Tomas Mraz wrote:
Not only crypto libraries but built-in code as well. I have checked that the packages actually contain the code.
I'm not sure how you checked, but it picked up false positives, setroubleshoot was flagged but it has no references to ssl, tls, or crypto in its sources.
But this still begs the question, was a consensus reached this activity represents a good use of maintainers time before a mass filing of bug reports?
Note, that question is far different than "We recommend NSS for new development", which I do think there is justifiable consensus on.
-- John Dennis <jdennis@xxxxxxxxxx> -- fedora-devel-list mailing list fedora-devel-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-devel-list