[prev in list] [next in list] [prev in thread] [next in thread] 

List:       openssl-dev
Subject:    Re: SSL_clear code
From:       Lutz Jaenicke <Lutz.Jaenicke () aet ! TU-Cottbus ! DE>
Date:       2002-02-27 11:28:50
[Download RAW message or body]

On Wed, Feb 27, 2002 at 12:16:13PM +0200, Yoram Zahavi wrote:
> Hi Lutz,
> I've just checked your last patch. I guess additional fix is required. 
> setting :
> s->shutdown=0;
> 
> should be done only after calling:
> if (ssl_clear_bad_session(s))
> 		{
> 		SSL_SESSION_free(s->session);
> 		s->session=NULL;
> 		}
> 
> Otherwise, the SSL_SENT_SHUTDOWN flag is not taken into account when
> checking out if session should be removed from cache.

Seems you are right again. Moved the bad-session-removal to the top...
	Lutz
-- 
Lutz Jaenicke                             Lutz.Jaenicke@aet.TU-Cottbus.DE
http://www.aet.TU-Cottbus.DE/personen/jaenicke/
BTU Cottbus, Allgemeine Elektrotechnik
Universitaetsplatz 3-4, D-03044 Cottbus
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       openssl-dev@openssl.org
Automated List Manager                           majordomo@openssl.org
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic