Is this a theoretical issue, or have you seen it in widespread use? I thought most servers these days picked what they wanted, and used the client ordering as a suggestion, at best.
-- Principal Security Engineer, Akamai Technologies IM: rs...@jabber.me Twitter: RichSalz _______________________________________________ openssl-dev mailing list openssl-dev@openssl.org https://mta.opensslfoundation.net/mailman/listinfo/openssl-dev