Mark renego-established sessions not resumable.

We do not call the new_session callback on renego, but a consumer using
SSL_get_session may still attempt to resume such a session. Leave the
not_resumable flag unset. Also document this renegotiation restriction.

This is a cherry-pick of https://boringssl-review.googlesource.com/19664
from BoringSSL, in preparation for cherry-picking
https://boringssl-review.googlesource.com/19665.

Exempt-From-Owner-Approval: flooey is on vacation 
Merged-In: I615af59fe8af4c56e6cf83a364c0fd69be70c415
Merged-In: I41df37881b9c2228b9a7b3569f1532f3b0dcbaea
Bug: 64827202
Change-Id: Ic81acb033d8166a6bd00edcbfa06157af12f98aa
4 files changed