Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

修复TLS 1.3使用商密套件时未严格遵循RFC 8998问题 #543

Merged
merged 1 commit into from
Dec 4, 2023
Merged

Conversation

dongbeiouba
Copy link
Member

Fixed #491

强制遵循RFC 8998时:
当使用商密套件且加载双证书时,修复未选择SM2证书问题;
收到CertificateVerify需要检查签名算法,如果不是sm2sig_sm3,应该alert。

修复TLS 1.3商密套件trace,unknown问题;
SSL conf中增加Trace配置项,Trace设置为on时,可以输出TLS消息,方便定位问题。

Checklist
  • https://yuque.com/tsdoc 增加或更新了必要的文档
  • 增加或更新了必要的测试用例
  • 对于重要修改,更新了CHANGES文件
  • 当前修改存在对已有API参数或返回值的改变
  • 当前修改存在对旧版本功能的兼容性改变(如网络协议或密码算法)

@dongbeiouba dongbeiouba added bug Something isn't working branch-8.3 labels Nov 29, 2023
@dongbeiouba dongbeiouba requested review from InfoHunter, wa5i and a team November 29, 2023 09:39
@dongbeiouba dongbeiouba linked an issue Nov 29, 2023 that may be closed by this pull request
Fixed #491

强制遵循RFC 8998时:
当使用商密套件且加载双证书时,修复未选择SM2证书问题;
收到CertificateVerify需要检查签名算法,如果不是sm2sig_sm3,应该alert。

修复TLS 1.3商密套件trace,unknown问题;
SSL conf中增加Trace配置项,Trace设置为on时,可以输出TLS消息,方便定位问题。
@InfoHunter InfoHunter merged commit 4e7aa2c into Tongsuo-Project:8.3-stable Dec 4, 2023
55 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
branch-8.3 bug Something isn't working
Projects
None yet
Development

Successfully merging this pull request may close these issues.

关于实现RFC 8998中存在几处不合理的点
2 participants