Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support
    Cybersecurity

    OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support

    adminBy adminApril 14, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support
    Share
    Facebook Twitter LinkedIn Pinterest Email

    OpenSSL 4.0.0 removes several long-deprecated features, adds support for Encrypted Client Hello, and introduces API-level changes that will require code updates for applications built against older versions.

    OpenSSL 4.0.0

    SSLv3, SSLv2 client hello, and engines are gone

    SSLv3 support has been removed. The protocol was deprecated in 2015, and OpenSSL had it disabled by default since version 1.1.0 in 2016. Support for the SSLv2 Client Hello has also been removed.

    The engine API, which provided a mechanism for integrating external cryptographic hardware and software implementations, has been removed entirely. The no-engine build option and the OPENSSL_NO_ENGINE macro are now always present. Deprecated custom EVP_CIPHER, EVP_MD, EVP_PKEY, and EVP_PKEY_ASN1 methods have also been cut, along with deprecated fixed SSL/TLS version method functions and the error-state functions ERR_get_state(), ERR_remove_state(), and ERR_remove_thread_state().

    Encrypted Client Hello and post-quantum additions

    The release adds support for Encrypted Client Hello (ECH) per RFC 9849, which allows the client hello message to be encrypted so passive observers cannot read the server name a client is connecting to.

    On the post-quantum side, the release adds the hybrid key exchange group curveSM2MLKEM768, the ML-DSA-MU digest algorithm, the cSHAKE function per NIST SP 800-185, and support for negotiated FFDHE key exchange in TLS 1.2 per RFC 7919.

    API and behavior changes that affect integrators

    ASN1_STRING has been made opaque. Signatures across a range of API functions, including those used in X.509 processing, now include const qualifiers where applicable. The functions X509_cmp_time(), X509_cmp_current_time(), and X509_cmp_timeframe() have been deprecated in favor of X509_check_certificate_times().

    libcrypto no longer cleans up globally allocated data via atexit(). OPENSSL_cleanup() now runs in a global destructor, or not at all by default. BIO_f_reliable() has been removed with no replacement, having been broken since the 3.0 release.

    When X509_V_FLAG_X509_STRICT is set, AKID verification checks are now enforced, and the CRL verification process has received additional checks. Lower bounds checks are now enforced when using PKCS5_PBKDF2_HMAC with the FIPS provider.

    Build and tooling changes

    Support for deprecated elliptic curves in TLS per RFC 8422 and support for explicit EC curves are both disabled at compile time by default, with configuration options available to re-enable each. Build targets for darwin-i386 and darwin-ppc variants have been dropped.

    The c_rehash script has been removed in favor of openssl rehash. FIPS self-tests can now be deferred using the -defer_tests option of openssl fipsinstall. On Windows, the release adds support for choosing between static and dynamic Visual C++ runtime linkage.

    OpenSSL 4.0.0 is available on GitHub.

    Must read:

    Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!

    4.0.0 cuts deprecated Gains OpenSSL PostQuantum protocols release Support
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleQuantum developments put focus on authentication
    Next Article How to watch The Dark Wizard online from anywhere
    admin
    • Website

    Related Posts

    Signed software abused to deploy antivirus-killing scripts

    April 15, 2026

    EFF Calls on Kuwait to Release Journalist Ahmed Shihab-Eldin

    April 15, 2026

    Sweden Blames Pro-Russian Group for Cyberattack Last Year on Its Energy Infrastructure

    April 15, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google Is Replacing Dynamic Search Ads With AI Max

    April 15, 2026

    I tried this Gemini feature and haven’t opened Canva, PowerPoint, or Notion since

    April 15, 2026

    Signed software abused to deploy antivirus-killing scripts

    April 15, 2026

    EFF Calls on Kuwait to Release Journalist Ahmed Shihab-Eldin

    April 15, 2026
    Categories
    • Blogging (63)
    • Cybersecurity (1,330)
    • Privacy & Online Earning (168)
    • SEO & Digital Marketing (816)
    • Tech Tools & Mobile / Apps (1,592)
    • WiFi / Internet & Networking (224)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google Is Replacing Dynamic Search Ads With AI Max

    April 15, 2026

    I tried this Gemini feature and haven’t opened Canva, PowerPoint, or Notion since

    April 15, 2026

    Signed software abused to deploy antivirus-killing scripts

    April 15, 2026
    Most Popular
    • Google Is Replacing Dynamic Search Ads With AI Max
    • I tried this Gemini feature and haven’t opened Canva, PowerPoint, or Notion since
    • Signed software abused to deploy antivirus-killing scripts
    • EFF Calls on Kuwait to Release Journalist Ahmed Shihab-Eldin
    • How to Show Up in ChatGPT Results and Get Noticed by Customers
    • Spotify will now let you buy physical books without leaving the app
    • Sweden Blames Pro-Russian Group for Cyberattack Last Year on Its Energy Infrastructure
    • The automation drift and how to correct course
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.