| 1 |
diff -up openssl-1.0.0-beta3/ssl/ssl.h.cipher-change openssl-1.0.0-beta3/ssl/ssl.h
|
| 2 |
--- openssl-1.0.0-beta3/ssl/ssl.h.cipher-change 2009-08-05 18:22:45.000000000 +0200
|
| 3 |
+++ openssl-1.0.0-beta3/ssl/ssl.h 2009-08-05 18:27:32.000000000 +0200
|
| 4 |
@@ -511,7 +511,7 @@ typedef struct ssl_session_st
|
| 5 |
|
| 6 |
#define SSL_OP_MICROSOFT_SESS_ID_BUG 0x00000001L
|
| 7 |
#define SSL_OP_NETSCAPE_CHALLENGE_BUG 0x00000002L
|
| 8 |
-#define SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG 0x00000008L
|
| 9 |
+#define SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG 0x00000008L /* can break some security expectations */
|
| 10 |
#define SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUG 0x00000010L
|
| 11 |
#define SSL_OP_MICROSOFT_BIG_SSLV3_BUFFER 0x00000020L
|
| 12 |
#define SSL_OP_MSIE_SSLV2_RSA_PADDING 0x00000040L /* no effect since 0.9.7h and 0.9.8b */
|
| 13 |
@@ -528,7 +528,7 @@ typedef struct ssl_session_st
|
| 14 |
|
| 15 |
/* SSL_OP_ALL: various bug workarounds that should be rather harmless.
|
| 16 |
* This used to be 0x000FFFFFL before 0.9.7. */
|
| 17 |
-#define SSL_OP_ALL 0x80000FFFL
|
| 18 |
+#define SSL_OP_ALL 0x80000FF7L
|
| 19 |
|
| 20 |
/* DTLS options */
|
| 21 |
#define SSL_OP_NO_QUERY_MTU 0x00001000L
|