From c5931ad56fc4b9351f10c9eafdb65a7f1c3b267b Mon Sep 17 00:00:00 2001 From: Simone Bordet Date: Fri, 5 Apr 2013 01:26:22 +0200 Subject: [PATCH] 404610 - Reintroduce ability to disallow TLS renegotiation. After review with Greg, avoid to clear the encrypted buffer after detection of reconnection denied. --- .../src/main/java/org/eclipse/jetty/io/ssl/SslConnection.java | 1 - 1 file changed, 1 deletion(-) diff --git a/jetty-io/src/main/java/org/eclipse/jetty/io/ssl/SslConnection.java b/jetty-io/src/main/java/org/eclipse/jetty/io/ssl/SslConnection.java index 301970d681c..4fca18f3f1b 100644 --- a/jetty-io/src/main/java/org/eclipse/jetty/io/ssl/SslConnection.java +++ b/jetty-io/src/main/java/org/eclipse/jetty/io/ssl/SslConnection.java @@ -759,7 +759,6 @@ public class SslConnection extends AbstractConnection if (DEBUG) LOG.debug("{} renegotiation denied", SslConnection.this); shutdownOutput(); - BufferUtil.clear(_encryptedOutput); return allConsumed; }