Public bug reported:

The sslscan package will require invasive changes to gain compatibility
with OpenSSL 4. Poking around, it looks like it uses pointers to some of
the removed functions to determine what version it's testing, and also
uses removed APIs to build raw TLS packets. Bringing it forward will
require a nontrivial investment from someone with experience.

Unfortunately, upstream issues have not received any acknowledgement in
~6 weeks:

https://github.com/rbsec/sslscan/issues/361
https://github.com/rbsec/sslscan/issues/362

Accordingly, in order to unblock the OpenSSL 4 transition, I think we
should remove the package from Stonking. It can be added back if it
gains compatibility in Debian or upstream.

I've already create a merge proposal for the only reverse dependency:

> reverse-depends -r stonking sslscan
Reverse-Depends
===============
* forensics-extra

The status of that work is tracked in this bug: 
https://bugs.launchpad.net/ubuntu/+source/forensics-extra/+bug/2161474

** Affects: sslscan (Ubuntu)
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2161476

Title:
  Please remove sslscan from stonking

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/sslscan/+bug/2161476/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to