CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]   2026/06/14 08:25:55

Modified files:
        lib/libssl     : ssl.h ssl_lib.c 

Log message:
Remove SSL_OP_LEGACY_SERVER_CONNECT from default options.

Remove SSL_OP_LEGACY_SERVER_CONNECT from the default SSL options and the
SSL_OP_ALL define. This means that we will now refuse to connect to a
TLSv1.2 server if it does not support the Renegotiation Indication (RI)
extension. This prevents a class of attacks against TLS clients that are
talking to TLSv1.2-only servers that permit client initiated renegotiation.

Raised by Lucca Hirschi et al from Inria.

ok beck@ tb@

Reply via email to