LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 09-15-2015, 12:21 AM   #1
l0rddarkf0rce
Member
 
Registered: Nov 2004
Location: Virginia, US
Distribution: Slackware 14.1 multilib
Posts: 149

Rep: Reputation: 33
OpenSSL vs LibreSSL


Will LibreSSL ever replace OpenSSL in Slackware? Any opinions appreciated.
 
Old 09-15-2015, 05:37 AM   #2
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS,Manjaro
Posts: 5,631

Rep: Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696Reputation: 2696
Hmmm.

You are asking the wrong crowd. There is, in fact, only one man that could answer that.
And he is not talking.
 
1 members found this post helpful.
Old 09-15-2015, 06:01 AM   #3
drmozes
Slackware Contributor
 
Registered: Apr 2008
Distribution: Slackware
Posts: 1,543

Rep: Reputation: 1312Reputation: 1312Reputation: 1312Reputation: 1312Reputation: 1312Reputation: 1312Reputation: 1312Reputation: 1312Reputation: 1312Reputation: 1312
Quote:
Originally Posted by l0rddarkf0rce View Post
Will LibreSSL ever replace OpenSSL in Slackware? Any opinions appreciated.
Why would we need to?
OpenSSL now has funding available for full time developers to address gaps, and there are new developers working (almost) full time on it to help address issues with the software, and also provide guidance regarding new features and how to implement them securely.
Akamai (my employer) has full time engineers now working on OpenSSL which is why I know.

Last edited by drmozes; 09-15-2015 at 06:11 AM.
 
1 members found this post helpful.
Old 09-15-2015, 02:27 PM   #4
metaschima
Senior Member
 
Registered: Dec 2013
Distribution: Slackware
Posts: 1,982

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
I switched back to openssl, because it's too much of a hassle to keep libressl up-to-date and working. I think it would be better than openssl. No, I don't trust the openssl devs at all. They have been ignoring critical bugs for years, and I don't think money is going to solve that.
 
1 members found this post helpful.
Old 09-16-2015, 06:26 AM   #5
GazL
LQ Veteran
 
Registered: May 2008
Posts: 6,897

Rep: Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019Reputation: 5019
I think the OpenBSD guys realise that there's only so far one can go trying to "fix" libssl. And, that's why as well as doing the libressl cleanup of libssl, they're also writing a new libtls library, with the intention of doing things properly from the start.

IMO 'libtls' is the more interesting part of the libressl project, though I'm sure some will try and dismiss it as just NIH syndrome. Whether it gains traction outside of OpenBSD will be interesting to see.
 
Old 09-16-2015, 08:22 PM   #6
gargamel
Senior Member
 
Registered: May 2003
Distribution: Slackware, OpenSuSE
Posts: 1,839

Rep: Reputation: 242Reputation: 242Reputation: 242
Another alternative to OpenSSL would be PolarSSL. Some months ago I read an article in a German Linux magazine (sorry, I don't recall, which one, ATM) comparing various OpenSSL alternatives, and PolarSSL scored high, as it shines with maturity, and clean and lean code.

The article started with a good sketch of how and why things went so awfully wrong with OpenSSL. While money alone won't solve the issues, it is a pre-requisite. You cannot respond to bug reports when you don't have resources. The author saw some changes in the way the project works now compared to the past, and was optimistic that OpenSSL is on the right track now. From a user perspective, OpenSSL is the choice that causes the least hassle. All the alternatives either lack features or suffer from an incompatible API, which can break applications relying on the OpenSSL.

LibreSSL was also considered a good choice, but a few months back the project was quite new. It will take time to mature and shares the advantage of incompatible API with PolarSSL and the others.

I don't remember the other contenders, anymore, but none of them would compete with PolarSSL or LibreSSL.
If I find the article I'll provide a reference, or a link, if it's available on the web.

gargamel
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: LibreSSL crypto library leaps from OpenBSD to Linux, OS X, more LXer Syndicated Linux News 3 07-13-2014 02:22 PM
LXer: OpenSSL code beyond repair, claims creator of “LibreSSL” fork LXer Syndicated Linux News 1 04-23-2014 11:43 AM
openssl: any simple examples no how to use openssl to do some decryption? eantoranz Programming 7 07-26-2012 07:57 PM
install of openssl-0.9.8b-8.3.el5 conflicts with file from package openssl-0.9.8b-8.3 jsaravana87 Linux - Server 1 09-26-2011 01:02 PM
oops openssl-0.9.8e over openssl-0.9.8d bad install now 2 copies? rcorkum Slackware 4 06-29-2007 01:58 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 01:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration