Make RI on TLS 1.3 alert with ILLEGAL_PARAMETER. Change-Id: I0e2e4166ad2c57e3192af058f23374f014a2fcf4 Reviewed-on: https://boringssl-review.googlesource.com/14377 Reviewed-by: David Benjamin <davidben@google.com> Commit-Queue: David Benjamin <davidben@google.com> CQ-Verified: CQ bot account: commit-bot@chromium.org <commit-bot@chromium.org>
diff --git a/ssl/t1_lib.c b/ssl/t1_lib.c index ef4a889..014432e 100644 --- a/ssl/t1_lib.c +++ b/ssl/t1_lib.c
@@ -719,6 +719,7 @@ CBS *contents) { SSL *const ssl = hs->ssl; if (contents != NULL && ssl3_protocol_version(ssl) >= TLS1_3_VERSION) { + *out_alert = SSL_AD_ILLEGAL_PARAMETER; return 0; }