Commit 217fa8a195 for openssl.org

commit 217fa8a195799a55a3d8d818462ddf35507c96a1
Author: Frederik Wedel-Heinen <frederik.wedel-heinen@dencrypt.dk>
Date:   Thu Jul 2 07:10:09 2026 +0200

    Removes redundant SSLv3 version checks and check against TLS1_VERSION_MAJOR instead of SSL3_VERSION_MAJOR.

    Reviewed-by: Andrew Dinh <andrewd@openssl.org>
    Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
    Merge-date: Fri Oct  2 07:28:05 2026
    Merged-from: https://github.com/openssl/openssl/pull/31823

diff --git a/ssl/record/methods/tls_common.c b/ssl/record/methods/tls_common.c
index bda1a17b9d..5773cb393c 100644
--- a/ssl/record/methods/tls_common.c
+++ b/ssl/record/methods/tls_common.c
@@ -1349,7 +1349,7 @@ int tls_int_new_record_layer(OSSL_LIB_CTX *libctx, const char *propq, int vers,
     }

     if ((rl->options & SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS) == 0
-        && rl->version <= TLS1_VERSION
+        && rl->version == TLS1_VERSION
         && !EVP_CIPHER_is_a(ciph, "NULL")
         && !EVP_CIPHER_is_a(ciph, "RC4")) {
         /*
diff --git a/ssl/record/methods/tlsany_meth.c b/ssl/record/methods/tlsany_meth.c
index f6b362eb5e..55d5f77c4b 100644
--- a/ssl/record/methods/tlsany_meth.c
+++ b/ssl/record/methods/tlsany_meth.c
@@ -48,7 +48,7 @@ static int tls_validate_record_header(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *rec)
     const int version1_3 = rl->isdtls ? DTLS1_3_VERSION : TLS1_3_VERSION;

     if (rl->version == TLS_ANY_VERSION) {
-        if ((rec->rec_version >> 8) != SSL3_VERSION_MAJOR) {
+        if ((rec->rec_version >> 8) != TLS1_VERSION_MAJOR) {
             if (rl->is_first_record) {
                 unsigned char *p;

diff --git a/ssl/ssl_asn1.c b/ssl/ssl_asn1.c
index 12cd62d773..67adc9d365 100644
--- a/ssl/ssl_asn1.c
+++ b/ssl/ssl_asn1.c
@@ -289,7 +289,7 @@ SSL_SESSION *d2i_SSL_SESSION_ex(SSL_SESSION **a, const unsigned char **pp,
         goto err;
     }

-    if ((as->ssl_version >> 8) != SSL3_VERSION_MAJOR
+    if ((as->ssl_version >> 8) != TLS1_VERSION_MAJOR
         && (as->ssl_version >> 8) != DTLS1_VERSION_MAJOR
         && as->ssl_version != DTLS1_BAD_VER) {
         ERR_raise(ERR_LIB_SSL, SSL_R_UNSUPPORTED_SSL_VERSION);
diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c
index 1d9f239afe..7e1ec200da 100644
--- a/ssl/ssl_ciph.c
+++ b/ssl/ssl_ciph.c
@@ -550,8 +550,7 @@ int ssl_cipher_get_evp(SSL_CTX *ctx, const SSL_SESSION *s,
         const EVP_CIPHER *evp = NULL;

         if (use_etm
-            || s->ssl_version >> 8 != TLS1_VERSION_MAJOR
-            || s->ssl_version < TLS1_VERSION)
+            || s->ssl_version >> 8 != TLS1_VERSION_MAJOR)
             return 1;

         if (c->algorithm_enc == SSL_RC4
diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
index 238e9d386c..240ae9bb6e 100644
--- a/ssl/ssl_lib.c
+++ b/ssl/ssl_lib.c
@@ -4199,11 +4199,7 @@ int SSL_export_keying_material(SSL *s, unsigned char *out, size_t olen,
 {
     SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s);

-    if (sc == NULL)
-        return -1;
-
-    if (sc->session == NULL
-        || (sc->version < TLS1_VERSION && sc->version != DTLS1_BAD_VER))
+    if (sc == NULL || sc->session == NULL)
         return -1;

     return sc->ssl.method->ssl3_enc->export_keying_material(sc, out, olen, label,
diff --git a/ssl/statem/extensions_clnt.c b/ssl/statem/extensions_clnt.c
index 3684360829..2b7be830a2 100644
--- a/ssl/statem/extensions_clnt.c
+++ b/ssl/statem/extensions_clnt.c
@@ -40,7 +40,7 @@ EXT_RETURN tls_construct_ctos_renegotiate(SSL_CONNECTION *s, WPACKET *pkt,
                 && ssl_security(s, SSL_SECOP_VERSION, 0, TLS1_VERSION, NULL)
                 && s->min_proto_version <= TLS1_VERSION)) {
             /*
-             * For TLS <= 1.0 SCSV is used instead, and for TLS 1.3 this
+             * For TLSv1.0 SCSV is used instead, and for TLS 1.3 this
              * extension isn't used at all.
              */
             return EXT_RETURN_NOT_SENT;
diff --git a/ssl/statem/statem.c b/ssl/statem/statem.c
index b8a31857bf..fa49ed85e6 100644
--- a/ssl/statem/statem.c
+++ b/ssl/statem/statem.c
@@ -435,7 +435,7 @@ static int state_machine(SSL_CONNECTION *s, int server)
                 goto end;
             }
         } else {
-            if ((s->version >> 8) != SSL3_VERSION_MAJOR) {
+            if ((s->version >> 8) != TLS1_VERSION_MAJOR) {
                 SSLfatal(s, SSL_AD_NO_ALERT, ERR_R_INTERNAL_ERROR);
                 goto end;
             }
diff --git a/ssl/t1_lib.c b/ssl/t1_lib.c
index 1ecdb87a85..dacc0169fe 100644
--- a/ssl/t1_lib.c
+++ b/ssl/t1_lib.c
@@ -3130,7 +3130,7 @@ SSL_TICKET_STATUS tls_get_ticket_from_client(SSL_CONNECTION *s,
      * (e.g. TLSv1.3) behave as if no ticket present to permit stateful
      * resumption.
      */
-    if (s->version <= SSL3_VERSION || !tls_use_ticket(s))
+    if (!tls_use_ticket(s))
         return SSL_TICKET_NONE;

     ticketext = &hello->pre_proc_exts[TLSEXT_IDX_session_ticket];