fix(tls): AEAD-only 1.2 suites, server preference, TOCTOU key load, IP SAN
C5: restrict the TLS 1.2 and below cipher list to ECDHE AEAD suites (ECDHE+AESGCM:ECDHE+CHACHA20, minus NULL/eNULL/MD5/RC4/3DES) instead of HIGH (which includes CBC), and set SSL_OP_CIPHER_SERVER_PREFERENCE so the server's order decides the negotiated cipher. Client and server share create_ssl_ctx, so both are updated. C7: load the private key through an O_RDONLY|O_NOFOLLOW|O_CLOEXEC fd, fstat that fd and validate owner/mode (now also rejecting group/other execute bits), then load from the fd via BIO_new_fd. This removes the stat-to-load TOCTOU race while keeping the exact-owner/0600 policy. C8: verify an IP-literal client hostname against the certificate IP SAN with X509_VERIFY_PARAM_set1_ip_asc instead of SSL_set1_host (a DNS check), falling back to SSL_set1_host for real names. Unit tests assert the server-preference option, the absence of CBC/RC4/ 3DES suites, and that context creation still succeeds.
This commit is contained in:
@@ -24,6 +24,17 @@ static void test_server_create_tls_without_certs() {
|
||||
#ifdef SSL_OP_NO_RENEGOTIATION
|
||||
EXPECT_TRUE((SSL_CTX_get_options(ctx) & SSL_OP_NO_RENEGOTIATION) != 0);
|
||||
#endif
|
||||
/* C5: the server's preference order decides the cipher and the TLS 1.2 list is
|
||||
* AEAD-only (no CBC/RC4/3DES legacy suites). */
|
||||
EXPECT_TRUE((SSL_CTX_get_options(ctx) & SSL_OP_CIPHER_SERVER_PREFERENCE) != 0);
|
||||
STACK_OF(SSL_CIPHER)* ciphers = SSL_CTX_get_ciphers(ctx);
|
||||
EXPECT_NOT_NULL(ciphers);
|
||||
for (int i = 0; i < sk_SSL_CIPHER_num(ciphers); i++) {
|
||||
const char* name = SSL_CIPHER_get_name(sk_SSL_CIPHER_value(ciphers, i));
|
||||
EXPECT_TRUE(name != NULL && strstr(name, "CBC") == NULL);
|
||||
EXPECT_TRUE(name != NULL && strstr(name, "RC4") == NULL);
|
||||
EXPECT_TRUE(name != NULL && strstr(name, "3DES") == NULL);
|
||||
}
|
||||
server_delete(&s);
|
||||
EXPECT_NULL(s);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user