OpenSSL version 3.5.0-beta1 released
Tomas Mraz <[email protected]>
| Newsgroups | gmane.comp.encryption.openssl.project,gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <[email protected]> |
OpenSSL version 3.5 beta 1 released
===================================
OpenSSL - The Open Source toolkit for SSL/TLS
https://www.openssl.org/
OpenSSL 3.5 is currently in beta.
OpenSSL 3.5 beta 1 has now been made available.
Note: This OpenSSL pre-release has been provided for testing ONLY.
It should NOT be used for security critical purposes.
The beta release is available for download at:
* https://github.com/openssl/openssl/releases
Please download and check this beta release as soon as possible.
To report a bug, open an issue on GitHub:
* https://github.com/openssl/openssl/issues
Release notes
=============
OpenSSL 3.5.0 beta1 is a feature release adding significant new functionality to
OpenSSL.
This release incorporates the following potentially significant or incompatible
changes:
* Default encryption cipher for the `req`, `cms`, and `smime` applications
changed from `des-ede3-cbc` to `aes-256-cbc`.
* The default TLS supported groups list has been changed to include and
prefer hybrid PQC KEM groups. Some practically unused groups were removed
from the default list.
* The default TLS keyshares have been changed to offer X25519MLKEM768 and
and X25519.
* All `BIO_meth_get_*()` functions were deprecated.
This release adds the following new features:
* Support for server side QUIC (RFC 9000)
* Support for 3rd party QUIC stacks including 0-RTT support
* Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA)
* A new configuration option `no-tls-deprecated-ec` to disable support for
TLS groups deprecated in RFC8422
* A new configuration option `enable-fips-jitter` to make the FIPS provider
to use the `JITTER` seed source
* Support for central key generation in CMP
* Support added for opaque symmetric key objects (EVP_SKEY)
* Support for multiple TLS keyshares and improved TLS key establishment group
configurability
* API support for pipelining in provided cipher algorithms
Yours,
The OpenSSL Project Team.
--
You received this message because you are subscribed to the Google Groups "openssl-project" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-project/0e22d41d14841692cfc657f5bec1d3bb07dd7212.camel%40openssl.org.
signature.asc
(application/pgp-signature, 858 B)
-----BEGIN PGP SIGNATURE----- iQJGBAABCAAwFiEE3HAyZir4heL0fyQ/UnRmohynnm0FAmfiyqcSHHRvbWFzQG9w ZW5zc2wub3JnAAoJEFJ0ZqIcp55teewP/2zUzUQkDE95EN6b1WEWoBOsG+Bt2jAa lbBW3AGvGHQBBJhlDCxr28UN9obDIIsyayU3qDM33GmjPg6WYdvOsK9ScM7q85Xb PoxiPW+QJjmAC0+2CoF0yPs6ytIo2xCjRzAQP8JMAFHOxPxEa/X6rkkX7n1+RPUH m6FV10nuCpr9BdUVNl4t+Te0h4cTu8O3Nqu9kdZV1Ck8jv2yzyCiyrs1eSZdxbsU M02BTq0QwQ3eW54IHccC5pEKgY6GmP2jIdhhFMOd/n9YIp5IVhBHdHPJaoMpUUS6 8rdx3rJbTI3NVlSD5xNFFiHZbmlspoSfP/IfCmWQ1e6Nj9HUgToJ7g81oaWY/svL 1NZvWr5w+Wn5BO1iMME6RVUrgDFBIiCz8WLI4PEzBgiUCp2L474545fohDXYBREB cOqqyYPwF3Bl3mzbkfZs9uwLubX7WM20q7RNULpDJKd5ncXMaquKzM7FMySAOUFZ lJ7JTe1GqYJlL7D4LOmkH4CLMd2sfViWlVKsH4QPyfSSFsiY9xY1IXtTHxLBY2Y7 jMi2IUrDrC8+Vn+OsxreOebA3V2kMrirpc/n6JI1pXkGI5PEYnNkyVn5fihw9rVV 0XuoDX2KEwXPMEWTsHEdmmYHhFj6SZdOrUY5NbEmeUvInORi1ju1P/k8nhkOuMkO PZ/Wxa+34x9f =skDI -----END PGP SIGNATURE-----