From c5c14bbd05ff3412dc70a19ff7eceb877a7690bd Mon Sep 17 00:00:00 2001 From: Zachary Ware Date: Mon, 28 Sep 2026 10:08:28 -0500 Subject: [PATCH] [3.13] gh-158010: Avoid recommending out-of-date OpenSSL in configure doc (GH-158266) (cherry picked from commit 869a50574fffac659dad2996591448a7270ec6f0) Co-authored-by: Zachary Ware Co-authored-by: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com> Co-authored-by: Stan Ulbrych --- Doc/using/configure.rst | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/Doc/using/configure.rst b/Doc/using/configure.rst index fde0ddba9f9d29..27e0e2784bb313 100644 --- a/Doc/using/configure.rst +++ b/Doc/using/configure.rst @@ -22,8 +22,14 @@ Features and minimum versions required to build CPython: * Support for threads. -* OpenSSL 1.1.1 is the minimum version and OpenSSL 3.0.18 is the recommended - minimum version for the :mod:`ssl` and :mod:`hashlib` extension modules. +* OpenSSL 1.1.1 is the minimum possible version to build the :mod:`ssl` and + :mod:`hashlib` extension modules against, but the series is end-of-life and + no longer receives public security fixes. Use the latest patch release of a + currently supported LTS release series (see the `OpenSSL Roadmap + `__), or the package + provided by your operating system if available. Other libraries that offer + an API compatible with OpenSSL 1.1.1 or later may work, but are not + officially supported. * SQLite 3.15.2 for the :mod:`sqlite3` extension module.