Clarify the need for calling mbedtls_ssl_derive_keys after extension parsing

Use a more straightforward condition to note that session resumption
is happening.
Co-authored-by: Ronald Cron <[email protected]>
Signed-off-by: Andrzej Kurek <[email protected]>
This commit is contained in:
Andrzej Kurek
2022-07-06 06:43:22 -04:00
parent 33b731f637
commit 77473eba5d
+6 -1
View File
@@ -2527,7 +2527,12 @@ static int ssl_parse_server_hello( mbedtls_ssl_context *ssl )
}
}
if( ssl->state == MBEDTLS_SSL_SERVER_CHANGE_CIPHER_SPEC )
/*
* mbedtls_ssl_derive_keys() has to be called after the parsing of the
* extensions. It sets the transform data for the resumed session which in
* case of DTLS includes the server CID extracted from the CID extension.
*/
if( ssl->handshake->resume )
{
if( ( ret = mbedtls_ssl_derive_keys( ssl ) ) != 0 )
{