From: Dr. Stephen Henson Date: Wed, 26 Dec 2012 17:09:39 +0000 (+0000) Subject: Use client version when deciding which cipher suites to disable. X-Git-Tag: OpenSSL_1_0_2-beta1~491 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=53bb723834f523d09cbb05adad4bc5ce3c672d59;p=oweals%2Fopenssl.git Use client version when deciding which cipher suites to disable. (backport from HEAD) --- diff --git a/ssl/t1_lib.c b/ssl/t1_lib.c index 31cce72e0e..984d4bbf7a 100644 --- a/ssl/t1_lib.c +++ b/ssl/t1_lib.c @@ -957,7 +957,7 @@ void ssl_set_client_disabled(SSL *s) c->mask_a = 0; c->mask_k = 0; /* If less than TLS 1.2 don't allow TLS 1.2 only ciphers */ - if (TLS1_get_version(s) < TLS1_2_VERSION) + if (TLS1_get_client_version(s) < TLS1_2_VERSION) c->mask_ssl = SSL_TLSV1_2; else c->mask_ssl = 0;