[OE-core] openssl10 unusable for many components

Alexander Kanavin alexander.kanavin at linux.intel.com
Fri Aug 18 18:30:23 UTC 2017


On 08/18/2017 08:41 PM, Martin Jansa wrote:
> openssl 1.1 goes out of upstream support on 2018-08-31 _more than a year
> before_ 1.0.2 support, see:
> 
> https://www.openssl.org/policies/releasestrat.html
> Version 1.1.0 will be supported until 2018-08-31.
> Version 1.0.2 will be supported until 2019-12-31 (LTS).
> 
> Given its history of major security vulnerabilities, I hope you'll
> remove openssl-1.1.0 even sooner than openssl-1.0.2.

openssl 1.1.1 should be released as soon as final TLS 1.3 spec is 
published. I expect it will go out of support much later than 1.1.0. I 
do not expect a situation where 1.0 is supported but 1.1.something is not.


Alex



More information about the Openembedded-core mailing list