Add CHANGES entry for OPENSSL_NO_TLSEXT removal
authorMatt Caswell <matt@openssl.org>
Fri, 15 May 2015 09:55:10 +0000 (10:55 +0100)
committerMatt Caswell <matt@openssl.org>
Fri, 22 May 2015 22:11:22 +0000 (23:11 +0100)
Reviewed-by: Rich Salz <rsalz@openssl.org>
Reviewed-by: Richard Levitte <levitte@openssl.org>
CHANGES
makevms.com
ssl/ssl_cert.c

diff --git a/CHANGES b/CHANGES
index 397ff2c..e1e0721 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -3,6 +3,11 @@
  _______________
 
  Changes between 1.0.2 and 1.1.0  [xx XXX xxxx]
+  *) Given the pervasive nature of TLS extensions it is inadvisable to run
+     OpenSSL without support for them. It also means that maintaining
+     the OPENSSL_NO_TLSEXT option within the code is very invasive (and probably
+     not well tested). Therefore the OPENSSL_NO_TLSEXT option has been removed.
+     [Matt Caswell]
 
   *) Version negotiation has been rewritten. In particular SSLv23_method(),
      SSLv23_client_method() and SSLv23_server_method() have been deprecated,
index 37efdc8..c1c3060 100755 (executable)
@@ -304,7 +304,6 @@ $ CONFIG_LOGICALS := AES,-
                     STATIC_ENGINE,-
                     STDIO,-
                     STORE,-
-                    TLSEXT,-
                     UNIT_TEST,-
                     WHIRLPOOL
 $ CONFIG_EXPERIMENTAL := JPAKE,-
@@ -332,11 +331,9 @@ $ CONFIG_DISABLE_RULES := RIJNDAEL/AES;-
                          SHA/SSL3,TLS1;-
                          RSA,DSA/SSL3,TLS1;-
                          DH/SSL3,TLS1;-
-                         TLS1/TLSEXT;-
                          EC/GOST;-
                          DSA/GOST;-
                          DH/GOST;-
-                         TLSEXT/SRP,HEARTBEAT;-
                          /STATIC_ENGINE;-
                          /DEPRECATED;-
                          /EC_NISTP_64_GCC_128;-
index ab138ec..6b39e25 100644 (file)
@@ -265,7 +265,6 @@ CERT *ssl_cert_dup(CERT *cert)
                 goto err;
             }
         }
-        rpk->valid_flags = 0;
         if (cert->pkeys[i].serverinfo != NULL) {
             /* Just copy everything. */
             ret->pkeys[i].serverinfo =