Gentoo Archives: gentoo-dev

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] LibreSSL import plan
Date: Wed, 30 Sep 2015 11:32:54
Message-Id: 560BC7A8.1050109@gentoo.org
In Reply to: Re: [gentoo-dev] LibreSSL import plan by hasufell
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA512
3
4 On 09/30/2015 01:27 PM, hasufell wrote:
5 > On 09/30/2015 01:22 PM, Rich Freeman wrote:
6 >> On Wed, Sep 30, 2015 at 2:35 AM, Paweł Hajdan, Jr.
7 >> <phajdan.jr@g.o> wrote:
8 >>> On 9/29/15 3:32 PM, Rich Freeman wrote:
9
10 ..
11
12 >> Perhaps the in-between solution would be for forking upstreams
13 >> to preserve the same symbol names as long as the APIs are
14 >> identical, and change them when they are not. I don't really see
15 >> that having any more impact on downstream consumers than silently
16 >> changing the APIs and it would probably get rid of the symbol
17 >> collision problem.
18 >>
19 >
20 > Again: can you take that to libressl mailing list or start another
21 > thread?
22 >
23
24 The way I see it this is relevant to the discussion at hand. Before
25 implementing any system wide change to support LibreSSL, in order to
26 avoid future issues, a proper cost/benefit analysis and discussion is
27 in order.
28
29 Do we have an overview of what functionality and other pros (hereunder
30 security gains that is not fixed in OpenSSL) is gained by implementing
31 global LibreSSL support?
32
33 Or is this just increasing our maintenance, and security tracking, etc
34 burdens without any strong benefits?
35
36 - --
37 Kristian Fiskerstrand
38 Public PGP key 0xE3EDFAE3 at hkp://pool.sks-keyservers.net
39 fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3
40 -----BEGIN PGP SIGNATURE-----
41
42 iQEcBAEBCgAGBQJWC8eiAAoJECULev7WN52FAFIH/jDZBAvKM7ZjlZt2+MA1tQ7W
43 HzMzqHlD5OwHUkeI58nBLtvgMzptIRvS0AWmmYfPFy3Gt9fCTIh7wcoNN1JJm69l
44 q+WeMQy+ZLMB2YtehoZWRpz6aVXcCXyA0h0ENl4Rt3NP1UX7YWgLJ7ZE2tcBhqQf
45 /GZBKDFjSAw92XJKc8vsiQrG3tl53Ub87bfMoqN0mZ0b0bAJlix5q8x/0mDZ0/4Q
46 fpAg2z0VLD2xQybtPwrNFn2vC19zM9DgqIxpYzxrzilwTMdD0BmcwwqpmLmKsCK6
47 RsBL+utM+gGmBPiYHBmCCim3KudNt91XBBCpKu/VQpGlBjeusqPjRrKwDwfzIeE=
48 =h8Ub
49 -----END PGP SIGNATURE-----

Replies

Subject Author
Re: [gentoo-dev] LibreSSL import plan hasufell <hasufell@g.o>
Re: [gentoo-dev] LibreSSL import plan Rich Freeman <rich0@g.o>