]> git.ipfire.org Git - thirdparty/openssl.git/commit - CHANGES.md
Stop disabling TLSv1.3 if ec and dh are disabled
authorMatt Caswell <matt@openssl.org>
Thu, 14 Jan 2021 15:50:20 +0000 (15:50 +0000)
committerMatt Caswell <matt@openssl.org>
Fri, 5 Feb 2021 15:22:40 +0000 (15:22 +0000)
commita763ca11777ce01a286751f3f3dd9b106ef74f30
tree7ad54dd22661b8373f57ffefdee897b6282dc225
parent8b1db5d329740bd5363fd1763d4030d0e015b521
Stop disabling TLSv1.3 if ec and dh are disabled

Even if EC and DH are disabled then we may still be able to use TLSv1.3
if we have groups that have been plugged in by an external provider.

Fixes #13767

Reviewed-by: Tomas Mraz <tomas@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/13916)
31 files changed:
CHANGES.md
Configure
test/helpers/ssltestlib.c
test/recipes/70-test_comp.t
test/recipes/70-test_key_share.t
test/recipes/70-test_sslcbcpadding.t
test/recipes/70-test_sslextension.t
test/recipes/70-test_sslrecords.t
test/recipes/70-test_sslsigalgs.t
test/recipes/70-test_sslsignature.t
test/recipes/70-test_sslversions.t
test/recipes/70-test_tls13alerts.t
test/recipes/70-test_tls13cookie.t
test/recipes/70-test_tls13downgrade.t
test/recipes/70-test_tls13hrr.t
test/recipes/70-test_tls13kexmodes.t
test/recipes/70-test_tls13psk.t
test/recipes/70-test_tlsextms.t
test/recipes/80-test_ssl_new.t
test/recipes/80-test_ssl_old.t
test/recipes/90-test_tls13ccs.t
test/recipes/90-test_tls13encryption.t
test/recipes/90-test_tls13secrets.t
test/recordlentest.c
test/servername_test.c
test/ssl-tests/04-client_auth.cnf.in
test/ssl-tests/27-ticket-appdata.cnf.in
test/ssl-tests/protocol_version.pm
test/ssl_old_test.c
test/ssl_test.c
test/sslapitest.c