From 85da05177570bf3b60617f4c4eda2528a9aeb7a2 Mon Sep 17 00:00:00 2001 From: Zachary Ware Date: Sat, 26 Sep 2026 20:56:41 -0500 Subject: [PATCH 1/4] gh-158010: Avoid recommending out-of-date OpenSSL in configure doc --- Doc/using/configure.rst | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/Doc/using/configure.rst b/Doc/using/configure.rst index 88b5f35a7967967..690d70794f9a8ce 100644 --- a/Doc/using/configure.rst +++ b/Doc/using/configure.rst @@ -95,8 +95,7 @@ Dependencies to build optional modules are: - - :mod:`curses` * - `OpenSSL `_ - - | 3.0.18 recommended - | (1.1.1 minimum) + - [8]_ - :mod:`ssl`, :mod:`hashlib` [6]_ * - `SQLite `_ - 3.15.2 @@ -131,6 +130,14 @@ Dependencies to build optional modules are: See :option:`--with-builtin-hashlib-hashes` for *forcing* usage of OpenSSL. .. [7] See :option:`--with-zlib` for choosing the backend for the :mod:`zlib` module. +.. [8] OpenSSL 1.1.1 is the minimum possible version to build against, + but the latest public release of the series has known vulnerabilities. + For best compatibility and security it is recommended to always use + the latest patch release of a current LTS release series (see the + `OpenSSL Roadmap `_), + or the package provided by your operating system if available. Other + libraries that offer an API compatible with OpenSSL 1.1.1 or later may + also be usable, but are not officially supported. Note that the table does not include all optional modules; in particular, platform-specific modules like :mod:`winreg` are not listed here. From 397a0273493e26f413500adc4a5c2af2d195c54f Mon Sep 17 00:00:00 2001 From: Zachary Ware Date: Sun, 27 Sep 2026 17:55:03 -0500 Subject: [PATCH 2/4] Apply batched suggestions from code review Co-authored-by: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com> --- Doc/using/configure.rst | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Doc/using/configure.rst b/Doc/using/configure.rst index 690d70794f9a8ce..bbd4e15ab6fb578 100644 --- a/Doc/using/configure.rst +++ b/Doc/using/configure.rst @@ -132,9 +132,9 @@ Dependencies to build optional modules are: :mod:`zlib` module. .. [8] OpenSSL 1.1.1 is the minimum possible version to build against, but the latest public release of the series has known vulnerabilities. - For best compatibility and security it is recommended to always use + For best compatibility and security it is recommended to use the latest patch release of a current LTS release series (see the - `OpenSSL Roadmap `_), + `OpenSSL Roadmap `__), or the package provided by your operating system if available. Other libraries that offer an API compatible with OpenSSL 1.1.1 or later may also be usable, but are not officially supported. From ce5c202b5570d853ac575f321a61a3cb8e1b9701 Mon Sep 17 00:00:00 2001 From: Zachary Ware Date: Sun, 27 Sep 2026 17:58:50 -0500 Subject: [PATCH 3/4] Rewording Co-Authored-By: Stan Ulbrych --- Doc/using/configure.rst | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/Doc/using/configure.rst b/Doc/using/configure.rst index bbd4e15ab6fb578..a7e54199b0339da 100644 --- a/Doc/using/configure.rst +++ b/Doc/using/configure.rst @@ -131,13 +131,13 @@ Dependencies to build optional modules are: .. [7] See :option:`--with-zlib` for choosing the backend for the :mod:`zlib` module. .. [8] OpenSSL 1.1.1 is the minimum possible version to build against, - but the latest public release of the series has known vulnerabilities. - For best compatibility and security it is recommended to use - the latest patch release of a current LTS release series (see the + but the series is end-of-life and no longer receives public security + fixes. Use + the latest patch release of a currently supported LTS release series (see the `OpenSSL Roadmap `__), or the package provided by your operating system if available. Other libraries that offer an API compatible with OpenSSL 1.1.1 or later may - also be usable, but are not officially supported. + work, but are not officially supported. Note that the table does not include all optional modules; in particular, platform-specific modules like :mod:`winreg` are not listed here. From f8dea766835d81a3cb36140e6f090fa8005cbdb7 Mon Sep 17 00:00:00 2001 From: Zachary Ware Date: Sun, 27 Sep 2026 18:00:18 -0500 Subject: [PATCH 4/4] Re-wrap --- Doc/using/configure.rst | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/Doc/using/configure.rst b/Doc/using/configure.rst index a7e54199b0339da..5b1676e504a6283 100644 --- a/Doc/using/configure.rst +++ b/Doc/using/configure.rst @@ -132,12 +132,12 @@ Dependencies to build optional modules are: :mod:`zlib` module. .. [8] OpenSSL 1.1.1 is the minimum possible version to build against, but the series is end-of-life and no longer receives public security - fixes. Use - the latest patch release of a currently supported LTS release series (see the - `OpenSSL Roadmap `__), - or the package provided by your operating system if available. Other - libraries that offer an API compatible with OpenSSL 1.1.1 or later may - work, but are not officially supported. + fixes. Use the latest patch release of a currently supported LTS + release series (see the `OpenSSL Roadmap + `__), or the package + provided by your operating system if available. Other libraries that + offer an API compatible with OpenSSL 1.1.1 or later may work, but are + not officially supported. Note that the table does not include all optional modules; in particular, platform-specific modules like :mod:`winreg` are not listed here.