diff options
author | Joel Sing <jsing@cvs.openbsd.org> | 2015-10-21 16:44:29 +0000 |
---|---|---|
committer | Joel Sing <jsing@cvs.openbsd.org> | 2015-10-21 16:44:29 +0000 |
commit | 4bb9547a002e989124ed06dd9020d62d9c2c649b (patch) | |
tree | c2abd226495470124443db79b40fcb7ac66d6350 /usr.sbin/smtpd/iobuf.h | |
parent | e406b8d2b07fd632185dfda31ba70efbfe6766ee (diff) |
Only enable SSL_VERIFY_PEER when the verify option is set on a listener.
Always enabling SSL_VERIFY_PEER unnecessarily increases the number of
messages/bytes in the TLS handshake and increases our attack surface,
since we request and then process client certificates.
ok gilles@
Diffstat (limited to 'usr.sbin/smtpd/iobuf.h')
0 files changed, 0 insertions, 0 deletions