From: Matt Caswell Date: Fri, 27 Jan 2017 15:18:51 +0000 (+0000) Subject: Add a TODO around validating the ticket age X-Git-Tag: OpenSSL_1_1_1-pre1~2538 X-Git-Url: https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff_plain;h=1b8bacff8cbab3d3bf4d2566be240a35c2f65b88;hp=40f805ad924e228d5e77c8f87bd4413b5767ac65 Add a TODO around validating the ticket age Reviewed-by: Rich Salz (Merged from https://github.com/openssl/openssl/pull/2259) --- diff --git a/ssl/statem/extensions_srvr.c b/ssl/statem/extensions_srvr.c index 41dd5b6fbb..df1e6c252e 100644 --- a/ssl/statem/extensions_srvr.c +++ b/ssl/statem/extensions_srvr.c @@ -711,6 +711,8 @@ int tls_parse_ctos_psk(SSL *s, PACKET *pkt, X509 *x, size_t chainidx, int *al) return 0; } + /* TODO(TLS1.3): Should we validate the ticket age? */ + ret = tls_decrypt_ticket(s, PACKET_data(&identity), PACKET_remaining(&identity), NULL, 0, &sess); if (ret == TICKET_FATAL_ERR_MALLOC || ret == TICKET_FATAL_ERR_OTHER) {