Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 507130 - dev-libs/openssl: disable tls-heartbeat by default
Summary: dev-libs/openssl: disable tls-heartbeat by default
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Core system (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords:
: 507322 507566 (view as bug list)
Depends on:
Blocks:
 
Reported: 2014-04-08 14:04 UTC by Dirkjan Ochtman (RETIRED)
Modified: 2014-04-18 10:24 UTC (History)
8 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Dirkjan Ochtman (RETIRED) gentoo-dev 2014-04-08 14:04:51 UTC
It appears that most people do not need this by default. It does represent relatively recent extra code, and thus added attack surface. It's also not enabled by default in upstream. On these grounds, I think we should not enable it by default.
Comment 1 SpanKY gentoo-dev 2014-04-08 18:17:17 UTC
not sure why you think it's not enabled by default upstream because it is.  the code might be confusing because it negates the definition (OPENSSL_NO_HEARTBEATS) and it isn't explicitly *disabled* by default.

hence the ebuild enables it by default.
Comment 2 Dirkjan Ochtman (RETIRED) gentoo-dev 2014-04-09 08:00:48 UTC
I gave three reasons for disabling, you dismissed just one. Do you think the others are completely worthless?
Comment 3 SpanKY gentoo-dev 2014-04-09 19:24:30 UTC
well, you've provided no data to back up the first claim.  that leaves the "extra code" part which isn't really enough to sway me -- upstream enables it by default is good enough for me.
Comment 4 Alex Legler (RETIRED) archtester gentoo-dev Security 2014-04-10 12:40:18 UTC
*** Bug 507322 has been marked as a duplicate of this bug. ***
Comment 6 Alex Legler (RETIRED) archtester gentoo-dev Security 2014-04-13 14:15:51 UTC
*** Bug 507566 has been marked as a duplicate of this bug. ***