aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorGravatar Nokis Mavrogiannopoulos 2007-12-02 16:17:54 +0000
committerGravatar Nokis Mavrogiannopoulos 2007-12-02 16:17:54 +0000
commit421bad90160111f2470565540db237351b5a3963 (patch)
tree9733d13336bb367846a3f1bf1d16b59ea2a16820
parentd51667e406c2099865a4eec366fdab9d4578b683 (diff)
The compatibility mode can now be enabled only using the GnuTLSPriorities string.
-rw-r--r--NEWS5
-rw-r--r--src/gnutls_hooks.c5
2 files changed, 4 insertions, 6 deletions
diff --git a/NEWS b/NEWS
index 30f67e4..5d67da5 100644
--- a/NEWS
+++ b/NEWS
@@ -4,4 +4,7 @@
4Only one per certificate is supported. 4Only one per certificate is supported.
5 5
6- New enviroment variables: SSL_CLIENT_M_VERSION, SSL_CLIENT_S_SAN%, 6- New enviroment variables: SSL_CLIENT_M_VERSION, SSL_CLIENT_S_SAN%,
7SSL_CLIENT_S_TYPE, SSL_SERVER_M_VERSION, SSL_SERVER_S_SAN%, SSL_SERVER_S_TYPE \ No newline at end of file 7SSL_CLIENT_S_TYPE, SSL_SERVER_M_VERSION, SSL_SERVER_S_SAN%, SSL_SERVER_S_TYPE
8
9- The compatibility mode can now be enabled explicitely with the
10%COMPAT keyword at the GnuTLSPriorities string. It is no longer the default.
diff --git a/src/gnutls_hooks.c b/src/gnutls_hooks.c
index 1af82a7..e3edba2 100644
--- a/src/gnutls_hooks.c
+++ b/src/gnutls_hooks.c
@@ -631,11 +631,6 @@ static mgs_handle_t *create_gnutls_handle(apr_pool_t * pool, conn_rec * c)
631 631
632 gnutls_init(&ctxt->session, GNUTLS_SERVER); 632 gnutls_init(&ctxt->session, GNUTLS_SERVER);
633 633
634 /* This is not very good as it trades security for compatibility,
635 * but it is the only way to be ultra-portable.
636 */
637 gnutls_session_enable_compatibility_mode(ctxt->session);
638
Nikos Mavrogiannopoulos 2008-01-24
* (no commit message)Gravatar Nikos Mavrogiannopoulos 2007-12-16
* more changes for openpgp support. Seems to be at a workable state.Gravatar Nikos Mavrogiannopoulos 2007-12-16
* print error if preconfiguration failsGravatar Nikos Mavrogiannopoulos 2007-12-15
* Initial support for openpgp keysGravatar Nikos Mavrogiannopoulos 2007-12-15
* (no commit message)Gravatar Nikos Mavrogiannopoulos 2007-12-10
* (no commit message)Gravatar Nikos Mavrogiannopoulos 2007-12-10
* (no commit message)Gravatar Nikos Mavrogiannopoulos 2007-12-09
* Do not allow resuming sessions on different servers.Gravatar Nikos Mavrogiannopoulos 2007-12-09
* Corrected bug which did not allow the TLS session cache to be used.Gravatar Nikos Mavrogiannopoulos 2007-12-09
* Added support for sending more than one certificate.Gravatar Nikos Mavrogiannopoulos 2007-12-08
* added more error checks.Gravatar Nikos Mavrogiannopoulos 2007-12-03
* better handling of RSAFile and DHFileGravatar Nikos Mavrogiannopoulos 2007-12-03
* report the missing GnuTLSPriorities for the gnutls enabled hosts only.Gravatar Nikos Mavrogiannopoulos 2007-12-02
* No more defaults for dhparams, rsaparams. Check for GnuTLSPriorities.Gravatar Nikos Mavrogiannopoulos 2007-12-02
* The compatibility mode can now be enabled only using the GnuTLSPriorities str...Gravatar Nikos Mavrogiannopoulos 2007-12-02
* (no commit message)Gravatar Nikos Mavrogiannopoulos 2007-12-02
* added SSL_SERVER/CLIENT_S_TYPEGravatar Nikos Mavrogiannopoulos 2007-12-02
* export the alternative names of the certificateGravatar Nikos Mavrogiannopoulos 2007-12-02
* added SSL_SERVER_M_SERIAL environment variableGravatar Nikos Mavrogiannopoulos 2007-12-02
* more fixes for subject alternative name.Gravatar Nikos Mavrogiannopoulos 2007-12-02
* some fixes in alternative name supportGravatar Nikos Mavrogiannopoulos 2007-12-02
* Added support for subject alternative names. (untested)Gravatar Nikos Mavrogiannopoulos 2007-12-01
* upgraded to 0.4.0Gravatar Nikos Mavrogiannopoulos 2007-11-28
* Put a limit on the number of times we try to handshake.Gravatar Paul Querna 2005-09-25
* start the CA Certificate code.Gravatar Paul Querna 2005-05-24
* - add lua to do client verificationGravatar Paul Querna 2005-05-17
* Refactor finding the correct server record to fix resumed sessions.0.2.00.2.xGravatar Paul Querna 2005-04-25
* apr_table_setn doesn't copy the data. oops.Gravatar Paul Querna 2005-04-24