Apache HTTP Server dependency on OpenSSL
Subject: Apache HTTP Server dependency on OpenSSL
Good day from Singapore,
I read that Apache HTTP Server depends on/requires OpenSSL 1.1.1 to operate a TLS 1.3 web server.
Can we use OpenSSL 3.0.7 instead of OpenSSL 1.1.1? Is it supported?
OpenSSL versions 3.0.0 through 3.0.6 have CVE-2022-3602 and CVE-2022-3786 security vulnerabilities, so we need to avoid these versions.
Please advise.
Thank you.
Regards,
Mr. Turritopsis Dohrnii Teo En Ming
Targeted Individual in Singapore
Blogs:
https://tdtemcerts.blogspot.com
https://tdtemcerts.wordpress.com
REFERENCES
===========
[01] https://lists.apache.org/thread/qxjkt4h7r605s7o07fhnlxxdrgfnkzz9
[02] https://www.mail-archive.com/users@httpd.apache.org/msg69011.html
[03] https://marc.info/?l=apache-httpd-users&m=166797810427491&w=2
[05] https://lists.apache.org/thread/8816pxfrs8mfw57hx4jn2vwmg6z79r6r
[06] https://www.mail-archive.com/dev@httpd.apache.org/msg76897.html
[07] https://marc.info/?l=apache-httpd-dev&m=166797863827753&w=2
Comments
Post a Comment