we may keep combo. both #ifdef EVP_PKEY_TLS1_PRF and comment related to supported openssl versions (to drop support if we decide)
вт, 9 мар. 2021 г. в 17:56, Gert Doering <g...@greenie.muc.de>: > Hi, > > On Tue, Mar 09, 2021 at 05:52:12PM +0500, ???????? ?????????????? wrote: > > > On Tue, Mar 09, 2021 at 04:54:13PM +0500, ???????? ?????????????? > wrote: > > > > if nobody minds, I can send several patches that eliminates > comparison of > > > > OPENSSL_VERSION, for example > > > > > > We do mind. They are coded this way on purpose - so when we drop > support > > > for OpenSSL before 1.1.0, it is clear from the code which sections can > > > > it is not much fun to catch things like > > > https://boringssl.googlesource.com/boringssl/+/49e9f67d8b7cbeb3953b5548ad1009d15947a523%5E%21/include/openssl/base.h > > > > (BoringSSL claims itself as 1.1.0, accidentally decided "I'm 1.1.1 now") > > We do not support BoringSSL. > > (Or any other SSL library that claims "I am compatible with OpenSSL 1.1.1" > but isn't, really - which is why the LibreSSL adjustments are always very > minimal) > > We sort-of-support LibreSSL because it is the system SSL library on > OpenBSD. Otherwise, the answer would be the same as for BoringSSL. > > gert > -- > "If was one thing all people took for granted, was conviction that if you > feed honest figures into a computer, honest figures come out. Never > doubted > it myself till I met a computer with a sense of humor." > Robert A. Heinlein, The Moon is a Harsh > Mistress > > Gert Doering - Munich, Germany > g...@greenie.muc.de >
_______________________________________________ Openvpn-devel mailing list Openvpn-devel@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openvpn-devel