More OpenSSL security fixes

Discussion in 'privacy technology' started by BoerenkoolMetWorst, Aug 7, 2014.

  1. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    5,029
    OpenSSL 3.5 [LTS] released - 08 Apr 2025

    More info:

    https://openssl-library.org/source/

    https://github.com/openssl/openssl/blob/master/CHANGES.md#openssl-35

    https://marc.info/?l=openssl-users&m=174411928201074&w=2

     
  2. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    5,029
    OpenSSL 3.6 Alpha Release Announcement
    Sep 2, 2025
    https://openssl-library.org/post/2025-09-02-openssl-3.6-alpha/

    Read there more.
     
  3. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    2,498
    Location:
    .
  4. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    5,029
  5. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    5,029
    Openssl 3.5.3 Release Announcement
    Sep 16, 2025

    https://openssl-library.org/post/2025-09-16-openssl-3.5.3/

    Read there more!
     
  6. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    5,029
    OpenSSL 3.6 Beta Release Announcement
    Sep 16, 2025

    https://openssl-library.org/post/2025-09-16-openssl-3.6-beta/

    Long quote:
    - Quoting -

    The OpenSSL Project is pleased to announce that OpenSSL 3.6 Beta1 pre-release is available, adding significant functionality to the OpenSSL Library.

    OpenSSL 3.6.0 is a feature pre-release adding significant new functionality, bug fixes and mitigations:

    • Added FIPS 140-3 PCT on DH key generation.
    • Added NIST security categories for PKEY objects.
    • Added support for EVP_SKEY opaque symmetric key objects to the key derivation and key exchange provider methods. Added EVP_KDF_CTX_set_SKEY(), EVP_KDF_derive_SKEY(), and EVP_PKEY_derive_SKEY() functions.
    • The FIPS provider now performs a PCT on key import for RSA, EC and ECX. This is mandated by FIPS 140-3 IG 10.3.A additional comment 1.
    • Added LMS signature verification support as per [SP 800-208]. This support is present in both the FIPS and default providers.
    • An ANSI-C toolchain is no longer sufficient for building OpenSSL. The code should build on compilers supporting C-99 features.
    • The VxWorks platforms have been removed.
    • Added an openssl configutl utility for processing the openssl configuration file and dumping the equal configuration file.
    • Added support for FIPS 186-5 deterministic ECDSA signature generation to the FIPS provider.
    • Deprecated EVP_PKEY_ASN1_METHOD related functions.

    - End quoting -

    Read there more!
     
    Last edited: Sep 18, 2025
  7. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    5,029
    OpenSSL Release Announcement for 3.5.4, 3.4.3, 3.3.5, 3.2.6, 3.0.18, 1.1.1zd and 1.0.2zm

    Sep 30, 2025

    Long list at :
    https://openssl-library.org/post/2025-09-30-release-announcement/

    List is too long to quote. See the details for all the versions at that link.

    Read there more!
     
  8. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    5,029
    PS:

    I don't see there at the moment newer info about the 3.6 Beta.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.