I like gnutls (my blog) it again was attack proof from logjam although that seems to affect weaker pki than what i use. However in apache modssl gets the most attention and unless i recompile apache and everything else on wheezy (my blog) i am not going to get tls 1.1 with modssl. with the 2.2 branch.

jesseSo gnutls is a no brainer. It will be interesting to see if when I go to Jesse (as in stable not debian testing) i keep with gnutls or go back to issue encumbered openssl.

Somehow i think gnutls is going to win that.

