Re: Bumping minimal OpenSSL version to 1.0.1 in master for PHP 7.1
| From: | David Zuelke | Date: | Tue, 13 Dec 2016 22:18:45 +0000 |
| Subject: | Re: Bumping minimal OpenSSL version to 1.0.1 in master for PHP 7.1 | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-97393@lists.php.net to get a copy of this message | ||
On 13.12.2016, at 11:31, Niklas Keller <me@kelunik.com> wrote:
>
> OpenSSL support for 1.0.1 will end this year.
>
> Support for version 1.0.1 will cease on 2016-12-31. No further releases of
>> 1.0.1 will be made after that date. Security fixes only will be applied to
>> 1.0.1 until then.
>> Version 1.0.0 is no longer supported.
>> Version 0.9.8 is no longer supported.
>
>
> We dropped 0.9.8 and 1.0.0 in 7.1.
>
> Should we drop support for 1.0.1 in master, so it's dropped for 7.2 then,
> as it will be unsupported then?
Please no.
Ubuntu's 14.04 LTS is on 1.0.1f and gets security backports. EOL is April 2019.
Unless there is a hard reason (API changes or whatever) that PHP 7.2 absolutely cannot live without,
it's a bad idea, as folks on 14.04 or similar (think RHEL etc) then have to either rely on
third parties for updates, or vendor in a newer version, even though their system libssl is still
receiving security updates.
David