diff options
author | Bodo Moeller <bodo@openssl.org> | 2014-10-21 22:41:27 +0200 |
---|---|---|
committer | Bodo Moeller <bodo@openssl.org> | 2014-10-21 22:41:27 +0200 |
commit | 6a04b0d5a432c7156764529d41aea18dea8010f0 (patch) | |
tree | c40ed3aa05d4785280ea6d4e9e75d9bc5c204808 /ssl/ssl.h | |
parent | 1acca28263f6f16f60c25b97eb82dca61ad5df88 (diff) |
Fix and improve SSL_MODE_SEND_FALLBACK_SCSV documentation.
Reviewed-by: Rich Salz <rsalz@openssl.org>
Diffstat (limited to 'ssl/ssl.h')
-rw-r--r-- | ssl/ssl.h | 9 |
1 files changed, 7 insertions, 2 deletions
@@ -564,8 +564,13 @@ typedef struct ssl_session_st /* Don't attempt to automatically build certificate chain */ #define SSL_MODE_NO_AUTO_CHAIN 0x00000008L /* Send TLS_FALLBACK_SCSV in the ClientHello. - * To be set by applications that reconnect with a downgraded protocol - * version; see draft-ietf-tls-downgrade-scsv-00 for details. */ + * To be set only by applications that reconnect with a downgraded protocol + * version; see draft-ietf-tls-downgrade-scsv-00 for details. + * + * DO NOT ENABLE THIS if your application attempts a normal handshake. + * Only use this in explicit fallback retries, following the guidance + * in draft-ietf-tls-downgrade-scsv-00. + */ #define SSL_MODE_SEND_FALLBACK_SCSV 0x00000080L |