Do not undefine _XOPEN_SOURCE. This is currently experimental, and
[openssl.git] / ssl / s2_enc.c
index 690252e3d312fbd65bafca9d4db7b1e5823b5e4b..18882bf70487f56bf73abff5b6b3a36ccaf849b4 100644 (file)
@@ -95,10 +95,12 @@ int ssl2_enc_init(SSL *s, int client)
 
        num=c->key_len;
        s->s2->key_material_length=num*2;
+       OPENSSL_assert(s->s2->key_material_length <= sizeof s->s2->key_material);
 
        if (ssl2_generate_key_material(s) <= 0)
                return 0;
 
+       OPENSSL_assert(c->iv_len <= (int)sizeof(s->session->key_arg));
        EVP_EncryptInit_ex(ws,c,NULL,&(s->s2->key_material[(client)?num:0]),
                s->session->key_arg);
        EVP_DecryptInit_ex(rs,c,NULL,&(s->s2->key_material[(client)?0:num]),