Hacker News new | ask | show | jobs
by vladak 1324 days ago
One can buy premium support from OpenSSL for 1.0.x and let them supply patches and releases. This is what the company I work for does.

At one point I was managing a fork of OpenSSL 0.9.7 for an OS version and in order to communicate what vulnerabilities were fixed, we appended the list of CVEs to the version string. The line grew to hideous dimensions as you can imagine.