9b4b062 Use OPENSSL_NO_HEARTBEATS for better wpa_supplicant interoperability
Google linked to this bug report... [1] This is almost identical to an issue we found with openssl 1.0.1b and Juniper
SBR version v6.13.4949. In our case we traced it to the heartbeat extension.
When the extension is sent in the ClientHello PEAP negotiation fails with fatal bad
certificate alert. By adding # define OPENSSL_NO_HEARTBEATS to opensslconf.h we
disabled the extension and PEAP negotiation is successful.
Similar dumb luck in Node.js disabling heartbeats because advertising it in the ClientHello apparently causes IIS issues [2] # Heartbeat is a TLS extension, that couldn't be turned off or
# asked to be not advertised. Unfortunately this is unacceptable for
# Microsoft's IIS, which seems to be ignoring whole ClientHello after
# seeing this extension.
'OPENSSL_NO_HEARTBEATS',
[1] - http://rt.openssl.org/Ticket/Display.html?id=2825&user=guest...[2] - https://github.com/joyent/node/blob/master/deps/openssl/open...