Ensure we don't call the OCSP callback if resuming a session
It makes no sense to call the OCSP status callback if we are resuming a session because no certificates will be sent. Reviewed-by: Viktor Dukhovni <viktor@openssl.org>
This commit is contained in:
parent
905943af3b
commit
0ac6239955
@ -3165,7 +3165,7 @@ int ssl_check_serverhello_tlsext(SSL *s)
|
||||
* callback
|
||||
*/
|
||||
if ((s->tlsext_status_type != -1) && !(s->tlsext_status_expected)
|
||||
&& s->ctx && s->ctx->tlsext_status_cb) {
|
||||
&& !(s->hit) && s->ctx && s->ctx->tlsext_status_cb) {
|
||||
int r;
|
||||
/*
|
||||
* Call callback with resp == NULL and resplen == -1 so callback
|
||||
|
Loading…
x
Reference in New Issue
Block a user