If the user has an openssl that supports my "release buffer ram" patch, use it.

svn:r14671
This commit is contained in:
Nick Mathewson
2008-05-19 18:13:00 +00:00
parent e6447a5a29
commit da67500336
2 changed files with 7 additions and 0 deletions
+3
View File
@@ -564,6 +564,9 @@ tor_tls_context_new(crypto_pk_env_t *identity, unsigned int key_lifetime)
SSL_CTX_set_options(result->ctx, SSL_OP_NO_SSLv2);
#endif
SSL_CTX_set_options(result->ctx, SSL_OP_SINGLE_DH_USE);
#ifdef SSL_MODE_RELEASE_BUFFERS
SSL_CTX_set_mode(result->ctx, SSL_MODE_RELEASE_BUFFERS);
#endif
if (cert && !SSL_CTX_use_certificate(result->ctx,cert))
goto error;
X509_free(cert); /* We just added a reference to cert. */