Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 17 Mar 2025 11:37:14 +0100 (CET)
From:      Ronald Klop <ronald-lists@klop.ws>
To:        "Enji Cooper (yaneurabeya)" <yaneurabeya@gmail.com>
Cc:        FreeBSD CURRENT <freebsd-current@freebsd.org>, Minsoo Choo <minsoochoo0122@proton.me>
Subject:   Re: Expected OpenSSL versions in 14-stable and 15-current
Message-ID:  <1985613956.4407.1742207834220@localhost>
In-Reply-To: <381937C3-47E7-4686-A47A-69A1A1B0F50B@gmail.com>
References:  <bI4bdFQ8wc8N5i6E_TIS7DpLvWi_FgxzbgMWiPeyCC0-diQtjtUQ_fT75OFtZweiQmU8_iyqdAkOj9M_oNRQdSAQeD76Tov-qehCQ746oSs=@proton.me> <381937C3-47E7-4686-A47A-69A1A1B0F50B@gmail.com>

index | next in thread | previous in thread | raw e-mail

[-- Attachment #1 --]
Van: "Enji Cooper (yaneurabeya)" <yaneurabeya@gmail.com>
Datum: maandag, 17 maart 2025 02:34
Aan: Minsoo Choo <minsoochoo0122@proton.me>
CC: FreeBSD CURRENT <freebsd-current@freebsd.org>
Onderwerp: Re: Expected OpenSSL versions in 14-stable and 15-current
> 
> > On Mar 12, 2025, at 4:19PM, Minsoo Choo <minsoochoo0122@proton.me> wrote:
> >
> > OpenSSL 3.5 LTS alpha has been just released [1]. The expected EOL date of OpenSSL 3.0 LTS is September 7th 2026 [2]. FreeBSD 15 is expected to be release in December 2025, and FreeBSD 14.5 is expected to be released in September 2026. 14-stable will be see its EOL on November 30th, 2028 [3].
> >
> > Will FreeBSD 15 contain OpenSSL 3.5 LTS in this December? And for 14-stable, will it have upgrade to OpenSSL 3.5 LTS before FreeBSD 14.5 or just maintain 3.0 LTS with our own bug/security fixes until 14-stable's end-of-life date?
> >
> > [1] https://github.com/openssl/openssl/releases/tag/openssl-3.5.0-alpha1
> > [2] https://en.wikipedia.org/wiki/OpenSSL#Major_version_releases
> > [3] https://www.freebsd.org/security/#sup
> 
> Hi Minsoo,
>     It makes sense to upgrade to 3.5 on CURRENT, but I don’t think we can do that on STABLE branches because of ABI/KBI compatibility guarantees.
> Cheers,
> -Enji
> 
> 
> 


According to the OpenSSL versioning definition[1] the change from 3.0 to 3.5 is a minor version change which only does "API/ABI compatible feature releases".
Although I think it is wise to first update CURRENT and learn from what the project encounters when doing that action before deciding about 14-stable.

[1] https://openssl-library.org/policies/releasestrat/index.html

Regards,
Ronald.
 
[-- Attachment #2 --]
<html><head></head><body><br>
<p><strong>Van:</strong> "Enji Cooper (yaneurabeya)" &lt;yaneurabeya@gmail.com&gt;<br>
<strong>Datum:</strong> maandag, 17 maart 2025 02:34<br>
<strong>Aan:</strong> Minsoo Choo &lt;minsoochoo0122@proton.me&gt;<br>
<strong>CC:</strong> FreeBSD CURRENT &lt;freebsd-current@freebsd.org&gt;<br>
<strong>Onderwerp:</strong> Re: Expected OpenSSL versions in 14-stable and 15-current</p>

<blockquote style="padding-right: 0px; padding-left: 5px; margin-left: 5px; border-left: #000000 2px solid; margin-right: 0px">
<div class="MessageRFC822Viewer" id="P">
<div class="TextPlainViewer" id="P.P"><br>
&gt; On Mar 12, 2025, at 4:19PM, Minsoo Choo &lt;minsoochoo0122@proton.me&gt; wrote:<br>
&gt;<br>
&gt; OpenSSL 3.5 LTS alpha has been just released [1]. The expected EOL date of OpenSSL 3.0 LTS is September 7th 2026 [2]. FreeBSD 15 is expected to be release in December 2025, and FreeBSD 14.5 is expected to be released in September 2026. 14-stable will be see its EOL on November 30th, 2028 [3].<br>
&gt;<br>
&gt; Will FreeBSD 15 contain OpenSSL 3.5 LTS in this December? And for 14-stable, will it have upgrade to OpenSSL 3.5 LTS before FreeBSD 14.5 or just maintain 3.0 LTS with our own bug/security fixes until 14-stable's end-of-life date?<br>
&gt;<br>
&gt; [1] <a href="https://github.com/openssl/openssl/releases/tag/openssl-3.5.0-alpha1">https://github.com/openssl/openssl/releases/tag/openssl-3.5.0-alpha1</a><br>;
&gt; [2] <a href="https://en.wikipedia.org/wiki/OpenSSL#Major_version_releases">https://en.wikipedia.org/wiki/OpenSSL#Major_version_releases</a><br>;
&gt; [3] <a href="https://www.freebsd.org/security/#sup">https://www.freebsd.org/security/#sup</a><br>;
<br>
Hi Minsoo,<br>
&nbsp;&nbsp;&nbsp;&nbsp;It makes sense to upgrade to 3.5 on CURRENT, but I don’t think we can do that on STABLE branches because of ABI/KBI compatibility guarantees.<br>
Cheers,<br>
-Enji</div>

<hr></div>
</blockquote>
<br>
<br>
According to the OpenSSL versioning definition[1] the change from 3.0 to 3.5 is a minor version change which only does "API/ABI compatible feature releases".<br>
Although I think it is wise to first update CURRENT and learn from what the project encounters when doing that action before deciding about 14-stable.<br>
<br>
[1]&nbsp;<a href="https://openssl-library.org/policies/releasestrat/index.html">https://openssl-library.org/policies/releasestrat/index.html</a><br>;
<br>
Regards,<br>
Ronald.<br>
&nbsp;</body></html>
help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?1985613956.4407.1742207834220>