[openssl-dev] [openssl.org #3711] [RFC PATCH] 1.0.2 regresssion: Wrong SSL version in DTLS_BAD_VER ClientHello

Matt Caswell via RT rt at openssl.org
Thu May 7 14:59:31 UTC 2015


Closing this ticket now. I've given some consideration to the proposal for a
DTLSv0_9_client_method(). I think however that the audience for this is *very*
limited...certainly no new applications should be using this. I am sincerely
hoping that sooner or later the whole DTLS1_BAD_VER thing will disappear and it
can be removed from the code completely. Given that we have a mechanism for
supporting this through SSL_OP_CISCO_ANYCONNECT, I'm not convinced its a good
thing to add a new API to support this dying version.

Matt



More information about the openssl-dev mailing list