SHA-2 ciphersuites now require TLS 1.x
diff --git a/include/polarssl/ssl.h b/include/polarssl/ssl.h
index bd7f1f7..bbc1f68 100644
--- a/include/polarssl/ssl.h
+++ b/include/polarssl/ssl.h
@@ -560,8 +560,8 @@
 
 #if defined(POLARSSL_SSL_PROTO_SSL3)
     /* Needed only for SSL v3.0 secret */
-    unsigned char mac_enc[48];          /*!<  SSL v3.0 secret (enc)   */
-    unsigned char mac_dec[48];          /*!<  SSL v3.0 secret (dec)   */
+    unsigned char mac_enc[20];          /*!<  SSL v3.0 secret (enc)   */
+    unsigned char mac_dec[20];          /*!<  SSL v3.0 secret (dec)   */
 #endif /* POLARSSL_SSL_PROTO_SSL3 */
 
     md_context_t md_ctx_enc;            /*!<  MAC (encryption)        */