CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]    2026/08/28 23:12:51

Modified files:
        lib/libssl     : ssl_tlsext.c 

Log message:
libssl: ensure server selected ALPN was advertised

Per RFC 7301, section 3.2, "In the event that the server supports no
protocols that the client advertises, then the server SHALL respond
with a fatal "no_application_protocol" alert.

If a server does not do that and chooses a protocol that we have not
advertised, we should abort the handshake. The RFC does not specify
an alert for this case. BoringSSL chose illegal_parameter and OpenSSL
decode_error. I slightly prefer illegal_parameter, so went with that.

Reported by Acts1631 with a similar diff.

ok jsing kenjiro

Reply via email to