summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMatt Caswell <matt@openssl.org>2017-01-18 11:52:50 +0000
committerMatt Caswell <matt@openssl.org>2017-01-30 10:18:21 +0000
commit71c94d3c6115ab853bbdc2e0e1e26da2c8aba76a (patch)
tree8087e91a5c81ddcd386128682ab7039637e12bd7
parentf4bbb37c4c95ea8cdb4b3470098a1b5d7d1977ed (diff)
Make sure we also cleanse the finished key
Reviewed-by: Rich Salz <rsalz@openssl.org> (Merged from https://github.com/openssl/openssl/pull/2259)
-rw-r--r--ssl/statem/extensions_clnt.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/ssl/statem/extensions_clnt.c b/ssl/statem/extensions_clnt.c
index 04dbea11fd..eb8cfa3b3d 100644
--- a/ssl/statem/extensions_clnt.c
+++ b/ssl/statem/extensions_clnt.c
@@ -820,6 +820,7 @@ int tls_construct_ctos_psk(SSL *s, WPACKET *pkt, X509 *x, size_t chainidx,
ret = 1;
err:
OPENSSL_cleanse(binderkey, sizeof(binderkey));
+ OPENSSL_cleanse(finishedkey, sizeof(finishedkey));
EVP_PKEY_free(mackey);
EVP_MD_CTX_free(mctx);