Five years is a long time. However, with something as important as OpenSSL, some degree of discretion and evaluation should be done before patches are merged.<p>Does anyone know the reason for the delay? I can't imagine that it's just them being lazy, for instance. Maybe they don't have the time and resources to properly analyze something as critical as this?<p>Edit: I guess what I mean to say is, for OpenSSL I'd rather have no feature than a feature with a security vulnerability.