看板FB_security
标 题Re: ports requiring OpenSSL not honouring OpenSSL from ports
发信站NCTU CS FreeBSD Server (Sun Apr 27 16:29:01 2014)
转信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
On Apr 27, 2014, at 8:08 AM, Jamie Landeg-Jones <
[email protected]> wrote:
> Basically what I'm asking: Shouldn't a port that uses OpenSSL *always*
> build against the port if it's installed?
Yes, that is a reasonable expectation. I certainly had it in my head when I rebuilt Sendmail+TLS after heartbleed, but I didn't think of checking it.
> I realise this isn't always possible to test, especially if the port Makefile
> doesn't have any openSSL configuration options, but I'd like to hear
> others opinions on the matter.
It would be good to add such options to as many ports as possible if it can be done cleanly.
Also, note that this is not bashing on OpenSSL: given their new significant funding, I would certainly expect the OpenSSL project to be finding-and-fixing Heartbleed-level bugs repeatedly in the coming years. It is basically impossible to fix such a bug without bad actors being able to determine and exploit some of the fixes in unpatched systems.
--Paul Hoffman
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"