Re: SSLKEYLOGFILE always enabled

2014-07-17 Thread Falcon Darkstar Momot
When it comes to key material, it's an outstanding idea to err on the side of caution. Does anyone actually require this feature in a non-debug build? If not, then it's completely unreasonable to leave it in such builds, even if it's not the weakest link and even if it doesn't break compliance.

Re: SSLKEYLOGFILE always enabled

2014-07-17 Thread Ryan Sleevi
On Wed, July 16, 2014 11:42 pm, Falcon Darkstar Momot wrote: When it comes to key material, it's an outstanding idea to err on the side of caution. Does anyone actually require this feature in a non-debug build? If not, then it's completely unreasonable to leave it in such builds, even

Re: SSLKEYLOGFILE always enabled

2014-07-17 Thread Falcon Darkstar Momot
On 17/07/2014 01:26, Ryan Sleevi wrote: On Wed, July 16, 2014 11:42 pm, Falcon Darkstar Momot wrote: When it comes to key material, it's an outstanding idea to err on the side of caution. Does anyone actually require this feature in a non-debug build? If not, then it's completely

Re: SSLKEYLOGFILE always enabled

2014-07-17 Thread Patrick McManus
If there would be a reduced risk by scoping the feature to debug builds I would agree with you that it should be scoped. But Ryan suggests there isn't. My much less informed opinion tends to agree with him. On Thu, Jul 17, 2014 at 3:41 AM, Falcon Darkstar Momot fal...@iridiumlinux.org wrote: