@henningw - it seems to be quite a lot of code for that random generator. Eventually it can be added as a subfolder in tls module, with sha256 included there. app_sqlang module has also code in a subfolder. Maybe this should be discussed on a separate issue or pull request, not to divert the discussion on this one from the real subject.
@jungle-boogie - importing libssl and patching it should be the last solution, because it will add a lot of maintenance overhead to take care of sync'ing with upstream for security patches, new features, etc...