Re: embedding openssl source in sslcan

2016-12-24 Thread Jonathan Yu
Given that this would be useful for other tools, perhaps it's best to create an "openssl-insecure" package which would ship a version of openssl that has all the bells-and-whistles enabled (including the insecure ones). We would have to take care that nothing is unintentionally linked to the librar

Re: embedding openssl source in sslcan

2016-12-24 Thread Moritz Mühlenhoff
Sebastian Andrzej Siewior schrieb: Please use t...@security.debian.org if you want to reach the security team, not debian-security@ldo. > tl;dr: Has anyone a problem if sslscan embeds openssl 1.0.2 in its > source? That's for post-stretch, right? Right now it can simply link against the 1.0.2 c