Overview

Request 87436 superseded

- Build with -DSSL_FORBID_ENULL so servers are not
able to use the NULL encryption ciphers (Those offering no
encryption whatsoever). (forwarded request 87144 from elvigia)

Loading...
Request History
Dirk Mueller's avatar

dirkmueller created request

- Build with -DSSL_FORBID_ENULL so servers are not
able to use the NULL encryption ciphers (Those offering no
encryption whatsoever). (forwarded request 87144 from elvigia)


Stephan Kulow's avatar

coolo added a reviewer

Please review sources


Ludwig Nussel's avatar

lnussel added a reviewer

questionable change


Ludwig Nussel's avatar

lnussel declined request

I don't think disabling NULL ciphers at compile time is a good idea.
There may be use cases for authenticated but not encrypted
connections.


Adrian Schröter's avatar

adrianSuSE superseded request

supersede declined request with a followup request


Saul Goodman's avatar

licensedigger accepted review

{"approve": "license and version number unchanged: 1.0.0e"}


Stephan Kulow's avatar

coolo accepted review

Builds for repo openSUSE_Factory

Output of check script (non-fatal):
- package has baselibs.conf: (unchanged)
(W) openssl.spec: patch 3 CVE-2010-1633_and_CVE-2010-0742.patch is commented out
(W) openssl.spec: patch 4 patchset-19727.diff is commented out
(W) openssl.spec: patch 5 CVE-2010-2939.patch is commented out
(W) openssl.spec: patch 6 CVE-2010-3864.patch is commented out
(W) openssl.spec: patch 8 CVE-2011-0014.patch is commented out


Ludwig Nussel's avatar

lnussel declined review

I don't think disabling NULL ciphers at compile time is a good idea.
There may be use cases for authenticated but not encrypted
connections.

openSUSE Build Service is sponsored by