Don't advertise ECC ciphersuits in SSLv2 compatible client hello.
PR#3374
(cherry picked from commit 0436369fcc
)
This commit is contained in:
parent
06f3746c62
commit
d9d5a12823
1 changed files with 7 additions and 0 deletions
|
@ -107,6 +107,13 @@ int ssl23_put_cipher_by_char(const SSL_CIPHER *c, unsigned char *p)
|
|||
long l;
|
||||
|
||||
/* We can write SSLv2 and SSLv3 ciphers */
|
||||
/* but no ECC ciphers */
|
||||
if (c->algorithm_mkey == SSL_kECDHr ||
|
||||
c->algorithm_mkey == SSL_kECDHe ||
|
||||
c->algorithm_mkey == SSL_kEECDH ||
|
||||
c->algorithm_auth == SSL_aECDH ||
|
||||
c->algorithm_auth == SSL_aECDSA)
|
||||
return 0;
|
||||
if (p != NULL)
|
||||
{
|
||||
l=c->id;
|
||||
|
|
Loading…
Reference in a new issue