Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 19 Feb 2000 13:39:01 -0800 (PST)
From:      Kris Kennaway <kris@FreeBSD.org>
To:        Victor Salaman <salaman@teknos.com>
Cc:        freebsd-current@freebsd.org
Subject:   Re: openssl in -current
Message-ID:  <Pine.BSF.4.21.0002191331560.76238-100000@freefall.freebsd.org>
In-Reply-To: <200002191513.HAA01528@www.geocrawler.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sat, 19 Feb 2000, Victor Salaman wrote:

> I personally think that it's braindead to add openssl to the system
> and stripout parts of it (RSA & IDEA). Don't get me wrong, I love to
> have

So do I. Unfortunately our hands are tied - the version of FreeBSD
distributed in the US must not contain these because they are patented
technologies and not available for unrestricted use. Unfortunately this is
also the same version distributed worldwide on FreeBSD CDs, install
images, etc (although internat.freebsd.org also produces crypto snapshots
which would have the international version of openssl). See chapter 6.5 in
the handbook for an explanation of the problem and the solutions - if
you're inside the US and comply with the rsaref license you can use the
OpenSSL-rsaref package, otherwise you're legally forbidden from using RSA.
There's no known workaround for IDEA, but thankfully not many ports make
use of it anyway.

> Imagine that you are setting up 100 FreeBSD machines, it's not an
> option to do make world from sources and build a "new" non-crippled
> crypto system. You just want to install it and go!

Hopefully at some point in the future sysinstall will have an option at
install-time for pulling in the "correct" version of openssl for your
situation. At present you can still just pkg_add the relevant package
post-install without having to do a make world. See
http://www.freebsd.org/~kris/openssl

Kris

----
"How many roads must a man walk down, before you call him a man?"
"Eight!"
"That was a rhetorical question!"
"Oh..then, seven!" -- Homer Simpson



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-current" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0002191331560.76238-100000>