1
0
mirror of https://github.com/ARMmbed/mbedtls.git synced 2025-05-31 01:51:23 +08:00

Tiny fix in ChangeLog

Signed-off-by: Elena Uziunaite <elena.uziunaite@arm.com>
This commit is contained in:
Elena Uziunaite 2024-08-22 09:00:57 +01:00
parent f72a510590
commit e0c6f80403

View File

@ -1,7 +1,7 @@
Security
* With TLS 1.3, when a server enables optional authentication of the
client, if the client-provided certificate does not have appropriate values
in if keyUsage or extKeyUsage extensions, then the return value of
in keyUsage or extKeyUsage extensions, then the return value of
mbedtls_ssl_get_verify_result() would incorrectly have the
MBEDTLS_X509_BADCERT_KEY_USAGE and MBEDTLS_X509_BADCERT_KEY_USAGE bits
clear. As a result, an attacker that had a certificate valid for uses other