Commit 74653a6df0 for openssl.org

commit 74653a6df0e54410feb7737b77b833a6b8f71c68
Author: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Date:   Sun Oct 4 15:50:42 2026 +0200

    apps: set cookie callbacks on s_server SNI context

    s_server only installed the DTLS and stateless cookie callbacks on its
    main SSL_CTX. When -servername matched, the connection was switched to
    the second context before the cookie was generated, so a DTLS 1.2
    client sending that name failed the handshake with a cookie generation
    callback failure instead of getting a HelloVerifyRequest.

    Install the callbacks on the SNI context as well and cover the case
    with a (D)TLSv1.2 server name handshake in the TLSProxy message test.

    Assisted-by: Claude:claude-fable-5-1
    Reviewed-by: Matt Caswell <matt@openssl.foundation>
    Reviewed-by: Mounir Idrassi <mounir.idrassi@idrix.fr>
    Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
    Merge-date: Tue Oct  6 14:46:55 2026
    Merged-from: https://github.com/openssl/openssl/pull/33093

diff --git a/apps/s_server.c b/apps/s_server.c
index 57c253d05a..3f689b0d13 100644
--- a/apps/s_server.c
+++ b/apps/s_server.c
@@ -3065,6 +3065,10 @@ int s_server_main(int argc, char *argv[])
             ERR_print_errors(bio_err);
             goto end;
         }
+        SSL_CTX_set_cookie_generate_cb(ctx2, generate_cookie_callback);
+        SSL_CTX_set_cookie_verify_cb(ctx2, verify_cookie_callback);
+        SSL_CTX_set_stateless_cookie_generate_cb(ctx2, generate_stateless_cookie_callback);
+        SSL_CTX_set_stateless_cookie_verify_cb(ctx2, verify_stateless_cookie_callback);
         tlsextcbp.biodebug = bio_s_out;
 #ifndef OPENSSL_NO_ECH
         SSL_CTX_set_tlsext_servername_callback(ctx2, ssl_ech_servername_cb);
diff --git a/test/recipes/70-test_tls13messages.t b/test/recipes/70-test_tls13messages.t
index df47080eb8..486b92206f 100644
--- a/test/recipes/70-test_tls13messages.t
+++ b/test/recipes/70-test_tls13messages.t
@@ -208,7 +208,7 @@ sub setup_extensions

 $ENV{OPENSSL_MODULES} = abs_path(bldtop_dir("test"));

-my $testcount = 19;
+my $testcount = 20;
 my $fatal_alert = 0;
 my $hello_request_added = 0;
 my $hello_request_after_server_hello = 0;
@@ -521,6 +521,27 @@ sub run_tests
            "HelloRequest ignored in $legacy_version");
     }

+    #Test 20: Server name handshake with a (D)TLSv1.2 client against a server
+    #         that also supports (D)TLSv1.3. For DTLS the HelloVerifyRequest
+    #         cookie is then generated after the switch to the SNI context.
+    SKIP: {
+        my $legacy_version = $run_test_as_dtls ? "DTLSv1.2" : "TLSv1.2";
+        my $legacy_version_disabled = $run_test_as_dtls
+                                      ? disabled("dtls1_2")
+                                      : disabled("tls1_2");
+
+        skip "$legacy_version disabled", 1 if $legacy_version_disabled;
+
+        $proxy->clear();
+        $proxy->cipherc("DEFAULT:\@SECLEVEL=2");
+        $proxy->clientflags("-no_rx_cert_comp -max_protocol $legacy_version"
+                            ." -servername testhost");
+        $proxy->serverflags("-no_rx_cert_comp -servername testhost");
+        $proxy->start();
+        ok(TLSProxy::Message->success(),
+           "Server name handshake with $legacy_version client");
+    }
+
     unlink $session;
 }