3 ms·
I was told OpenSSL 3 was bad for the longest time, I used 1.1x for everything, but switched to Libressl. Now that I need to switch to AWS Linux they are using
by nekoashide 4y ago
I was told OpenSSL 3 was bad for the longest time, I used 1.1x for everything, but switched to Libressl.
Now that I need to switch to AWS Linux they are using OpenSSL 3, my question is should I still be hating on OpenSSL?
- dylan604 4y agowhich AWS Linux are you using that has OpenSSL 3? Linux 2 still has some variant of 1.0.2 which I'm in the middle of dealing with as a recent audit says that's a problem that needs to be at least 1.1.1[someLetter]. even after enabling openssl11 in the amazon-linux-extras, installing it via yum, still remnants of 1.0.2 is popping up. i haven't seen mention of openssl 3 anywhere within the context of Linux 2
- nekoashide 4y agoSorry, should have been more clear, AL 2022 https://docs.aws.amazon.com/linux/al2022/ug/compare-al2-to-AL2022.html#security-updates https://docs.aws.amazon.com/linux/al2022/ug/compare-al2-to-A...
- deleted 4y ago[deleted]
- loeg 4y ago> I was told OpenSSL 3 was bad for the longest time, I used 1.1x for everything, but switched to Libressl. Not sure who told you OpenSSL 3 (2021) was bad. It postdates the period where OpenSSL might not have been the right choice. (Among other things, OpenSSL 3 unifies FIPS and non-FIPS consumers, which is nice if you need FIPS.) > There was a dark period between 2010 and 2016 where OpenSSL might not have been the right answer, but that time has passed. OpenSSL has gotten better, and, more importantly, OpenSSL is on-the-ball with vulnerability disclosure and response. > Using anything besides OpenSSL will drastically complicate your system for little, no, or even negative security benefit. So just keep it simple. https://latacora.micro.blog/2018/04/03/cryptographic-right-answers.html https://latacora.micro.blog/2018/04/03/cryptographic-right-a...
- taskforcegemini 4y agoI think you mean "SSL3" (or "SSLv3"), which is a deprecated protocoll. OpenSSL (3) however is a library that supports many different protocols. This confusion is easy to make and is imho reason enough for a jump to Version 4
- taskforcegemini 4y ago* by this I meant it would make sense if they changed the new version name/number to 4