• Fwd: Heads-up: upcoming security/openssl 3.5 update

    From Bernard Spil@brnrd@freebsd.org to muc.lists.freebsd.ports on Fri Sep 11 08:09:13 2026
    From Newsgroup: muc.lists.freebsd.ports

    Hi all,

    As per OpenSSL's releasse strategy[1], OpenSSL 3.0 is End-of-Life per 2026-09-07. There will be no more public releases that fix known vulnerabilities. Vulnerabilities in OpenSSL 3.0 will still be reported
    by the project.
    This prompts me to change the default security/openssl to the next LTS
    version 3.5.

    Personally, I'd like the security/openssl port to track "latest LTS
    after first patch" of OpenSSL (e.g. 4.2.1), but for now I intend to
    track "oldest not end-of-life LTS in use in FreeBSD-base". Let me know
    your preference and motivation.

    Upcoming changes, likely during 2026Q4:

    1. With the next security or patch release of OpenSSL, the
    security/openssl port will change to 3.5
    2. The security/openssl port will be renamed to security/openssl30 for
    those requiring, the now with known vulnerabilities, 3.0 branch.
    3. The security/openssl30 port will be resurrected (i.e. removed) from
    MOVED
    4. The (new) security/openssl port will use MASTERDIR concept to include
    the security/openssl35 port without the PKGNAMESUFFIX
    5. An UPDATING entry will be created for the change in version and SHLIB version prompting users of the port to upgrade all dependent ports.
    6. Future upgrades to the next LTS version, currently planned for
    2030Q2, will follow the MASTERDIR concept.

    For people using
    DEFAULT_VERSIONS=ssl=openssl35
    no change is required until 2030Q2 when 3.5 goes end-of-life.

    With kind regards, Bernard Spil (maintainer of security/openssl* ports).

    1: https://openssl-library.org/policies/releasestrat/index.html


    --
    Posted automagically by a mail2news gateway at muc.de e.V.
    Please direct questions, flames, donations, etc. to news-admin@muc.de
    --- Synchronet 3.22a-Linux NewsLink 1.2