On Fri, Oct 24, 2014 at 7:15 AM, mclellan, dave <dave.mclel...@emc.com> wrote:
> I have also had this same experience (1.0.1i)  with SSLv3 being negotiated
> though I used the SSL_OP_NO_SSLv3 flag on the SSL_set_options call. (I have
> NOT re-built with SSLv3 disabled).
>
If that's the case, then a security related defect should be filed at
https://www.openssl.org/support/rt.html.

I have to qualify it with "if that's the case" because I use those
same options, and I have not observed the behavior.
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           majord...@openssl.org

Reply via email to