HomeFreeBSD

ktls: Fix assertion for TLS 1.0 CBC when using non-zero starting seqno.

Description

ktls: Fix assertion for TLS 1.0 CBC when using non-zero starting seqno.

The starting sequence number used to verify that TLS 1.0 CBC records
are encrypted in-order in the OCF layer was always set to 0 and not to
the initial sequence number from the struct tls_enable.

In practice, OpenSSL always starts TLS transmit offload with a
sequence number of zero, so this only matters for tests that use a
random starting sequence number.

Reviewed by: markj
Sponsored by: Netflix
Differential Revision: https://reviews.freebsd.org/D32676

(cherry picked from commit 4827bf76bce8814b9d9a0d883467a3d2366e59a2)

Details

Provenance
jhbAuthored on Oct 27 2021, 11:35 PM
Reviewer
markj
Differential Revision
D32676: ktls: Fix assertion for TLS 1.0 CBC when using non-zero starting seqno.
Parents
rGba6b771d1732: ktls: Ensure FIFO encryption order for TLS 1.0.
Branches
Unknown
Tags
Unknown