Forthcoming OpenSSL release announced
mta.openssl.org
mta.openssl.org
I wonder what the 0.9.8 EOL means for squeeze-lts. Does the Debian LTS team just backport all applicable 1.0.1 patches? Isn't this a little risky? They might not have an intimate understanding of the opaque codebase.
What about Wheezy and Jessie after support for 1.0.1 ends on 31 December?
It's unclear if that's the beginning or end of the month.
If you're waiting until the very end of LTS support to upgrade, you're doing it wrong anyways.
> Please see the following page for further details of severity levels: https://www.openssl.org/policies/secpolicy.html
There was a time in the not so distant past when we didn't even get a "heads up" like this so, personally, I am appreciative of the advance notice.