mirror of
https://github.com/OpenVPN/openvpn3.git
synced 2024-09-20 12:12:15 +02:00
bbae814864
On the server side, we add the abstract base class SNIHandlerBase to provide a hook (sni_hello) where servers can inspect the SNI name given in the client hello message and possibly return a different SSLFactoryAPI. In other changes, we rename the ENABLE_SNI flag to ENABLE_CLIENT_SNI to be clear that this flag only affects the client-side SNI implementation. We also add the NO_VERIFY_HOSTNAME flag on the client side to allow the SNI name to be transmitted to the server without requiring a match between the SNI name and the common name or subject alternative name in the server certificate. Signed-off-by: James Yonan <james@openvpn.net> |
||
---|---|---|
.. | ||
crypto | ||
pki | ||
ssl | ||
util |