Skip to content
This repository was archived by the owner on Oct 1, 2026. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions README
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,10 @@ following libraries to be installed:
* libnl3
* libyaml

The Linux UAPI headers must be v5.10 or later. tlshd reads the
kernel's generic netlink attribute policy to detect optional
handshake features, and the definitions for that arrived in v5.10.

## Installation

See [NEWS](NEWS) to see what has changed in the latest release,
Expand Down
4 changes: 4 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,10 @@ following libraries to be installed:
* libnl3
* libyaml

The Linux UAPI headers must be v5.10 or later. tlshd reads the
kernel's generic netlink attribute policy to detect optional
handshake features, and the definitions for that arrived in v5.10.

## Installation

See [NEWS](NEWS) to see what has changed in the latest release,
Expand Down
11 changes: 11 additions & 0 deletions configure.ac
Original file line number Diff line number Diff line change
Expand Up @@ -136,6 +136,17 @@ if test "x$have_tls_tx_max_payload_len" = xyes ; then
AC_DEFINE([HAVE_TLS_TX_MAX_PAYLOAD_LEN], [1], [Define to 1 if linux/tls.h defines TLS_TX_MAX_PAYLOAD_LEN])
fi

AC_MSG_CHECKING(for CTRL_ATTR_OP_POLICY in linux/genetlink.h)
AC_COMPILE_IFELSE(
[AC_LANG_PROGRAM([[ #include <linux/genetlink.h> ]],
[[ (void) CTRL_ATTR_OP_POLICY; ]])],
[ have_ctrl_attr_op_policy=yes ],
[ have_ctrl_attr_op_policy=no ])
AC_MSG_RESULT([$have_ctrl_attr_op_policy])
if test "x$have_ctrl_attr_op_policy" = xno ; then
AC_MSG_ERROR([Linux UAPI headers v5.10 or later are required])
fi

AC_SUBST([AM_CPPFLAGS])

AC_CONFIG_FILES([Makefile \
Expand Down
30 changes: 24 additions & 6 deletions src/tlshd/client.c
Original file line number Diff line number Diff line change
Expand Up @@ -96,6 +96,16 @@ static void tlshd_tls13_client_anon_handshake(struct tlshd_handshake_parms *parm
unsigned int flags;
int ret;

/*
* Without a peer name, GnuTLS verifies the certificate chain
* but not who presented it. session_status is already EIO, so
* the early return fails the kernel's request.
*/
if (!parms->peername) {
tlshd_log_error("No peer name: cannot verify the server's identity");
return;
}

ret = gnutls_certificate_allocate_credentials(&xcred);
if (ret != GNUTLS_E_SUCCESS) {
tlshd_log_gnutls_error(ret);
Expand Down Expand Up @@ -417,6 +427,11 @@ static void tlshd_tls13_client_x509_handshake(struct tlshd_handshake_parms *parm
unsigned int flags;
int ret;

if (!parms->peername) {
tlshd_log_error("No peer name: cannot verify the server's identity");
return;
}

ret = gnutls_certificate_allocate_credentials(&xcred);
if (ret != GNUTLS_E_SUCCESS) {
tlshd_log_gnutls_error(ret);
Expand Down Expand Up @@ -646,6 +661,11 @@ static void tlshd_quic_client_set_x509_session(struct tlshd_quic_conn *conn)
gnutls_session_t session;
int ret;

if (!parms->peername) {
tlshd_log_error("No peer name: cannot verify the server's identity");
return;
}

if (conn->cert_req != TLSHD_QUIC_NO_CERT_AUTH) {
if (!tlshd_x509_client_get_certs(parms) || !tlshd_x509_client_get_privkey(parms)) {
tlshd_log_error("Failed to get cert or privkey");
Expand Down Expand Up @@ -683,12 +703,10 @@ static void tlshd_quic_client_set_x509_session(struct tlshd_quic_conn *conn)
ret = gnutls_credentials_set(session, GNUTLS_CRD_CERTIFICATE, cred);
if (ret)
goto err_session;
if (parms->peername) {
ret = gnutls_server_name_set(session, GNUTLS_NAME_DNS,
parms->peername, strlen(parms->peername));
if (ret)
goto err_session;
}
ret = gnutls_server_name_set(session, GNUTLS_NAME_DNS,
parms->peername, strlen(parms->peername));
if (ret)
goto err_session;
conn->session = session;
return;

Expand Down
Loading