3 ms·
I don't have much familiarity with OpenSSL and crypto scares me away from reading the sources. I wish someone could give a full run-down of everything that is
by blitmap 6y ago
I don't have much familiarity with OpenSSL and crypto scares me away from reading the sources. I wish someone could give a full run-down of everything that is in OpenSSL, an overview. You hear all the time about it being bloated and supporting too many things. I wish I better understood that. It's why people turn to wolfssl and mbedtls, right?
Smaller projects that aim for minimalism and robustness probably suffer from a lack of peer review with a more niche community backing them. Trade-offs trade-offs. I also wish I understood where they compete:
OpenSSL <-> WolfSSL <-> mbedtls
- als0 6y ago> It's why people turn to wolfssl and mbedtls, right? I tried to use a single algorithm from OpenSSL for an embedded project and seems like it needs hacking for all the dependencies to be met. I gave up. With mbedTLS it was done within a minute (simpler to build and read IMO). There aren't many differences between mbedTLS and WolfSSL. Both are small libraries designed for embedded use. The latter supports TLS 1.3. Today OpenSSL probably has the best support for hardware acceleration and secure elements.
- blitmap 6y agoI had not considered that it may have support for hardware accelerated crypto.
- oefrha 6y agoThe documentation already has an overview: https://www.openssl.org/docs/manmaster/man7/ https://www.openssl.org/docs/manmaster/man7/
- blitmap 6y agoThat goes a long way, thank you :-) One of the other comments was saying OpenSSL probably has the best support for secure elements (hardware accelerated crypto?).
- stock_toaster 6y agodon't forget BearSSL[1]! [1]: https://bearssl.org https://bearssl.org
- mrweasel 6y agoThere is a fascinating and funny talk by Bob Beck from OpenBSD on the first 30 days after forking OpenSSL. One of the things he addresses is the scary code and how is prevents community involvement. He also talks a great deal about all that stuff that's not really relevant anymore and how much they removed from the LibreSSL source code. Apparently the crypto modules are pretty well made according to the OpenBSD developers. LibreSSL: The first 30 days, and what the Future Holds: https://www.youtube.com/watch?v=oM6S7FEUfkU https://www.youtube.com/watch?v=oM6S7FEUfkU