From b6622f9623de09a08596d1ee1127e1c5b02ec84e Mon Sep 17 00:00:00 2001 From: =?utf8?q?Bodo=20M=C3=B6ller?= Date: Thu, 26 Nov 2009 17:25:38 +0000 Subject: [PATCH] Remove obsolete information about a change for 0.9.7n. (No further releases from the 0.9.7 branch are planned. Note that the "deleted" change is also in 0.9.8f.) --- CHANGES | 13 ------------- 1 file changed, 13 deletions(-) diff --git a/CHANGES b/CHANGES index c45b286f4a..fe9473080b 100644 --- a/CHANGES +++ b/CHANGES @@ -1599,19 +1599,6 @@ differing sizes. [Richard Levitte] - Changes between 0.9.7m and 0.9.7n [xx XXX xxxx] - - *) In the SSL/TLS server implementation, be strict about session ID - context matching (which matters if an application uses a single - external cache for different purposes). Previously, - out-of-context reuse was forbidden only if SSL_VERIFY_PEER was - set. This did ensure strict client verification, but meant that, - with applications using a single external cache for quite - different requirements, clients could circumvent ciphersuite - restrictions for a given session ID context by starting a session - in a different context. - [Bodo Moeller] - Changes between 0.9.7l and 0.9.7m [23 Feb 2007] *) Cleanse PEM buffers before freeing them since they may contain -- 2.25.1