From e75d06de207e9afe4259d5e731cb77ae25faf003 Mon Sep 17 00:00:00 2001 From: Laurent Bercot Date: Thu, 28 Jan 2021 14:31:38 +0000 Subject: Remove SSL_TLS_SNI_SERVERNAME (instead of defined but empty) if no SNI --- src/sbearssl/sbearssl_send_environment.c | 13 ++++++++++--- src/stls/stls_send_environment.c | 15 ++++++++++----- 2 files changed, 20 insertions(+), 8 deletions(-) (limited to 'src') diff --git a/src/sbearssl/sbearssl_send_environment.c b/src/sbearssl/sbearssl_send_environment.c index 2439351..bb0fb35 100644 --- a/src/sbearssl/sbearssl_send_environment.c +++ b/src/sbearssl/sbearssl_send_environment.c @@ -12,6 +12,7 @@ int sbearssl_send_environment (br_ssl_engine_context *ctx, int fd) char buf[4096] ; buffer b = BUFFER_INIT(&buffer_write, fd, buf, 4096) ; unsigned int v = br_ssl_engine_get_version(ctx) ; + char const *name = br_ssl_engine_get_server_name(ctx) ; char const *suite ; br_ssl_session_parameters params ; @@ -26,9 +27,15 @@ int sbearssl_send_environment (br_ssl_engine_context *ctx, int fd) || buffer_puts(&b, "SSL_CIPHER=") < 0 || buffer_puts(&b, suite) < 0 || buffer_put(&b, "", 1) < 0 - || buffer_puts(&b, "SSL_TLS_SNI_SERVERNAME=") < 0 - || buffer_puts(&b, br_ssl_engine_get_server_name(ctx)) < 0 - || buffer_putflush(&b, "\0", 2) < 0) + || buffer_puts(&b, "SSL_TLS_SNI_SERVERNAME") < 0) + return 0 ; + if (name[0]) + { + if (buffer_put(&b, "=", 1) < 0 + || buffer_puts(&b, name) < 0) + return 0 ; + } + if (buffer_putflush(&b, "\0", 2) < 0) return 0 ; return 1 ; } diff --git a/src/stls/stls_send_environment.c b/src/stls/stls_send_environment.c index af0eeb6..c7cb9c7 100644 --- a/src/stls/stls_send_environment.c +++ b/src/stls/stls_send_environment.c @@ -11,18 +11,23 @@ int stls_send_environment (struct tls *ctx, int fd) { - char const *servername = tls_conn_servername(ctx) ; + char const *name = tls_conn_servername(ctx) ; char buf[4096] ; buffer b = BUFFER_INIT(&buffer_write, fd, buf, 4096) ; - if (!servername) servername = "" ; if (buffer_puts(&b, "SSL_PROTOCOL=") < 0 || buffer_puts(&b, tls_conn_version(ctx)) < 0 || buffer_put(&b, "", 1) < 0 || buffer_puts(&b, "SSL_CIPHER=") < 0 || buffer_puts(&b, tls_conn_cipher(ctx)) < 0 || buffer_put(&b, "", 1) < 0 - || buffer_puts(&b, "SSL_TLS_SNI_SERVERNAME=") < 0 - || buffer_puts(&b, servername) < 0 - || buffer_putflush(&b, "\0", 2) < 0) return 0 ; + || buffer_puts(&b, "SSL_TLS_SNI_SERVERNAME") < 0) + return 0 ; + if (name && name[0]) + { + if (buffer_put(&b, "=", 1) < 0 + || buffer_puts(&b, name) < 0) + return 0 ; + } + if (buffer_putflush(&b, "\0", 2) < 0) return 0 ; return 1 ; } -- cgit v1.2.3