Now the latest version of Apache mod_ssl (2.2) embeds an option to reactivate old way client renegociation :
Check the official doc for more details. With this option activated, you can now safely upgrade openSSL and mod_ssl without breaking your clients. They should have done it from the begining, shouldn’t they ?
The next step will be to move on to the new protocol definitely, to solve for good the CVE-2009-3555 vulnerability. For that we have to wait for the browsers to support it.
Firefox has started to work seriously on it and we can expect some support in the next releases (some settings will be possible through about:config).