Also, I believe that only binaries can be FIPS certified, not source code, so there are times when one has to use an old, out-dated openssl binary in order to be compliant.
On the other hand, you can't change the source without losing the certification, so it doesn't actually matter.
This is why you might have to use old versions of OpenSSL for FIPS compliance - not all versions might be certified.