|
Matej Habrnal |
fa1950 |
From 9c1e3a75c81aa498231e59b1997a2408c580b879 Mon Sep 17 00:00:00 2001
|
|
Matej Habrnal |
fa1950 |
From: Jakub Filak <jfilak@redhat.com>
|
|
Matej Habrnal |
fa1950 |
Date: Tue, 4 Feb 2014 13:03:21 +0100
|
|
Matej Habrnal |
fa1950 |
Subject: [PATCH] retrace-client: stop failing on SSL2
|
|
Matej Habrnal |
fa1950 |
|
|
Matej Habrnal |
fa1950 |
Closes rhbz#1200852
|
|
Matej Habrnal |
fa1950 |
|
|
Matej Habrnal |
fa1950 |
Signed-off-by: Jakub Filak <jfilak@redhat.com>
|
|
Matej Habrnal |
fa1950 |
---
|
|
Matej Habrnal |
fa1950 |
src/plugins/https-utils.c | 9 +++++----
|
|
Matej Habrnal |
fa1950 |
1 file changed, 5 insertions(+), 4 deletions(-)
|
|
Matej Habrnal |
fa1950 |
|
|
Matej Habrnal |
fa1950 |
diff --git a/src/plugins/https-utils.c b/src/plugins/https-utils.c
|
|
Matej Habrnal |
fa1950 |
index cb3c606..7a22729 100644
|
|
Matej Habrnal |
fa1950 |
--- a/src/plugins/https-utils.c
|
|
Matej Habrnal |
fa1950 |
+++ b/src/plugins/https-utils.c
|
|
Matej Habrnal |
fa1950 |
@@ -213,12 +213,13 @@ void ssl_connect(struct https_cfg *cfg, PRFileDesc **tcp_sock, PRFileDesc **ssl_
|
|
Matej Habrnal |
fa1950 |
error_msg_and_die(_("Failed to wrap TCP socket by SSL."));
|
|
Matej Habrnal |
fa1950 |
if (SECSuccess != SSL_OptionSet(*ssl_sock, SSL_HANDSHAKE_AS_CLIENT, PR_TRUE))
|
|
Matej Habrnal |
fa1950 |
error_msg_and_die(_("Failed to enable client handshake to SSL socket."));
|
|
Matej Habrnal |
fa1950 |
- if (SECSuccess != SSL_OptionSet(*ssl_sock, SSL_ENABLE_SSL2, PR_TRUE))
|
|
Matej Habrnal |
fa1950 |
- error_msg_and_die(_("Failed to enable client handshake to SSL socket."));
|
|
Matej Habrnal |
fa1950 |
+ // https://bugzilla.redhat.com/show_bug.cgi?id=1189952
|
|
Matej Habrnal |
fa1950 |
+ //if (SECSuccess != SSL_OptionSet(*ssl_sock, SSL_ENABLE_SSL2, PR_TRUE))
|
|
Matej Habrnal |
fa1950 |
+ // error_msg_and_die(_("Failed to enable SSL2."));
|
|
Matej Habrnal |
fa1950 |
if (SECSuccess != SSL_OptionSet(*ssl_sock, SSL_ENABLE_SSL3, PR_TRUE))
|
|
Matej Habrnal |
fa1950 |
- error_msg_and_die(_("Failed to enable client handshake to SSL socket."));
|
|
Matej Habrnal |
fa1950 |
+ error_msg_and_die(_("Failed to enable SSL3."));
|
|
Matej Habrnal |
fa1950 |
if (SECSuccess != SSL_OptionSet(*ssl_sock, SSL_ENABLE_TLS, PR_TRUE))
|
|
Matej Habrnal |
fa1950 |
- error_msg_and_die(_("Failed to enable client handshake to SSL socket."));
|
|
Matej Habrnal |
fa1950 |
+ error_msg_and_die(_("Failed to enable TLS."));
|
|
Matej Habrnal |
fa1950 |
if (SECSuccess != SSL_SetURL(*ssl_sock, cfg->url))
|
|
Matej Habrnal |
fa1950 |
error_msg_and_die(_("Failed to set URL to SSL socket."));
|
|
Matej Habrnal |
fa1950 |
|
|
Matej Habrnal |
fa1950 |
--
|
|
Matej Habrnal |
fa1950 |
2.1.0
|
|
Matej Habrnal |
fa1950 |
|