> Why wouldn't we require a certain openssl version as there are a number of
> security vulnerabilities in (older) openssl?

Do you have a pointer to a list of the insecure versions with a summary of 
the bug so we can see if we use that feature?

