Given the OpenSSL trackrecord [1], I recommend switching to LibreSSL [2] if possible. They tore through OpenSSL to pull out all the horrors they found and beat it into shape. OpenSSL's code was so unbelievably bad that there's certainly more problems lurking in there.
[1] http://www.openbsd.org/papers/bsdcan14-libressl/mgp00001.htm...
[2] http://www.libressl.org/releases.html