[gnutls-devel] GnuTLS | Unknown certificate compression algorithm leads to an illegal_parameter alert (#1416)

Read-only notification of GnuTLS library development activities gnutls-devel at lists.gnutls.org
Thu Oct 20 17:17:49 CEST 2022



Alexander Sosedkin created an issue: https://gitlab.com/gnutls/gnutls/-/issues/1416



Advertizing a certificate compression not known to gnutls in CompressCertificateExtension leads to `illegal_parameter` instead of ignoring the extension and proceeding with no compression.

Code pointer: https://gitlab.com/gnutls/gnutls/-/blob/b69cbc76e46bbface6f92a0485a6c7ae646c6d6b/lib/ext/compress_certificate.c#L197

(Found using tlsfuzzer, though the [corresponding](https://github.com/tlsfuzzer/tlsfuzzer/pull/802) [code](https://github.com/tlsfuzzer/tlslite-ng/pull/484) isn't mainlined yet.)

CC @ZoltanFridrich.

-- 
Reply to this email directly or view it on GitLab: https://gitlab.com/gnutls/gnutls/-/issues/1416
You're receiving this email because of your account on gitlab.com.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.gnupg.org/pipermail/gnutls-devel/attachments/20221020/295f1858/attachment.html>


More information about the Gnutls-devel mailing list