Gentoo Archives: gentoo-dev

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-dev@l.g.o, Ulrich Mueller <ulm@g.o>
Cc: "Michał Górny" <mgorny@g.o>
Subject: Re: [gentoo-dev] [PATCH] use.desc: Correct/clarify SSL/TLS-related flags
Date: Tue, 30 Jan 2018 23:39:42
Message-Id: 2735c531-9977-a604-0438-7d0c16437e97@gentoo.org
In Reply to: Re: [gentoo-dev] [PATCH] use.desc: Correct/clarify SSL/TLS-related flags by Ulrich Mueller
1 On 01/31/2018 12:22 AM, Ulrich Mueller wrote:
2 >> gnome-keyring - Enable support for storing passwords via gnome-keyring
3 >> gnuplot - Enable support for gnuplot (data and function plotting)
4 >> -gnutls - Add support for net-libs/gnutls (TLS 1.0 and SSL 3.0 support)
5 >> +gnutls - Prefer net-libs/gnutls as SSL/TLS provider (requires USE=ssl if present)
6 > NACK. This seems to imply that USE="-ssl gnutls" is not a valid
7 > configuration? What if the user prefers gnutls and therefore has
8 > globally enabled the gnutls flag, but -ssl for a single package?
9 >
10 > How about "(needs USE=ssl to take effect)" instead?
11 >
12
13 as I understand it ssl is intended as a generic use flag, of which
14 gnutls can be one of the providers. In the case of of app-crypt/gnupg
15 there are only two possible providers, gnutls, and ntbtls, of which only
16 one is available in tree, so gnutls is the only one, so the only one
17 relevant for Gentoo is gnutls, hence no use flag for it, either TLS is
18 enabled, or it is not.
19
20 in this scenario I don't see why "ssl -gnutls" would not be a valid
21 configuration as long as ssl is a generic use flag as it is presented to
22 be. It doesn't mean never install gnutls, but just not preferring it in
23 cases where there are other providers of ssl/tls, that the global
24 description already indicate.
25
26 --
27 Kristian Fiskerstrand
28 OpenPGP keyblock reachable at hkp://pool.sks-keyservers.net
29 fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3

Attachments

File name MIME type
signature.asc application/pgp-signature