Loosen MAX_PSK_ID_LEN check in TLSX_PopulateExtensions() to only server side

This commit is contained in:
Chris Conlon
2024-12-19 14:26:22 -07:00
parent 836ee1cbd5
commit 1101841b95

View File

@ -13781,7 +13781,7 @@ int TLSX_PopulateExtensions(WOLFSSL* ssl, byte isServer)
word64 now, milli;
#endif
if (sess->ticketLen > MAX_PSK_ID_LEN) {
if (isServer && (sess->ticketLen > MAX_PSK_ID_LEN)) {
WOLFSSL_MSG("Session ticket length for PSK ext is too large");
return BUFFER_ERROR;
}