Tweak gnutls-peer-status reporting

* src/gnutls.c (Fgnutls_peer_status): Report :compression and
:encrypt-then-mac only if the underlying GnuTLS library has
the corresponding features.  This give the Elisp caller a bit
more information about the peer status.
* lisp/net/nsm.el (nsm-protocol-check--compression):
Don’t worry about compression in newer GnuTLS versions
that do not support compression.
This commit is contained in:
Paul Eggert 2019-08-23 11:50:40 -07:00
parent c5210fd00a
commit 8037694595
2 changed files with 9 additions and 10 deletions

View file

@ -692,7 +692,8 @@ Sheffer, Holz, Saint-Andre (May 2015). \"Recommendations for Secure
Use of Transport Layer Security (TLS) and Datagram Transport Layer
Security (DTLS)\", `https://tools.ietf.org/html/rfc7525'"
(let ((compression (plist-get status :compression)))
(and (string-match "^\\bDEFLATE\\b" compression)
(and compression
(string-match "^\\bDEFLATE\\b" compression)
(format-message
"compression method (%s) may lead to leakage of sensitive information"
compression))))

View file

@ -1493,20 +1493,18 @@ returned as the :certificate entry. */)
/* Compression name. */
#ifdef HAVE_GNUTLS_COMPRESSION_GET
Lisp_Object compression = build_string (gnutls_compression_get_name
(gnutls_compression_get (state)));
#else
Lisp_Object compression = build_string ("NULL");
result = nconc2
(result, list2 (intern (":compression"),
build_string (gnutls_compression_get_name
(gnutls_compression_get (state)))));
#endif
result = nconc2 (result, list2 (intern (":compression"), compression));
/* Encrypt-then-MAC. */
Lisp_Object etm_status = Qnil;
#ifdef HAVE_GNUTLS_ETM_STATUS
if (gnutls_session_etm_status (state))
etm_status = Qt;
result = nconc2
(result, list2 (intern (":encrypt-then-mac"),
gnutls_session_etm_status (state) ? Qt : Qnil));
#endif
result = nconc2 (result, list2 (intern (":encrypt-then-mac"), etm_status));
/* Renegotiation Indication */
result = nconc2