#3495 Default for OpenSSL for crypto
Closed: Fixed 5 years ago Opened 6 years ago by jhrozek.

Currently we default to NSS for crypto operations. We should switch to OpenSSL as it's more widely used, easier to develop for. Also, many distributions, like fedora, are moving away from NSS in an attempt to only have a single crypto library in the default installation.


Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD 2.0

6 years ago

Metadata Update from @jhrozek:
- Issue priority set to: blocker

6 years ago

Could you share more information about this plan to move away from NSS?

I'm not sure what exactly is it you're asking, but Fedora as a whole is moving away from NSS. curl dropped NSS, openldap dropped NSS, so SSSD might be one of the last packages requiring OpenSSL in the distribution.

It's unclear when exactly this will happen, probably in the F-29 cycle rather than F-28.

Commit 8adf6ea relates to this ticket

Commit ee76c68 relates to this ticket

Metadata Update from @fidencio:
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

5 years ago

This was actually fixed in 1.16.2. The defaults are left for the distribution to choose.

Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD 1.16.2 (was: SSSD 2.0)

5 years ago

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/4521

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Login to comment on this ticket.

Metadata