Re: Introducing OpenSSL as a dependency to ClamAV

Mark Allan <[email protected]>
Newsgroups gmane.comp.security.virus.clamav.devel
Message-ID <[email protected]>
Looks like relying on OpenSSL might cause problems for ClamAV on OS X.

Al (a regular contributor to this list) pointed me towards the following blog post

https://hynek.me/articles/apple-openssl-verification-surprises/

It explains some of the problems with Apple's installation of OpenSSL, and offers some workarounds.  Relying on homebrew or MacPorts isn't an option for me because I produce compiled pre-packaged installers for ClamAV on OS X; I provide these to the general public, so have to expect users to be running the standard Apple-supplied OpenSSL.

Can I ask you to consider one of the two code-level solutions proposed in that blog post please?  Presumably it would have to be implemented as a configure flag rather than for all Mac builds as I suspect some of the more advanced ClamAV users out there *will* have compiled their own OpenSSL.

Thanks
Mark

_______________________________________________
http://lurker.clamav.net/list/clamav-devel.html
Please submit your patches to our Bugzilla: http://bugs.clamav.net
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.