diff --git a/CHANGES b/CHANGES index 734c3752bf83fc43df5ad682a7284aafb8f12658..d292bd53ee3d36b9b499e3f1bc5632e8deb9122d 100644 --- a/CHANGES +++ b/CHANGES @@ -4,6 +4,14 @@ Changes between 1.0.x and 1.1.0 [xx XXX xxxx] + *) Add option SSL_OP_SAFARI_ECDHE_ECDSA_BUG (part of SSL_OP_ALL) which + avoids preferring ECDHE-ECDSA ciphers when the client appears to be + Safari on OS X. Safari on OS X 10.8..10.8.3 advertises support for + several ECDHE-ECDSA ciphers, but fails to negotiate them. The bug + is fixed in OS X 10.8.4, but Apple have ruled out both hot fixing + 10.8..10.8.3 and forcing users to upgrade to 10.8.4 or newer. + [Rob Stradling, Adam Langley] + *) Experimental encrypt-then-mac support. Experimental support for encrypt then mac from