5 ms·
Relevant fixes have been commited to OpenBSD https://marc.info/?l=openbsd-cvs&m=142677386615089&w=2 https://marc.info/?l=openbsd-cvs&m=142677386615089&w=2 htt
by Nusyne 12y ago
Relevant fixes have been commited to OpenBSD
https://marc.info/?l=openbsd-cvs&m=142677386615089&w=2 https://marc.info/?l=openbsd-cvs&m=142677386615089&w=2
https://marc.info/?l=openbsd-cvs&m=142677382215078&w=2 https://marc.info/?l=openbsd-cvs&m=142677382215078&w=2
https://marc.info/?l=openbsd-cvs&m=142677372515025&w=2 https://marc.info/?l=openbsd-cvs&m=142677372515025&w=2
https://marc.info/?l=openbsd-cvs&m=142677368815015&w=2 https://marc.info/?l=openbsd-cvs&m=142677368815015&w=2
- clarry 12y agoSo 4 out of 14 needed fixing in -current, while the rest were either already fixed or not relevant to libressl. It would be interesting to know who fixed the ones that were fixed already, and when.
- deleted 12y ago[deleted]
- vog 12y agoI guess that most of these were "fixed" by simply throwing away lots of garbage code from OpenSSL during the evolution of LibreSSL.
- oskarth 12y agoThere are no quotation marks about it; it still counts.
- InclinedPlane 12y agoDon't undersell that man, priority zero in security is reducing the threat surface.
- vog 12y agoYou may be interested in the experience report of Ted Unangst about fixing security issues in OpenBSD: http://www.tedunangst.com/flak/post/making-security-sausage http://www.tedunangst.com/flak/post/making-security-sausage
- zdw 12y agoOf the 14 CVE reports, only 7 applied to LibreSSL. None of the "High" severity applied: http://marc.info/?l=openbsd-tech&m=142677518515567&w=2 http://marc.info/?l=openbsd-tech&m=142677518515567&w=2 By severity, 4 of 9 of the "Moderate", and 1 of 3 "Low" were already fixed in LibreSSL, by my quick count.
- InclinedPlane 12y agoIs there an update anywhere about how close libressl is to "prime time"?
- peatmoss 12y agoWell, it's in OpenBSD, so now?
- marios 12y agoLibreSSL is ready for prime time. It is the default SSL library on OpenBSD since version 5.6 [1], which was released on November, 1st 2014. Since then, more cleanup went in, and they developed libtls which is a new TLS API. The latter is also included in several OpenBSD projects (OpenSMTPD, relayd, httpd). The goal of libtls is to provide a sane API to develop new applications needing TLS. The problem with OpenSSL's API is that it exposes too much, and it's extremely easy to shoot yourself in the foot. If you want to know more regarding LibreSSL, I recommend reading these: http://www.openbsd.org/papers/bsdcan14-libressl/ http://www.openbsd.org/papers/bsdcan14-libressl/ http://www.openbsd.org/papers/eurobsdcon2014-libressl.html http://www.openbsd.org/papers/eurobsdcon2014-libressl.html Despite what the URL suggests, these are not papers but presentations at BSD related conferences. You might be able to find recordings of them on YouTube. [1] http://www.openbsd.org/56.html http://www.openbsd.org/56.html
- throwaway5752 12y agoSo, I am pretty proficient in these things, but I don't consider myself competent to declare it ready by code audit. I like the Google support, and I like the OpenBSD adoption. But since I am not running OpenBSD, I'd really like to see it make it into my distro's upstream by some community process. Endless ink and bits have gone into talking about 'cruft' in code that provokes big refactorings, when the what was considered cruft ends up being quite meaningful to correct and/or stability. To summarize - I'm with the gp post, I'm not convinced it's ready for primetime, either: it's stepping into giant shoes and has a very short track record.
- masklinn 12y agoAnd an important note from http://undeadly.org/cgi?action=article&sid=20150319145126 http://undeadly.org/cgi?action=article&sid=20150319145126 > The OpenSSL project provided information and patches to the LibreSSL project in advance of the announcements.