imap-send: avoid deprecated TLSv1_method()
Use SSLv23_method always and disable SSL if needed. TLSv1_method() function is deprecated in OpenSSL 1.1.0 and the compiler emits a warning. SSLv23_method() is also deprecated, but the alternative, TLS_method(), is new in OpenSSL 1.1.0 so requires checking by configure. Stick to SSLv23_method() for now (this is aliased to TLS_method()). Signed-off-by: Kazuki Yamaguchi <k@rhe.jp> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Kazuki Yamaguchi committed
Apr 9, 2016 at 01:22 UTC
b51c0d4b4c70b3d2ddac1657b98b17e77af1c404
1 file changed
+4
-5
imap-send.c
+4
-5
@@ -287,11 +287,7 @@ static int ssl_socket_connect(struct imap_socket *sock, int use_tls_only, int ve
287
SSL_library_init();
288
SSL_load_error_strings();
289
290
- if (use_tls_only)
291
- meth = TLSv1_method();
292
- else
293
- meth = SSLv23_method();
294
-
290
+ meth = SSLv23_method();
291
if (!meth) {
292
ssl_socket_perror("SSLv23_method");
293
return -1;
@@ -303,6 +299,9 @@ static int ssl_socket_connect(struct imap_socket *sock, int use_tls_only, int ve
299
return -1;
300
}
301
302
+ if (use_tls_only)
303
+ SSL_CTX_set_options(ctx, SSL_OP_NO_SSLv2 | SSL_OP_NO_SSLv3);
304
+
305
if (verify)
306
SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL);
307