)]}'
{"id":"openvpn~1728","triplet_id":"openvpn~master~Iaf1f3475e4f27a920c028cd73b1a2497953583d0","project":"openvpn","branch":"master","topic":"multipeer","attention_set":{},"removed_from_attention_set":{"1000003":{"account":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"last_update":"2026-08-14 07:04:43.000000000","reason":"Change was submitted"},"1000001":{"account":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"last_update":"2026-08-07 14:59:30.000000000","reason":"removed on reply"}},"hashtags":[],"change_id":"Iaf1f3475e4f27a920c028cd73b1a2497953583d0","subject":"Do not differentiate TLS server and client context initialisation","status":"MERGED","created":"2026-06-22 15:31:08.000000000","updated":"2026-08-14 07:04:43.000000000","submitted":"2026-08-14 07:04:43.000000000","submitter":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"total_comment_count":15,"unresolved_comment_count":0,"has_review_started":true,"submission_id":"1728-multipeer","meta_rev_id":"47cea0e4e4bfc41d66be3248a8bf640ba8683195","_number":1728,"virtual_id_number":1728,"owner":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"actions":{},"labels":{"Code-Review":{"all":[{"value":0,"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},{"value":0,"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}],"values":{"-2":"This shall not be submitted","-1":"I would prefer this is not submitted as is"," 0":"No score","+1":"Looks good to me, but someone else must approve","+2":"Looks good to me, approved"},"description":"","default_value":0}},"removable_reviewers":[],"reviewers":{"REVIEWER":[{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."}],"CC":[{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"}]},"pending_reviewers":{},"reviewer_updates":[{"updated":"2026-06-22 15:31:16.000000000","updated_by":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"reviewer":{"_account_id":1000026,"name":"openvpn-devel","email":"openvpn-devel@lists.sourceforge.net","username":"openvpn-devel"},"state":"CC"},{"updated":"2026-07-06 14:25:47.000000000","updated_by":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"reviewer":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"state":"REVIEWER"}],"messages":[{"id":"81f0cab4d5c0fef0c250a4122a2e5e990580aed1","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-06-22 15:31:08.000000000","message":"Uploaded patch set 1.","accounts_in_message":[],"_revision_number":1},{"id":"47033a8cfdaa4849afcf4939e5dcafbf899b8bdd","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-06-25 13:37:02.000000000","message":"Uploaded patch set 2: Patch Set 1 was rebased.","accounts_in_message":[],"_revision_number":2},{"id":"032d79713d97267b9a76046d7fe0ec53781e564e","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-07-06 14:25:47.000000000","message":"Patch Set 2: Code-Review-1\n\n(3 comments)","accounts_in_message":[],"_revision_number":2},{"id":"ee75d4793596a704ffdfb3fdf36db6b2314de149","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-17 14:32:28.000000000","message":"Uploaded patch set 3: Patch Set 2 was rebased.\n\nCopied Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR is:MIN\")\n","accounts_in_message":[],"_revision_number":3},{"id":"d7a5ec13246dd1e2fc46ad652d51ca9d4a5aebc9","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-23 12:01:42.000000000","message":"Patch Set 3:\n\n(3 comments)","accounts_in_message":[],"_revision_number":3},{"id":"01b5cb349d514527e1a9ab321c5057eb1e7dc4c7","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-23 12:04:23.000000000","message":"Uploaded patch set 4: Patch Set 3 was rebased. Commit message was updated.\n\nOutdated Votes:\n* Code-Review-1 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":4},{"id":"876d80ab318f8fb5d5c2d18b39d622f4dd641e47","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-07-23 12:14:35.000000000","message":"Patch Set 4: Code-Review+2\n\n(5 comments)","accounts_in_message":[],"_revision_number":4},{"id":"b402b1690d5790b1b3dfc136b5a401107bec5da0","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-07-26 00:06:29.000000000","message":"Uploaded patch set 5: Patch Set 4 was rebased.\n\nCopied Votes:\n* Code-Review+2 (copy condition: \"changekind:NO_CHANGE OR **changekind:TRIVIAL_REBASE** OR is:MIN\")\n","accounts_in_message":[],"_revision_number":5},{"id":"101e2eb2989a7a7f51e0bdaba046d2f02dded605","tag":"autogenerated:gerrit:newPatchSet","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-07 13:49:36.000000000","message":"Uploaded patch set 6: Patch Set 5 was rebased. Commit message was updated.