Conversation
lmaisons
left a comment
There was a problem hiding this comment.
Looks OK to me given the constraints. I wish I had a better idea for what to do with the underscore / dash foot-gun between the Conan variables and what OpenSSL's Configure script expects.
It's something that would require a larger refactor, and then proposing upstream too, to reduce future conflicts. Definitely something for a future PR, if at all. |
mathbunnyru
left a comment
There was a problem hiding this comment.
@bthomee I think security-related changes should always have 2 approvals, and everything openssl-related is definitely a security-related change.
This change introduces a bug, where some options won't be passed correctly to the openssl build configuration.
To have more granular control over the ciphers we support, this change supports selectively disabling DTLS and TLSv1.