The OpenSSL Library no longer includes SSLv3

Blog on OpenSSL Library <[email protected]> Thu, 09 Apr 2026 01:00:19 -0000
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <37ced5fa-a4c5-4cd1-9c37-a00138b344ca@localhost>
Previous posts about the upcoming OpenSSL 4.0 release:

  1. [removing ENGINE code](https://openssl-library.org/post/2025-12-18-remove-engines)
  2. [removing deprecated functions for creating or modifying custom METHODS](https://openssl-library.org/post/2026-02-03-remove-methods)
  3. [no longer registering a function via atexit function](https://openssl-library.org/post/2026-03-10-remove-atexit)
  4. [adding ECH support](https://openssl-library.org/post/2026-03-11-ech)

## Summary

Secure Sockets Layer version 3.0 (SSLv3) was deprecated in [RFC
7568](https://www.rfc-editor.org/rfc/rfc7568). SSLv3 was disabled at build-
time in OpenSSL 1.0.2h by default. As of OpenSSL 4.0, SSLv3 support has been
removed altogether.

In addition, OpenSSL no longer supports the SSLv2 Client Hello.



URL: https://openssl-library.org/post/2026-04-07-ssl3/

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/37ced5fa-a4c5-4cd1-9c37-a00138b344ca%40localhost.