Comment 8 for bug 1963834

Revision history for this message
Simon Chopin (schopin) wrote :

I'm marking this bug as `Won't Fix` as this new behavior is a deliberate upstream choice that is documented in their migration documentation https://www.openssl.org/docs/manmaster/man7/migration_guide.html

Granted, the documentation in question isn't exactly obvious (search for RFC 5746), but we've showed here that there's a workaround for those who can't convince their server admins to upgrade to a more secure SSL implementation. Thank you all for your work on testing and documenting said workarounds!