• Tom Lane's avatar
    Remove duplicate setting of SSL_OP_SINGLE_DH_USE option. · f352f91c
    Tom Lane authored
    Commit c0a15e07 moved the setting of OpenSSL's SSL_OP_SINGLE_DH_USE option
    into a new subroutine initialize_dh(), but forgot to remove it from where
    it was.  SSL_CTX_set_options() is a trivial function, amounting indeed to
    just "ctx->options |= op", hence there's no reason to contort the code or
    break separation of concerns to avoid calling it twice.  So separating the
    DH setup from disabling of old protocol versions is a good change, but we
    need to finish the job.
    
    Noted while poking into the question of SSL session tickets.
    f352f91c
be-secure-openssl.c 32 KB