OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • [solved]OpenSSL or LibreSSL
« previous next »
  • Print
Pages: [1]

Author Topic: [solved]OpenSSL or LibreSSL  (Read 8522 times)

bmail

  • Newbie
  • *
  • Posts: 37
  • Karma: 1
    • View Profile
[solved]OpenSSL or LibreSSL
« on: April 23, 2019, 10:28:16 am »
Hello,

Small and perhaps silly question:

Is it possible and safe to swith from OpenSSL to LibreSSL for the choice of the firmware cryptography flavour (firmware > parameters) ?

Present Release: 19.1.6 running with OpenSSL

Purpose: to get closer to the work of OpenBSD team.

Thanks a lot for your advices

« Last Edit: April 23, 2019, 05:55:49 pm by bmail »
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: OpenSSL or LibreSSL
« Reply #1 on: April 23, 2019, 11:05:23 am »
I'm using LibreSSL on 2 installs with openVPN tunnels. Only problem is with unbound and DNS-over-TLS, otherwise doing fine...
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

bmail

  • Newbie
  • *
  • Posts: 37
  • Karma: 1
    • View Profile
Re: OpenSSL or LibreSSL
« Reply #2 on: April 23, 2019, 05:18:54 pm »
Hello Chemlud,

Thanks for sharing your experience.
For the moment I use unbound without TLS, so that should work.

But, can I now, safely, switch (in the gui) to  LibreSSL without breaking anything. I suppose this will be taken into account after the next update, and not right now.

Thanks.
Logged

chemlud

  • Hero Member
  • *****
  • Posts: 2488
  • Karma: 112
    • View Profile
Re: OpenSSL or LibreSSL
« Reply #3 on: April 23, 2019, 05:28:55 pm »
I switched to LibreSSL last year without any trouble. What happenz nowadays if you switch? I would assume that nothing will break. But I'm not an insurance company... :-D
Logged
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

fabian

  • Hero Member
  • *****
  • Posts: 2769
  • Karma: 200
  • OPNsense Contributor (Language, VPN, Proxy, etc.)
    • View Profile
    • Personal Homepage
Re: OpenSSL or LibreSSL
« Reply #4 on: April 23, 2019, 05:30:00 pm »
As far as I know there may be also a problem with wireguard (or was it another plugin?) if I remember that correctly that it is not available in LibreSSL. There is no problem to expect with the major plugins.
Logged

bmail

  • Newbie
  • *
  • Posts: 37
  • Karma: 1
    • View Profile
[solved]Re: OpenSSL or LibreSSL
« Reply #5 on: April 23, 2019, 05:55:08 pm »
OK, thanks to all !

I'm going to test openvpn and squid ssl inspection within a test environment.

Have a good day.
Best regards
Bertrand

Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • [solved]OpenSSL or LibreSSL
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2