\n\nOutdated Votes:\n* Code-Review+2 (copy condition: \"changekind:NO_CHANGE OR changekind:TRIVIAL_REBASE OR is:MIN\")\n","accounts_in_message":[],"_revision_number":6},{"id":"d94069718e8c8a3885b24da545054d67dbd5d136","author":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"date":"2026-08-07 13:49:37.000000000","message":"Patch Set 5:\n\n(4 comments)","accounts_in_message":[],"_revision_number":5},{"id":"b51de4dc46f75e9be66aba52b3eb381de249fcfa","author":{"_account_id":1000001,"name":"flichtenheld","display_name":"Frank Lichtenheld","email":"frank@lichtenheld.com","username":"flichtenheld","status":"OpenVPN Inc."},"date":"2026-08-07 14:59:30.000000000","message":"Patch Set 6: Code-Review+2","accounts_in_message":[],"_revision_number":6},{"id":"47cea0e4e4bfc41d66be3248a8bf640ba8683195","tag":"autogenerated:gerrit:merged","author":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"date":"2026-08-14 07:04:43.000000000","message":"Change has been successfully pushed.","accounts_in_message":[],"_revision_number":7}],"current_revision_number":7,"current_revision":"37acc42ce769a1c7415311eaf40b9013316d8a61","revisions":{"1eec88cff05fc7eb8135943739c1ab670014a490":{"kind":"REWORK","_number":1,"created":"2026-06-22 15:31:08.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/28/1728/1","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/28/1728/1","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/1 \u0026\u0026 git checkout -b change-1728 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/1 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/1 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/1 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/28/1728/1","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/1 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"0fefdd1d70ac3f8183ca1d136e37071853a692c1","subject":"Add lookup of multi session by session id"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-04-14 23:36:33.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-06-22 15:30:51.000000000","tz":120},"subject":"Do not differentiate TLS server and client context initialisation","message":"Do not differentiate TLS server and client context initialisation\n\nOpenSSL has the quite curious way of allowing to create contexts\nthat allow only server or only client. This creates extra\ncomplications when we want to use both server and client SSL\nobjects and does not seem to have any advantages.\n\nWe later explicitly tell initialise the SSL objects to be a server or\nclient object in key_state_ssl_init via SSL_set_accept_state or\nSSL_set_connect_state. If this is mismatched we end up getting an\nerror from OpenSSL (\"called a function you should not call\") that\nthat ends up calling a function that is not defined in that\nTLS_method.\n\nLooking into the OpenSSL source (IMPLEMENT_tls_meth_func) the main\ndifference between the methods is whether they have a proper\naccept/connect or have the ssl_undefined_function that triggers the\n\"called a function you should not call\".\n\nOur mBed TLS code basically does give the SSL contet any personlity\nof client or server until we the same area where the OpenSSL code\ncalls the set accept/connect state call.\n\nChange-Id: Iaf1f3475e4f27a920c028cd73b1a2497953583d0\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"9e251ce7c48f9a749e46bb4051ceaf79b41dc1b8":{"kind":"TRIVIAL_REBASE","_number":2,"created":"2026-06-25 13:37:02.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/28/1728/2","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/28/1728/2","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/2 \u0026\u0026 git checkout -b change-1728 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/2 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/2 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/2 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/28/1728/2","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/2 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"3d148280b63a069b8d6879a7d9be7e5175292aa9","subject":"Add lookup of multi session by session id"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-04-14 23:36:33.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-06-25 13:36:38.000000000","tz":120},"subject":"Do not differentiate TLS server and client context initialisation","message":"Do not differentiate TLS server and client context initialisation\n\nOpenSSL has the quite curious way of allowing to create contexts\nthat allow only server or only client. This creates extra\ncomplications when we want to use both server and client SSL\nobjects and does not seem to have any advantages.