From 7ae491922905fbc800c6c389517a5fbcce6f5734 Mon Sep 17 00:00:00 2001 From: Emanuele Giaquinta Date: Sun, 24 Jun 2012 09:50:08 +0000 Subject: Do not set SSL_OP_ALL, it is not needed to disable SSLv2 and it can prevent connections to TLSv1.1 servers from working. Patch by pi-rho. git-svn-id: file:///var/www/svn.irssi.org/SVN/irssi/trunk@5216 dbcabf3a-b0e7-0310-adc4-f8d773084564 --- src/core/network-openssl.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'src') diff --git a/src/core/network-openssl.c b/src/core/network-openssl.c index eaa51a13..8aeb5a6e 100644 --- a/src/core/network-openssl.c +++ b/src/core/network-openssl.c @@ -410,7 +410,7 @@ static GIOChannel *irssi_ssl_get_iochannel(GIOChannel *handle, const char *hostn g_error("Could not allocate memory for SSL context"); return NULL; } - SSL_CTX_set_options(ctx, SSL_OP_ALL | SSL_OP_NO_SSLv2); + SSL_CTX_set_options(ctx, SSL_OP_NO_SSLv2); if (mycert && *mycert) { char *scert = NULL, *spkey = NULL; -- cgit v1.2.3