Skip to content

Keep offering extended_master_secret on a resumed TLS 1.2 hello and tighten two parsers - #219

Merged
Xor-el merged 1 commit into
deep-audit-fixesfrom
audit-hs-handshake
Oct 6, 2026
Merged

Xor-el merged 1 commit into
deep-audit-fixesfrom
audit-hs-handshake

Conversation

@Xor-el

@Xor-el Xor-el commented Oct 6, 2026

Copy link
Copy Markdown
Owner

A TLS 1.2 client aligned its extended_master_secret offer to the cached session, so resuming a non-EMS session sent a hello without the extension; if the server then declined the ticket, the full handshake ran without EMS. The hello now always carries the extension per the configuration, and a hello that omits it no longer presents an EMS session (the server would have to abort that). A non-EMS session is still offered with EMS: BoGo's ExtendedMasterSecret-NoToNo-Client needs the resume and rustls does it too, so I left the "skip non-EMS sessions" refinement out.

Also: a server_name host_name with a byte outside printable ASCII is refused with illegal_parameter instead of becoming a lossy string that reaches the credential resolver, ticket host check and logs (same alert rustls uses for an invalid SNI); and the TLS 1.3 client parses the ServerHello extension block once and runs the allow-list before the decoders, so a malformed extension that may not appear there is reported as unsupported_extension. The CertificateRequest path reuses its parsed vector. The two stale BoGo [deferred] certificate_authorities entries are removed (both tests pass).

Tests: EMS offered with a non-EMS session, EMS session withheld without EMS, matching choices offered, the SNI byte boundaries, and the allow-list order; each fails when the matching logic is broken. FPC x64 and i386 1427/0, Delphi Win32 OK 1427, BoGo hard gate and fuzzer smoke clean.

…ighten two parsers

- A TLS 1.2 client no longer drops extended_master_secret from its hello
  because the cached session was made without it. A server that declines
  the old session then completes the full handshake with the extension, as
  RFC 7627 5.3 requires. The reverse is also closed: a hello that omits the
  extension does not present a session that was made with it.
- A server_name host_name with a byte outside printable ASCII is refused with
  illegal_parameter instead of collapsing to a lossy string that reaches the
  credential resolver, ticket host check and logs.
- The TLS 1.3 client parses the ServerHello extension block once and runs the
  allow-list before the decoders, so a malformed extension that may not appear
  there is reported as unsupported_extension. The CertificateRequest path
  reuses the vector it already parsed.
- Drop the two stale BoGo deferrals for certificate_authorities; both tests
  pass.
@Xor-el
Xor-el merged commit 184c09c into deep-audit-fixes Oct 6, 2026
15 checks passed
@Xor-el
Xor-el deleted the audit-hs-handshake branch October 7, 2026 19:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant