On 2025-07-13 15:10:50 [+0200], Simon Josefsson wrote: > Sebastian Andrzej Siewior <[email protected]> writes: > > > --- openssl-3.0.16/CHANGES.md 2025-02-11 15:47:41.000000000 +0100 > > +++ openssl-3.0.17/CHANGES.md 2025-07-01 14:11:11.000000000 +0200 > ... > > + * SSLv3 is by default disabled at build-time. Builds that are not > > + configured with "enable-ssl3" will not support SSLv3. > > I'm all for disabling SSLv3, but could you clarify if this package > update actually disable SSLv3 by default or merely fix the CHANGES to > accurately describe a change of defaults that happened earlier?
SSLv3 is disabled in Debian since 1.0.2d-2. > /Simon Sebastian

