Re: [systemd-devel] RFC: Moving fully to OpenSSL (aka. stopping support for gnutls/gcrypt)?

2020-12-10 Thread Lennart Poettering
On Do, 10.12.20 10:58, Arian Van Putten (ar...@wire.com) wrote: > I think it's an excellent idea. > > Question: Currently systemd-importd still has an indirect dependency on > libgcrypt through it depending on the gnupg binary for signatures. > Would it maybe be an idea to add support for other

Re: [systemd-devel] RFC: Moving fully to OpenSSL (aka. stopping support for gnutls/gcrypt)?

2020-12-10 Thread Arian Van Putten
I think it's an excellent idea. Question: Currently systemd-importd still has an indirect dependency on libgcrypt through it depending on the gnupg binary for signatures. Would it maybe be an idea to add support for other signature schemes to importd that can be directly implemented with

Re: [systemd-devel] RFC: Moving fully to OpenSSL (aka. stopping support for gnutls/gcrypt)?

2020-12-10 Thread Umut Tezduyar Lindskog
Hi. Really good initiative! Also wanted to inform about connectedhomeip project which has an abstraction layer for OpenSSL and Mbed TLS. Probably the layer is far from being ready for systemd to use though. Umut On Wed, Dec 9, 2020 at 10:51 AM Lennart Poettering wrote: > Heya! > > Currently,

Re: [systemd-devel] RFC: Moving fully to OpenSSL (aka. stopping support for gnutls/gcrypt)?

2020-12-09 Thread Luca Boccassi
On Wed, 2020-12-09 at 10:50 +0100, Lennart Poettering wrote: > Heya! > > Currently, some parts of the systemd tree link against OpenSSL, others > link against gnutls and libgcrypt, and even others support either, > controlled by a compile time switch. > > This is of course less than ideal, since

[systemd-devel] RFC: Moving fully to OpenSSL (aka. stopping support for gnutls/gcrypt)?

2020-12-09 Thread Lennart Poettering
Heya! Currently, some parts of the systemd tree link against OpenSSL, others link against gnutls and libgcrypt, and even others support either, controlled by a compile time switch. This is of course less than ideal, since it means we need to maintain needlessly complex, redundant code to support