Openembedded Core Discussions
 help / color / mirror / Atom feed
From: "Shachar Menashe" <shachar@vdoo.com>
To: openembedded-core@lists.openembedded.org
Subject: Re: [yocto-security] [PATCH] busybox: use openssl for TLS connections whenever possible
Date: Tue, 20 Apr 2021 13:45:59 -0700	[thread overview]
Message-ID: <1397.1618951559627472345@lists.openembedded.org> (raw)
In-Reply-To: <CAJ86T=XGxEyZYc7pH3Me1_Cx+H1+OAjNjo45veLhyPFv+eEWsA@mail.gmail.com>

[-- Attachment #1: Type: text/plain, Size: 815 bytes --]

Last time we talked about this I thought we would need to change something in openssl build settings to make the openssl binary get built just for this solution, and that was what got rejected.
But actually now I see (or perhaps it got changed) that the openssl binary is built anyways, in any build that already relies on openssl.
So my suggestion is to enable this feature. Like I said in builds with openssl it will make everything more secure in a transparent manner, and in builds without openssl it will display a warning just like today.
I wouldn't consider it a hacky solution since this is the official solution for this issue.
This is also exacerbated due to the fact that there are no other alternatives for secure download from CLI (ex. the sato build doesn't contain the "curl" standalone binary)

[-- Attachment #2: Type: text/html, Size: 831 bytes --]

  reply	other threads:[~2021-04-20 20:45 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <mMlg.1618670463873919193.89er@lists.yoctoproject.org>
2021-04-20 17:23 ` [yocto-security] [PATCH] busybox: use openssl for TLS connections whenever possible Randy MacLeod
2021-04-20 20:28   ` [OE-core] " Andre McCurdy
2021-04-20 20:45     ` Shachar Menashe [this message]
2021-04-20 21:02       ` Khem Raj
2021-04-21  3:57       ` Andre McCurdy
2021-04-21  9:22         ` Shachar Menashe
2021-04-21 18:53           ` [OE-core] " Andre McCurdy

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1397.1618951559627472345@lists.openembedded.org \
    --to=shachar@vdoo.com \
    --cc=openembedded-core@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox