[FFe] openssl 1.1.1
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
openssl (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
python2.7 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
python3.6 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Merge openssl 1.1.1 from debian unstable.
OpenSSL 1.1.1 is now out, with TLS1.3 support, and is the new upstream LTS release.
Resulting in the following changes in Ubuntu:
- openssl moves from 1.1.0 series to 1.1.1 LTS series
- TLS1.3 is enabled, and used by default, when possible. Major feature.
- All existing delta, and minimally accepted key sizes, and minimally accepted protocol versions remain the same.
Proposed package is in https:/
===
Ubuntu delta summary versus debian unstable in this merge:
- Replace duplicate files in the doc directory with symlinks.
- debian/
+ Display a system restart required notification on libssl1.1
upgrade on servers.
+ Use a different priority for libssl1.
on whether a desktop, or server dist-upgrade is being performed.
- Revert "Enable system default config to enforce TLS1.2 as a
minimum" & "Increase default security level from 1 to 2".
- Further decrease security level from 1 to 0, for compatibility with
openssl 1.0.2.
These mitigate most of the runtime incompatibilities, and ensure client<->server compatibility between 1.1.1, 1.1.0, and 1.0.2 series and thus one can continue to mix & match xenial/
tags: | added: needs-debian-merge upgrade-software-version |
description: | updated |
description: | updated |
Changed in openssl (Ubuntu): | |
status: | Incomplete → New |
tags: | added: block-proposed |
tags: | added: block-proposed |
tags: | removed: block-proposed |
Changed in openssl (Ubuntu): | |
status: | Triaged → Fix Committed |
Changed in python2.7 (Ubuntu): | |
status: | Triaged → Fix Committed |
Changed in python3.6 (Ubuntu): | |
status: | Triaged → Fix Committed |
Big ACK from the security team. We would like to see this backported into bionic at some point and having it in cosmic first would allow us to identify and fix any issues.