From 50662c9c9eaacda38d97d376948dc478a03eb30a Mon Sep 17 00:00:00 2001 From: Tatsuhiro Tsujikawa Date: Mon, 6 Sep 2021 20:07:38 +0900 Subject: [PATCH] nghttpx: Guard TLS1_3_VERSION --- src/shrpx_tls.cc | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/shrpx_tls.cc b/src/shrpx_tls.cc index c9038ae0..b26bc482 100644 --- a/src/shrpx_tls.cc +++ b/src/shrpx_tls.cc @@ -560,11 +560,13 @@ int ticket_key_cb(SSL *ssl, unsigned char *key_name, unsigned char *iv, nullptr); EVP_DecryptInit_ex(ctx, key.cipher, nullptr, key.data.enc_key.data(), iv); +#ifdef TLS1_3_VERSION // If ticket_key_cb is not set, OpenSSL always renew ticket for // TLSv1.3. if (SSL_version(ssl) == TLS1_3_VERSION) { return 2; } +#endif // TLS1_3_VERSION return i == 0 ? 1 : 2; }