Richard Levitte cbb92dfaf0 Fixes for the following claims:
1) Certificate Message with no certs

  OpenSSL implementation sends the Certificate message during SSL
  handshake, however as per the specification, these have been omitted.

  -- RFC 2712 --
     CertificateRequest, and the ServerKeyExchange shown in Figure 1
     will be omitted since authentication and the establishment of a
     master secret will be done using the client's Kerberos credentials
     for the TLS server.  The client's certificate will be omitted for
     the same reason.
  -- RFC 2712 --

  3) Pre-master secret Protocol version

  The pre-master secret generated by OpenSSL does not have the correct
  client version.

  RFC 2712 says, if the Kerberos option is selected, the pre-master
  secret structure is the same as that used in the RSA case.

  TLS specification defines pre-master secret as:
         struct {
             ProtocolVersion client_version;
             opaque random[46];
         } PreMasterSecret;

  where client_version is the latest protocol version supported by the
  client

  The pre-master secret generated by OpenSSL does not have the correct
  client version. The implementation does not update the first 2 bytes
  of random secret for Kerberos Cipher suites. At the server-end, the
  client version from the pre-master secret is not validated.

PR: 1336
2006-09-28 12:22:58 +00:00
..
2005-07-26 04:25:05 +00:00
2005-12-05 17:21:22 +00:00
2006-01-29 23:12:22 +00:00
2006-04-08 13:04:31 +00:00
2005-12-05 17:21:22 +00:00
2005-11-15 23:32:11 +00:00
2005-12-05 17:21:22 +00:00
2006-09-28 12:22:58 +00:00
2006-09-28 12:22:58 +00:00
2006-01-11 07:18:35 +00:00
2002-07-10 07:01:54 +00:00
2001-11-10 01:16:28 +00:00
2006-06-09 15:44:59 +00:00
2006-06-14 08:55:23 +00:00
2006-05-07 12:30:37 +00:00
2006-06-14 17:51:46 +00:00