Skip to content

Set upper bound on post-auth cert reqs#9908

Merged
douzzer merged 1 commit intowolfSSL:masterfrom
julek-wolfssl:fenrir/205
Mar 7, 2026
Merged

Set upper bound on post-auth cert reqs#9908
douzzer merged 1 commit intowolfSSL:masterfrom
julek-wolfssl:fenrir/205

Conversation

@julek-wolfssl
Copy link
Member

F-205

Copilot AI review requested due to automatic review settings March 6, 2026 15:08
@julek-wolfssl julek-wolfssl self-assigned this Mar 6, 2026
@julek-wolfssl julek-wolfssl added the For This Release Release version 5.9.0 label Mar 6, 2026
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a hard upper bound on post-handshake certificate requests (PHA) by validating the existing certificate-request context before issuing a new request.

Changes:

  • Validate certReqCtx state (len == 1) before proceeding with a post-auth certificate request.
  • Enforce a maximum of 255 post-auth certificate requests by rejecting when the context counter reaches the limit.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@douzzer douzzer added the Staged Staged for merge pending final test results and review label Mar 6, 2026
@douzzer douzzer merged commit 5f15d57 into wolfSSL:master Mar 7, 2026
454 of 456 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

For This Release Release version 5.9.0 Staged Staged for merge pending final test results and review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants