It is nevertheless a bit weird to see test sourcecode for TLS support on a site that does not support HTTPS!
Maybe when the cleanup is complete and it's shored up, they might actually use it? :)
I think I prefer BoringSSL's cmake/make process, because OpenSSL's build system is simply horrible, I've never liked it. But it doesn't do shared libraries yet, so I'm having to take the .a files and link them by hand (well, by script anyway). Not optimal, but better than having to rebase my own patches so frequently, and it's only a test box.
I love the sheer amount of renovation-via-demolition libreSSL's doing. OpenSSL really does have a terrifying amount of #if 0, crufty ciphers and code no-one ever wants to use.
By the way, you may as well take RC4 out: it's about to get another significant result...
Like if no RC4 meant no youtube, I don't think we're quite popular enough to demand that youtube change ciphers.
Btw, did you have a look into ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/ ?
Unfortunately, without that notice, my first thought was "why is it linking me to an HTTP site". The notice prevents visitors like me from guessing as to why that is by setting the appropriate context and letting us know you're aware of the right steps but they aren't feasible right now.
While LibreSSL does appear to be going in the right direction, especially after the disastrous few months that OpenSSL has had, the community at large does want to be reassured that the LibreSSL project truly does revere security. A more security-conscious release in this case would have helped with that.
However, I really like to download code related to cryptography securely. Perhaps you didn't have the resources or the time to do this.
There were a few easy to do things: posting the hashes of the downloads in various places like GitHub, mailing lists, this HN thread and a few others. GitHub is useful for serving source releases, as long as you post the hashes in more places.
OpenSSL has been heavily criticized. That has been debated ad nauseam in countless places. The one thing I like about OpenSSL is that they're providing secure downloads. Their code might be bad, but at least you can download it from them via HTTPS.
Many would like to contribute, but the OpenBSD project isn't the friendliest (that's a mild way to put it).