Matej Habrnal fa1950
From 9c1e3a75c81aa498231e59b1997a2408c580b879 Mon Sep 17 00:00:00 2001
Matej Habrnal fa1950
From: Jakub Filak <jfilak@redhat.com>
Matej Habrnal fa1950
Date: Tue, 4 Feb 2014 13:03:21 +0100
Matej Habrnal fa1950
Subject: [PATCH] retrace-client: stop failing on SSL2
Matej Habrnal fa1950
Matej Habrnal fa1950
Closes rhbz#1200852
Matej Habrnal fa1950
Matej Habrnal fa1950
Signed-off-by: Jakub Filak <jfilak@redhat.com>
Matej Habrnal fa1950
---
Matej Habrnal fa1950
 src/plugins/https-utils.c | 9 +++++----
Matej Habrnal fa1950
 1 file changed, 5 insertions(+), 4 deletions(-)
Matej Habrnal fa1950
Matej Habrnal fa1950
diff --git a/src/plugins/https-utils.c b/src/plugins/https-utils.c
Matej Habrnal fa1950
index cb3c606..7a22729 100644
Matej Habrnal fa1950
--- a/src/plugins/https-utils.c
Matej Habrnal fa1950
+++ b/src/plugins/https-utils.c
Matej Habrnal fa1950
@@ -213,12 +213,13 @@ void ssl_connect(struct https_cfg *cfg, PRFileDesc **tcp_sock, PRFileDesc **ssl_
Matej Habrnal fa1950
         error_msg_and_die(_("Failed to wrap TCP socket by SSL."));
Matej Habrnal fa1950
     if (SECSuccess != SSL_OptionSet(*ssl_sock, SSL_HANDSHAKE_AS_CLIENT, PR_TRUE))
Matej Habrnal fa1950
         error_msg_and_die(_("Failed to enable client handshake to SSL socket."));
Matej Habrnal fa1950
-    if (SECSuccess != SSL_OptionSet(*ssl_sock, SSL_ENABLE_SSL2, PR_TRUE))
Matej Habrnal fa1950
-        error_msg_and_die(_("Failed to enable client handshake to SSL socket."));
Matej Habrnal fa1950
+    // https://bugzilla.redhat.com/show_bug.cgi?id=1189952
Matej Habrnal fa1950
+    //if (SECSuccess != SSL_OptionSet(*ssl_sock, SSL_ENABLE_SSL2, PR_TRUE))
Matej Habrnal fa1950
+    //    error_msg_and_die(_("Failed to enable SSL2."));
Matej Habrnal fa1950
     if (SECSuccess != SSL_OptionSet(*ssl_sock, SSL_ENABLE_SSL3, PR_TRUE))
Matej Habrnal fa1950
-        error_msg_and_die(_("Failed to enable client handshake to SSL socket."));
Matej Habrnal fa1950
+        error_msg_and_die(_("Failed to enable SSL3."));
Matej Habrnal fa1950
     if (SECSuccess != SSL_OptionSet(*ssl_sock, SSL_ENABLE_TLS, PR_TRUE))
Matej Habrnal fa1950
-        error_msg_and_die(_("Failed to enable client handshake to SSL socket."));
Matej Habrnal fa1950
+        error_msg_and_die(_("Failed to enable TLS."));
Matej Habrnal fa1950
     if (SECSuccess != SSL_SetURL(*ssl_sock, cfg->url))
Matej Habrnal fa1950
         error_msg_and_die(_("Failed to set URL to SSL socket."));
Matej Habrnal fa1950
 
Matej Habrnal fa1950
-- 
Matej Habrnal fa1950
2.1.0
Matej Habrnal fa1950