)]}'
{
  "commit": "3fbc298104c150ed18f10eed2d2e66633f05ee98",
  "tree": "c1d8161d2b3346ab0b98e506615d7f7c14d58218",
  "parents": [
    "54e455157a6e1899eb6fef9440d2410cb7fedeff"
  ],
  "author": {
    "name": "Adam Langley",
    "email": "agl@google.com",
    "time": "Thu Feb 26 11:07:37 2015 -0800"
  },
  "committer": {
    "name": "Adam Langley",
    "email": "agl@google.com",
    "time": "Thu Feb 26 21:35:29 2015 +0000"
  },
  "message": "Only allow ephemeral RSA keys in export ciphersuites.\n\nOpenSSL clients would tolerate temporary RSA keys in non-export ciphersuites.\nIt also had an option SSL_OP_EPHEMERAL_RSA which enabled this server side.\nRemove both options as they are a protocol violation.\n\nThanks to Karthikeyan Bhargavan for reporting this issue. (CVE-2015-0204)\n\n(This is a backport of upstream\u0027s\n37580f43b5a39f5f4e920d17273fab9713d3a744 to the M40 branch. In BoringSSL\nmaster we fixed this with\nhttps://boringssl.googlesource.com/boringssl/+/525a0fe315282ca1840f8f9f170c8a26ce5fab2a,\nbut that\u0027s a larger patch than we really want to be backporting.)\n\nChange-Id: Ibfb0c46648bbecffb9d3b1a4ebdf10a5a79523b3\nReviewed-on: https://boringssl-review.googlesource.com/3640\nReviewed-by: David Benjamin \u003cdavidben@chromium.org\u003e\nReviewed-by: Adam Langley \u003cagl@google.com\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "64bccfaa3df46576ad5cc58dcd465d9ce93ddd20",
      "old_mode": 33188,
      "old_path": "ssl/s3_clnt.c",
      "new_id": "0c37f76101911fd6819db256812433ff6fb5661a",
      "new_mode": 33188,
      "new_path": "ssl/s3_clnt.c"
    }
  ]
}