\n\nWe later explicitly tell initialise the SSL objects to be a server or\nclient object in key_state_ssl_init via SSL_set_accept_state or\nSSL_set_connect_state. If this is mismatched we end up getting an\nerror from OpenSSL (\"called a function you should not call\") that\nthat ends up calling a function that is not defined in that\nTLS_method.\n\nLooking into the OpenSSL source (IMPLEMENT_tls_meth_func) the main\ndifference between the methods is whether they have a proper\naccept/connect or have the ssl_undefined_function that triggers the\n\"called a function you should not call\".\n\nOur mBed TLS code basically does give the SSL contet any personlity\nof client or server until we the same area where the OpenSSL code\ncalls the set accept/connect state call.\n\nChange-Id: Iaf1f3475e4f27a920c028cd73b1a2497953583d0\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"ec9d50c318b67c8836815a0029916cf8e8f43ea5":{"kind":"TRIVIAL_REBASE","_number":3,"created":"2026-07-17 14:32:28.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/28/1728/3","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/28/1728/3","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/3 \u0026\u0026 git checkout -b change-1728 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/3 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/3 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/3 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/28/1728/3","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/3 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"2c063aab2095cb86186f395d73a59626431ea289","subject":"Add lookup of multi session by session id"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-04-14 23:36:33.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-15 12:17:21.000000000","tz":120},"subject":"Do not differentiate TLS server and client context initialisation","message":"Do not differentiate TLS server and client context initialisation\n\nOpenSSL has the quite curious way of allowing to create contexts\nthat allow only server or only client. This creates extra\ncomplications when we want to use both server and client SSL\nobjects and does not seem to have any advantages.\n\nWe later explicitly tell initialise the SSL objects to be a server or\nclient object in key_state_ssl_init via SSL_set_accept_state or\nSSL_set_connect_state. If this is mismatched we end up getting an\nerror from OpenSSL (\"called a function you should not call\") that\nthat ends up calling a function that is not defined in that\nTLS_method.\n\nLooking into the OpenSSL source (IMPLEMENT_tls_meth_func) the main\ndifference between the methods is whether they have a proper\naccept/connect or have the ssl_undefined_function that triggers the\n\"called a function you should not call\".\n\nOur mBed TLS code basically does give the SSL contet any personlity\nof client or server until we the same area where the OpenSSL code\ncalls the set accept/connect state call.\n\nChange-Id: Iaf1f3475e4f27a920c028cd73b1a2497953583d0\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"6ad6d340bf9bd7ae183521fc973ecb115f124f03":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":4,"created":"2026-07-23 12:04:23.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/28/1728/4","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/28/1728/4","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/4 \u0026\u0026 git checkout -b change-1728 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/4 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/4 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/4 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/28/1728/4","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/4 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"4b80a129999aceaeb429ebd703f618a51775d955","subject":"Remove --providers from --help output for Mbed TLS"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-04-14 23:36:33.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-23 12:03:48.000000000","tz":120},"subject":"Do not differentiate TLS server and client context initialisation","message":"Do not differentiate TLS server and client context initialisation\n\nOpenSSL has the quite curious way of allowing to create contexts\nthat allow only server or only client. This creates extra\ncomplications when we want to use both server and client SSL\nobjects and does not seem to have any advantages.