5ae4ceb92c
In light of potential UKS (unknown key share) attacks on some applications, primarily browsers, despite RFC761, name checks are by default applied with DANE-EE(3) TLSA records. Applications for which UKS is not a problem can optionally disable DANE-EE(3) name checks via the new SSL_CTX_dane_set_flags() and friends. Reviewed-by: Rich Salz <rsalz@openssl.org> |
||
---|---|---|
.. | ||
bio.h | ||
comp.h | ||
conf.h | ||
constant_time_locl.h | ||
dane.h | ||
dso.h | ||
err.h | ||
numbers.h | ||
o_dir.h | ||
o_str.h |