看板 FB_security 關於我們 聯絡資訊
Dirk Meyer a =E9crit: > >OPENSSL_OVERWRITE_BASE=3Dyes >sould be used with extreme caution! > >This might break your base application in cases like this, when the = base uses a diffrent api as the ports does. > That's totally true. I was wondering if, to avoid ports problem with openssl (and maybe some = over libs/important parts) - because somes refers directly to the openssl = base, others to the ports one -, we might try to find a way to have openssl - = in future release - in the base system being like a pre-installed port. It will be very hopeful too when security issues are discovered, because instead of patching the system base (and rebuilding the world...) we = have only to do a portupgrade... Saving times :) An other interest in doing this, is that the system will be reported unsecure by portaudit... OpenSSH should have the same treatment :) -- Cl=E9ment Moulin SimpleRezo _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"