Re: enforcing tls1.3 no-sni in unbound, or globally

void <[email protected]> Wed, 15 Jul 2026 12:28:36 +0100
Newsgroups gmane.os.openbsd.misc
Message-ID <aldu5BlDeJLaUX3P@int21h>
On Wed, Jul 15, 2026 at 02:03:47AM +0100, void wrote:

>Maybe I need to manually build lynx from the ports.

Seems completely impractical to disable SNI due to tls spec.
tls1.2 is in the client hello part, nowhere else.
At least I know more about how ssl works!! :D thanks everyone
--