Skip to content

Commit 85da051

Browse files
committed
gh-158010: Avoid recommending out-of-date OpenSSL in configure doc
1 parent 1e8ff18 commit 85da051

1 file changed

Lines changed: 9 additions & 2 deletions

File tree

‎Doc/using/configure.rst‎

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -95,8 +95,7 @@ Dependencies to build optional modules are:
9595
-
9696
- :mod:`curses`
9797
* - `OpenSSL <https://openssl-library.org/>`_
98-
- | 3.0.18 recommended
99-
| (1.1.1 minimum)
98+
- [8]_
10099
- :mod:`ssl`, :mod:`hashlib` [6]_
101100
* - `SQLite <https://sqlite.org/>`_
102101
- 3.15.2
@@ -131,6 +130,14 @@ Dependencies to build optional modules are:
131130
See :option:`--with-builtin-hashlib-hashes` for *forcing* usage of OpenSSL.
132131
.. [7] See :option:`--with-zlib` for choosing the backend for the
133132
:mod:`zlib` module.
133+
.. [8] OpenSSL 1.1.1 is the minimum possible version to build against,
134+
but the latest public release of the series has known vulnerabilities.
135+
For best compatibility and security it is recommended to always use
136+
the latest patch release of a current LTS release series (see the
137+
`OpenSSL Roadmap <https://openssl-library.org/roadmap/index.html>`_),
138+
or the package provided by your operating system if available. Other
139+
libraries that offer an API compatible with OpenSSL 1.1.1 or later may
140+
also be usable, but are not officially supported.
134141
135142
Note that the table does not include all optional modules; in particular,
136143
platform-specific modules like :mod:`winreg` are not listed here.

0 commit comments

Comments
 (0)