I have my own small TLS implementation and when I'm using it to connect to an OpenSSL TLS server, I've noticed that OpenSSL accepts two different types of ClientKeyExchange messages. When using an RSA key exchange mode, OpenSSL apparently doesn't care whether I prepend the EncryptedPreMasterSecret with its length or not. According to the TLS standard, implementations are required to prepend the length of the public-key-encrypted PreMasterSecret because it is sent as an opaque vector.
Why does OpenSSL accept the 'wrong' ClientKeyExchange message? I've noticed that MS's implementation also accepts both versions, however other implementations, such as Sun's, do not accept the version without the prepended length. Regards, Pieter Philippaerts ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]
