public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
From: Patrick Steinhardt <ps@pks.im>
To: gentoo-dev@lists.gentoo.org
Cc: libressl@gentoo.org
Subject: Re: [gentoo-dev] non conflicting libressl?
Date: Wed, 29 Jan 2020 11:44:01 +0100	[thread overview]
Message-ID: <20200129104401.GA6885@ncase> (raw)
In-Reply-To: <CAHmME9psB6n5U8tuEsM_jAa5LOJd+1ggfjcU0NNsHXCd--mL_w@mail.gmail.com>

[-- Attachment #1: Type: text/plain, Size: 1313 bytes --]

On Wed, Jan 29, 2020 at 10:27:04AM +0100, Jason A. Donenfeld wrote:
> For a long time now, OpenSMTPD stopped supporting OpenSSL, only
> supporting LibreSSL. For that reason Gentoo's opensmtpd ebuild is
> stuck on the 6.0 version. I'm not happy about this.

I've got OpenSMTPD v6.6.2-p1 running on Gentoo with OpenSSL 1.1
without any patches or problems whatsoever. So while upstream
encourages to use LibreSSL, OpenSSL is still supported by
OpenSMTPD. Quoting their CHANGES.md:

    It's preferable to depend on LibreSSL as OpenSMTPD is written
    and tested with that dependency. In addition, the features
    parity is not respected, some features will not be available
    with OpenSSL, like ECDSA server-side certificates support in
    this release. OpenSSL library is considered as a best effort
    target TLS library and provided as a commodity, LibreSSL has
    become our target TLS library.

So as long as you don't require any features implemented with
libressl, only, you should be fine.

> It looks like other distros solve this by allowing libressl to install
> its libraries to /usr/lib/libressl or similar, so that they can
> coexist with openssl, allowing programs like OpenSMTPD.
> 
> Any libressl developers interested in this sort of thing?
> 
> Jason

Patrick

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

      parent reply	other threads:[~2020-01-29 10:43 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-01-29  9:27 [gentoo-dev] non conflicting libressl? Jason A. Donenfeld
2020-01-29 10:34 ` Marcel Schilling
2020-01-29 10:44 ` Patrick Steinhardt [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20200129104401.GA6885@ncase \
    --to=ps@pks.im \
    --cc=gentoo-dev@lists.gentoo.org \
    --cc=libressl@gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox