Check for the enforcing and fail handshake if the peer doesn't support
diff --git a/library/ssl_tls.c b/library/ssl_tls.c
index ca9131a..27e55d9 100644
--- a/library/ssl_tls.c
+++ b/library/ssl_tls.c
@@ -8343,7 +8343,7 @@
 }
 
 void mbedtls_ssl_conf_extended_master_secret_enforce( mbedtls_ssl_config *conf,
-                                                        char ems_enf );
+                                                        char ems_enf )
 {
     conf->enforce_extended_master_secret = ems_enf;
 }