RE: I cannot upgrade openssl-stablr



Dirk Meyer a écrit:

OPENSSL_OVERWRITE_BASE=yes
sould be used with extreme caution!

This might break your base application in cases like this, when the base
uses a diffrent api as the ports does.


That's totally true.

I was wondering if, to avoid ports problem with openssl (and maybe some over
libs/important parts) - because somes refers directly to the openssl base,
others to the ports one -, we might try to find a way to have openssl - in
future release - in the base system being like a pre-installed port.

It will be very hopeful too when security issues are discovered, because
instead of patching the system base (and rebuilding the world...) we have
only to do a portupgrade... Saving times :)
An other interest in doing this, is that the system will be reported
unsecure by portaudit...

OpenSSH should have the same treatment :)

--
Clément Moulin
SimpleRezo

_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: broken openssl on freebsd60
    ... Russell E. Meek schrieb: ... >> I would suppose that any port, which requires openssl, would take it ... > ports look to for build information. ... So I was forced to install the ...
    (freebsd-questions)
  • Re: adding opentsa to the systems openssl
    ... > The current version in ports is 0.9.7f. ... > with freebsd patches to openssl, so I should just grab the stock openssl ... > stuff to use the independently built openssl. ...
    (freebsd-stable)
  • Re: openoffice-2 & openssl-beta-0.9.8a
    ... > Installing openssl-beta from ports at first doesn't hurt. ... > of portupgrading next time it starts to be a pain, ... > openssl-beta instead of openssl from the base system. ...
    (freebsd-questions)
  • Re: openoffice-2 & openssl-beta-0.9.8a
    ... >> Installing openssl-beta from ports at first doesn't hurt. ... >> openssl-beta instead of openssl from the base system. ... Building OOo-2 ...
    (freebsd-questions)
  • Re: openssl/openssh from ports or base?
    ... >What is the preferred method that people are using for keeping openssl and ... Are most people using the ports version? ... Just curious what other freebsd users are doing. ... When using the GENERIC kernel you can get the updated kernel ...
    (freebsd-questions)