mirror of
https://github.com/curl/curl.git
synced 2026-04-14 22:21:41 +03:00
socks_gssapi: remove the forced "no protection"
If a protected connection is requested, don't claim to drop down to "no protection". Reported in Joshua's sarif data Closes #18712
This commit is contained in:
parent
aaa39873ea
commit
98dae1d992
1 changed files with 1 additions and 2 deletions
|
|
@ -359,8 +359,7 @@ CURLcode Curl_SOCKS5_gssapi_negotiate(struct Curl_cfilter *cf,
|
|||
infof(data, "SOCKS5 server supports GSS-API %s data protection.",
|
||||
(gss_enc == 0) ? "no" :
|
||||
((gss_enc == 1) ? "integrity" : "confidentiality"));
|
||||
/* force for the moment to no data protection */
|
||||
gss_enc = 0;
|
||||
|
||||
/*
|
||||
* Sending the encryption type in clear seems wrong. It should be
|
||||
* protected with gss_seal()/gss_wrap(). See RFC1961 extract below
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue