Hi Everyone,available. After that, fixes will only be available via support contract (which I can facilitate, but it is not a trivial cost because of the OpenSSL extended support contract cost). ITUGLIB will stop building 1.1.1 releases when OpenSSL stops delivering
I want to remind people that the OpenSSL 1.1.1 version thread goes off support on Sept 11, 2023, which is 204 days from now - just over 6 months, meaning no security fixes will be available after that time. Currently, only security fixes are made
Migration to OpenSSL 3.x as soon as you can is recommended. There are a few reasons:ITUGLIB repository.
1. Functional and security fix support is currently available.
2. Upgrading to 3.x generally only requires recompile for your application. 3. OpenSSL versions 3.x, 1.1.1, and 1.0.2 can generally communicate with each other, as long as common cyphers are available at both ends - which they generally are. You do have to be careful to ensure that your certificates are usable on all versions.
4. The 3.x thread is identical to the standard OpenSSL code base without change for NonStop. You can easily build OpenSSL yourself from git or with the standard OpenSSL tarballs. 1.1.1 requires that someone (usually me) apply patches manually to the
5. An added bonus for git users on L-series (as well as OpenSSL users), you do not need to run PRNDG, because the NonStop build supports the x86 hardware random number generator.
Regards,
Randall Becker
On Behalf of the ITUGLIB Technical Committee
On Sunday, February 19, 2023 at 6:37:59 p.m. UTC-5, Randall wrote:available. After that, fixes will only be available via support contract (which I can facilitate, but it is not a trivial cost because of the OpenSSL extended support contract cost). ITUGLIB will stop building 1.1.1 releases when OpenSSL stops delivering
Hi Everyone,
I want to remind people that the OpenSSL 1.1.1 version thread goes off support on Sept 11, 2023, which is 204 days from now - just over 6 months, meaning no security fixes will be available after that time. Currently, only security fixes are made
versions.Migration to OpenSSL 3.x as soon as you can is recommended. There are a few reasons:
1. Functional and security fix support is currently available.
2. Upgrading to 3.x generally only requires recompile for your application.
3. OpenSSL versions 3.x, 1.1.1, and 1.0.2 can generally communicate with each other, as long as common cyphers are available at both ends - which they generally are. You do have to be careful to ensure that your certificates are usable on all
ITUGLIB repository.4. The 3.x thread is identical to the standard OpenSSL code base without change for NonStop. You can easily build OpenSSL yourself from git or with the standard OpenSSL tarballs. 1.1.1 requires that someone (usually me) apply patches manually to the
5. An added bonus for git users on L-series (as well as OpenSSL users), you do not need to run PRNDG, because the NonStop build supports the x86 hardware random number generator.
Regards,Edit: Should be PRNGD
Randall Becker
On Behalf of the ITUGLIB Technical Committee
On Monday, February 20, 2023 at 12:30:31 p.m. UTC-5, Randall wrote:available. After that, fixes will only be available via support contract (which I can facilitate, but it is not a trivial cost because of the OpenSSL extended support contract cost). ITUGLIB will stop building 1.1.1 releases when OpenSSL stops delivering
On Sunday, February 19, 2023 at 6:37:59 p.m. UTC-5, Randall wrote:
Hi Everyone,
I want to remind people that the OpenSSL 1.1.1 version thread goes off support on Sept 11, 2023, which is 204 days from now - just over 6 months, meaning no security fixes will be available after that time. Currently, only security fixes are made
versions.Migration to OpenSSL 3.x as soon as you can is recommended. There are a few reasons:
1. Functional and security fix support is currently available.
2. Upgrading to 3.x generally only requires recompile for your application.
3. OpenSSL versions 3.x, 1.1.1, and 1.0.2 can generally communicate with each other, as long as common cyphers are available at both ends - which they generally are. You do have to be careful to ensure that your certificates are usable on all
the ITUGLIB repository.4. The 3.x thread is identical to the standard OpenSSL code base without change for NonStop. You can easily build OpenSSL yourself from git or with the standard OpenSSL tarballs. 1.1.1 requires that someone (usually me) apply patches manually to
September 2026. ITUGLIB will be building and deploying both. The OpenSSL 3.1 notice should come out in the next day or two.5. An added bonus for git users on L-series (as well as OpenSSL users), you do not need to run PRNDG, because the NonStop build supports the x86 hardware random number generator.
OpenSSL 3.1 is in the pipeline now. This release seems to be primarily a result of FIPS-140-3 standards instead of the FIPS-140-2 used in 3.0. A bit of a surprise is that OpenSSL 3.1 planned support (LTS) runs until March 2025 while 3.0 runs untilRegards,Edit: Should be PRNGD
Randall Becker
On Behalf of the ITUGLIB Technical Committee
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 546 |
Nodes: | 16 (0 / 16) |
Uptime: | 168:44:55 |
Calls: | 10,385 |
Calls today: | 2 |
Files: | 14,057 |
Messages: | 6,416,551 |