I have my own small TLS implementation and when I'm using it to connect to
an OpenSSL TLS server, I've noticed that OpenSSL accepts two different types
of ClientKeyExchange messages. When using an RSA key exchange mode, OpenSSL
apparently doesn't care whether I prepend the EncryptedPreMasterSecret with
its length or not. According to the TLS standard, implementations are
required to prepend the length of the public-key-encrypted PreMasterSecret
because it is sent as an opaque vector.

Why does OpenSSL accept the 'wrong' ClientKeyExchange message? I've noticed
that MS's implementation also accepts both versions, however other
implementations, such as Sun's, do not accept the version without the
prepended length.

Regards,
Pieter Philippaerts

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to