Francesco Poli wrote:
> Let's leave things as they are, until OpenSSL v3.0.0 gets released and
> included in Debian unstable and testing.
>
> Please see [933252#10] for further details.
>
> [933252#10]: <https://bugs.debian.org/933252#10>

>> https://salsa.debian.org/frx-guest/apt-listbugs/-/blob/master/FAQ.md#how-can-i-use-apt-listbugs-with-apt-cacherapt-cacher-ng-proxies
>> Since Acquire::https::Proxy is ignored, I guess I have to do this.  Blech.
>
> Probably you have, for the time being.
> I admit that having to add one more configuration line sucks a bit,
> but... please bear with apt-listbugs, which currently knows nothing
> about SSL!
>
> Have you tried this workaround?
> I hope it can solve your unattended-upgrade issues.

Yes, I have deployed the workaround from FAQ.md.
I think it works;
I have to wait a week or two to see if it is truly works.

On that basis, I agree it is reasonable to ignore this issue until OpenSSL 3.x 
lands.

On that basis, I also won't bother digging into "could libruby2.7 use 
libgnutls30/libnss3/libmbedtls12/libwolfssl24 instead of libssl1.1?"

>>    5. I found this bug where people are bikeshedding the moral hazards
>>       of condoning SSL.
>>       I get annoyed.
>
> I think that potential licensing incompatibilities are serious issues
> that really have to be taken into account. I don't consider paying
> attention to them as "bikeshedding".

I have also fought OpenSSL exemptions from hundreds of authors (some dead); you 
have my deepest sympathy.
I agree that is not bikeshedding.

I was referring to the people saying (paraphrasing) "if we use SSL then an evil 
CA might break Debian!"

Reply via email to