Skip to content

Commit b1a5fc1

Browse files
zwarehugovkStanFromIreland
authored
[3.15] gh-158010: Avoid recommending out-of-date OpenSSL in configure doc (GH-158266) (#158349)
Co-authored-by: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com> Co-authored-by: Stan Ulbrych <stan@python.org>
1 parent 50c7a59 commit b1a5fc1

1 file changed

Lines changed: 9 additions & 2 deletions

File tree

‎Doc/using/configure.rst‎

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -94,8 +94,7 @@ Dependencies to build optional modules are:
9494
-
9595
- :mod:`curses`
9696
* - `OpenSSL <https://openssl-library.org/>`_
97-
- | 3.0.18 recommended
98-
| (1.1.1 minimum)
97+
- [6]_
9998
- :mod:`ssl`, :mod:`hashlib` [5]_
10099
* - `SQLite <https://sqlite.org/>`_
101100
- 3.15.2
@@ -124,6 +123,14 @@ Dependencies to build optional modules are:
124123
.. [5] If OpenSSL is not available, the :mod:`hashlib` module will use
125124
bundled implementations of several hash functions.
126125
See :option:`--with-builtin-hashlib-hashes` for *forcing* usage of OpenSSL.
126+
.. [6] OpenSSL 1.1.1 is the minimum possible version to build against,
127+
but the series is end-of-life and no longer receives public security
128+
fixes. Use the latest patch release of a currently supported LTS
129+
release series (see the `OpenSSL Roadmap
130+
<https://openssl-library.org/roadmap/index.html>`__), or the package
131+
provided by your operating system if available. Other libraries that
132+
offer an API compatible with OpenSSL 1.1.1 or later may work, but are
133+
not officially supported.
127134
128135
Note that the table does not include all optional modules; in particular,
129136
platform-specific modules like :mod:`winreg` are not listed here.

0 commit comments

Comments
 (0)