There's already a `vendor/openssl-3.0` branch in their git repo, but those changes look like way too big to release in just a security patch for 13.2.
FreeBSD 14.0 is scheduled for July (2 months before OpenSSL 1.1.1 EOL), so maybe we'll get OpenSSL 3.0 in that release, and then a backport with the OpenSSL upgrade.
But the timelines seem too tight, so I'm not too optimistic.
Comments
OpenSSL 1.1.1 is deprecated and loses security patches in under 6 months.
I'm curious how this will be handled.
There's already a `vendor/openssl-3.0` branch in their git repo, but those changes look like way too big to release in just a security patch for 13.2.
FreeBSD 14.0 is scheduled for July (2 months before OpenSSL 1.1.1 EOL), so maybe we'll get OpenSSL 3.0 in that release, and then a backport with the OpenSSL upgrade.
But the timelines seem too tight, so I'm not too optimistic.
The same way as Ubuntu 20.04 LTS, which is supported by the vendor for five years (2025):
* https://packages.ubuntu.com/focal/openssl
Or Debian 11 (bullseye), which has LTS support until 2026:
* https://packages.debian.org/bullseye/openssl
* https://en.wikipedia.org/wiki/Debian_version_history