Conversation
Documentation build overview
5 files changed ·
|
| * - `OpenSSL <https://openssl-library.org/>`_ | ||
| - | 3.0.18 recommended | ||
| | (1.1.1 minimum) | ||
| - [8]_ |
There was a problem hiding this comment.
| - [8]_ | |
| - 1.1.1 [8]_ |
I think keeping the bare minimum here would be reasonable?
There was a problem hiding this comment.
Honestly, I would prefer not to mention 1.1.1 at all: realistically, nobody reading this should ever use it, and anyone who really needs to use it anyway should already know what they're doing. I only keep it in the prose note because it's technically the minimum.
| .. [8] OpenSSL 1.1.1 is the minimum possible version to build against, | ||
| but the latest public release of the series has known vulnerabilities. | ||
| For best compatibility and security it is recommended to always use | ||
| the latest patch release of a current LTS release series (see the | ||
| `OpenSSL Roadmap <https://openssl-library.org/roadmap/index.html>`_), | ||
| or the package provided by your operating system if available. Other | ||
| libraries that offer an API compatible with OpenSSL 1.1.1 or later may | ||
| also be usable, but are not officially supported. |
There was a problem hiding this comment.
| .. [8] OpenSSL 1.1.1 is the minimum possible version to build against, | |
| but the latest public release of the series has known vulnerabilities. | |
| For best compatibility and security it is recommended to always use | |
| the latest patch release of a current LTS release series (see the | |
| `OpenSSL Roadmap <https://openssl-library.org/roadmap/index.html>`_), | |
| or the package provided by your operating system if available. Other | |
| libraries that offer an API compatible with OpenSSL 1.1.1 or later may | |
| also be usable, but are not officially supported. | |
| .. [8] OpenSSL 1.1.1 is the minimum possible version to build against, | |
| but that series is end-of-life and no longer receives | |
| security fixes. Use the latest patch release of a currently supported | |
| LTS series (see the `OpenSSL Roadmap | |
| <https://openssl-library.org/roadmap/index.html>`_), or the package | |
| provided by your operating system. Other libraries with an API | |
| compatible with OpenSSL 1.1.1 or later may work, but are not | |
| officially supported. |
Some little wording suggestions, feel free to reject as you see fit.
There was a problem hiding this comment.
Technically, 1.1.1 does still receive security fixes, if you pay for them :)
I agree that my wording is probably not the best, though; most of the CVEs affecting 1.1.1 since 1.1.1w are low or moderate (with a couple of highs), but it's stretching a bit far to refer to them as "known vulnerabilities" as that phrase usually implies.
I'm wary of removing the "if available" note for OS packages; at least two major OSes don't provide OpenSSL at all.
To address @hugovk's comment on GH-158015, this adjusts the configure doc to avoid recommending a concrete version of OpenSSL at all, but instead point to what should be up-to-date resources and explain things a bit in prose.
This patch won't backport all the way to 3.13, but I plan to backport the idea manually after there's some agreement on the message.