All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jan Just Keijser <jan.just.keijser@gmail.com>
To: linux-ppp@vger.kernel.org
Subject: Re: ppp 2.4.4 eap-tls patch
Date: Tue, 25 Jul 2006 15:17:33 +0000	[thread overview]
Message-ID: <44C6360D.1080305@gmail.com> (raw)
In-Reply-To: <44C5F014.40202@gmail.com>

to follow up on my previous posting:

- gnutls does not provide the HMAC functions, which are needed for MPPE, 
hence I will rule that out for now
- matrixssl seems to have a very odd licence, with the split between 
commercial and non-commerical use...
- openwrt already provides support for openvpn, which in turn uses 
openssl so why is there a need to switch to matrixssl ?

conclusion: for now, I won't be bothered to migrate my patch from 
openssl to gnutls or matrixssl any time soon. Others are most welcome to 
try , of course, and I am willing to test any patches that others provide.

share and enjoy,

JJK

Jan Just Keijser wrote:

> The patch is based on OpenSSL basically because I have used openssl in 
> the past and have come to know it a bit; I don't see any reason why 
> MatrixSSL (which I do not know) or libgnutls (which I know a little 
> but have had problems with in the past) could not be used. The EAP-TLS 
> patch uses an SSL TLSv1 context and not much more than that, so I 
> can't think of a reason why any other package which provides the same 
> functionality could not be used.
>
> I will give libgnutls a shot over the next few days/weeks, and perhaps 
> MatrixSSL as well.
>
> share and enjoy,
>
> JJK
>
>
> Marco d'Itri wrote:
>
>> On Jul 25, James Cameron <james.cameron@hp.com> wrote:
>>
>>  
>>
>>> You've used OpenSSL, which has a license that is not altogether open,
>>> specifically clause 6 which requires acknowledgement.  Is there any
>>> reason why you couldn't use MatrixSSL?
>>>   
>>
>> I would hate to see EAP-TLS depend on a niche license.
>> I do not think I would enable EAP-TLS in the Debian package in this case
>> since it would require pulling the MatrixSSL package in the base system.
>>
>> If you do not like the advertisement clause in the OpenSSL license there
>> is libgnutls which is LGPL'ed and widely used (and has a sane API...).
>>
>>  
>>
>
>


  parent reply	other threads:[~2006-07-25 15:17 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-07-25 10:19 ppp 2.4.4 eap-tls patch Jan Just Keijser
2006-07-25 11:04 ` James Cameron
2006-07-25 11:31 ` Marco d'Itri
2006-07-25 11:46 ` Jan Just Keijser
2006-07-25 15:17 ` Jan Just Keijser [this message]
2006-07-25 15:20 ` Marco d'Itri
2006-07-25 23:03 ` James Cameron
2006-07-25 23:07 ` Marco d'Itri

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=44C6360D.1080305@gmail.com \
    --to=jan.just.keijser@gmail.com \
    --cc=linux-ppp@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.