Clarify the need for calling mbedtls_ssl_derive_keys after extension parsing

Use a more straightforward condition to note that session resumption
is happening.
Co-authored-by: Ronald Cron <[email protected]>
Signed-off-by: Andrzej Kurek <[email protected]>
This commit is contained in:
Andrzej Kurek
2022-07-06 03:26:55 -04:00
parent 3a29e9cf57
commit 21b50808cd
+6 -1
View File
@@ -1644,7 +1644,12 @@ static int ssl_parse_server_hello( mbedtls_ssl_context *ssl )
}
}
if( ssl->state == MBEDTLS_SSL_SERVER_CHANGE_CIPHER_SPEC )
/*
* mbedtls_ssl_derive_keys() has to be called after the parsing of the
* extensions. It sets the transform data for the resumed session which in
* case of DTLS includes the server CID extracted from the CID extension.
*/
if( ssl->handshake->resume )
{
if( ( ret = mbedtls_ssl_derive_keys( ssl ) ) != 0 )
{