From aaaec0fb476bbf875fb81548b443f5eb3127788e Mon Sep 17 00:00:00 2001 From: Zachary Ware Date: Mon, 28 Sep 2026 10:08:28 -0500 Subject: [PATCH] [3.14] gh-158010: Avoid recommending out-of-date OpenSSL in configure doc (GH-158266) (cherry picked from commit 869a50574fffac659dad2996591448a7270ec6f0) Co-authored-by: Zachary Ware Co-authored-by: Hugo van Kemenade <1324225+hugovk@users.noreply.github.com> Co-authored-by: Stan Ulbrych --- Doc/using/configure.rst | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/Doc/using/configure.rst b/Doc/using/configure.rst index 2c0d81d4800701..e190c85920c7b9 100644 --- a/Doc/using/configure.rst +++ b/Doc/using/configure.rst @@ -94,8 +94,7 @@ Dependencies to build optional modules are: - - :mod:`curses` * - `OpenSSL `_ - - | 3.0.18 recommended - | (1.1.1 minimum) + - [6]_ - :mod:`ssl`, :mod:`hashlib` [5]_ * - `SQLite `_ - 3.15.2 @@ -124,6 +123,14 @@ Dependencies to build optional modules are: .. [5] If OpenSSL is not available, the :mod:`hashlib` module will use bundled implementations of several hash functions. See :option:`--with-builtin-hashlib-hashes` for *forcing* usage of OpenSSL. +.. [6] OpenSSL 1.1.1 is the minimum possible version to build against, + but the series is end-of-life and no longer receives public security + fixes. Use the latest patch release of a currently supported LTS + release series (see the `OpenSSL Roadmap + `__), or the package + provided by your operating system if available. Other libraries that + offer an API compatible with OpenSSL 1.1.1 or later may work, but are + not officially supported. Note that the table does not include all optional modules; in particular, platform-specific modules like :mod:`winreg` are not listed here.