Using SSL v2 (and even v3) is essentially as secure as using plaintext. The only use case I'd see for these old protocols would be to connect to some extremely cursed antique software which only supports these old protocols and don't allow to disable them. In that case, the person wanting to interact with said cursed software could simply use an older release of curl.
if you also have BoringSSL and AWS-LC support, then I don’t see much reason to keep supporting ancient OpenSSL versions. But then, curl and Netty are used very differently.
just wait until you learn how slow corporate life is moving towards never OpenSSL versions. You can still get paid support from OpenSSL for at least 1.1.1 release.
@ondrej in general LibreSSL is far behind all the other forks in the family feature wise and I expect that it basically never will catch up. I recommend not using LibreSSL. Plain QUIC works however fine with LibreSSL with ngtcp2.
in my special experience (industry OT), if you don't cut the support, no one else will. You have to force push the updates in that kind of legacy systems
Emilion
in reply to daniel:// stenberg:// • • •Samantaz Fox
in reply to daniel:// stenberg:// • • •vsz
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to vsz • • •Samantaz Fox
in reply to daniel:// stenberg:// • • •Programmer 832-529 🍅
in reply to daniel:// stenberg:// • • •Chris Vest
in reply to daniel:// stenberg:// • • •SpaceLifeForm
in reply to daniel:// stenberg:// • • •Quentin Pradet
in reply to daniel:// stenberg:// • • •Amazon Linux 2 still ships with OpenSSL 1.0.2! Is 1.0.2 still supported by curl?
docs.aws.amazon.com/linux/al20…
OpenSSL 3 - Amazon Linux 2023
docs.aws.amazon.comHans-Christian
in reply to daniel:// stenberg:// • • •Stefan Eissing
in reply to daniel:// stenberg:// • • •Ondřej Surý
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Ondřej Surý • • •Ondřej Surý
in reply to daniel:// stenberg:// • • •Hmm, dropping LibreSSL support completely. That's an interesting thought…
.
But to answer your original question - dropping OpenSSL <= 1.1.1 support is reasonable, unless you care about RHEL 8.
daniel:// stenberg://
in reply to Ondřej Surý • • •Santiago Piqueras
in reply to daniel:// stenberg:// • • •NGC-Ollie
in reply to daniel:// stenberg:// • • •