Gentoo Archives: gentoo-dev

From: m1027 <m1027@××××××.net>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [RFC] Discontinuing LibreSSL support?
Date: Mon, 28 Dec 2020 22:26:58
Message-Id: X+pbq0yDaKhbokhz@host
In Reply to: Re: [gentoo-dev] [RFC] Discontinuing LibreSSL support? by Peter Stuge
1 I've been kindly asked by a gentoo dev to send my two pence in here:
2
3 peter:
4
5 > Michał Górny wrote:
6 >
7 > > LibreSSL users, does LibreSSL today have any benefit over OpenSSL?
8 >
9 > Yes, at least two:
10 >
11 > [...]
12 >
13 > B. It brings its own TLS API, a unique feature which by itself warrants
14 > the package.
15
16 Yeah, since openssl and libressl cannot be installed at the same
17 time, I wonder what will be the future of libtls? To recall, it is
18 a "a new TLS library, designed to make it easier to write foolproof
19 applications" (see libressl.org). I've been using it for some time.
20 It's great, and it is part of libressl.
21
22 Another thing: Besides libressl there are boringssl and others. Even
23 if still not the case (?), having virtual alternatives should in
24 theory help keeping polished interfaces. If for whatever reason this
25 not the case in practise, I believe dropping the alternatives should
26 be worse.
27
28 I cannot judge on the work the maintainers have to deal with
29 compatibility issues between libressl and openssl, though. Let me
30 know when I can help.

Replies

Subject Author
Re: [gentoo-dev] [RFC] Discontinuing LibreSSL support? "Michał Górny" <mgorny@g.o>