#3495 Default for OpenSSL for crypto
Closed: Fixed Opened by jhrozek.

Currently we default to NSS for crypto operations. We should switch to OpenSSL as it's more widely used, easier to develop for. Also, many distributions, like fedora, are moving away from NSS in an attempt to only have a single crypto library in the default installation.


Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD 2.0

Metadata Update from @jhrozek:
- Issue priority set to: blocker

Could you share more information about this plan to move away from NSS?

I'm not sure what exactly is it you're asking, but Fedora as a whole is moving away from NSS. curl dropped NSS, openldap dropped NSS, so SSSD might be one of the last packages requiring OpenSSL in the distribution.

It's unclear when exactly this will happen, probably in the F-29 cycle rather than F-28.

Commit 8adf6ead relates to this ticket

Commit ee76c686 relates to this ticket

Fixed as part of the following series ...
master:
2f897af
176e4d2
842daeb
4f63a1a
7190e0e
165f58a
b5136cd
6d6e4a5
4eed225
075f2f3
ee76c68
8adf6ea
8127b58

Metadata Update from @fidencio:
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

This was actually fixed in 1.16.2. The defaults are left for the distribution to choose.

Metadata Update from @jhrozek:
- Issue set to the milestone: SSSD 1.16.2 (was: SSSD 2.0)

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/4521

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Metadata