Disable OpenSSL
Marc Haber <[email protected]> Thu, 27 Mar 2025 17:10:22 +0100
| Newsgroups | gmane.comp.tools.sudo.user |
|---|---|
| Message-ID | <[email protected]> |
I have recently learned that sudo uses OpenSSL or WolfSSL. Judging from the place where, for example, the sha2 function is called, this is meant to support the digest option in sudoers. As the maintainer of sudo in one of the major distributions, I am not very comfortable with a suid binary linking to a library that has such a bad security record. As far as I see, OpenSSL is automatically pulled in when it is found. Would it be possible to have a compile-time option to disable the functions that need OpenSSL and/or WolfSSL? What do the other users think about that? I am not sure whether this is a valid request, hence I am posting this here and not as a bug. Greetings Marc -- ----------------------------------------------------------------------------- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Leimen, Germany | lose things." Winona Ryder | Fon: *49 6224 1600402 Nordisch by Nature | How to make an American Quilt | Fax: *49 6224 1600421 ____________________________________________________________ sudo-users mailing list <[email protected]> For list information, options, or to unsubscribe, visit: https://www.sudo.ws/mailman/listinfo/sudo-users