[openssl-dev] [openssl.org #2021] sni bug

Salz, Rich via RT rt at openssl.org
Mon Feb 8 18:51:27 UTC 2016


> A correct logic is one single function(the code of check and parse combined)
> that collects the values of extensions and then treat them calls callbacks in a
> defined order.

Yes, but right now we've got what we've got :)
 
> Actually it seems that you could influence the server behavoiur if you change
> the order of extensions in the clienthello.

Probably.

> sni first or last for example.
> That makes server application code difficult.

Yes.  It would be great to have a single function that got all parsed extensions.  Sadly, I don't know if we'll get it fixed before the final API-change deadline. :(


-- 
Ticket here: http://rt.openssl.org/Ticket/Display.html?id=2021
Please log in as guest with password guest if prompted



More information about the openssl-dev mailing list