Mailing List Archive

OpenSSL 1.1 - don't upgrade (yet)
Hi together,

OpenSSL version 1.1 is out since August 25th (https://www.openssl.org/source/).

* Please do not upgrade yet! *

OpenSSL 1.1 breaks many APIs used by ucspi-ssl and other SW based on previous versions.

At least me, I need to cross-check compatibility with ucspi-0.97.

Probably it is better to wait until TLS (1.3) will incorporate ed25519 (DJB's curve) for ECC ( https://tools.ietf.org/html/draft-ietf-tls-rfc4492bis-07) and a subsequent new OpenSSL release supports it.

Best regards.
--eh.

PS. For German language enabled readers: http://blog.fefe.de/?ts=a93f56bb

Dr. Erwin Hoffmann | FEHCom | http://www.fehcom.de | PGP Key-Id: EE00CF65
Re: OpenSSL 1.1 - don't upgrade (yet) [ In reply to ]
Hi Erwin.

On Sat, 27 Aug 2016 18:55:32 +0200, Erwin Hoffmann wrote:
> OpenSSL 1.1 breaks many APIs used by ucspi-ssl and other SW based on
> previous versions.

Does that mean that OpenSSL 1.1 is utterly useless ? :)

-Eg. I would certainly not update it, if it breaks *any* API, because who knows what might silently no longer work, if I do ?

Maybe most of my server software would work, but what if I had software installed, that I use, which I might not notice wouldn't work - it would take a lot of time before realizing what no longer works and perhaps longer to figure out why.

Thank you for sending out a warning early; the best cure is to prevent disease. =)


Love
Jens