Add server side support for TLSv1.3 downgrade mechanism
[openssl.git] / ssl / statem / statem_clnt.c
index d584bd72fe9f0c76b438dcaad05426c692e34e71..04908130f77b7c8d36e8c062a2c5e691160a5a4b 100644 (file)
@@ -1094,7 +1094,8 @@ int tls_construct_client_hello(SSL *s, WPACKET *pkt)
     } else
         i = 1;
 
-    if (i && ssl_fill_hello_random(s, 0, p, sizeof(s->s3->client_random)) <= 0)
+    if (i && ssl_fill_hello_random(s, 0, p, sizeof(s->s3->client_random),
+                                   DOWNGRADE_NONE) <= 0)
         return 0;
 
     /*-