4 ms·
A lot of packages can be compiled with a more modern version, though, even if it means more work.
by danielhlockard 11y ago
A lot of packages can be compiled with a more modern version, though, even if it means more work.
- peterwwillis 11y agoThe problem isn't whether modern versions work; the problem is re-testing & re-certifying your application on the platform, because you don't know what features might have changed or broken with the upgrade. It can sometimes be cheaper to pay an engineer to backport or make custom patches if vulns are found in the future.
- yeukhon 11y agoYeah. regression testing, even though it is likely that most people won't see breakage or regression from upgrading to the latest, but some testing should still be done.
- peterwwillis 11y agoSome companies also have entire application suites based on a patchset based on a particular version, so before you can even do your whole regression suite, you first have to re-write your entire patchset to work with the upgrade. In short: Ouch.
- Sanddancer 11y agoAye, but a lot of others won't. Also, there are a number of other vendors, like RedHat and CentOS, that have assumedly committed to continue supporting OpenSSL 0.9.8xx for up to nine more years per their support policy.
- pzone 11y agoThat is bordering on the absurd. Kudos to Red Hat for what they do.
- feld 11y agoCan be, but there are other problems with correctly getting software to compile against the right one when there are multiple OpenSSL's on the system.