Replace OPENSSL_NO_TLS_PHA with SSL_VERIFY_POST_HANDSHAKE #1668
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Notes
PR #1526 introduced the
OPENSSL_NO_TLS_PHA
directive mostly for the purposes of AWS-LC's compatibility with CPython, but in cpython PR #117785 @encukou points out that detecting the absence of OpenSSL's ownSSL_VERIFY_POST_HANDSHAKE
directive is sufficient. This change removes AWS-LC'sOPENSSL_NO_TLS_PHA
directive in favor of detecting absence ofSSL_VERIFY_POST_HANDSHAKE
.Testing
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license and the ISC license.