summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorLars Magne Ingebrigtsen <larsi@gnus.org>2014-11-26 23:11:57 +0100
committerLars Magne Ingebrigtsen <larsi@gnus.org>2014-11-26 23:11:57 +0100
commitfc4d2c7784184a01bdbf9d428fe22aed4039b159 (patch)
treec882bdc2927b6c3aa162169de35d50a35e26b7fd
parentccae04f205db7cffa0f247a463272f6c5af77122 (diff)
downloademacs-fc4d2c7784184a01bdbf9d428fe22aed4039b159.tar.gz
Only send SNI if the host name is not an IP address
* gnutls.c (gnutls_ip_address_p): New function. (Fgnutls_boot): Only send SNI if the host name is not an IP address.
-rw-r--r--src/ChangeLog5
-rw-r--r--src/gnutls.c23
2 files changed, 24 insertions, 4 deletions
diff --git a/src/ChangeLog b/src/ChangeLog
index 17e3c5988a6..df704efdf2d 100644
--- a/src/ChangeLog
+++ b/src/ChangeLog
@@ -1,3 +1,8 @@
+2014-11-26 Lars Magne Ingebrigtsen <larsi@gnus.org>
+
+ * gnutls.c (gnutls_ip_address_p): New function.
+ (Fgnutls_boot): Only send SNI if the host name is not an IP address.
+
2014-11-26 Toke Høiland-Jørgensen <toke@toke.dk> (tiny change)
* gnutls.c (Fgnutls_boot): Send the server name over (bug#18208).
diff --git a/src/gnutls.c b/src/gnutls.c
index 5a4b39f789a..752df3c8edd 100644
--- a/src/gnutls.c
+++ b/src/gnutls.c
@@ -1095,6 +1095,18 @@ emacs_gnutls_global_init (void)
return gnutls_make_error (ret);
}
+static bool
+gnutls_ip_address_p (char *string)
+{
+ char c;
+
+ while ((c = *string++) != 0)
+ if (! ((c == '.' || c == ':' || (c >= '0' && c <= '9'))))
+ return false;
+
+ return true;
+}
+
#if 0
/* Deinitializes global GnuTLS state.
See also `gnutls-global-init'. */
@@ -1418,10 +1430,13 @@ one trustfile (usually a CA bundle). */)
if (ret < GNUTLS_E_SUCCESS)
return gnutls_make_error (ret);
- ret = fn_gnutls_server_name_set (state, GNUTLS_NAME_DNS, c_hostname,
- strlen(c_hostname));
- if (ret < GNUTLS_E_SUCCESS)
- return gnutls_make_error (ret);
+ if (!gnutls_ip_address_p (c_hostname))
+ {
+ ret = fn_gnutls_server_name_set (state, GNUTLS_NAME_DNS, c_hostname,
+ strlen (c_hostname));
+ if (ret < GNUTLS_E_SUCCESS)
+ return gnutls_make_error (ret);
+ }
GNUTLS_INITSTAGE (proc) = GNUTLS_STAGE_CRED_SET;
ret = emacs_gnutls_handshake (XPROCESS (proc));