Re: embedding openssl source in sslcan

2017-01-05 Thread Moritz Mühlenhoff
On Thu, Jan 05, 2017 at 09:39:16PM +0100, Sebastian Andrzej Siewior wrote: > On 2016-12-31 17:35:47 [+0100], Julien Cristau wrote: > > Is this really something we need to be shipping? If yes, I'd personally > > really like this to get an explicit exemption from normal policy by the > > security te

Re: embedding openssl source in sslcan

2017-01-05 Thread Sebastian Andrzej Siewior
On 2016-12-31 17:35:47 [+0100], Julien Cristau wrote: > Is this really something we need to be shipping? If yes, I'd personally > really like this to get an explicit exemption from normal policy by the > security team, so please talk to them (debian-security@ldo is not it). I have been made aware

Re: embedding openssl source in sslcan

2017-01-02 Thread Christian Seiler
Hi, Am 2. Januar 2017 11:35:30 MEZ, schrieb Thijs Kinkhorst : >On Fri, December 23, 2016 18:53, Moritz Mühlenhoff wrote: >> Sebastian Andrzej Siewior schrieb: >> >> Please use t...@security.debian.org if you want to reach the security >> team, not debian-security@ldo. >> >>> tl;dr: Has anyone a

Re: embedding openssl source in sslcan

2017-01-02 Thread Thijs Kinkhorst
On Fri, December 23, 2016 18:53, Moritz Mühlenhoff wrote: > Sebastian Andrzej Siewior schrieb: > > Please use t...@security.debian.org if you want to reach the security > team, not debian-security@ldo. > >> tl;dr: Has anyone a problem if sslscan embeds openssl 1.0.2 in its >> source? > > That's f

Re: [Pkg-openssl-devel] embedding openssl source in sslcan

2017-01-01 Thread Kurt Roeckx
On Sun, Jan 01, 2017 at 04:37:48PM +0100, Raphael Hertzog wrote: > On Sat, 31 Dec 2016, Julien Cristau wrote: > > On Thu, Dec 22, 2016 at 13:37:11 +0100, Sebastian Andrzej Siewior wrote: > > > > > tl;dr: Has anyone a problem if sslscan embeds openssl 1.0.2 in its > > > source? > > > > > > sslscan

Re: embedding openssl source in sslcan

2017-01-01 Thread Raphael Hertzog
On Sat, 31 Dec 2016, Julien Cristau wrote: > On Thu, Dec 22, 2016 at 13:37:11 +0100, Sebastian Andrzej Siewior wrote: > > > tl;dr: Has anyone a problem if sslscan embeds openssl 1.0.2 in its > > source? > > > > sslscan [0] as packaged in Debian currently relies on external libssl as > > provided

Re: embedding openssl source in sslcan

2016-12-31 Thread Julien Cristau
On Thu, Dec 22, 2016 at 13:37:11 +0100, Sebastian Andrzej Siewior wrote: > tl;dr: Has anyone a problem if sslscan embeds openssl 1.0.2 in its > source? > > sslscan [0] as packaged in Debian currently relies on external libssl as > provided by the openssl package. The openssl package disables supp

Re: embedding openssl source in sslcan

2016-12-24 Thread Jonathan Yu
Given that this would be useful for other tools, perhaps it's best to create an "openssl-insecure" package which would ship a version of openssl that has all the bells-and-whistles enabled (including the insecure ones). We would have to take care that nothing is unintentionally linked to the librar

embedding openssl source in sslcan

2016-12-22 Thread Sebastian Andrzej Siewior
tl;dr: Has anyone a problem if sslscan embeds openssl 1.0.2 in its source? sslscan [0] as packaged in Debian currently relies on external libssl as provided by the openssl package. The openssl package disables support compression, SSLv2 and SSLv3 which is good but it also means that sslscan can no