From: William Lallemand Date: Mon, 3 Aug 2026 12:38:34 +0000 (+0200) Subject: DOC: stop supporting OpenSSL version < 1.1.1 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=672e2722f128e29a5ad3b2ae9d4ef746b5d994d6;p=thirdparty%2Fhaproxy.git DOC: stop supporting OpenSSL version < 1.1.1 Remove versions of OpenSSL before 1.1.1 from the documentation, 1.1.1 is the minimal requirement. --- diff --git a/INSTALL b/INSTALL index afe7def46..5a4a4cf6e 100644 --- a/INSTALL +++ b/INSTALL @@ -237,18 +237,18 @@ to forcefully enable it using "USE_LIBCRYPT=1". ----------------- For SSL/TLS, it is necessary to use a cryptography library. HAProxy currently supports the OpenSSL library, and is known to build and work with branches -1.0.0, 1.0.1, 1.0.2, 1.1.0, 1.1.1, and 3.0 to 4.0. It is recommended to use -at least OpenSSL 1.1.1 to have support for all SSL keywords and configuration -in HAProxy. OpenSSL follows a long-term support cycle similar to HAProxy's, -and each of the branches above receives its own fixes, without forcing you to -upgrade to another branch. There is no excuse for staying vulnerable by not -applying a fix available for your version. There is always a small risk of -regression when jumping from one branch to another one, especially when it's -very new, so it's preferable to observe for a while if you use a different -version than your system's defaults. Specifically, it has been well established -that OpenSSL 3.0 can be 2 to 20 times slower than earlier versions on -multiprocessor systems due to design issues that cannot be fixed without a -major redesign, so in this case upgrading should be carefully thought about +1.1.1, and 3.0 to 4.0. It is recommended to use at least OpenSSL 1.1.1 to have +support for all SSL keywords and configuration in HAProxy. OpenSSL follows a +long-term support cycle similar to HAProxy's, and each of the branches above +receives its own fixes, without forcing you to upgrade to another branch. There +is no excuse for staying vulnerable by not applying a fix available for your +version. There is always a small risk of regression when jumping from one +branch to another one, especially when it's very new, so it's preferable to +observe for a while if you use a different version than your system's defaults. +Specifically, it has been well established that OpenSSL 3.0 can be 2 to 20 +times slower than earlier versions on multiprocessor systems due to design +issues that cannot be fixed without a major redesign, so in this case upgrading +should be carefully thought about (please see https://github.com/openssl/openssl/issues/20286 and https://github.com/openssl/openssl/issues/17627). If a migration to 3.x is mandated by support reasons, at least 3.1 recovers a small fraction of this