From: Kazuki Yamaguchi Date: Fri, 8 Apr 2016 16:22:15 +0000 (+0900) Subject: imap-send: avoid deprecated TLSv1_method() X-Git-Tag: v2.8.3~25^2~1 X-Git-Url: http://git.osdn.net/view?a=commitdiff_plain;h=b51c0d4b4c70b3d2ddac1657b98b17e77af1c404;p=git-core%2Fgit.git imap-send: avoid deprecated TLSv1_method() Use SSLv23_method always and disable SSL if needed. TLSv1_method() function is deprecated in OpenSSL 1.1.0 and the compiler emits a warning. SSLv23_method() is also deprecated, but the alternative, TLS_method(), is new in OpenSSL 1.1.0 so requires checking by configure. Stick to SSLv23_method() for now (this is aliased to TLS_method()). Signed-off-by: Kazuki Yamaguchi Signed-off-by: Junio C Hamano --- diff --git a/imap-send.c b/imap-send.c index e964e2a7f..78b6ff649 100644 --- a/imap-send.c +++ b/imap-send.c @@ -287,11 +287,7 @@ static int ssl_socket_connect(struct imap_socket *sock, int use_tls_only, int ve SSL_library_init(); SSL_load_error_strings(); - if (use_tls_only) - meth = TLSv1_method(); - else - meth = SSLv23_method(); - + meth = SSLv23_method(); if (!meth) { ssl_socket_perror("SSLv23_method"); return -1; @@ -303,6 +299,9 @@ static int ssl_socket_connect(struct imap_socket *sock, int use_tls_only, int ve return -1; } + if (use_tls_only) + SSL_CTX_set_options(ctx, SSL_OP_NO_SSLv2 | SSL_OP_NO_SSLv3); + if (verify) SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL);