Re: Cutting support for OpenSSL 1.0.1 and 1.0.2 in 17~?

Поиск
Список
Период
Сортировка
От Daniel Gustafsson
Тема Re: Cutting support for OpenSSL 1.0.1 and 1.0.2 in 17~?
Дата
Msg-id BE7EA829-3213-4B78-9B74-E64C82DF556D@yesql.se
обсуждение исходный текст
Ответ на Re: Cutting support for OpenSSL 1.0.1 and 1.0.2 in 17~?  (Thomas Munro <thomas.munro@gmail.com>)
Ответы Re: Cutting support for OpenSSL 1.0.1 and 1.0.2 in 17~?  (Michael Paquier <michael@paquier.xyz>)
Re: Cutting support for OpenSSL 1.0.1 and 1.0.2 in 17~?  (Thomas Munro <thomas.munro@gmail.com>)
Список pgsql-hackers
> On 7 Sep 2023, at 13:30, Thomas Munro <thomas.munro@gmail.com> wrote:

> I don't like the idea that our *next* release's library version
> horizon is controlled by Red Hat's "ELS" phase.

Agreed.  If we instead fence it by "only non-EOL version" then 1.1.1 is also on
the chopping block for v17 as it goes EOL in 4 days from now with 1.1.1w (which
contains a CVE, going out with a bang).  Not sure what the best strategy is,
but whichever we opt for I think the most important point is to document it
clearly.

> These hypothetical users that want to run
> an OS even older than that and don't know how to get modern crypto
> libraries on it but insist on a shiny new PostgreSQL release and build
> it from source because there are no packages available... don't exist?

Sadly I wouldn't be the least bit surprised if there are 1.0.2 users on modern
operating systems, especially given its LTS status (which OpenSSL hasn't even
capped but sells by "for as long as it remains commercially viable to do so"
basis).  That being said, my gut feeling is that 3.x has gotten pretty good
market penetration.

--
Daniel Gustafsson




В списке pgsql-hackers по дате отправления:

Предыдущее
От: Thomas Munro
Дата:
Сообщение: Re: Cutting support for OpenSSL 1.0.1 and 1.0.2 in 17~?
Следующее
От: Daniel Gustafsson
Дата:
Сообщение: Re: add (void) cast inside advance_aggregates for function ExecEvalExprSwitchContext