Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 27 Oct 2016 11:17:35 +0200
From:      Franco Fichtner <franco@lastsummer.de>
To:        Mathieu Arnold <mat@FreeBSD.org>
Cc:        David Demelier <demelier.david@gmail.com>, Don Lewis <truckman@freebsd.org>, mad@madpilot.net, freebsd-ports@freebsd.org
Subject:   Re: lighttpd does not pull OpenSSL dependency
Message-ID:  <F7455AF1-451F-407E-A785-6CDD0BF207E1@lastsummer.de>
In-Reply-To: <7fb24c94-1efa-d1b5-9028-8dec8330e543@FreeBSD.org>
References:  <201610252214.u9PME6br070248@gw.catspoiler.org> <ded708c9-f2bf-6b2f-84cf-f97f91c39888@FreeBSD.org> <CAO%2BPfDdXbbgVMZnxiJig%2B_drLNYRftD4ruqXxHpybztiR1eBAA@mail.gmail.com> <7fb24c94-1efa-d1b5-9028-8dec8330e543@FreeBSD.org>

next in thread | previous in thread | raw e-mail | index | archive | help

> On 27 Oct 2016, at 11:00 AM, Mathieu Arnold <mat@FreeBSD.org> wrote:
>=20
> Le 26/10/2016 =C3=A0 15:44, David Demelier a =C3=A9crit :
>> 2016-10-26 10:46 GMT+02:00 Mathieu Arnold <mat@freebsd.org>:
>>> Le 26/10/2016 =C3=A0 00:14, Don Lewis a =C3=A9crit :
>>>> Then the question is, if DEFAULT_VERSIONS+=3Dssl=3Dopenssl is not =
in
>>>> make.conf, then why is OpeSSL from ports installed?  Nothing should
>>>> be depending on it.
>>> Well, the problem is that many ports have WITH_OPENSSL_PORT defined, =
so,
>>> something could have brought it along. I have a git branch changing =
it
>>> to WANT_OPENSSL_PORT that will mark the port IGNOREd if using base
>>> OpenSSL, I should commit it one day.
>>>=20
>>> Also, I'll change the default for ports from base to openssl, one =
day.
>> I can help if needed.
>=20
> But I don't use all of that, so I need help figuring out which should =
be
> the default afterwards (it can't be base, because you can't mix base
> heimdal with non base openssl)

Having stripped Kerberos from base for our 11.0 builds makes for a
nice test bed in places where GSSAPI is not yet in a port, but actually
required, leading to quick build errors.

gssapi:heimdal is the closes thing to base as far as we could see, and
we've rolled out several OPNsense releases with both OpenSSL and Heimdal
from ports that work nicely with external AD servers.


Cheers,
Franco=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?F7455AF1-451F-407E-A785-6CDD0BF207E1>