\n\nWe later explicitly tell OpenSSL to initialise the SSL objects\nto be a server or client object in key_state_ssl_init via\nSSL_set_accept_state or SSL_set_connect_state. If this is\nmismatched we end up getting an error from OpenSSL (\"called a\nfunction you should not call\") that ends up calling a function\nthat is not defined in that TLS_method.\n\nLooking into the OpenSSL source (IMPLEMENT_tls_meth_func) the main\ndifference between the methods is whether they have a proper\naccept/connect or have the ssl_undefined_function that triggers the\n\"called a function you should not call\".\n\nOur mbed TLS code basically does give the SSL context any personality\nof client or server until we are in the same area in which the OpenSSL\ncode calls SSL_set_accept_state/SSL_set_connect_sate.\n\nThis also modifies the mbedTLS to use the decision to pick client\nand server in that path as the OpenSSL code path.\n\nChange-Id: Iaf1f3475e4f27a920c028cd73b1a2497953583d0\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"65f7bf08caa1a473bf6ca5c0f1464485908e7231":{"kind":"TRIVIAL_REBASE","_number":5,"created":"2026-07-26 00:06:29.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/28/1728/5","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/28/1728/5","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/5 \u0026\u0026 git checkout -b change-1728 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/5 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/5 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/5 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/28/1728/5","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/5 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"3bd2439ef73b52b21da56b85c7cef4c62709c9b3","subject":"Only announce support push updates/IV_NCP when actually supporting it"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-04-14 23:36:33.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-07-26 00:06:24.000000000","tz":120},"subject":"Do not differentiate TLS server and client context initialisation","message":"Do not differentiate TLS server and client context initialisation\n\nOpenSSL has the quite curious way of allowing to create contexts\nthat allow only server or only client. This creates extra\ncomplications when we want to use both server and client SSL\nobjects and does not seem to have any advantages.\n\nWe later explicitly tell OpenSSL to initialise the SSL objects\nto be a server or client object in key_state_ssl_init via\nSSL_set_accept_state or SSL_set_connect_state. If this is\nmismatched we end up getting an error from OpenSSL (\"called a\nfunction you should not call\") that ends up calling a function\nthat is not defined in that TLS_method.\n\nLooking into the OpenSSL source (IMPLEMENT_tls_meth_func) the main\ndifference between the methods is whether they have a proper\naccept/connect or have the ssl_undefined_function that triggers the\n\"called a function you should not call\".\n\nOur mbed TLS code basically does give the SSL context any personality\nof client or server until we are in the same area in which the OpenSSL\ncode calls SSL_set_accept_state/SSL_set_connect_sate.\n\nThis also modifies the mbedTLS to use the decision to pick client\nand server in that path as the OpenSSL code path.\n\nChange-Id: Iaf1f3475e4f27a920c028cd73b1a2497953583d0\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"7f4541b3b554f681d3e102c57d9c50f9ebc51199":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":6,"created":"2026-08-07 13:49:36.000000000","uploader":{"_account_id":1000003,"name":"plaisthos","display_name":"Arne Schwabe","email":"arne-openvpn@rfc2549.org","username":"plaisthos"},"ref":"refs/changes/28/1728/6","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/28/1728/6","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/6 \u0026\u0026 git checkout -b change-1728 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/6 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/6 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/6 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/28/1728/6","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/6 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"d1106970f76e955b0a5fa19b566e97bba98d4c9b","subject":"Change hash iv to a be a fixed sized array"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-04-14 23:36:33.000000000","tz":120},"committer":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-08-07 13:47:15.000000000","tz":120},"subject":"Do not differentiate TLS server and client context initialisation","message":"Do not differentiate TLS server and client context initialisation\n\nOpenSSL has the quite curious way of allowing to create contexts\nthat allow only server or only client. This creates extra\ncomplications when we want to use both server and client SSL\nobjects and does not seem to have any advantages.