+ <p>Remove compiler warnings. "log_error(LOG_LEVEL_FATAL, ..." doesn't return but apparently the compiler
+ doesn't know that. Get rid of several "this statement may fall through [-Wimplicit-fallthrough=]"
+ warnings.</p>
+ </li>
+ <li>
+ <p>If the the response is chunk-encoded, ignore the Content-Length header sent by the server. Allows to
+ load https://redmine.lighttpd.net/ with filtering enabled.</p>
+ </li>
+ <li>
+ <p>Store the PEM certificate in a dynamically allocated buffer when https-inspecting. Should prevent errors
+ like: 2021-03-16 22:36:19.148 7f47bbfff700 Error: X509 PEM cert len 16694 is larger than buffer len 16383
+ As a bonus it should slightly reduce the memory usage as most certificates are smaller than the previously
+ used fixed buffer. Reported by: Wen Yue</p>
+ </li>
+ <li>
+ <p>Don't log the applied actions in process_encrypted_request() Log them in continue_https_chat() instead
+ to mirror chat(). Prevents the applied actions from getting logged twice for the first request on an
+ https-inspected connection.</p>
+ </li>
+ <li>
+ <p>OpenSSL generate_host_certificate(): Use config.privoxy.org as Common Name Org and Org Unit if the real
+ host name is too long to get accepted by OpenSSL. Clients should only care about the Subject Alternative
+ Name anyway and we can continue to use the real host name for it. Reported by Miles Wen on
+ privoxy-users@.</p>
+ </li>
+ <li>
+ <p>OpenSSL generate_host_certificate(): Fix two error messsages.</p>
+ </li>
+ <li>
+ <p>Improve description of handle_established_connection()</p>
+ </li>
+ <li>
+ <p>OpenSSL ssl_store_cert(): Translate EVP_PKEY_EC to a string.</p>
+ </li>
+ <li>
+ <p>OpenSSL ssl_store_cert(): Remove pointless variable initialization.</p>
+ </li>
+ <li>
+ <p>OpenSSL ssl_store_cert(): Initialize pointer with NULL instead of 0.</p>