Since DTLS 1.0 is based on TLS 1.1 we should never return a decryption_failed
authorDr. Stephen Henson <steve@openssl.org>
Tue, 4 Jan 2011 19:34:20 +0000 (19:34 +0000)
committerDr. Stephen Henson <steve@openssl.org>
Tue, 4 Jan 2011 19:34:20 +0000 (19:34 +0000)
alert.

ssl/d1_enc.c
ssl/d1_pkt.c

index 8fa5734..becbab9 100644 (file)
@@ -231,11 +231,7 @@ int dtls1_enc(SSL *s, int send)
                if (!send)
                        {
                        if (l == 0 || l%bs != 0)
-                               {
-                               SSLerr(SSL_F_DTLS1_ENC,SSL_R_BLOCK_CIPHER_PAD_IS_WRONG);
-                               ssl3_send_alert(s,SSL3_AL_FATAL,SSL_AD_DECRYPTION_FAILED);
-                               return 0;
-                               }
+                               return -1;
                        }
                
                EVP_Cipher(ds,rec->data,rec->input,l);
index ee67561..4677110 100644 (file)
@@ -414,7 +414,8 @@ dtls1_process_record(SSL *s)
                        goto err;
 
                /* otherwise enc_err == -1 */
-               goto err;
+               al=SSL_AD_BAD_RECORD_MAC;
+               goto f_err;
                }
 
 #ifdef TLS_DEBUG