OpenSSL version 4.0.0-beta1 released

"'Tomas Mraz' via openssl-project" <[email protected]> Tue, 24 Mar 2026 16:30:33 +0100
Newsgroups gmane.comp.encryption.openssl.project,gmane.comp.encryption.openssl.user
Message-ID <b3645508264165a2e78b0428aec13b11db1a4b50.camel@openssl.foundation>
--=-CtHy4OiYAFiFw/JWxJlA
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

OpenSSL version 4.0 beta 1 released
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

 OpenSSL - The Open Source toolkit for SSL/TLS
 https://www.openssl-library.org/

 OpenSSL 4.0 is currently in beta.

 OpenSSL 4.0 beta 1 has now been made available.

 Note: This OpenSSL pre-release has been provided for testing ONLY.
 It should NOT be used for security critical purposes.

 The beta release is available for download at:

=C2=A0=C2=A0 * https://github.com/openssl/openssl/releases

 Please download and check this beta release as soon as possible.
 To report a bug, open an issue on GitHub:

   * https://github.com/openssl/openssl/issues


Release notes
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

OpenSSL 4.0.0-beta1 is a feature release adding significant new functionali=
ty
to OpenSSL.

This release incorporates the following potentially significant or incompat=
ible
changes:

  * Removed extra leading '00:' when printing key data such as an RSA modul=
us
    in hexadecimal format where the first (most significant) byte is >=3D 0=
x80.

  * Standardized the width of hexadecimal dumps to 24 bytes for signatures
    (to stay within the 80 characters limit) and 16 bytes for everything el=
se.

  * Lower bounds checks are now enforced when using `PKCS5_PBKDF2_HMAC` API
    with FIPS provider.

  * Added AKID verification checks when `X509_V_FLAG_X509_STRICT` is set.

  * Augmented CRL verification process with several additional checks.

  * `libcrypto` no longer cleans up globally allocated data via `atexit()`.

  * `OPENSSL_cleanup()` now runs in a global destructor, or not at all
    by default.

  * `ASN1_STRING` has been made opaque.

  * Signatures of numerous API functions, including those that are related
    to X509 processing, are changed to include `const` qualifiers for argum=
ent
    and return types, where suitable.

  * Deprecated `X509_cmp_time()`, `X509_cmp_current_time()`,
    and `X509_cmp_timeframe()` in favor of `X509_check_certificate_times()`=
.

  * Removed support for the SSLv2 Client Hello.

  * Removed support for SSLv3.  SSLv3 has been deprecated since 2015,
    and OpenSSL had it disabled by default since version 1.1.0 (2016).

  * Removed support for engines.  The `no-engine` build option
    and the `OPENSSL_NO_ENGINE` macro are always present.

  * Support of deprecated elliptic curves in TLS according to [RFC 8422] wa=
s
    disabled at compile-time by default. To enable it, use the
    `enable-tls-deprecated-ec` configuration option.

  * Support of explicit EC curves was disabled at compile-time by default.
    To enable it, use the `enable-ec_explicit_curves` configuration option.

  * Removed `c_rehash` script tool.  Use `openssl rehash` instead.

  * Removed the deprecated `msie-hack` option from the `openssl ca` command=
.

  * Removed `BIO_f_reliable()` implementation without replacement.
    It was broken since 3.0 release without any complaints.

  * Removed deprecated functions `ERR_get_state()`, `ERR_remove_state()`
    and `ERR_remove_thread_state()`. The `ERR_STATE` object is now always o=
paque.

  * Dropped `darwin-i386{,-cc}` and `darwin-ppc{,64}{,-cc}` targets
    from Configurations.

This release adds the following new features:

  * Support for Encrypted Client Hello (ECH, [RFC 9849]).
    See `doc/designs/ech-api.md` for details.

  * Support for [RFC 8998], signature algorithm `sm2sig_sm3`, key exchange
    group `curveSM2`, and [tls-hybrid-sm2-mlkem] post-quantum group
    `curveSM2MLKEM768`.

  * cSHAKE function support as per [SP 800-185].

  * "ML-DSA-MU" digest algorithm support.

  * Support for SNMP KDF and SRTP KDF.

  * FIPS self tests can now be deferred and run as needed when installing
    the FIPS module with the `-defer_tests` option of the `openssl fipsinst=
all`
    command.

  * Support for using either static or dynamic VC runtime linkage
    on Windows.

  * Support for negotiated FFDHE key exchange in TLS 1.2 in accordance
    with [RFC 7919].

[RFC 8422]: https://datatracker.ietf.org/doc/html/rfc8422
[RFC 9849]: https://datatracker.ietf.org/doc/html/rfc9849
[RFC 8998]: https://datatracker.ietf.org/doc/html/rfc8998#name-iana-conside=
rations
[SP 800-185]: https://csrc.nist.gov/pubs/sp/800/185/final
[RFC 7919]: https://datatracker.ietf.org/doc/html/rfc7919

Yours,

The OpenSSL Project Team.

--=20
You received this message because you are subscribed to the Google Groups "=
openssl-project" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to [email protected].
To view this discussion visit https://groups.google.com/a/openssl.org/d/msg=
id/openssl-project/b3645508264165a2e78b0428aec13b11db1a4b50.camel%40openssl=
.foundation.

--=-CtHy4OiYAFiFw/JWxJlA
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----

iQJNBAABCgA3FiEE3HAyZir4heL0fyQ/UnRmohynnm0FAmnCrhkZHHRvbWFzQG9w
ZW5zc2wuZm91bmRhdGlvbgAKCRBSdGaiHKeebbLnD/9JaXlZw0Bm+7V/3btKSKQW
PDqt8T5m9Aqt28rvx3RuiwT0R9SBftNZa9bpdua6AEBZWhvBpc9AssZ+6FJo72wy
MdPiGyLtRUiTLoeLecqmAMkia2G6n1/Pc8IYrKD6xsT2pIqrqket0E509sR8H5H/
bL9NNb9H0DfyrfT7OES1HBvxbwkuA2RK8EIRUIZBZGQFL2f8tHkgUG5xwBp80nFb
V1zvV0TQOPhJHgNI8VB8z4NhWkInfGlJRtiWaAToEVTjFIhxcIYHvJ80D4rp2fXa
WTUoMdU/mXdvnJy/kCfTr7FNFcoNF/yhleb/NFZUkuzmpqg8Y79eRpUFd30CeyIK
fWDRaBVNP779ltRF+ZdaCua/K/z8RZJMkldFQarKJh09+ghIOuq5YC1WBNI8Lg/r
Kv1676Gz6Me3m7dsOvWWrt8V8+YBdPvMmazfAl18p2nSEc93ZFe8+GUzJIkBWzgU
533SdY2M3CAj6kFpR8k0Yf02z453Bp4qU/aWrCt2AiMlNNELWeWGhP7vpuiGbt6i
RbDdZRDvwmwU2dU97Whem4vW6+RyZr6SCJxqh2FoByxi9MmZHd8OmbdJxxqm1S+Z
H13aAdYC5dZn7NJJQHvGm14Zc+rfQFBCU52cqMUgE/oHjGU88c9jyIfLBMcI1vEf
afDSgvbHOBUkuP+a4qJGiQ==
=dXHB
-----END PGP SIGNATURE-----

--=-CtHy4OiYAFiFw/JWxJlA--