• B
    Fix SSL 2.0 rollback checking: The previous implementation of the · 37569e64
    Bodo Möller 提交于
    test was never triggered due to an off-by-one error.
    
    In s23_clnt.c, don't use special rollback-attack detection padding
    (RSA_SSLV23_PADDING) if SSL 2.0 is the only protocol enabled in the
    client; similarly, in s23_srvr.c, don't do the rollback check if
    SSL 2.0 is the only protocol enabled in the server.
    37569e64
rsa_ssl.c 4.8 KB