These no longer apply due to the elapsed time. The verify patch doesn't quite make sense (maybe it did when this was written) because SSL_VERIFY_FAIL_IF_NO_PEER_CERT is a server side only option.
The "manual" option to starttls is quite a neat idea, but will not be applied in its current state. A new patch should be developed against current master if this is still wanted!! Closing this ticket. Matt -- Ticket here: http://rt.openssl.org/Ticket/Display.html?id=1241 Please log in as guest with password guest if prompted -- openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev