OpenSSL version 3.5.0-beta1 released

Tomas Mraz <[email protected]>
Newsgroups gmane.comp.encryption.openssl.project,gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
OpenSSL version 3.5 beta 1 released
===================================

 OpenSSL - The Open Source toolkit for SSL/TLS
 https://www.openssl.org/

 OpenSSL 3.5 is currently in beta.

 OpenSSL 3.5 beta 1 has now been made available.

 Note: This OpenSSL pre-release has been provided for testing ONLY.
 It should NOT be used for security critical purposes.

 The beta release is available for download at:

   * https://github.com/openssl/openssl/releases

 Please download and check this beta release as soon as possible.
 To report a bug, open an issue on GitHub:

   * https://github.com/openssl/openssl/issues


Release notes
=============

OpenSSL 3.5.0 beta1 is a feature release adding significant new functionality to
OpenSSL.

This release incorporates the following potentially significant or incompatible
changes:

  * Default encryption cipher for the `req`, `cms`, and `smime` applications
    changed from `des-ede3-cbc` to `aes-256-cbc`.

  * The default TLS supported groups list has been changed to include and
    prefer hybrid PQC KEM groups. Some practically unused groups were removed
    from the default list.

  * The default TLS keyshares have been changed to offer X25519MLKEM768 and
    and X25519.

  * All `BIO_meth_get_*()` functions were deprecated.

This release adds the following new features:

  * Support for server side QUIC (RFC 9000)

  * Support for 3rd party QUIC stacks including 0-RTT support

  * Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA)

  * A new configuration option `no-tls-deprecated-ec` to disable support for
    TLS groups deprecated in RFC8422

  * A new configuration option `enable-fips-jitter` to make the FIPS provider
    to use the `JITTER` seed source

  * Support for central key generation in CMP

  * Support added for opaque symmetric key objects (EVP_SKEY)

  * Support for multiple TLS keyshares and improved TLS key establishment group
    configurability

  * API support for pipelining in provided cipher algorithms

Yours,

The OpenSSL Project Team.

-- 
You received this message because you are subscribed to the Google Groups "openssl-project" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-project/0e22d41d14841692cfc657f5bec1d3bb07dd7212.camel%40openssl.org.
signature.asc (application/pgp-signature, 858 B)
-----BEGIN PGP SIGNATURE-----

iQJGBAABCAAwFiEE3HAyZir4heL0fyQ/UnRmohynnm0FAmfiyqcSHHRvbWFzQG9w
ZW5zc2wub3JnAAoJEFJ0ZqIcp55teewP/2zUzUQkDE95EN6b1WEWoBOsG+Bt2jAa
lbBW3AGvGHQBBJhlDCxr28UN9obDIIsyayU3qDM33GmjPg6WYdvOsK9ScM7q85Xb
PoxiPW+QJjmAC0+2CoF0yPs6ytIo2xCjRzAQP8JMAFHOxPxEa/X6rkkX7n1+RPUH
m6FV10nuCpr9BdUVNl4t+Te0h4cTu8O3Nqu9kdZV1Ck8jv2yzyCiyrs1eSZdxbsU
M02BTq0QwQ3eW54IHccC5pEKgY6GmP2jIdhhFMOd/n9YIp5IVhBHdHPJaoMpUUS6
8rdx3rJbTI3NVlSD5xNFFiHZbmlspoSfP/IfCmWQ1e6Nj9HUgToJ7g81oaWY/svL
1NZvWr5w+Wn5BO1iMME6RVUrgDFBIiCz8WLI4PEzBgiUCp2L474545fohDXYBREB
cOqqyYPwF3Bl3mzbkfZs9uwLubX7WM20q7RNULpDJKd5ncXMaquKzM7FMySAOUFZ
lJ7JTe1GqYJlL7D4LOmkH4CLMd2sfViWlVKsH4QPyfSSFsiY9xY1IXtTHxLBY2Y7
jMi2IUrDrC8+Vn+OsxreOebA3V2kMrirpc/n6JI1pXkGI5PEYnNkyVn5fihw9rVV
0XuoDX2KEwXPMEWTsHEdmmYHhFj6SZdOrUY5NbEmeUvInORi1ju1P/k8nhkOuMkO
PZ/Wxa+34x9f
=skDI
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.