diff --git a/docs/DEPRECATE.md b/docs/DEPRECATE.md index 807b79ac0f..61b4c23991 100644 --- a/docs/DEPRECATE.md +++ b/docs/DEPRECATE.md @@ -12,10 +12,6 @@ email the as soon as possible and explain to us why this is a problem for you and how your use case cannot be satisfied properly using a workaround. -## c-ares 1.16.0 - -In March 2026, we drop support for all c-ares versions before 1.16.0. - ## TLS-SRP Authentication Transport Layer Security Secure Remote Password is a TLS feature that does not @@ -26,9 +22,9 @@ TLS-SRP support gets removed in August 2026. ## SMB goes opt-in -The SMB protocol has weak security and is rarely used these days. After curl +The SMB protocol has weak security and is rarely used these days. -8.19.0 SMB support becomes opt-in. +SMB support gets removed in September 2026. ## NTLM goes opt-in @@ -36,7 +32,28 @@ The NTLM authentication method has weak security and is rarely used these days. It has been deprecated by Microsoft and does not work over HTTP/2 or HTTP/3. -After curl 8.19.0 NTLM support becomes opt-in. +NTLM support gets removed in September 2026 + +## Local crypto implementations + +Since the dawn of time, curl bundles code for a few crypto and hash algorithms +in order to enable functionality for builds without TLS libraries. This list +includes MD4, MD5, SHA256, SHA256_512 and perhaps something more. + +Meanwhile, curl is almost always built to use a TLS/crypto library which for +sure has better maintained and better performing versions of these algorithms. + +Also, the local curl implementations are not as widely tested since curl +builds without TLS are rare. + +Since these implementations are going away, a good idea is to verify ahead of +time that builds using your preferred TLS library use the crypto functions +provided by that library and are not bundled by curl. + +The removal of local crypto functions subsequently disables some functions in +future curl versions when built without TLS support. For example Digest. + +Local crypto gets removed in October 2026. ## Past removals @@ -63,3 +80,6 @@ After curl 8.19.0 NTLM support becomes opt-in. - OpenSSL-QUIC (removed in 8.19.0) - CMake 3.17 and older (removed in 8.20.0) - RTMP (removed in 8.20.0) +- SMB (became opt-in in 8.20.0) +- NTLM (became opt-in in 8.20.0) +- c-ares < 1.16.0 (removed in 8.20.0)