we may keep combo.
both #ifdef EVP_PKEY_TLS1_PRF and comment related to supported openssl
versions (to drop support if we decide)

вт, 9 мар. 2021 г. в 17:56, Gert Doering <g...@greenie.muc.de>:

> Hi,
>
> On Tue, Mar 09, 2021 at 05:52:12PM +0500, ???????? ?????????????? wrote:
> > > On Tue, Mar 09, 2021 at 04:54:13PM +0500, ???????? ??????????????
> wrote:
> > > > if nobody minds, I can send several patches that eliminates
> comparison of
> > > > OPENSSL_VERSION, for example
> > >
> > > We do mind.  They are coded this way on purpose - so when we drop
> support
> > > for OpenSSL before 1.1.0, it is clear from the code which sections can
> >
> > it is not much fun to catch things like
> >
> https://boringssl.googlesource.com/boringssl/+/49e9f67d8b7cbeb3953b5548ad1009d15947a523%5E%21/include/openssl/base.h
> >
> > (BoringSSL claims itself as 1.1.0, accidentally decided "I'm 1.1.1 now")
>
> We do not support BoringSSL.
>
> (Or any other SSL library that claims "I am compatible with OpenSSL 1.1.1"
> but isn't, really - which is why the LibreSSL adjustments are always very
> minimal)
>
> We sort-of-support LibreSSL because it is the system SSL library on
> OpenBSD.  Otherwise, the answer would be the same as for BoringSSL.
>
> gert
> --
> "If was one thing all people took for granted, was conviction that if you
>  feed honest figures into a computer, honest figures come out. Never
> doubted
>  it myself till I met a computer with a sense of humor."
>                              Robert A. Heinlein, The Moon is a Harsh
> Mistress
>
> Gert Doering - Munich, Germany
> g...@greenie.muc.de
>
_______________________________________________
Openvpn-devel mailing list
Openvpn-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-devel

Reply via email to