Fix and improve SSL_MODE_SEND_FALLBACK_SCSV documentation.
Reviewed-by: Rich Salz <rsalz@openssl.org>
This commit is contained in:
parent
d60de314f4
commit
981545e1e7
@ -71,12 +71,16 @@ SSL_CTX->freelist_max_len, which defaults to 32. Using this flag can
|
|||||||
save around 34k per idle SSL connection.
|
save around 34k per idle SSL connection.
|
||||||
This flag has no effect on SSL v2 connections, or on DTLS connections.
|
This flag has no effect on SSL v2 connections, or on DTLS connections.
|
||||||
|
|
||||||
=item SSL_MODE_FALLBACK_SCSV
|
=item SSL_MODE_SEND_FALLBACK_SCSV
|
||||||
|
|
||||||
Send TLS_FALLBACK_SCSV in the ClientHello.
|
Send TLS_FALLBACK_SCSV in the ClientHello.
|
||||||
To be set by applications that reconnect with a downgraded protocol
|
To be set only by applications that reconnect with a downgraded protocol
|
||||||
version; see draft-ietf-tls-downgrade-scsv-00 for details.
|
version; see draft-ietf-tls-downgrade-scsv-00 for details.
|
||||||
|
|
||||||
|
DO NOT ENABLE THIS if your application attempts a normal handshake.
|
||||||
|
Only use this in explicit fallback retries, following the guidance
|
||||||
|
in draft-ietf-tls-downgrade-scsv-00.
|
||||||
|
|
||||||
=back
|
=back
|
||||||
|
|
||||||
=head1 RETURN VALUES
|
=head1 RETURN VALUES
|
||||||
|
@ -682,8 +682,13 @@ struct ssl_session_st
|
|||||||
#define SSL_MODE_SEND_CLIENTHELLO_TIME 0x00000020L
|
#define SSL_MODE_SEND_CLIENTHELLO_TIME 0x00000020L
|
||||||
#define SSL_MODE_SEND_SERVERHELLO_TIME 0x00000040L
|
#define SSL_MODE_SEND_SERVERHELLO_TIME 0x00000040L
|
||||||
/* Send TLS_FALLBACK_SCSV in the ClientHello.
|
/* Send TLS_FALLBACK_SCSV in the ClientHello.
|
||||||
* To be set by applications that reconnect with a downgraded protocol
|
* To be set only by applications that reconnect with a downgraded protocol
|
||||||
* version; see draft-ietf-tls-downgrade-scsv-00 for details. */
|
* version; see draft-ietf-tls-downgrade-scsv-00 for details.
|
||||||
|
*
|
||||||
|
* DO NOT ENABLE THIS if your application attempts a normal handshake.
|
||||||
|
* Only use this in explicit fallback retries, following the guidance
|
||||||
|
* in draft-ietf-tls-downgrade-scsv-00.
|
||||||
|
*/
|
||||||
#define SSL_MODE_SEND_FALLBACK_SCSV 0x00000080L
|
#define SSL_MODE_SEND_FALLBACK_SCSV 0x00000080L
|
||||||
|
|
||||||
/* Cert related flags */
|
/* Cert related flags */
|
||||||
|
Loading…
x
Reference in New Issue
Block a user