Index: lib/cpp/src/thrift/transport/TSSLSocket.cpp
--- lib/cpp/src/thrift/transport/TSSLSocket.cpp.orig
+++ lib/cpp/src/thrift/transport/TSSLSocket.cpp
@@ -157,18 +157,6 @@ void cleanupOpenSSL() {
 #endif
   EVP_cleanup();
   CRYPTO_cleanup_all_ex_data();
-#if OPENSSL_VERSION_NUMBER >= 0x10100000
-  // Do nothing unless an openssl derivative is detected
-#  if !defined(OPENSSL_IS_BORINGSSL) && !defined(OPENSSL_IS_AWSLC)
-  // https://www.openssl.org/docs/man1.1.1/man3/OPENSSL_thread_stop.html
-  OPENSSL_thread_stop();
-#  endif
-#else
-  // ERR_remove_state() was deprecated in OpenSSL 1.0.0 and ERR_remove_thread_state()
-  // was deprecated in OpenSSL 1.1.0; these functions and should not be used.
-  // https://www.openssl.org/docs/manmaster/man3/ERR_remove_state.html
-  ERR_remove_state(0);
-#endif
   ERR_free_strings();
 
   mutexes.reset();
@@ -405,18 +393,6 @@ void TSSLSocket::close() {
     SSL_free(ssl_);
     ssl_ = nullptr;
     handshakeCompleted_ = false;
-#if OPENSSL_VERSION_NUMBER >= 0x10100000
-    // Do nothing unless an openssl derivative is detected
-#  if !defined(OPENSSL_IS_BORINGSSL) && !defined(OPENSSL_IS_AWSLC)
-    // https://www.openssl.org/docs/man1.1.1/man3/OPENSSL_thread_stop.html
-    OPENSSL_thread_stop();
-#  endif
-#else
-    // ERR_remove_state() was deprecated in OpenSSL 1.0.0 and ERR_remove_thread_state()
-    // was deprecated in OpenSSL 1.1.0; these functions and should not be used.
-    // https://www.openssl.org/docs/manmaster/man3/ERR_remove_state.html
-    ERR_remove_state(0);
-#endif
   }
   TSocket::close();
 }
@@ -770,7 +746,7 @@ void TSSLSocket::authorize() {
       if (name == nullptr) {
         continue;
       }
-      char* data = (char*)ASN1_STRING_data(name->d.ia5);
+      const char* data = (const char*)ASN1_STRING_get0_data(name->d.ia5);
       int length = ASN1_STRING_length(name->d.ia5);
       switch (name->type) {
       case GEN_DNS:
