mturk / rpms / openssl

Forked from rpms/openssl 3 years ago
Clone
2ccfa6b
diff -up openssl-1.0.0-beta3/ssl/ssl.h.cipher-change openssl-1.0.0-beta3/ssl/ssl.h
2ccfa6b
--- openssl-1.0.0-beta3/ssl/ssl.h.cipher-change	2009-08-05 18:22:45.000000000 +0200
2ccfa6b
+++ openssl-1.0.0-beta3/ssl/ssl.h	2009-08-05 18:27:32.000000000 +0200
2ccfa6b
@@ -511,7 +511,7 @@ typedef struct ssl_session_st
f1d9cb4
 
f1d9cb4
 #define SSL_OP_MICROSOFT_SESS_ID_BUG			0x00000001L
f1d9cb4
 #define SSL_OP_NETSCAPE_CHALLENGE_BUG			0x00000002L
f1d9cb4
-#define SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG		0x00000008L
f1d9cb4
+#define SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG		0x00000008L /* can break some security expectations */
f1d9cb4
 #define SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUG		0x00000010L
f1d9cb4
 #define SSL_OP_MICROSOFT_BIG_SSLV3_BUFFER		0x00000020L
f1d9cb4
 #define SSL_OP_MSIE_SSLV2_RSA_PADDING			0x00000040L /* no effect since 0.9.7h and 0.9.8b */
2ccfa6b
@@ -528,7 +528,7 @@ typedef struct ssl_session_st
f1d9cb4
 
f1d9cb4
 /* SSL_OP_ALL: various bug workarounds that should be rather harmless.
f1d9cb4
  *             This used to be 0x000FFFFFL before 0.9.7. */
2ccfa6b
-#define SSL_OP_ALL					0x80000FFFL
2ccfa6b
+#define SSL_OP_ALL					0x80000FF7L
f1d9cb4
 
f1d9cb4
 /* DTLS options */
f1d9cb4
 #define SSL_OP_NO_QUERY_MTU                 0x00001000L