Skip to content

Vendored OpenSSL #905

Description

@lubo

Since 9aee0f3, vendored OpenSSL is built and statically linked into the resulting executable. Most of the time, this is undesired, as it requires the executable to be rebuilt whenever a (security) bug is discovered in OpenSSL. Plus, it makes it more difficult for package maintainers to know whether this package and the resulting executables are affected by such issues.

While I understand that you wanna provide zero-dependency, pre-built executables, this behavior should not be the default. Instead, either Rustls (default-tls reqwest feature) or dynamically-linked OpenSSL (native-tls reqwest feature) should be the default. Although Rustls is better than OpenSSL, FIPS compliance requires OpenSSL.

To satisfy all the requirements, a compile-time feature flag that'd allow for changing the TLS engine used by reqwest should be added.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions