OpenSSL Project Roadmap
openssl.org
openssl.org
It is a little weird though that it's almost the libressl game plan, verbatim. It could literally just say "do whatever libressl" does.
Some of the specifics, like memory management is dangerous, fips code is tangly, win16 support is obsolete, seem a little too familiar. We haven't really tried to make an exhaustive list of issues to fix in libressl. I know there are things we haven't looked at yet. But for the OpenSSL roadmap to match 100% our public work is weird. They haven't found anything to fix that we've overlooked?
Also, there are definitely some problems in OpenSSL that we've identified, but haven't talked about. I'd expect any independent review/roadmap planning to identify them. They're missing from this list.
I'll be running LibReSSL, and I expect most Linux distributions to do the same by default once the Linux port is released.
Why use OpenSSL, if LibReSSL already has had a head start on each issue? And OpenSSL probably doesn't even intend to address some of these, like removal of FIPS support.
I'm pretty sure that OpenBSD, Debian, Slackware, Arch Linux and many others don't care about supporting some insecure and obscure government standards.
In fact, FIPS was removed from LibReSSL in OpenBSD due to being unmaintained and insecure.
What about adequately supporting developers who have provided a product used by a huge number of people? Yes, they've had failures and have clearly done some things wrong. But they have also made positive contributions. I guess it's a matter of whether one thinks the baby should be thrown out with the bathwater.
Wouldn't be entirely surprising to see something similar happen here.
This happens occasionally, a product is the leader in it's market because it was the only game in town, but eventually it's replaced as something beats it in one or more of the categories of features, speed, reliability, or freedom. See ssh.com vs OpenSSH.
The truth of the matter is, many people have concerns about the security of OpenSSL (and IMHO, rightly so), and no matter how bad we feel for the developers, this is not a case where we should trust in our loyalty. This is our personal security, the security of the businesses we work for, and the customers that use them. I can't in good faith use anything but what I consider the best choice, given whatever constraints I already face.
English is hard man, I know.
Which is not wrong, but I wouldn't say it's right now well-baked for inclusion in major Linux distributions.
However, I expect Fedora and its derivatives to stick with openssl-fips. Red Hat makes a big deal of FIPS due to selling to customers who are subject to the FIPS bureaucracy. :-(
This definitely increases my confidence in them.
24-Jun-2014: Team status changes including six new development team members
The article listed links to: https://www.openssl.org/about/
Hopefully the new team can deliver on the promise in this roadmap.
It will be interesting to see whether this turns out to be just words or if they'll stick it through. If the actually implement what they're planning the future for OpenSSL will be a lot better.
Things are looking up, IMO.