Right. I'll expect a lot of other pains with openssl 1.0.2 then. But basically, without distros doing wierd backporting well be looking at 2.2.10 and 3.0.11 being the minimum release version that works with EAP clients (and TLS 1.2?) if openssl 1.0.2 is being used? alan