The -no_legacy_server_connect option applies to client
authorTomas Mraz <tomas@openssl.org>
Thu, 12 May 2022 09:53:27 +0000 (11:53 +0200)
committerTomas Mraz <tomas@openssl.org>
Fri, 27 May 2022 06:47:31 +0000 (08:47 +0200)
Reviewed-by: Paul Dale <pauli@openssl.org>
Reviewed-by: Ben Kaduk <kaduk@mit.edu>
(Merged from https://github.com/openssl/openssl/pull/18296)

doc/man1/openssl-s_client.pod.in
doc/man1/openssl-s_server.pod.in
ssl/ssl_conf.c

index 0d38d46d257670e948f02c0c75d325d60eb62bf4..6e380cb1475d112d278cf681d04742c17bb1dd46 100644 (file)
@@ -87,6 +87,7 @@ B<openssl> B<s_client>
 [B<-no_comp>]
 [B<-brief>]
 [B<-legacy_server_connect>]
+[B<-no_legacy_server_connect>]
 [B<-allow_no_dhe_kex>]
 [B<-sigalgs> I<sigalglist>]
 [B<-curves> I<curvelist>]
index f0f78670ec4699e64c63e1bb3aeb0e8f6b4e5bbc..06c2c6d67a8d1790f13cdd1ede7aaccaa448a16b 100644 (file)
@@ -99,7 +99,6 @@ B<openssl> B<s_server>
 [B<-legacy_renegotiation>]
 [B<-no_renegotiation>]
 [B<-no_resumption_on_reneg>]
-[B<-no_legacy_server_connect>]
 [B<-allow_no_dhe_kex>]
 [B<-prioritize_chacha>]
 [B<-strict>]
index 767faf2452a6d1f2b95822d0e78787b3c2e70158..b83f9fe3a904c63d9ce8e1059e04a5de81d5f658 100644 (file)
@@ -702,7 +702,7 @@ static const ssl_conf_cmd_tbl ssl_conf_cmds[] = {
     SSL_CONF_CMD_SWITCH("legacy_server_connect", SSL_CONF_FLAG_CLIENT),
     SSL_CONF_CMD_SWITCH("no_renegotiation", 0),
     SSL_CONF_CMD_SWITCH("no_resumption_on_reneg", SSL_CONF_FLAG_SERVER),
-    SSL_CONF_CMD_SWITCH("no_legacy_server_connect", SSL_CONF_FLAG_SERVER),
+    SSL_CONF_CMD_SWITCH("no_legacy_server_connect", SSL_CONF_FLAG_CLIENT),
     SSL_CONF_CMD_SWITCH("allow_no_dhe_kex", 0),
     SSL_CONF_CMD_SWITCH("prioritize_chacha", SSL_CONF_FLAG_SERVER),
     SSL_CONF_CMD_SWITCH("strict", 0),