4 ms·
HTTPS is a really huge scope to tackle, and requires a lot of policy which OpenSSL traditionally hasn't encoded (how to root trust, for example — possibly invol
by Tobu 6y ago
HTTPS is a really huge scope to tackle, and requires a lot of policy which OpenSSL traditionally hasn't encoded (how to root trust, for example — possibly involving system stores or custom ones, stapling, pinning…). Also, OpenSSL generally is embedded in HTTP clients, and having distinct implementations of HTTP calling into each other from the same library seems terrible, with potential for security issues related to policy or implementation mismatches.
Of course, there's all the traditional bug surface of any code that talks to the network to consider as well.
Defining an interface for calling back into another HTTP library might be doable, but there's still a question of scope creep.
The motivation seems to be this fork and pull request:
- https://github.com/mpeylo/cmpossl https://github.com/mpeylo/cmpossl
- https://github.com/openssl/openssl/issues/5926 https://github.com/openssl/openssl/issues/5926
The use case is far away from what most users of OpenSSL need, and could quite easily be tackled outside OpenSSL.