[squid-dev] Libnettle, default? when?

Amos Jeffries squid3 at treenet.co.nz
Wed Nov 5 04:23:22 UTC 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 5/11/2014 9:02 a.m., Eliezer Croitoru wrote:
> I am building squid RPMs and I wanted to use the default base repos
> as a vector point for the relevant package requirements.
> 
> In CentOS 6.5 and back the default is to not have epel which
> contains libnettle.
> 
> For now I will provide the same packages with "--without-nettle"
> option.
> 
> Later I would like to start building squid with it..
> 
> Any approaches or ideas to the matter?

Is Squid normally provided by the base repos or the epel? IMO you
should feel confident building it with any library in the repo its
normally provided.

There was pushback on making nettle required by Squid, so for now its
just recommended unless you are building with GnuTLS support, then it
is pulled in anyway as a dependency of GnuTLS.

There is probably some base library behind the basic crypto hashes in
CentOS/RHEL that we could make use of in nettles' absence.

There is openssl libcrypto and the krb5 crypto library available for
example in builds where OpenSSL or Kerberos are enabled. They do not
offer quite the range of algorithms with such simple API, but are usable.

Amos
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (MingW32)

iQEcBAEBAgAGBQJUWaY6AAoJELJo5wb/XPRjHTcIANiVgZ8qLpL67UaEY7Twe+rp
JqkBLSizEedn21ZqUAb3aUOtH6seGk1i/6PAq1OO8ytO5vaUXOvRjiRSccIQKuUP
EmGP70ai0MkPfoCjeWZgnNyy7X58NwIhAS3WNWQIA/ipTySPeLpmXk7IgisxI6Lt
7Nd0CTMe5o5wKldI9Er47wwJ3gtvmUyCJrIy+yEK1hGK17i/yldkR7yk5Fe5oY8Z
A2H6nt3Nqxh/VAAYhyQXKJhQ146oG02th14eQWEL9818MkFCU9Lltz5NuPmQ911u
eYPxvpMKNnEgZM4mup33HQpGzk8M1NEd9MgE3fKWYlEv6cpzZgcvRTINV/kkJSk=
=VZUr
-----END PGP SIGNATURE-----


More information about the squid-dev mailing list