If a protected connection is requested, don't claim to drop down to "no
protection".
Reported in Joshua's sarif data
Closes #18712
infof(data, "SOCKS5 server supports GSS-API %s data protection.",
(gss_enc == 0) ? "no" :
((gss_enc == 1) ? "integrity" : "confidentiality"));
- /* force for the moment to no data protection */
- gss_enc = 0;
+
/*
* Sending the encryption type in clear seems wrong. It should be
* protected with gss_seal()/gss_wrap(). See RFC1961 extract below