Use ciphersuite id when matching if we've got one
When matching a ciphersuite if we are given an id, make sure we use it otherwise we will match another ciphersuite which is identical except for the TLS version. Reviewed-by: Rich Salz <rsalz@openssl.org>
This commit is contained in:
parent
582a17d662
commit
0ced42e050
1 changed files with 2 additions and 0 deletions
|
@ -859,6 +859,8 @@ static void ssl_cipher_apply_rule(uint32_t cipher_id, uint32_t alg_mkey,
|
|||
cp->algorithm_enc, cp->algorithm_mac, cp->min_tls,
|
||||
cp->algo_strength);
|
||||
#endif
|
||||
if (cipher_id != 0 && (cipher_id != cp->id))
|
||||
continue;
|
||||
if (alg_mkey && !(alg_mkey & cp->algorithm_mkey))
|
||||
continue;
|
||||
if (alg_auth && !(alg_auth & cp->algorithm_auth))
|
||||
|
|
Loading…
Reference in a new issue