From: Dr. Stephen Henson Date: Sat, 11 Jul 2015 00:17:36 +0000 (+0100) Subject: Don't request certificates for any PSK ciphersuite X-Git-Tag: OpenSSL_1_1_0-pre1~877 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=a3f7ff2b2d1b1267cdf0bbce2374ebe149ed264a;p=oweals%2Fopenssl.git Don't request certificates for any PSK ciphersuite Reviewed-by: Matt Caswell --- diff --git a/ssl/s3_srvr.c b/ssl/s3_srvr.c index caf45d1afb..72deedc0c5 100644 --- a/ssl/s3_srvr.c +++ b/ssl/s3_srvr.c @@ -503,7 +503,7 @@ int ssl3_accept(SSL *s) * With normal PSK Certificates and Certificate Requests * are omitted */ - || (s->s3->tmp.new_cipher->algorithm_mkey & SSL_kPSK)) { + || (s->s3->tmp.new_cipher->algorithm_mkey & SSL_PSK)) { /* no cert request */ skip = 1; s->s3->tmp.cert_request = 0;