Francesco Poli wrote: > Let's leave things as they are, until OpenSSL v3.0.0 gets released and > included in Debian unstable and testing. > > Please see [933252#10] for further details. > > [933252#10]: <https://bugs.debian.org/933252#10>
>> https://salsa.debian.org/frx-guest/apt-listbugs/-/blob/master/FAQ.md#how-can-i-use-apt-listbugs-with-apt-cacherapt-cacher-ng-proxies >> Since Acquire::https::Proxy is ignored, I guess I have to do this. Blech. > > Probably you have, for the time being. > I admit that having to add one more configuration line sucks a bit, > but... please bear with apt-listbugs, which currently knows nothing > about SSL! > > Have you tried this workaround? > I hope it can solve your unattended-upgrade issues. Yes, I have deployed the workaround from FAQ.md. I think it works; I have to wait a week or two to see if it is truly works. On that basis, I agree it is reasonable to ignore this issue until OpenSSL 3.x lands. On that basis, I also won't bother digging into "could libruby2.7 use libgnutls30/libnss3/libmbedtls12/libwolfssl24 instead of libssl1.1?" >> 5. I found this bug where people are bikeshedding the moral hazards >> of condoning SSL. >> I get annoyed. > > I think that potential licensing incompatibilities are serious issues > that really have to be taken into account. I don't consider paying > attention to them as "bikeshedding". I have also fought OpenSSL exemptions from hundreds of authors (some dead); you have my deepest sympathy. I agree that is not bikeshedding. I was referring to the people saying (paraphrasing) "if we use SSL then an evil CA might break Debian!"

