From nobody Mon Mar 17 10:37:14 2025 X-Original-To: freebsd-current@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4ZGWcs35kQz5qNyD for ; Mon, 17 Mar 2025 10:37:17 +0000 (UTC) (envelope-from SRS0=p7+9=WE=klop.ws=ronald-lists@realworks.nl) Received: from smtp-relay-int.realworks.nl (smtp-relay-int.realworks.nl [194.109.157.24]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4ZGWcr5xnkz3gs2 for ; Mon, 17 Mar 2025 10:37:16 +0000 (UTC) (envelope-from SRS0=p7+9=WE=klop.ws=ronald-lists@realworks.nl) Authentication-Results: mx1.freebsd.org; none Date: Mon, 17 Mar 2025 11:37:14 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=klop.ws; s=rw2; t=1742207834; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=UKipz/KFEsDgS9HElzK3XvbhfVh2A2+8V+0gV+O2RwE=; b=HyJQQp0kb7wyi/HVJziIyadGTGjhYQYF3dWbXHHixHRb7lj4kJrpZEpH1wgeELWMHN/Ybn SRWYoa8zo8vSRr6oh3F2jwu/hU6QBya17kEK5hdZiyWlAv4ElLnpeXBcIASMYdTa0yGX/W ch1MuKkXTgfAXsMoFLNaendBXl6czjwGjFatSeu9AoFsNvMIy4XmWYugTGFB0QzKm2qpQR Bx4LoAVSV+gtUoT1b7lOUG/OBeylH3A3Hx2oSGhC/0HNLDugCpMtaYHnGh3f17bEAzVUzX FG7y7SnC76x64nzIRfNcVoSNHEny/3M4z7PmWIxIQqwt0FT6cuoMm+d3RnfcwQ== From: Ronald Klop To: "Enji Cooper (yaneurabeya)" Cc: FreeBSD CURRENT , Minsoo Choo Message-ID: <1985613956.4407.1742207834220@localhost> In-Reply-To: <381937C3-47E7-4686-A47A-69A1A1B0F50B@gmail.com> References: <381937C3-47E7-4686-A47A-69A1A1B0F50B@gmail.com> Subject: Re: Expected OpenSSL versions in 14-stable and 15-current List-Id: Discussions about the use of FreeBSD-current List-Archive: https://lists.freebsd.org/archives/freebsd-current List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-current@FreeBSD.org MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_Part_4406_1302921396.1742207834215" X-Mailer: Realworks (742.22) Importance: Normal X-Priority: 3 (Normal) X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; TAGGED_FROM(0.00)[9=WE=klop.ws=ronald-lists]; ASN(0.00)[asn:3265, ipnet:194.109.0.0/16, country:NL] X-Rspamd-Queue-Id: 4ZGWcr5xnkz3gs2 X-Spamd-Bar: ---- ------=_Part_4406_1302921396.1742207834215 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: quoted-printable Van: "Enji Cooper (yaneurabeya)" Datum: maandag, 17 maart 2025 02:34 Aan: Minsoo Choo CC: FreeBSD CURRENT Onderwerp: Re: Expected OpenSSL versions in 14-stable and 15-current >=20 > > On Mar 12, 2025, at 4:19PM, Minsoo Choo wrot= e: > > > > OpenSSL 3.5 LTS alpha has been just released [1]. The expected EOL date= of OpenSSL 3.0 LTS is September 7th 2026 [2]. FreeBSD 15 is expected to be= release in December 2025, and FreeBSD 14.5 is expected to be released in S= eptember 2026. 14-stable will be see its EOL on November 30th, 2028 [3]. > > > > Will FreeBSD 15 contain OpenSSL 3.5 LTS in this December? And for 14-st= able, will it have upgrade to OpenSSL 3.5 LTS before FreeBSD 14.5 or just m= aintain 3.0 LTS with our own bug/security fixes until 14-stable's end-of-li= fe date? > > > > [1] https://github.com/openssl/openssl/releases/tag/openssl-3.5.0-alpha= 1 > > [2] https://en.wikipedia.org/wiki/OpenSSL#Major_version_releases > > [3] https://www.freebsd.org/security/#sup >=20 > Hi Minsoo, > It makes sense to upgrade to 3.5 on CURRENT, but I don=E2=80=99t thin= k we can do that on STABLE branches because of ABI/KBI compatibility guaran= tees. > Cheers, > -Enji >=20 >=20 >=20 According to the OpenSSL versioning definition[1] the change from 3.0 to 3.= 5 is a minor version change which only does "API/ABI compatible feature rel= eases". Although I think it is wise to first update CURRENT and learn from what the= project encounters when doing that action before deciding about 14-stable. [1] https://openssl-library.org/policies/releasestrat/index.html Regards, Ronald. =20 ------=_Part_4406_1302921396.1742207834215 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable

Van: "Enji Cooper (yaneurabeya)" <yaneurabeya@gmail.= com>
Datum: maandag, 17 maart 2025 02:34
Aan: Minsoo Choo <minsoochoo0122@proton.me>
CC: FreeBSD CURRENT <freebsd-current@freebsd.org> Onderwerp: Re: Expected OpenSSL versions in 14-stable and = 15-current


> On Mar 12, 2025, at 4:19PM, Minsoo Choo <minsoochoo0122@proton.me&g= t; wrote:
>
> OpenSSL 3.5 LTS alpha has been just released [1]. The expected EOL dat= e of OpenSSL 3.0 LTS is September 7th 2026 [2]. FreeBSD 15 is expected to b= e release in December 2025, and FreeBSD 14.5 is expected to be released in = September 2026. 14-stable will be see its EOL on November 30th, 2028 [3]. >
> Will FreeBSD 15 contain OpenSSL 3.5 LTS in this December? And for 14-s= table, will it have upgrade to OpenSSL 3.5 LTS before FreeBSD 14.5 or just = maintain 3.0 LTS with our own bug/security fixes until 14-stable's end-of-l= ife date?
>
> [1] https://github.com/openssl/openssl/releases/tag/openssl-3.5.= 0-alpha1
> [2] https://en.wikipedia.org/wiki/OpenSSL#Major_version_releases
> [3] https://www.free= bsd.org/security/#sup

Hi Minsoo,
    It makes sense to upgrade to 3.5 on CURRENT, but I = don=E2=80=99t think we can do that on STABLE branches because of ABI/KBI co= mpatibility guarantees.
Cheers,
-Enji



According to the OpenSSL versioning definition[1] the change from 3.0 to 3.= 5 is a minor version change which only does "API/ABI compatible feature rel= eases".
Although I think it is wise to first update CURRENT and learn from what the= project encounters when doing that action before deciding about 14-stable.=

[1] https://openssl-library.org/policies/releasestrat/index.html

Regards,
Ronald.
  ------=_Part_4406_1302921396.1742207834215--