|
@@ -564,6 +564,11 @@ tor_tls_context_new(crypto_pk_env_t *identity, unsigned int key_lifetime)
|
|
|
SSL_CTX_set_options(result->ctx, SSL_OP_NO_SSLv2);
|
|
|
#endif
|
|
|
SSL_CTX_set_options(result->ctx, SSL_OP_SINGLE_DH_USE);
|
|
|
+
|
|
|
+#ifdef SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION
|
|
|
+ SSL_CTX_set_options(result->ctx,
|
|
|
+ SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION);
|
|
|
+#endif
|
|
|
/* Don't actually allow compression; it uses ram and time, but the data
|
|
|
* we transmit is all encrypted anyway. */
|
|
|
if (result->ctx->comp_methods)
|