.. of course this conflicts with o->renegotiate_seconds_min...
Nevertheless, thanks for the patch :-) - it makes my FreeBSD 10.3
(mbedTLS 2.6) buildslave now happy again (on the default settings - with
--tls-cert-profile preferred, it refuses the old-hash cert, as it should).
Also tested with openssl 1.0.1, where it warns and does nothing, as
expected. Good :-)
Commit subject amended according to Antonio's comment.
Your patch has been applied to the master and release/2.4 branch.
commit aba758740d26224b7b3957df221def7ab80c5802 (master)
commit 8bcabf0a1621e6ccc7a44465a73de29fd2d541b3 (release/2.4)
Author: Steffan Karger
Date: Sun Nov 12 17:36:36 2017 +0100
Add --tls-cert-profile option.
Signed-off-by: Steffan Karger <[email protected]>
Acked-by: Antonio Quartulli <[email protected]>
Message-Id: <[email protected]>
URL:
https://www.mail-archive.com/[email protected]/msg15848.html
Signed-off-by: Gert Doering <[email protected]>
--
kind regards,
Gert Doering
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Openvpn-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openvpn-devel