* modules/ssl/ssl_engine_kernel.c (ssl_check_vhost_sni_policy):
Fix handling of STRICT mode.
Reviewed by: jorton, rpluem, covener
git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.4.x@
1929939 13f79535-47bb-0310-9956-
ffa450edef68
return 1;
/* Policy: strict => fail for any vhost transition. */
- if (policy == MODSSL_SNIVH_STRICT && sc1 != sc2)
- return 0;
+ if (policy == MODSSL_SNIVH_STRICT)
+ return sc1 == sc2;
/* For authonly/secure policy, compare the hash. */
AP_DEBUG_ASSERT(sc1->sni_policy_hash);