From patchwork Wed Aug 5 16:34:40 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5202 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:77c3:b0:87d:ab56:3700 with SMTP id r3csp6560169mau; Wed, 5 Aug 2026 09:35:03 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RqHIKlSl8folXMLy3LNZ6uMWR4LcJhADxVRlcnCfyoY+28sDgs0AKOrh/yeuVnk2G6hpSXTDoK3te8=@openvpn.net X-Received: by 2002:a05:6830:67f4:b0:7dd:9b19:a87b with SMTP id 46e09a7af769-7f1e5d0f308mr5309692a34.4.1785947703227; Wed, 05 Aug 2026 09:35:03 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785947703; cv=none; d=google.com; s=arc-20260327; b=nU+ofVpDF5p64+Ux3T905Cj2LXc2/ZPE7e4lFAyk5d+pTRIe4S/lpAON47byXrEY2+ md3qPuOekCQiXGrtOzpr2tPqhqreQ3ep5/abMKM9QYUyXaQrt7MyZOGNc4ykGWWffRY/ 9zHDClZo+gBxCaGO5U+VCp34C9KL2wNXSuyfumJVuosKIHmklglSDlQHsBH0/uFaUjwb 4A7hsgRz0ke0hrOS7RVv6L9nG2dxy8cboic3+TRNgt0Bty9JJdIj42e1rE3J9XhLY5gU borfuGP+i4LWAso0Fc5YJjn11AWaMdXaEc8428stGVON0c207abBeJbsUW9bb+nSZ9QX gPmg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=rbhaM9dsCgZz+Zshwcpm87u14YCAuvZBc559FzJgyTY=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=fQ3CiHacFU1GY9KDVMx5NZK1K0Wohw+2M3TrSSav+6SGjMHLg+R2An8hZP3ARvJOPY t6witqXfpsvUArPsDF8jj4Nf9jdPYYasOi9puR2AB+av6KXqGO+UqEPmAQPQDddooN9f RNRFKx7jQB07+W+lmpy0+5UoLuM3OJbTJ0fkWD42doqF/r9TPqgYTcVqcBnoKB420ncd 5Dr6O1/eM7RCzHLlfFnFbKgyoCeznrkLKZosbu5SZrXt3GFwWb/N977AW7WeKa9n0SbR KxKbAhKJ0Lf0FHg8UWXVRstPiwIloS+m+yhJb8v+MUDsNV+mVlJuM6AYIYH8sY9Zoaez taMg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=B4wSD0by; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=MjedzRTc; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=DY8x7zMJ; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7f1df6b87bdsi3815890a34.125.2026.08.05.09.35.02 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 05 Aug 2026 09:35:03 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=B4wSD0by; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=MjedzRTc; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=DY8x7zMJ; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=rbhaM9dsCgZz+Zshwcpm87u14YCAuvZBc559FzJgyTY=; b=B4wSD0byvT2Toq6zrZQXiiM4qU Z0vsj5Zr/JVJnFr8+A3BxYNtaBTf9dEm5N0dpvkhQsR8iB6+/6W7g7ufM63JYH3+5Ib/vVxHKYj8v Wi2PL5w5tXDDvLwJL/y9GerkqKARghr9YonPtu2XKIW6l8VTcbHOEoQ5vCN8r8RkWqlI=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wreZz-0006yO-8w; Wed, 05 Aug 2026 16:34:56 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wreZy-0006yD-6w for openvpn-devel@lists.sourceforge.net; Wed, 05 Aug 2026 16:34:55 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=nvJybsn1c7JZYY5cJoQQZZgBlbsczaHyqoR6SxNyq1E=; b=MjedzRTcGfWmb4g780VhKT1e+0 T6Pi4vhnE1WAJs7JDAMeXZQLGHGK82rbpKS3i5SiOU4l0ch1jFslVUkqwP7C/2+nkmq7/7ARMoKWf REbtIjYntUxgAVQSl/MC3nmDG1LTa0a1fehtxnfrd1DEQ7nKFNCFqk2Bg25CzOSekTmY=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=nvJybsn1c7JZYY5cJoQQZZgBlbsczaHyqoR6SxNyq1E=; b=DY8x7zMJzRFwHggPo5C1Z+BUWn adp131eVG/Y7lsuzVTE5Ti+9WY98CG9gFhiyAEDPe2dvB1S5hK71yNMYCgPuBw/NFWWj+8Df5EWmH roH143hisiIDdF0sJ6OS5WAblV1pGeblU12u8M/h0vNYgcETLuf/VPTncTpS7Qhs/0Ss=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wreZx-0008Hc-Ag for openvpn-devel@lists.sourceforge.net; Wed, 05 Aug 2026 16:34:54 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 675GYkDx029346 for ; Wed, 5 Aug 2026 18:34:46 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 