|
|
Log in / Subscribe / Register

Worse API?

Worse API?

Posted Jan 15, 2026 8:50 UTC (Thu) by maniax (subscriber, #4509)
Parent article: The State of OpenSSL for pyca/cryptography

I had to do some work with the API of OpenSSL 1.x in the olden days, and it always struck me as horrible, complicated and pretty much impossible to use correctly. I do remember a case where the documentation was wrong, most examples were wrong and the only working example was in an email in some OpenSSL list. I know that OpenSSL's locking/multithreaded support is so complicated that people solve that with single-process workers that handle just SSL, and skip all that.

I can't believe they actually made this worse.

Even though it'll be a pain, moving away from OpenSSL might be the right thing to do, overly complicating an already complicated system that people should be able to understand is just wrong.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds