ef93cf9
SHA1 is allowed in @SECLEVEL=2 only if allowed by TLS SigAlgs configuration Also some small TLS protocol fixes/changes: Disallow dropping Extended Master Secret extension on renegotiation Return alert from s_server if ALPN protocol does not match