httpd icon indicating copy to clipboard operation
httpd copied to clipboard

improve proxy alpn check

Open icing opened this issue 4 years ago • 0 comments

r1890696 r1890693

*) mod_ssl: tighten the handling of ALPN for outgoing (proxy) connections. If ALPN protocols are provided and sent to the remote server, the received protocol selected is inspected and checked for a match. Without match, the peer handshake fails. An exception is the proposal of "http/1.1" where it is accepted if the remote server did not answer ALPN with a selected protocol. This accomodates for hosts that do not observe/support ALPN and speak http/1.x be default.

icing avatar Jul 06 '21 12:07 icing