Fix length check in ssl_write_ticket()
diff --git a/library/ssl_srv.c b/library/ssl_srv.c
index d0ef6ef..c6bcf25 100644
--- a/library/ssl_srv.c
+++ b/library/ssl_srv.c
@@ -212,7 +212,7 @@
      */
     state = p + 2;
     if( ssl_save_session( ssl->session_negotiate, state,
-                          SSL_MAX_CONTENT_LEN - ( state - ssl->out_ctr ) - 48,
+                          SSL_MAX_CONTENT_LEN - ( state - ssl->out_msg ) - 48,
                           &clear_len ) != 0 )
     {
         return( POLARSSL_ERR_SSL_CERTIFICATE_TOO_LARGE );