Make nextprotoneg work with CCS patch. steve/1.0.1h-secfix
authorDr. Stephen Henson <steve@openssl.org>
Thu, 29 May 2014 16:27:25 +0000 (17:27 +0100)
committerDr. Stephen Henson <steve@openssl.org>
Thu, 29 May 2014 16:32:08 +0000 (17:32 +0100)
ssl/s3_srvr.c

index a648af137e92b96b5e1325ff4f484d1491a648fa..29f8b14b46694368e6cd54bc1d14f64aa42a97c7 100644 (file)
@@ -772,7 +772,10 @@ int ssl3_accept(SSL *s)
                                s->s3->tmp.next_state=SSL3_ST_SR_FINISHED_A;
 #else
                                if (s->s3->next_proto_neg_seen)
+                                       {
+                                       s->s3->flags |= SSL3_FLAGS_CCS_OK;
                                        s->s3->tmp.next_state=SSL3_ST_SR_NEXT_PROTO_A;
+                                       }
                                else
                                        s->s3->tmp.next_state=SSL3_ST_SR_FINISHED_A;
 #endif