xtn;
|
||||
return SECSuccess;
|
||||
}
|
||||
|
||||
/* Adds the DC extension if we're committed to authenticating with a DC. */
|
||||
static SECStatus
|
||||
tls13_ServerSendDelegatedCredentialsXtn(const sslSocket *ss,
|
||||
TLSExtensionData *xtnData,
|
||||
sslBuffer *buf, PRBool *added)
|
||||
{
|
||||
if (tls13_IsSigningWithDelegatedCredential(ss)) {
|
||||
const SECItem *dc = &ss->sec.serverCert->delegCred;
|
||||
|
||||
if (tls13_IsSigningWithDelegatedCredential(ss)) {
|
||||
SECStatus rv;
|
||||
rv = sslBuffer_Append(buf, dc->data, dc->len);
|
||||
if (rv != SECSuccess) {
|
||||
return SECFailure;
|
||||
}
|
||||
}
|
||||
|
||||
*added = PR_TRUE;
|
||||
return SECSuccess;
|
||||
}
|
||||
|
||||
return SECSuccess;
|
||||
}
|
||||
|
||||
/* The client has indicated support of DCs. We can't act on this information
|
||||
* until we've committed to signing with a DC, so just set a callback for
|
||||
* sending the DC extension later. */
|
||||
SECStatus
|
||||
tls13_ServerHandleDelegatedCredentialsXtn(const sslSocket *ss,
|
||||
TLSExtensionData *xtnData,
|
||||
SECItem *data)
|
||||
{
|
||||
xtnData->peerRequestedDelegCred = PR_TRUE;
|
||||
xtnData->negotiated[xtnData->numNegotiated++] =
|
||||
ssl_delegated_credentials_xtn;
|
||||
|
||||
return ssl3_RegisterExtensionSender(
|
||||
ss, xtnData, ssl_delegated_credentials_xtn,
|
||||
tls13_ServerSendDelegatedCredentialsXtn);
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue