Reject unknown fields in d2i_SSL_SESSION. The original OpenSSL implementation did the same. M_ASN1_D2I_Finish checks this. Forwards compatibility with future sessions with unknown fields is probably not desirable. Change-Id: I116a8c482cbcc47c3fcc31515c4a3718f66cf268 Reviewed-on: https://boringssl-review.googlesource.com/4941 Reviewed-by: Adam Langley <agl@google.com>