@dgcom:
I perfectly understand implications of this particular issue, and yes - it is not just a matter of replacing openssl executable… What I am saying is that recompiling everything is not very efficient. But, I guess, you know your product :)
…
@dgcom:
shouldn't build system be smart enough to recompile only if dependencies changed?
the build system is, but the system is packaged in a way that is a forklift upgrade on every update.
We're exploring ways to update differently (such that updates are more like freebsd-update), but even here
there are impacts that you might not imagine.
PBIs are dead after 2.2, btw.
@dgcom:
I, personally, do not run anything, based on recent versions of openssl - except pfSense.
this is probably mistake at this point.