Move ExpectTicketAge out of AcceptAnySession. It doesn't particular matter, but AcceptAnySession should only skip the things that would cause us to note accept a ticket. ExpectTicketAge is an assertion, not part of protocol logic. Accordingly, fix the text. Change-Id: I3bea9c58f4d5f912308252ec8834f183287d632f Reviewed-on: https://boringssl-review.googlesource.com/12308 CQ-Verified: CQ bot account: commit-bot@chromium.org <commit-bot@chromium.org> Reviewed-by: Nick Harper <nharper@chromium.org> Reviewed-by: David Benjamin <davidben@google.com> Commit-Queue: David Benjamin <davidben@google.com>
diff --git a/ssl/test/runner/handshake_server.go b/ssl/test/runner/handshake_server.go index a9b2ff1..6f86a21 100644 --- a/ssl/test/runner/handshake_server.go +++ b/ssl/test/runner/handshake_server.go
@@ -437,12 +437,6 @@ continue } - clientTicketAge := time.Duration(uint32(pskIdentity.obfuscatedTicketAge-sessionState.ticketAgeAdd)) * time.Millisecond - if config.Bugs.ExpectTicketAge != 0 && clientTicketAge != config.Bugs.ExpectTicketAge { - c.sendAlert(alertHandshakeFailure) - return errors.New("tls: invalid ticket age") - } - cipherSuiteOk := false // Check that the client is still offering the ciphersuite in the session. for _, id := range hs.clientHello.cipherSuites { @@ -457,6 +451,12 @@ } + clientTicketAge := time.Duration(uint32(pskIdentity.obfuscatedTicketAge-sessionState.ticketAgeAdd)) * time.Millisecond + if config.Bugs.ExpectTicketAge != 0 && clientTicketAge != config.Bugs.ExpectTicketAge { + c.sendAlert(alertHandshakeFailure) + return errors.New("tls: invalid ticket age") + } + // Check that we also support the ciphersuite from the session. suite := c.tryCipherSuite(sessionState.cipherSuite, c.config.cipherSuites(), c.vers, true, true) if suite == nil {