\n\nWe later explicitly tell OpenSSL to initialise the SSL objects\nto be a server or client object in key_state_ssl_init via\nSSL_set_accept_state or SSL_set_connect_state. If this is\nmismatched we end up getting an error from OpenSSL (\"called a\nfunction you should not call\") that ends up calling a function\nthat is not defined in that TLS_method.\n\nLooking into the OpenSSL source (IMPLEMENT_tls_meth_func) the main\ndifference between the methods is whether they have a proper\naccept/connect or have the ssl_undefined_function that triggers the\n\"called a function you should not call\".\n\nOur mbed TLS code basically does not give the TLS context any personality\nof client or server until we are in the same area in which the OpenSSL\ncode calls SSL_set_accept_state/SSL_set_connect_state.\n\nThis also modifies the mbedTLS backend to make the decision to use\nclient or server TLS context personality in key_state_ssl_init.\nsame as the OpenSSL backend.\n\nChange-Id: Iaf1f3475e4f27a920c028cd73b1a2497953583d0\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\n"},"branch":"refs/heads/master"},"37acc42ce769a1c7415311eaf40b9013316d8a61":{"kind":"TRIVIAL_REBASE_WITH_MESSAGE_UPDATE","_number":7,"created":"2026-08-14 07:04:43.000000000","uploader":{"_account_id":1000002,"name":"cron2","display_name":"Gert Doering","email":"gert@greenie.muc.de","username":"cron2"},"ref":"refs/changes/28/1728/7","fetch":{"anonymous http":{"url":"http://gerrit.openvpn.net/openvpn","ref":"refs/changes/28/1728/7","commands":{"Branch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/7 \u0026\u0026 git checkout -b change-1728 FETCH_HEAD","Checkout":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/7 \u0026\u0026 git checkout FETCH_HEAD","Cherry Pick":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/7 \u0026\u0026 git cherry-pick FETCH_HEAD","Format Patch":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/7 \u0026\u0026 git format-patch -1 --stdout FETCH_HEAD","Pull":"git pull http://gerrit.openvpn.net/openvpn refs/changes/28/1728/7","Reset To":"git fetch http://gerrit.openvpn.net/openvpn refs/changes/28/1728/7 \u0026\u0026 git reset --hard FETCH_HEAD"}}},"commit":{"parents":[{"commit":"ffa0e712eadab73b7e7b94de637d88c539cf6bc6","subject":"Replace SHA256 with SIPHASH24 in HMAC cookie approach"}],"author":{"name":"Arne Schwabe","email":"arne@rfc2549.org","date":"2026-08-13 18:52:51.000000000","tz":120},"committer":{"name":"Gert Doering","email":"gert@greenie.muc.de","date":"2026-08-13 20:38:54.000000000","tz":120},"subject":"Do not differentiate TLS server and client context initialisation","message":"Do not differentiate TLS server and client context initialisation\n\nOpenSSL has the quite curious way of allowing to create contexts\nthat allow only server or only client. This creates extra\ncomplications when we want to use both server and client SSL\nobjects and does not seem to have any advantages.\n\nWe later explicitly tell OpenSSL to initialise the SSL objects\nto be a server or client object in key_state_ssl_init via\nSSL_set_accept_state or SSL_set_connect_state. If this is\nmismatched we end up getting an error from OpenSSL (\"called a\nfunction you should not call\") that ends up calling a function\nthat is not defined in that TLS_method.\n\nLooking into the OpenSSL source (IMPLEMENT_tls_meth_func) the main\ndifference between the methods is whether they have a proper\naccept/connect or have the ssl_undefined_function that triggers the\n\"called a function you should not call\".\n\nOur mbed TLS code basically does not give the TLS context any personality\nof client or server until we are in the same area in which the OpenSSL\ncode calls SSL_set_accept_state/SSL_set_connect_state.\n\nThis also modifies the mbedTLS backend to make the decision to use\nclient or server TLS context personality in key_state_ssl_init.\nsame as the OpenSSL backend.\n\nChange-Id: Iaf1f3475e4f27a920c028cd73b1a2497953583d0\nSigned-off-by: Arne Schwabe \u003carne@rfc2549.org\u003e\nAcked-by: Frank Lichtenheld \u003cfrank@lichtenheld.com\u003e\nGerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1728\nMessage-Id: \u003c20260813185258.7084-1-gert@greenie.muc.de\u003e\nURL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg38340.html\nSigned-off-by: Gert Doering \u003cgert@greenie.muc.de\u003e\n"},"branch":"refs/heads/master"}},"requirements":[],"submit_records":[],"submit_requirements":[]}
