PLATFORM: All
VERSION: 0.9.6

DESCRIPTION: If you have your server configured to support only
SSLv3 or only TLS (SSLv3_method, SSLv3_server_method, TLSv1_method,
TLSv1_server_method) then the server will simply attempt to
use whatever version of SSL/TLS it is configured to, ignoring
the client's version number. This isn't a problem when the server
is TLS and the client is SSLv3, but it is a problem in the reverse
case as the following ssldump shows:

New TCP connection #4: localhost.rtfm.com(2363) <-> localhost.rtfm.com(4433)
4 1  0.0024 (0.0024)  C>S  Handshake
      ClientHello
        Version 3.0 
        cipher suites
        SSL_RSA_WITH_RC4_128_SHA
        compression methods
                  NULL
4 2  0.0029 (0.0004)  S>C  Handshake
      ServerHello
        Version 3.1 
        session_id[32]=
          b7 51 7d 74 1e 85 09 43 a7 51 8f 03 d7 ba 1a 8a 
          53 43 61 b7 c8 f2 0c ab 5b df 21 d1 f1 0e d5 eb 
        cipherSuite         TLS_RSA_WITH_RC4_128_SHA
        compressionMethod                   NULL
4 3  0.0029 (0.0000)  S>C  Handshake
      Certificate
4 4  0.0029 (0.0000)  S>C  Handshake
      ServerHelloDone
4 5  0.0035 (0.0005)  C>S  Alert
    level           fatal
    value           handshake_failure
4    0.0052 (0.0017)  S>C  TCP FIN
4    0.0057 (0.0004)  C>S  TCP FIN


The correct behavior for a TLS-only server at this point would be to
generate an alert (probably handshake_failure) not to attempt to
continue with TLSv1 even though the client has explicitly only offered

HOW TO REPRODUCE: 
Start a server with:
openssl s_server -tls1

And connect to it with a client with:
openssl s_client -ssl3

WHERE THE PROBLEM IS:
The problem is in ssl3_server.c. It simply reads the client's version
and places it into s->client_version. It needs to look at it using
some code analagous to that in ssl23_client_hello.

I'm willing to provide a fix for this (it doesn't look that difficult)
but I think that it might be more straightforward for someone on the 
team to do so. If you guys would like me to do so, let me know.


This problem was originally discovered by Robert R. Branum, Jr. at Cisco.

-Ekr





______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to