3 ms·
Because, quite frankly, many FOSS components are not that actively maintained, and all of the alternatives either raise licensing considerations, were not inten
by binarycrusader 11y ago
Because, quite frankly, many FOSS components are not that actively maintained, and all of the alternatives either raise licensing considerations, were not intended for use by general projects, or are not significantly mature yet.
Many projects have also invested heavily into optimizing the performance of OpenSSL itself or the use of its interfaces.
You can't sprinkle "magic SSL dust" over these components and just start using an alternative. In some cases, significant, non-trivial changes would be required to change which library is used.
The reality is, as fast as OpenSSL development is moving now, it remains the better option for a lot of projects because of the significant investments already being made and concerns I mentioned earlier.