]> git.ipfire.org Git - thirdparty/openssl.git/commit - apps/include/opt.h
Add option `SSL_OP_PREFER_NO_DHE_KEX`, allowing the server to prefer non-dhe psk...
authorMarkus Minichmayr <markus@tapkey.com>
Tue, 21 Nov 2023 19:42:12 +0000 (20:42 +0100)
committerMatt Caswell <matt@openssl.org>
Fri, 24 Nov 2023 15:08:04 +0000 (15:08 +0000)
commitb8590b2f365a963965d799c438c5c92659c2fcae
treebc6575840fa2b8b3e6ac4c4fb1bc71832a308368
parent40a24c20a809916b43116c2bb16a36bdc40221f3
Add option `SSL_OP_PREFER_NO_DHE_KEX`, allowing the server to prefer non-dhe psk key exchange over psk with dhe (config file option `PreferNoDHEKEX`, server option `prefer_no_dhe_kex`).

Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Matt Caswell <matt@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/22794)
apps/include/opt.h
include/openssl/ssl.h.in
ssl/ssl_conf.c
ssl/statem/extensions.c
ssl/statem/extensions_srvr.c
test/recipes/70-test_tls13kexmodes.t