The root security certificate bundle in WordPress coreCore Core is the set of software required to run WordPress. The Core Team builds WordPress. still includes some 1024-bit certificates to provide support for what appears to be a narrow range of buggy OpenSSL versions that have been unsupported since 2016. In https://core.trac.wordpress.org/ticket/64063 there is a proposal to remove them from the bundle.
Does anyone know of a reason these certificates should be retained? As far as I understand this really only affects CentOS 7 which is EOL since 2024.
If there’s no objection then I’ll remove them next week (ready for WordPress 7.0 in April).