cron2 has uploaded a new patch set (#3) to the change originally created by plaisthos. ( http://gerrit.openvpn.net/c/openvpn/+/1829?usp=email )
The following approvals got outdated and were removed: Code-Review+2 by ordex Change subject: Correctly calculate packet id size when epoch packet format is in use ...................................................................... Correctly calculate packet id size when epoch packet format is in use The code assumed that always when tls mode (without CFB/OFB) is in use that the packet size is 4 bytes. With epoch packet format is incorrect as that uses 64 bit. Even thought packet_id_long_form has a the same size (8 byte) it is not the same header format (32 bit time + 32 bit IV) as the epoch format (16 bit epoch + 48 IV). Use a simple sizeof(uint64_t) to avoid suggesting that it might be the same. Github: closes OpenVPN/openvpn#1074 Change-Id: I5b862eabe032eb4d2229ff5b2f4f6af7406f6f4e Signed-off-by: Arne Schwabe <[email protected]> Acked-by: Antonio Quartulli <[email protected]> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1829 Message-Id: <[email protected]> URL: https://www.mail-archive.com/[email protected]/msg37983.html Signed-off-by: Gert Doering <[email protected]> --- M src/openvpn/mtu.c 1 file changed, 8 insertions(+), 0 deletions(-) git pull ssh://gerrit.openvpn.net:29418/openvpn refs/changes/29/1829/3 diff --git a/src/openvpn/mtu.c b/src/openvpn/mtu.c index e5db8ab..f3c2874 100644 --- a/src/openvpn/mtu.c +++ b/src/openvpn/mtu.c @@ -35,6 +35,7 @@ #include "crypto.h" #include "memdbg.h" +#include "ssl_common.h" /* allocate a buffer for socket or tun layer */ void @@ -51,6 +52,13 @@ calc_packet_id_size_dc(const struct options *options, const struct key_type *kt) { bool tlsmode = options->tls_server || options->tls_client; + bool epoch = options->imported_protocol_flags & CO_EPOCH_DATA_KEY_FORMAT; + + /* epoch format uses a 64-bit packet id: 16 bit epoch + 48 bit per-epoch counter */ + if (epoch) + { + return sizeof(uint64_t); + } bool packet_id_long_form = !tlsmode || cipher_kt_mode_ofb_cfb(kt->cipher); -- To view, visit http://gerrit.openvpn.net/c/openvpn/+/1829?usp=email To unsubscribe, or for help writing mail filters, visit http://gerrit.openvpn.net/settings?usp=email Gerrit-MessageType: newpatchset Gerrit-Project: openvpn Gerrit-Branch: master Gerrit-Change-Id: I5b862eabe032eb4d2229ff5b2f4f6af7406f6f4e Gerrit-Change-Number: 1829 Gerrit-PatchSet: 3 Gerrit-Owner: plaisthos <[email protected]> Gerrit-Reviewer: ordex <[email protected]> Gerrit-CC: openvpn-devel <[email protected]>
_______________________________________________ Openvpn-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/openvpn-devel
