[openssl-dev] [openssl.org #3712] TLS Renegotiation with Java is broken

Alessandro Ghedini via RT rt at openssl.org
Fri Oct 9 19:03:45 UTC 2015


On Fri, Oct 09, 2015 at 06:05:19pm +0000, Matt Caswell via RT wrote:
> 
> 
> On 09/10/15 19:02, Hubert Kario via RT wrote:
> > And for good measure, I also created a test script that
> > combines fragmentation with interleaving.
> 
> Did you try my patch with it? And if so what happened?

I just tried both the test-interleaved-application-data-in-renegotiation.py and
test-interleaved-application-data-and-fragmented-handshakes-in-renegotiation.py
scripts and they both fail with your patch applied. In fact, your patch made
one more test from the first script to fail (3 failures with your patch, only
2 without the patch). On the other hand your patch makes the test in the
test-openssl-3712.py script succeed (which was the original test for thus bug
AFAIU).

I haven't really followed this discussion though, so I'm not sure what the
outcome should be (I'd imagine all tests should pass though).

Cheers




More information about the openssl-dev mailing list