From ad76fc8ee191ac27c7614f9a37b6a8c1cc615aca Mon Sep 17 00:00:00 2001 From: jsing <> Date: Wed, 11 Jun 2014 15:44:10 +0000 Subject: Stop setting the EVP_MD_CTX_FLAG_NON_FIPS_ALLOW - it has been ignored since OpenSSL 1.0.0. ok miod@ (a little while back) --- src/lib/libssl/s3_clnt.c | 2 -- 1 file changed, 2 deletions(-) (limited to 'src/lib/libssl/s3_clnt.c') diff --git a/src/lib/libssl/s3_clnt.c b/src/lib/libssl/s3_clnt.c index 45dfb64f92..e86d58c671 100644 --- a/src/lib/libssl/s3_clnt.c +++ b/src/lib/libssl/s3_clnt.c @@ -1603,8 +1603,6 @@ ssl3_get_key_exchange(SSL *s) j = 0; q = md_buf; for (num = 2; num > 0; num--) { - EVP_MD_CTX_set_flags(&md_ctx, - EVP_MD_CTX_FLAG_NON_FIPS_ALLOW); EVP_DigestInit_ex(&md_ctx, (num == 2) ? s->ctx->md5 : s->ctx->sha1, NULL); -- cgit v1.2.3-55-g6feb