Date: Mon, 17 Mar 2025 11:37:14 +0100 (CET) From: Ronald Klop <ronald-lists@klop.ws> To: "Enji Cooper (yaneurabeya)" <yaneurabeya@gmail.com> Cc: FreeBSD CURRENT <freebsd-current@freebsd.org>, Minsoo Choo <minsoochoo0122@proton.me> Subject: Re: Expected OpenSSL versions in 14-stable and 15-current Message-ID: <1985613956.4407.1742207834220@localhost> In-Reply-To: <381937C3-47E7-4686-A47A-69A1A1B0F50B@gmail.com> References: <bI4bdFQ8wc8N5i6E_TIS7DpLvWi_FgxzbgMWiPeyCC0-diQtjtUQ_fT75OFtZweiQmU8_iyqdAkOj9M_oNRQdSAQeD76Tov-qehCQ746oSs=@proton.me> <381937C3-47E7-4686-A47A-69A1A1B0F50B@gmail.com>
index | next in thread | previous in thread | raw e-mail
[-- Attachment #1 --] Van: "Enji Cooper (yaneurabeya)" <yaneurabeya@gmail.com> Datum: maandag, 17 maart 2025 02:34 Aan: Minsoo Choo <minsoochoo0122@proton.me> CC: FreeBSD CURRENT <freebsd-current@freebsd.org> Onderwerp: Re: Expected OpenSSL versions in 14-stable and 15-current > > > On Mar 12, 2025, at 4:19PM, Minsoo Choo <minsoochoo0122@proton.me> wrote: > > > > OpenSSL 3.5 LTS alpha has been just released [1]. The expected EOL date of OpenSSL 3.0 LTS is September 7th 2026 [2]. FreeBSD 15 is expected to be release in December 2025, and FreeBSD 14.5 is expected to be released in September 2026. 14-stable will be see its EOL on November 30th, 2028 [3]. > > > > Will FreeBSD 15 contain OpenSSL 3.5 LTS in this December? And for 14-stable, will it have upgrade to OpenSSL 3.5 LTS before FreeBSD 14.5 or just maintain 3.0 LTS with our own bug/security fixes until 14-stable's end-of-life date? > > > > [1] https://github.com/openssl/openssl/releases/tag/openssl-3.5.0-alpha1 > > [2] https://en.wikipedia.org/wiki/OpenSSL#Major_version_releases > > [3] https://www.freebsd.org/security/#sup > > Hi Minsoo, > It makes sense to upgrade to 3.5 on CURRENT, but I don’t think we can do that on STABLE branches because of ABI/KBI compatibility guarantees. > Cheers, > -Enji > > > According to the OpenSSL versioning definition[1] the change from 3.0 to 3.5 is a minor version change which only does "API/ABI compatible feature releases". Although I think it is wise to first update CURRENT and learn from what the project encounters when doing that action before deciding about 14-stable. [1] https://openssl-library.org/policies/releasestrat/index.html Regards, Ronald. [-- Attachment #2 --] <html><head></head><body><br> <p><strong>Van:</strong> "Enji Cooper (yaneurabeya)" <yaneurabeya@gmail.com><br> <strong>Datum:</strong> maandag, 17 maart 2025 02:34<br> <strong>Aan:</strong> Minsoo Choo <minsoochoo0122@proton.me><br> <strong>CC:</strong> FreeBSD CURRENT <freebsd-current@freebsd.org><br> <strong>Onderwerp:</strong> Re: Expected OpenSSL versions in 14-stable and 15-current</p> <blockquote style="padding-right: 0px; padding-left: 5px; margin-left: 5px; border-left: #000000 2px solid; margin-right: 0px"> <div class="MessageRFC822Viewer" id="P"> <div class="TextPlainViewer" id="P.P"><br> > On Mar 12, 2025, at 4:19PM, Minsoo Choo <minsoochoo0122@proton.me> wrote:<br> ><br> > OpenSSL 3.5 LTS alpha has been just released [1]. The expected EOL date of OpenSSL 3.0 LTS is September 7th 2026 [2]. FreeBSD 15 is expected to be release in December 2025, and FreeBSD 14.5 is expected to be released in September 2026. 14-stable will be see its EOL on November 30th, 2028 [3].<br> ><br> > Will FreeBSD 15 contain OpenSSL 3.5 LTS in this December? And for 14-stable, will it have upgrade to OpenSSL 3.5 LTS before FreeBSD 14.5 or just maintain 3.0 LTS with our own bug/security fixes until 14-stable's end-of-life date?<br> ><br> > [1] <a href="https://github.com/openssl/openssl/releases/tag/openssl-3.5.0-alpha1">https://github.com/openssl/openssl/releases/tag/openssl-3.5.0-alpha1</a><br> > [2] <a href="https://en.wikipedia.org/wiki/OpenSSL#Major_version_releases">https://en.wikipedia.org/wiki/OpenSSL#Major_version_releases</a><br> > [3] <a href="https://www.freebsd.org/security/#sup">https://www.freebsd.org/security/#sup</a><br> <br> Hi Minsoo,<br> It makes sense to upgrade to 3.5 on CURRENT, but I don’t think we can do that on STABLE branches because of ABI/KBI compatibility guarantees.<br> Cheers,<br> -Enji</div> <hr></div> </blockquote> <br> <br> According to the OpenSSL versioning definition[1] the change from 3.0 to 3.5 is a minor version change which only does "API/ABI compatible feature releases".<br> Although I think it is wise to first update CURRENT and learn from what the project encounters when doing that action before deciding about 14-stable.<br> <br> [1] <a href="https://openssl-library.org/policies/releasestrat/index.html">https://openssl-library.org/policies/releasestrat/index.html</a><br> <br> Regards,<br> Ronald.<br> </body></html>help
Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?1985613956.4407.1742207834220>
