use client version when deciding whether to send supported signature algorithms extension
authorDr. Stephen Henson <steve@openssl.org>
Wed, 21 Mar 2012 21:33:23 +0000 (21:33 +0000)
committerDr. Stephen Henson <steve@openssl.org>
Wed, 21 Mar 2012 21:33:23 +0000 (21:33 +0000)
ssl/t1_lib.c

index dfd397f9b7d033a2df650f4a0ff20def7cb7a8ea..da941ad73e83828c7819a2e99d8704ece7a976e6 100644 (file)
@@ -544,7 +544,7 @@ unsigned char *ssl_add_clienthello_tlsext(SSL *s, unsigned char *p, unsigned cha
                }
                skip_ext:
 
-       if (TLS1_get_version(s) >= TLS1_2_VERSION)
+       if (TLS1_get_client_version(s) >= TLS1_2_VERSION)
                {
                if ((size_t)(limit - ret) < sizeof(tls12_sigalgs) + 6)
                        return NULL;