OpenSSL v0.9.8.k Release Notes

Release Date: 2009-11-05 // over 14 years ago
    • Disable renegotiation completely - this fixes a severe security problem [CVE-2009-3555][] at the cost of breaking all renegotiation. Renegotiation can be re-enabled by setting SSL3_FLAGS_ALLOW_UNSAFE_LEGACY_RENEGOTIATION in s3->flags at run-time. This is really not recommended unless you know what you're doing.

    Ben Laurie