> IIRC the behaviour is different in the forthcoming OpenSSL 1.1.0. In > that version the client does not fix its version to the session version. > The client remains version flexible - if the server does not wish to use > the same version as was in the session then they can still negotiate a > different one and the session simply does not get used. Thanks Matt, for that detailed and helpful reply. Is it at all possible to merge these changes being done in OpenSSL 1.1.0 to older version of OpenSSL (as we build and ship our own version of OpenSSL)? Or is the nature of changes very complex in nature? Thanks, Prabhat <https://mta.openssl.org/mailman/listinfo/openssl-users> -------------- next part -------------- An HTML attachment was scrubbed... URL: <http://mta.openssl.org/pipermail/openssl-users/attachments/20160801/8843827d/attachment-0001.html>