Index: net/ssl/ssl_config_service.cc |
diff --git a/net/ssl/ssl_config_service.cc b/net/ssl/ssl_config_service.cc |
index 0561e7ffa34a7bd5b5fa26632de219c6aa04b17b..604d7f02f5a1640e762c31b04d6553c7ad6793b0 100644 |
--- a/net/ssl/ssl_config_service.cc |
+++ b/net/ssl/ssl_config_service.cc |
@@ -20,9 +20,9 @@ static uint16 g_default_version_min = SSL_PROTOCOL_VERSION_SSL3; |
static uint16 g_default_version_max = |
#if defined(USE_OPENSSL) |
-#if defined(SSL_OP_NO_TLSv1_2) |
- SSL_PROTOCOL_VERSION_TLS1_2; |
-#elif defined(SSL_OP_NO_TLSv1_1) |
+// TODO(wtc): do not enable TLS 1.2 until we can keep ClientHello under 256 |
+// bytes. See http://crbug.com/245500 and http://crbug.com/247691. |
+#if defined(SSL_OP_NO_TLSv1_1) |
SSL_PROTOCOL_VERSION_TLS1_1; |
#else |
SSL_PROTOCOL_VERSION_TLS1; |