Re: Bumping minimal OpenSSL version to 1.0.1 in master for PHP 7.1

From: Date: Tue, 13 Dec 2016 22:18:45 +0000
Subject: Re: Bumping minimal OpenSSL version to 1.0.1 in master for PHP 7.1
References: 1 2 3 4 5 6 7 8  Groups: php.internals 
Request: Send a blank email to internals+get-97393@lists.php.net to get a copy of this message
On 13.12.2016, at 11:31, Niklas Keller <me@kelunik.com> wrote: > > OpenSSL support for 1.0.1 will end this year. > > Support for version 1.0.1 will cease on 2016-12-31. No further releases of >> 1.0.1 will be made after that date. Security fixes only will be applied to >> 1.0.1 until then. >> Version 1.0.0 is no longer supported. >> Version 0.9.8 is no longer supported. > > > We dropped 0.9.8 and 1.0.0 in 7.1. > > Should we drop support for 1.0.1 in master, so it's dropped for 7.2 then, > as it will be unsupported then? Please no. Ubuntu's 14.04 LTS is on 1.0.1f and gets security backports. EOL is April 2019. Unless there is a hard reason (API changes or whatever) that PHP 7.2 absolutely cannot live without, it's a bad idea, as folks on 14.04 or similar (think RHEL etc) then have to either rely on third parties for updates, or vendor in a newer version, even though their system libssl is still receiving security updates. David

« previous php.internals (#97393) next »