From 20c8675ba46bda97330a4117c459a59a9f1c465e Mon Sep 17 00:00:00 2001 From: Alberto Gonzalez Iniesta Date: Mon, 21 Nov 2016 09:37:33 +0100 Subject: New upstream version 2.4~beta1 --- src/openvpn/ssl_openssl.h | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) (limited to 'src/openvpn/ssl_openssl.h') diff --git a/src/openvpn/ssl_openssl.h b/src/openvpn/ssl_openssl.h index 73a6c49..97dc742 100644 --- a/src/openvpn/ssl_openssl.h +++ b/src/openvpn/ssl_openssl.h @@ -35,15 +35,14 @@ /** * SSL_OP_NO_TICKET tells OpenSSL to disable "stateless session resumption", * as this is something we do not want nor need, but could potentially be - * used for a future attack. For compatibility reasons, in the 2.3.x - * series, we keep building if the OpenSSL version is too old to support - * this. 2.4 requires it and will fail configure if not present. + * used for a future attack. For compatibility reasons we keep building if the + * OpenSSL version is too old (pre-0.9.8f) to support stateless session + * resumption (and the accompanying SSL_OP_NO_TICKET flag). */ #ifndef SSL_OP_NO_TICKET # define SSL_OP_NO_TICKET 0 #endif - /** * Structure that wraps the TLS context. Contents differ depending on the * SSL library used. -- cgit v1.2.3