Tomáš Mráz
Tomáš Mráz
@tmshort please reconfirm
I do not think this will cherry-pick cleanly to 3.0 branch.
It removes the protocol version support, not necessarily any cipher suites. I.E., you will not be able to use TLS version 1.0 or 1.1.
There is a `-cert_chain` option that should be used for the certificate chain. I am not sure why your use-case worked with 1.0.2 though.
The SSL_CTX_set1_chain() sets stack of X509 certs as the chain for the server.
No, SSL_CTX_set1_chain sets the chain in sk to the SSL_CTX ctx.
I am afraid this is potentially asking for security issues. It would have to be implemented very carefully.
CI is relevant
I'd suggest reporting this to nmap. It looks like a nmap bug. There are no providers in OpenSSL 1.1.1.