I'll be running LibReSSL, and I expect most Linux distributions to do the same by default once the Linux port is released.
I'll be running LibReSSL, and I expect most Linux distributions to do the same by default once the Linux port is released.
This happens occasionally, a product is the leader in it's market because it was the only game in town, but eventually it's replaced as something beats it in one or more of the categories of features, speed, reliability, or freedom. See ssh.com vs OpenSSH.
The truth of the matter is, many people have concerns about the security of OpenSSL (and IMHO, rightly so), and no matter how bad we feel for the developers, this is not a case where we should trust in our loyalty. This is our personal security, the security of the businesses we work for, and the customers that use them. I can't in good faith use anything but what I consider the best choice, given whatever constraints I already face.
English is hard man, I know.
What about adequately supporting developers who have provided a product used by a huge number of people? Yes, they've had failures and have clearly done some things wrong. But they have also made positive contributions. I guess it's a matter of whether one thinks the baby should be thrown out with the bathwater.
Why use OpenSSL, if LibReSSL already has had a head start on each issue? And OpenSSL probably doesn't even intend to address some of these, like removal of FIPS support.
I'm pretty sure that OpenBSD, Debian, Slackware, Arch Linux and many others don't care about supporting some insecure and obscure government standards.
In fact, FIPS was removed from LibReSSL in OpenBSD due to being unmaintained and insecure.
However, I expect Fedora and its derivatives to stick with openssl-fips. Red Hat makes a big deal of FIPS due to selling to customers who are subject to the FIPS bureaucracy. :-(
Which is not wrong, but I wouldn't say it's right now well-baked for inclusion in major Linux distributions.
Wouldn't be entirely surprising to see something similar happen here.