On Tue, Feb 02, 2016 at 08:15:03PM +0000, Tim Small wrote: > It would seem that the best fix would be to pull this upstream code > into an upcoming Jessie point release, because as this gives the least > surprising / least broken behaviour, and is in-line the the behaviour of > most (all?) modern SSL/TLS implementations.
This is one of those changes that I've been trying to get into the stable point release for a long time now. Kurt

