diff options
| author | Vladimir Homutov <vl@nginx.com> | 2020-06-18 13:58:46 +0300 |
|---|---|---|
| committer | Vladimir Homutov <vl@nginx.com> | 2020-06-18 13:58:46 +0300 |
| commit | 28f1acdb6f6404cfffc7158d109e1c460dac8d94 (patch) | |
| tree | a57b373263e70d9b4ea35cdf7666aa19d2ab1135 /src/misc/ngx_cpp_test_module.cpp | |
| parent | a213258b5beb8d83a0907eed00fe402d67610303 (diff) | |
| download | nginx-28f1acdb6f6404cfffc7158d109e1c460dac8d94.tar.gz nginx-28f1acdb6f6404cfffc7158d109e1c460dac8d94.tar.bz2 | |
QUIC: added ALPN checks.
quic-transport draft 29:
section 7:
* authenticated negotiation of an application protocol (TLS uses
ALPN [RFC7301] for this purpose)
...
Endpoints MUST explicitly negotiate an application protocol. This
avoids situations where there is a disagreement about the protocol
that is in use.
section 8.1:
When using ALPN, endpoints MUST immediately close a connection (see
Section 10.3 of [QUIC-TRANSPORT]) with a no_application_protocol TLS
alert (QUIC error code 0x178; see Section 4.10) if an application
protocol is not negotiated.
Changes in ngx_quic_close_quic() function are required to avoid attempts
to generated and send packets without proper keys, what happens in case
of failed ALPN check.
Diffstat (limited to 'src/misc/ngx_cpp_test_module.cpp')
0 files changed, 0 insertions, 0 deletions
