I would like to ask FESCo to review this Change proposal:
Currently, OpenLDAP in Fedora is compiled with NSS (aka MozNSS) for cypto. OpenLDAP is going to be compiled with OpenSSL, instead.
+1 I guess. I'm not really experienced enough in this area to ask intelligent questions.
I'm +1 to the desire, but given the constrained timeframe of the F27 cycle, I'm extremely reluctant to believe that this is feasible.
Given the reservations of a major stakeholder (FreeIPA), I'm somewhat inclined to recommend deferral of this to F28.
I'm also inclined to defer this to F28, unless someone can convince me of an overriding reason this needs to be done in F27.
I'd like to +1 this. OpenLDAP being cobbled to NSS has been a sore point for many years.
This would at least bring it into alignment with just about every other person who builds openldap.
To be clear, this definitely needs to be done. I'm just concerned that it can't be accomplished in the timeframe of F27 and I don't want anyone killing themselves to do so (or causing us to slip because critical components are broken mid-switch).
Metadata Update from @maxamillion: - Issue tagged with: meeting
Please note that compiling with OpenSSL is simple, the effort is mainly focused on keeping a backward compatibility with NSS database backed PKI so that there are possibly no regressions when the change takes place. With PEM files will OpenLDAP work even better as there are currently issues when nss-pem module is used causing pain for other components. The most critical dependants are 389DS (which is already prepared even for the change to pure OpenLDAP with OpenSSL), FreeIPA, and SSSD; with those the change is going to be tested thoroughly.
Also, tendency to switch to OpenSSL is ongoing all over the base Fedora and, as [crcinau] mentioned, we are the only ones to use OpenLDAP with NSS; upstream will most probably drop its implementation with OpenLDAP 2.5.
Eventually, there is no regression mere git revert would not fix; so no slip should occur. I hope this sheds some more light at the current status.
Still +1
This was voted on in last Friday's FESCo meeting. Due to the short F27 cycle, we defer this until F28 and accept it for that release. Please land it as soon after branching as possible.
Metadata Update from @jsmith: - Issue untagged with: meeting - Issue close_status updated to: Fixed - Issue status updated to: Closed (was: Open)
I am reopening this ticket to make sure FESCo is aware of this Change beeing part of the F28 release (see the bugzilla tracking bug #1413515).
Metadata Update from @jkurik: - Issue status updated to: Open (was: Closed) - Issue tagged with: meeting
Let's update the ticket title to say "F28" :)
Oh, we did...
AGREED: F28 System Wide Change: Switch OpenLDAP from NSS to OpenSSL is reapproved (+6, 0, 0)