so, after testing ...
=dev-libs/openssl-3.0.8 supports "blowfish" via "legacy" engines, but it has a terrible bug detecting the dev-crypto hashing method and is not always recognized during sessions, which causes ssh connections to randomly close.
=dev-libs/openssl-1.0.2u compiles and works, but its Makefile doesn't respect "make install DESTDIR", the DESTDIR rule is not always respected, and this causes QA SandBox Access Violation ... so it fails on Catalyst
moral of the story, I am back with =dev-libs/openssl-1.1.1t-r3

By switching from =dev-libs/openssl-3.0.* to =dev-libs/openssl-1.1.* you need to rebuild { sys-apps/coreutils, net-misc/wget, net-misc/curl, dev-libs/libevent } packages because they have a dependency with a specific version of =dev-libs/openssl-*
e.g.
# ldd /usr/bin/curl
libssl.so.1.1 => /usr/lib/libssl.so.1.1 (0x77ac0000)
libcrypto.so.1.1 => /usr/lib/libcrypto.so.1.1 (0x77860000)
libssl.so.1.0, libcrypto.so.1.0 ----> =dev-libs/openssl-1.0.*
libssl.so.1.1, libcrypto.so.1.1 ----> =dev-libs/openssl-1.1.*
libssl.so.3.1, libcrypto.so.3.0 ----> =dev-libs/openssl-3.0.*
p.s.
net-misc/openssh needs to be "hacked" in order to enable the "none" cipher since it's already supported by only for internal use.
# ssh -Q ciphers
aes128-cbc
aes192-cbc
aes256-cbc
aes128-ctr
aes192-ctr
aes256-ctr
none
now the stage4 is *exactly* as I want it to be
