TLS: Enable ecc point compression

If available in Botan.

There is an issue where, if botan supports it but we don’t enable it, then
the TLS handshake may fail with some servers
This commit is contained in:
louiz’
2016-12-02 11:30:27 +01:00
parent ad22be4171
commit 5f9568ca20
2 changed files with 13 additions and 2 deletions
+1 -1
View File
@@ -16,7 +16,7 @@
# include <botan/tls_exceptn.h> # include <botan/tls_exceptn.h>
Botan::AutoSeeded_RNG TCPSocketHandler::rng; Botan::AutoSeeded_RNG TCPSocketHandler::rng;
Botan::TLS::Policy TCPSocketHandler::policy; BiboumiTLSPolicy TCPSocketHandler::policy;
Botan::TLS::Session_Manager_In_Memory TCPSocketHandler::session_manager(TCPSocketHandler::rng); Botan::TLS::Session_Manager_In_Memory TCPSocketHandler::session_manager(TCPSocketHandler::rng);
#endif #endif
+12 -1
View File
@@ -19,6 +19,17 @@
#include <string> #include <string>
#include <list> #include <list>
class BiboumiTLSPolicy: public Botan::TLS::Policy
{
public:
#if BOTAN_VERSION_CODE >= BOTAN_VERSION_CODE_FOR(1,11,33)
bool use_ecc_point_compression() const override
{
return true;
}
#endif
};
/** /**
* Does all the read/write, buffering etc. With optional tls. * Does all the read/write, buffering etc. With optional tls.
* But doesn’t do any connect() or accept() or anything else. * But doesn’t do any connect() or accept() or anything else.
@@ -191,7 +202,7 @@ private:
* Botan stuff to manipulate a TLS session. * Botan stuff to manipulate a TLS session.
*/ */
static Botan::AutoSeeded_RNG rng; static Botan::AutoSeeded_RNG rng;
static Botan::TLS::Policy policy; static BiboumiTLSPolicy policy;
static Botan::TLS::Session_Manager_In_Memory session_manager; static Botan::TLS::Session_Manager_In_Memory session_manager;
protected: protected:
BasicCredentialsManager credential_manager; BasicCredentialsManager credential_manager;