@@ -484,17 +484,15 @@ static int apply_peer_verification_policy(SSL *ssl, X509 *peer, php_stream *stre
484484 int err ,
485485 must_verify_peer ,
486486 must_verify_peer_name ,
487- must_verify_fingerprint ,
488- has_cnmatch_ctx_opt ;
487+ must_verify_fingerprint ;
489488
490489 php_openssl_netstream_data_t * sslsock = (php_openssl_netstream_data_t * )stream -> abstract ;
491490
492491 must_verify_peer = GET_VER_OPT ("verify_peer" )
493492 ? zend_is_true (val )
494493 : sslsock -> is_client ;
495494
496- has_cnmatch_ctx_opt = GET_VER_OPT ("CN_match" );
497- must_verify_peer_name = (has_cnmatch_ctx_opt || GET_VER_OPT ("verify_peer_name" ))
495+ must_verify_peer_name = GET_VER_OPT ("verify_peer_name" )
498496 ? zend_is_true (val )
499497 : sslsock -> is_client ;
500498
@@ -549,12 +547,6 @@ static int apply_peer_verification_policy(SSL *ssl, X509 *peer, php_stream *stre
549547 if (must_verify_peer_name ) {
550548 GET_VER_OPT_STRING ("peer_name" , peer_name );
551549
552- if (has_cnmatch_ctx_opt ) {
553- GET_VER_OPT_STRING ("CN_match" , peer_name );
554- php_error (E_DEPRECATED ,
555- "the 'CN_match' SSL context option is deprecated in favor of 'peer_name'"
556- );
557- }
558550 /* If no peer name was specified we use the autodetected url name in client environments */
559551 if (peer_name == NULL && sslsock -> is_client ) {
560552 peer_name = sslsock -> url_name ;
@@ -1429,11 +1421,6 @@ static void enable_client_sni(php_stream *stream, php_openssl_netstream_data_t *
14291421
14301422 GET_VER_OPT_STRING ("peer_name" , sni_server_name );
14311423
1432- if (GET_VER_OPT ("SNI_server_name" )) {
1433- GET_VER_OPT_STRING ("SNI_server_name" , sni_server_name );
1434- php_error (E_DEPRECATED , "SNI_server_name is deprecated in favor of peer_name" );
1435- }
1436-
14371424 if (sni_server_name ) {
14381425 SSL_set_tlsext_host_name (sslsock -> ssl_handle , sni_server_name );
14391426 }
0 commit comments