675GYkPB029345 for openvpn-devel@lists.sourceforge.net; Wed, 5 Aug 2026 18:34:46 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Wed, 5 Aug 2026 18:34:40 +0200 Message-ID: <20260805163445.29330-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Antonio Quartulli The epoch data key format is defined for AEAD ciphers only. Both places that enable it locally verify this - multi.c when picking the cipher to push and ssl_ncp.c for p2p NCP - but the pulling side im [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1wreZx-0008Hc-Ag Subject: [Openvpn-devel] [PATCH v2] ssl: reject a pushed epoch data format tag with a non-AEAD cipher X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872701898406932544 X-GMAIL-MSGID: 1872701898406932544 From: Antonio Quartulli The epoch data key format is defined for AEAD ciphers only. Both places that enable it locally verify this - multi.c when picking the cipher to push and ssl_ncp.c for p2p NCP - but the pulling side imports the "aead-epoch" protocol flag without validating it against the cipher that was actually negotiated. A peer pushing "protocol-flags aead-epoch" together with a non-AEAD cipher therefore makes us reach the M_FATAL in init_key_contexts() and terminate the process. This can be triggered whenever a non-AEAD cipher is part of our own --data-ciphers, which is not unusual in configurations kept compatible with old peers, e.g. data-ciphers AES-256-GCM:AES-256-CBC Validate the combination in do_deferred_options(), next to the existing data v2 check, so that the mismatch is reported as an OPTIONS ERROR and the connection is restarted. Turn the now unreachable M_FATAL in init_key_contexts() into a session error as well, so that no future code path can promote this to a process exit. Change-Id: Icc0721fd4a910110507d06b4e941e9e6dbb11e9f Signed-off-by: Antonio Quartulli Acked-by: Arne Schwabe Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1836 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1836 This mail reflects revision 2 of this Change. Acked-by according to Gerrit (reflected above): Arne Schwabe diff --git a/src/openvpn/init.c b/src/openvpn/init.c index 0236886..84de986 100644 --- a/src/openvpn/init.c +++ b/src/openvpn/init.c @@ -2711,6 +2711,18 @@ return false; } + /* The epoch data format is defined for AEAD ciphers only. A peer may push + * the tag along with a non-AEAD cipher, so this has to be checked here + * rather than trusted */ + if (epoch_data && !cipher_kt_mode_aead(c->options.ciphername)) + { + msg(D_PUSH_ERRORS, + "OPTIONS ERROR: Epoch key data format tag requires an AEAD " + "cipher, but '%s' was negotiated.", + c->options.ciphername); + return false; + } + if (found & OPT_P_PUSH_MTU) { diff --git a/src/openvpn/ssl.c b/src/openvpn/ssl.c index b5ab51e..2c7e672 100644 --- a/src/openvpn/ssl.c +++ b/src/openvpn/ssl.c @@ -1413,10 +1413,14 @@ { if (!cipher_kt_mode_aead(key_type->cipher)) { - msg(M_FATAL, - "AEAD cipher (currently %s) " + /* The pulled options are validated in do_deferred_options(), so + * reaching this point means a code path escaped that check. Fail + * the session instead of the whole process */ + msg(D_TLS_ERRORS, + "TLS Error: AEAD cipher (currently %s) " "required for epoch data format.", cipher_kt_name(key_type->cipher)); + return KEY_GEN_FAILED; } init_epoch_keys(ks, multi, key_type, server, key2); }