X-Git-Url: https://bearssl.org/gitweb//home/git/?p=BearSSL;a=blobdiff_plain;f=src%2Fssl%2Fssl_scert_single_rsa.c;h=b2c77679fe38b98dc3466c660c24052fdb2738af;hp=879a84ce30697b7b579ae527ec542144aade472b;hb=57b217502046db74ea25bb84a1284e74e57bc8e8;hpb=ea95d8264c6aefe742a9c3f4f9d834b188566a29 diff --git a/src/ssl/ssl_scert_single_rsa.c b/src/ssl/ssl_scert_single_rsa.c index 879a84c..b2c7767 100644 --- a/src/ssl/ssl_scert_single_rsa.c +++ b/src/ssl/ssl_scert_single_rsa.c @@ -33,12 +33,17 @@ sr_choose(const br_ssl_server_policy_class **pctx, const br_suite_translated *st; size_t u, st_num; unsigned hash_id; + int fh; pc = (br_ssl_server_policy_rsa_context *)pctx; st = br_ssl_server_get_client_suites(cc, &st_num); - hash_id = br_ssl_choose_hash(br_ssl_server_get_client_hashes(cc)); if (cc->eng.session.version < BR_TLS12) { hash_id = 0; + fh = 1; + } else { + hash_id = br_ssl_choose_hash( + br_ssl_server_get_client_hashes(cc)); + fh = (hash_id != 0); } choices->chain = pc->chain; choices->chain_len = pc->chain_len; @@ -54,9 +59,7 @@ sr_choose(const br_ssl_server_policy_class **pctx, } break; case BR_SSLKEYX_ECDHE_RSA: - if ((pc->allowed_usages & BR_KEYTYPE_SIGN) != 0 - && hash_id != 0) - { + if ((pc->allowed_usages & BR_KEYTYPE_SIGN) != 0 && fh) { choices->cipher_suite = st[u][0]; choices->algo_id = hash_id + 0xFF00; return 1;