CVSROOT: /cvs Module name: src Changes by: t...@cvs.openbsd.org 2020/05/09 08:02:24
Modified files: lib/libssl : tls13_server.c Log message: Make the test for the legacy_compression_method vector in the ClientHello stricter. Previously, we would accept any vector if it advertised the "null" compression method. RFC 8446 4.1.2 specifies that the only legal vector has length one and contains a zero byte for the null method. ok jsing