Hacker News new | past | comments | ask | show | jobs | submit login

> An OpenSSL API emulation could then have been layered on top.

Not really. OpenSSL exposes "internal" data structures in its API, leaking e.g. x.509 datastructures through[0]. The only way to expose an OpenSSL API emulation is to be OpenSSL.

That's why the libressl project started libtls[1] (née ReSSL) as a clean-slate abstracted API.

[0] http://www.tedunangst.com/flak/post/goreSSL

[1] http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man3/...




Oh thank goodness someone is making a saner API.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: