# HG changeset patch # User Matthew Wild # Date 1363811512 0 # Node ID 18ebc38743648596b67efa445590a2f50ed85fc1 # Parent 8c3f28f5c1c1541028a5fa4cf41515309d6cb6c2 net.http: Disable SSLv2 support for HTTPS connections diff -r 8c3f28f5c1c1 -r 18ebc3874364 net/http.lua --- a/net/http.lua Wed Mar 20 20:31:02 2013 +0000 +++ b/net/http.lua Wed Mar 20 20:31:52 2013 +0000 @@ -190,7 +190,7 @@ local sslctx = false; if using_https then - sslctx = ex and ex.sslctx or { mode = "client", protocol = "sslv23" }; + sslctx = ex and ex.sslctx or { mode = "client", protocol = "sslv23", options = { "no_sslv2" } }; end req.handler, req.conn = server.wrapclient(conn, req.host, port, listener, "*a", sslctx);