Simon Josefsson commented on a discussion: 
https://gitlab.com/gnutls/gnutls/-/issues/1739#note_2764724851


I think it is technically impossible to tell those two situations apart, and 
that is also why the specification mandates that the alert has to be sent, so 
that recipient knows it has reached EOF.  Some TLS implementations historically 
just ignored this error case, but that is a security problem.  How does OpenSSL 
behave in this situation?  Or some other TLS library.

-- 
Reply to this email directly or view it on GitLab: 
https://gitlab.com/gnutls/gnutls/-/issues/1739#note_2764724851
You're receiving this email because of your account on gitlab.com.


_______________________________________________
Gnutls-devel mailing list
[email protected]
http://lists.gnupg.org/mailman/listinfo/gnutls-devel
  • [gnutls-de... Read-only notification of GnuTLS library development activities
    • Re: [... Read-only notification of GnuTLS library development activities
    • Re: [... Read-only notification of GnuTLS library development activities
    • Re: [... Read-only notification of GnuTLS library development activities
    • Re: [... Read-only notification of GnuTLS library development activities
    • Re: [... Read-only notification of GnuTLS library development activities
    • Re: [... Read-only notification of GnuTLS library development activities
    • Re: [... Read-only notification of GnuTLS library development activities
    • Re: [... Read-only notification of GnuTLS library development activities

Reply via email to