4 ms·
While OpenSSL is among the building blocks of the Internet, I find NSS to be a higher quality library, mostly because it doesn't break API like OpenSSL does, bu
by plq 4y ago
While OpenSSL is among the building blocks of the Internet, I find NSS to be a higher quality library, mostly because it doesn't break API like OpenSSL does, but also because it's a more complete solution that comes with an OS abstraction layer (thanks to NSPR) a certificate storage component, and lots of other goodies. Not to mention the elephant in the room that is OpenSSL's abysmal track record, but that can change very fast for NSS as well so I don't think it's the biggest factor when comparing the two. At the end of the day, both are well-supported libraries.
The only area where OpenSSL wins hands down vs NSS is documentation, and by extension of its popularity, the easiness of googling a problem and finding its solution. As a comparison, I don't even know what the official NSS homepage is. But IME the source code of NSS is quite readable, so consider having another look at NSS if you need to deal with cryptography in your code.
Not a cryptographer, just a happy user, so YMMV.
- terinjokes 4y ago> I don't even know what the official NSS homepage is. It looks like it's at https://firefox-source-docs.mozilla.org/security/nss/index.html https://firefox-source-docs.mozilla.org/security/nss/index.h..., but it looks like they might want documentation improvement patches. > This NSS documentation was just imported from our legacy MDN repository. It currently is very deprecated and likely incorrect or broken in many places.
- hannob 4y agoI once did a Google Summer of Code project with NSS, and tbh I found the codebase quite hard to work with. It has a lot of what appears to be unnecessary API layers upon API layers that require changes in a lot of places if you want to add something. Also - I don't know if this is still the case, but it was back then - they had bugs in their ASN1 code which they knew about, and workarounds all over the codebase to comply with these underlying bugs. You could really see that this code is old and has a lot of technical debt - after all it is the "original" Netscape SSL implementation. And the API stability comes at the price that you cannot really get rid of all that complexity even if you wanted to.
- plq 4y agoThat's insightful, thanks. I contributed a script for building NSS on windows to vcpkg and even the build system in use (GYP, abandonware at this point) is technical debt in and of itself.
- nine_k 4y agoWhat about LibreSSL in comparison? Has it become different enough?
- ilyt 4y agoI vehemently hate the "storage component" in any SSL implementation when it is not just "file per cert" "Just drop a file in directory" instead of "run a tool that checks whether cert is in store and if it isn't then run import" is so much more automation-friendly.