[PATCH] ALPN validation fix

Hal Murray hmurray at megapathdsl.net
Sun Dec 8 14:15:17 UTC 2019


> Why only TLS 1.3? The spec makes it mandatory for all versions.

Because ALPN is not supported by TLSv1.2 and there are many distros that are 
still using old versions of OpenSSL that don't support TLSv1.3  It seemed 
better to support old systems rather then be hard-nosed about a corner of the 
spec.

It's getting much better.  OpenSSL is dropping support for 1.0.2 at the end of 
the year.  That may kick a few more distros into action.

-- 
These are my opinions.  I hate spam.





More information about the devel mailing list