Ignore an s_client psk in TLSv1.3 if not TLSv1.3 suitable
[openssl.git] / ssl / statem / extensions.c
index daf43c6276a05ab811dc5f52f4f992dc27ad7a2d..7d456f353ab976e4a6977a04253cc88b4e7b9f2b 100644 (file)
@@ -358,7 +358,7 @@ static const EXTENSION_DEFINITION ext_defs[] = {
     {
         TLSEXT_TYPE_early_data,
         SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS
-        | SSL_EXT_TLS1_3_NEW_SESSION_TICKET,
+        | SSL_EXT_TLS1_3_NEW_SESSION_TICKET | SSL_EXT_TLS1_3_ONLY,
         NULL, tls_parse_ctos_early_data, tls_parse_stoc_early_data,
         tls_construct_stoc_early_data, tls_construct_ctos_early_data,
         final_early_data