Attention is currently required from: plaisthos.

ralf_lici has posted comments on this change by ralf_lici. ( 
http://gerrit.openvpn.net/c/openvpn/+/1478?usp=email )

Change subject: tls: reject incoming reneg request if primary key is not fully 
valid
......................................................................


Patch Set 3:

(2 comments)

Commit Message:

http://gerrit.openvpn.net/c/openvpn/+/1478/comment/02b189c3_6784af74?usp=email :
PS2, Line 12: checks deauthenticate the key without demoting its TLS state.
> Should we add the scenario where we just waiting for the hand-window to have 
> the key be fully authen […]
Done


File src/openvpn/ssl.c:

http://gerrit.openvpn.net/c/openvpn/+/1478/comment/5ea276c4_a76158a4?usp=email :
PS2, Line 3757:                     "TLS Error: rejecting incoming 
renegotiation request: key not fully authenticated/valid");
> Maybe make this message a bit more verbose to help later debugging and print 
> the key-id in ks too?
Done



--
To view, visit http://gerrit.openvpn.net/c/openvpn/+/1478?usp=email
To unsubscribe, or for help writing mail filters, visit 
http://gerrit.openvpn.net/settings?usp=email

Gerrit-MessageType: comment
Gerrit-Project: openvpn
Gerrit-Branch: master
Gerrit-Change-Id: I704c560fa23c03237d0f8adc30908a617265a5a1
Gerrit-Change-Number: 1478
Gerrit-PatchSet: 3
Gerrit-Owner: ralf_lici <[email protected]>
Gerrit-Reviewer: plaisthos <[email protected]>
Gerrit-CC: openvpn-devel <[email protected]>
Gerrit-Attention: plaisthos <[email protected]>
Gerrit-Comment-Date: Tue, 17 Feb 2026 08:10:55 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
Comment-In-Reply-To: plaisthos <[email protected]>
_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel

Reply via email to