From faf83d7824358f545049cc030c8e77f661ce892d Mon Sep 17 00:00:00 2001 From: Kentaro Hayashi Date: Mon, 1 Jun 2026 17:24:35 +0900 Subject: [PATCH] fix: drop misleading SSL_set1_host for OpenSSL 4.0.0 It will fix the following warning: In member function 'int SecureSocket::secureConnect(int)': /build/deskflow.work/src/lib/net/SecureSocket.cpp:479:16: warning: 'int SSL_set1_host(SSL*, const char*)' is deprecated: Since OpenSSL 4.0 [ -Wdeprecated-declarations] 479 | SSL_set1_host(m_ssl->m_ssl, name.c_str()); | ~~~~~~~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~~~~ In file included from /build/deskflow.work/src/lib/net/SslLogger.h:8, from /build/deskflow.work/src/lib/net/SecureSocket.cpp:20: /usr/include/openssl/ssl.h:1922:34: note: declared here 1922 | OSSL_DEPRECATEDIN_4_0 __owur int SSL_set1_host(SSL *s, const char *host); | ^~~~~~~~~~~~~ NOTE: It seems that SSL_set1_host setup params for hostname verification, but it will not be used correctly afterward (See SSL_CTX_set_cert_verify_callback in SecureSocket::initContext). This implicit behavior cause misleading and harmful. Signed-off-by: Kentaro Hayashi --- src/lib/net/SecureSocket.cpp | 3 --- 1 file changed, 3 deletions(-) diff --git a/src/lib/net/SecureSocket.cpp b/src/lib/net/SecureSocket.cpp index 365f46b67..fff7d2364 100644 --- a/src/lib/net/SecureSocket.cpp +++ b/src/lib/net/SecureSocket.cpp @@ -474,9 +474,6 @@ int SecureSocket::secureConnect(int socket) LOG_VERBOSE("connecting secure socket"); - // enable hostname verification. - const auto name = Settings::value(Settings::Core::ComputerName).toString().toStdString(); - SSL_set1_host(m_ssl->m_ssl, name.c_str()); int r = SSL_connect(m_ssl->m_ssl); static int retry;