Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(582)

Issue 19607008: net: allow fallback down to TLS 1.0 in the event of a bad-record-MAC alert. (Closed)

Created:
7 years, 5 months ago by agl
Modified:
7 years, 5 months ago
CC:
chromium-reviews, cbentzel+watch_chromium.org, wtc
Visibility:
Public.

Description

net: allow fallback down to TLS 1.0 in the event of a bad-record-MAC alert. TLS 1.1 support has uncovered several examples of a new kind of broken server: they negotiate TLS 1.0 correctly in the face of a 1.1 or 1.2 ClientHello, but then fail with a bad-record-MAC alert when processing the client's Finished message. This bug is exhibited by at least two different types of SSL "accelerator" device, which will probably take forever to be fixed. So, with a heavy heart, this change adds yet another workaround. BUG=260358 R=rsleevi@chromium.org Committed: https://src.chromium.org/viewvc/chrome?view=rev&revision=212122

Patch Set 1 #

Unified diffs Side-by-side diffs Delta from patch set Stats (+9 lines, -0 lines) Patch
M net/socket/ssl_client_socket_nss.cc View 1 chunk +9 lines, -0 lines 0 comments Download

Messages

Total messages: 7 (0 generated)
agl
jar: sending this to you because wtc and sleevi are away. It probably needs a ...
7 years, 5 months ago (2013-07-17 16:52:25 UTC) #1
Ryan Sleevi
On 2013/07/17 16:52:25, agl wrote: > jar: sending this to you because wtc and sleevi ...
7 years, 5 months ago (2013-07-17 17:35:11 UTC) #2
Ryan Sleevi
Can you provide more details on the bug, so that we can track this appropriately? ...
7 years, 5 months ago (2013-07-17 17:42:05 UTC) #3
Ryan Sleevi
Oh, and LGTM for the NSS side.
7 years, 5 months ago (2013-07-17 17:42:15 UTC) #4
agl
On Wed, Jul 17, 2013 at 1:42 PM, <rsleevi@chromium.org> wrote: > Can you provide more ...
7 years, 5 months ago (2013-07-17 19:15:17 UTC) #5
agl
On Wed, Jul 17, 2013 at 3:14 PM, Adam Langley <agl@chromium.org> wrote: > I think ...
7 years, 5 months ago (2013-07-17 19:19:13 UTC) #6
agl
7 years, 5 months ago (2013-07-17 20:15:30 UTC) #7
Message was sent while issue was closed.
Committed patchset #1 manually as r212122 (presubmit successful).

Powered by Google App Engine
This is Rietveld 408576698