On Thu, 2 Feb 2012, Daniel Stenberg wrote:

As a longer term fix I could see us accepting a patch that allows a user to explicitly ask for diabling of this work-around.

I've received and read several more cases where people experience this problem. I suggest we introduce a new setopt option (and corresponding command line option) that simply switches off this work-around for those SSL libraries that use it. CURLOPT_SSL_ALLOW_INSECURE or something like that. Possibly even more specific like CURLOPT_SSL_NO_EMPTY_FRAGMENTS...

Opinions?

--

 / daniel.haxx.se
-------------------------------------------------------------------
List admin: http://cool.haxx.se/list/listinfo/curl-library
Etiquette:  http://curl.haxx.se/mail/etiquette.html

Reply via email to