Skip to main content


#openssl 3 does not seem to perform very well against the competition, as Willy of #haproxy fame details here: github.com/haproxy/haproxy/iss…
This entry was edited (1 month ago)
in reply to daniel:// stenberg://

as someone who is using HAproxy a lot and talks to others who also do: most people either get substantially more hardware or switch to aws-lc, which is not too hard. Sometimes depends on who pays the server bill. ;) More servers create additional problems though. Would love to see wolfssl stable and with high performance! ❤ We will benchmark when ready. :)
in reply to Howard Chu @ Symas

@hyc I think everything taken together points to that indeed. It's within their rights of course, but I find it rather strange.
in reply to daniel:// stenberg://

It's ok to deprioritize performance in favor of correctness. Unfortunately they don't seem to care much about correctness either.

We've been working with WolfSSL lately. I think we'll be promoting it more now.

in reply to daniel:// stenberg://

I think if OpenSSL devs ever faced with a set of alt implementation choices, with say one better for security and code clarity (can overlap, imo) on one hand, versus say perf on the other, they should pick bias to former.

since ssh/sshd is one of the biggest security SPOFs in modern computing. a massive pinata for black hats

so I *hope* thats why their perf is non-ideal

This entry was edited (1 month ago)