Another renegotiation patch

Nikos Mavrogiannopoulos nmav at gnutls.org
Thu Jan 21 21:42:00 CET 2010


Steve Dispensa wrote:
> Here is another patch that fixes an interoperability problem with safe
> renegotiation and resumption. In copying forward the safe renegotiation
> state across resumptions, I got a little carried away and copied too much
> data (new connections should start with empty RI data).

I was thinking about the safe renegotiation case. Currently with the
defaults the client behavior is to drop the connection to servers that
do not advertise safe renegotiation... This is quite an inconvenience.
How do you think of instead of failing disabling renegotiation for this
session? I think this will prevent a lot of people from completely
disabling safe renegotiation and only disables the part of the protocol
that isn't secure..

regards,
Nikos





More information about the Gnutls-devel mailing list