From owner-freebsd-ports@FreeBSD.ORG Tue Apr 9 13:09:42 2013 Return-Path: Delivered-To: freebsd-ports@freebsd.org Received: from mx1.freebsd.org (mx1.FreeBSD.org [8.8.178.115]) by hub.freebsd.org (Postfix) with ESMTP id 8F8548A0 for ; Tue, 9 Apr 2013 13:09:42 +0000 (UTC) (envelope-from list_freebsd@bluerosetech.com) Received: from rush.bluerosetech.com (rush.bluerosetech.com [IPv6:2607:fc50:1000:9b00::25]) by mx1.freebsd.org (Postfix) with ESMTP id 67AD894E for ; Tue, 9 Apr 2013 13:09:42 +0000 (UTC) Received: from chombo.houseloki.net (montesse-2-pt.tunnel.tserv3.fmt2.ipv6.he.net [IPv6:2001:470:1f04:19b9::2]) by rush.bluerosetech.com (Postfix) with ESMTPSA id EE1F21144E; Tue, 9 Apr 2013 06:09:41 -0700 (PDT) Received: from [IPv6:fc00:970::e812:4ecc:5220:8206] (unknown [IPv6:fc00:970::e812:4ecc:5220:8206]) by chombo.houseloki.net (Postfix) with ESMTPSA id 88E9AC2F; Tue, 9 Apr 2013 06:09:40 -0700 (PDT) Message-ID: <51641315.3080704@bluerosetech.com> Date: Tue, 09 Apr 2013 06:09:41 -0700 From: Darren Pilgrim User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:17.0) Gecko/20130107 Thunderbird/17.0.2 MIME-Version: 1.0 To: Florent Peterschmitt Subject: Re: Growing list of required(ish) ports References: <51622F44.3050604@FreeBSD.org> <1365441764.4112.1.camel@localhost> In-Reply-To: <1365441764.4112.1.camel@localhost> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Cc: FreeBSD Mailing List X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list Reply-To: FreeBSD Mailing List List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 09 Apr 2013 13:09:42 -0000 On 2013-04-08 10:22, Florent Peterschmitt wrote: > Yep, OpenSSH is tiny enought to keep it in base system. It would be a > big loss not to have it by default, securely installed in the base > system. I really wish it wasn't. Having OpenSSH (and thus OpenSSL) in the base means FreeBSD has an outdated version installed by default. You have to install openssl from ports in order to have modern cipher support, TLS v1.1/1.2, DTLS, etc. This puts two sets of openssl libs on the system and creates recurrent headaches with builds where the autoconfiguration selects the wrong set of libs.