From 7cedd8bed2948e60816d9bea4e6384d62d5aefd3 Mon Sep 17 00:00:00 2001 From: Hanno Becker Date: Mon, 22 Jul 2019 11:04:16 +0100 Subject: [PATCH] Remove overly strict guard in ssl_server2 get_auth_mode() is needed for a change of authmode through SNI, which is possible even if the original authmode is hardcoded. --- programs/ssl/ssl_server2.c | 2 -- 1 file changed, 2 deletions(-) diff --git a/programs/ssl/ssl_server2.c b/programs/ssl/ssl_server2.c index cb62b528c..bc97149ef 100644 --- a/programs/ssl/ssl_server2.c +++ b/programs/ssl/ssl_server2.c @@ -791,7 +791,6 @@ static int send_cb( void *ctx, unsigned char const *buf, size_t len ) return( mbedtls_net_send( io_ctx->net, buf, len ) ); } -#if !defined(MBEDTLS_SSL_CONF_AUTHMODE) /* * Return authmode from string, or -1 on error */ @@ -806,7 +805,6 @@ static int get_auth_mode( const char *s ) return( -1 ); } -#endif /* !MBEDTLS_SSL_CONF_AUTHMODE */ /* * Used by sni_parse and psk_parse to handle coma-separated lists