Ensure the ECDSA signature scheme is bound to the certificate curve. Always validate MFL for TLS 1.3, even when WOLFSSL_OLD_UNSUPPORTED_EXTENSION is defined. - #11494
Conversation
There was a problem hiding this comment.
🟡 Changes recommended
The ECDSA validation compares curve sizes rather than exact curve identities, allowing same-sized mismatched curves.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Strengthens TLS 1.3 validation for ECDSA signature schemes and Maximum Fragment Length responses.
Changes:
- Validates peer ECDSA certificate curves during
CertificateVerify. - Enforces TLS 1.3 MFL validation despite legacy extension handling.
- Adds regression tests for both behaviors.
File summaries
| File | Description |
|---|---|
wolfssl/internal.h |
Exposes the ECC strength comparison helper. |
src/internal.c |
Makes the ECC helper externally accessible. |
src/tls13.c |
Adds ECDSA curve validation. |
src/tls.c |
Enforces TLS 1.3 MFL response checks. |
tests/api/test_tls13.c |
Tests ECDSA scheme/curve mismatches. |
tests/api/test_tls13.h |
Registers the new TLS 1.3 test. |
tests/api/test_tls_parse.c |
Tests TLS 1.3 MFL validation. |
Review details
- Files reviewed: 7/7 changed files
- Comments generated: 1
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
Re-ran the F03 checks at f4010ce, built from base 3babd37 plus the three PR commits,
|
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #11494
Scan targets checked: wolfssl-src, wolfssl-bugs
Coverage: 3 of 6 in-scope changed file(s) opened by the reviewer; not opened: tests/api/test_tls13.c, tests/api/test_tls_parse.c, wolfssl/internal.h
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
f4010ce to
554ef2a
Compare
| return 0; | ||
| } | ||
|
|
||
| return CmpEccStrength(hashAlgo, key->dp->size) == 0; |
There was a problem hiding this comment.
This isn't possible as RFC 8446 defines no ECDSA codepoint for secp256k1 at all, so any TLS 1.3 use of it
must borrow secp256r1's. secp256k1 has roughly equivalent security as secp256r1, so this is not a security issue.
554ef2a to
6099ef8
Compare
…PPORTED_EXTENSION defined. Fixes F-11837.
…atches expected sigalg for the OID sum.
6099ef8 to
8102a6a
Compare

Description
Fixes zd#22471, F-11837
Thanks to Eva Crystal (0xiviel), XSource Security for the ECDSA report!
Testing
Built in/added tests, provided reproducer
Checklist