]> git.ipfire.org Git - thirdparty/haproxy.git/commitdiff
DOC: stop supporting OpenSSL version < 1.1.1
authorWilliam Lallemand <wlallemand@haproxy.com>
Mon, 3 Aug 2026 12:38:34 +0000 (14:38 +0200)
committerWilliam Lallemand <wlallemand@haproxy.com>
Mon, 3 Aug 2026 12:42:31 +0000 (14:42 +0200)
Remove versions of OpenSSL before 1.1.1 from the documentation, 1.1.1 is
the minimal requirement.

INSTALL

diff --git a/INSTALL b/INSTALL
index afe7def4603b3c6e45a44d96f75694c95a21984c..5a4a4cf6ea0c8b27dd6f86d6f41675469a62ff43 100644 (file)
--- a/INSTALL
+++ b/INSTALL
@@ -237,18 +237,18 @@ to forcefully enable it using "USE_LIBCRYPT=1".
 -----------------
 For SSL/TLS, it is necessary to use a cryptography library. HAProxy currently
 supports the OpenSSL library, and is known to build and work with branches
-1.0.0, 1.0.1, 1.0.2, 1.1.0, 1.1.1, and 3.0 to 4.0. It is recommended to use
-at least OpenSSL 1.1.1 to have support for all SSL keywords and configuration
-in HAProxy. OpenSSL follows a long-term support cycle similar to HAProxy's,
-and each of the branches above receives its own fixes, without forcing you to
-upgrade to another branch. There is no excuse for staying vulnerable by not
-applying a fix available for your version. There is always a small risk of
-regression when jumping from one branch to another one, especially when it's
-very new, so it's preferable to observe for a while if you use a different
-version than your system's defaults. Specifically, it has been well established
-that OpenSSL 3.0 can be 2 to 20 times slower than earlier versions on
-multiprocessor systems due to design issues that cannot be fixed without a
-major redesign, so in this case upgrading should be carefully thought about
+1.1.1, and 3.0 to 4.0. It is recommended to use at least OpenSSL 1.1.1 to have
+support for all SSL keywords and configuration in HAProxy. OpenSSL follows a
+long-term support cycle similar to HAProxy's, and each of the branches above
+receives its own fixes, without forcing you to upgrade to another branch. There
+is no excuse for staying vulnerable by not applying a fix available for your
+version. There is always a small risk of regression when jumping from one
+branch to another one, especially when it's very new, so it's preferable to
+observe for a while if you use a different version than your system's defaults.
+Specifically, it has been well established that OpenSSL 3.0 can be 2 to 20
+times slower than earlier versions on multiprocessor systems due to design
+issues that cannot be fixed without a major redesign, so in this case upgrading
+should be carefully thought about
 (please see https://github.com/openssl/openssl/issues/20286 and
 https://github.com/openssl/openssl/issues/17627). If a migration to 3.x is
 mandated by support reasons, at least 3.1 recovers a small fraction of this