Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support
    Cybersecurity

    OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support

    adminBy adminApril 14, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support
    Share
    Facebook Twitter LinkedIn Pinterest Email

    OpenSSL 4.0.0 removes several long-deprecated features, adds support for Encrypted Client Hello, and introduces API-level changes that will require code updates for applications built against older versions.

    OpenSSL 4.0.0

    SSLv3, SSLv2 client hello, and engines are gone

    SSLv3 support has been removed. The protocol was deprecated in 2015, and OpenSSL had it disabled by default since version 1.1.0 in 2016. Support for the SSLv2 Client Hello has also been removed.

    The engine API, which provided a mechanism for integrating external cryptographic hardware and software implementations, has been removed entirely. The no-engine build option and the OPENSSL_NO_ENGINE macro are now always present. Deprecated custom EVP_CIPHER, EVP_MD, EVP_PKEY, and EVP_PKEY_ASN1 methods have also been cut, along with deprecated fixed SSL/TLS version method functions and the error-state functions ERR_get_state(), ERR_remove_state(), and ERR_remove_thread_state().

    Encrypted Client Hello and post-quantum additions

    The release adds support for Encrypted Client Hello (ECH) per RFC 9849, which allows the client hello message to be encrypted so passive observers cannot read the server name a client is connecting to.

    On the post-quantum side, the release adds the hybrid key exchange group curveSM2MLKEM768, the ML-DSA-MU digest algorithm, the cSHAKE function per NIST SP 800-185, and support for negotiated FFDHE key exchange in TLS 1.2 per RFC 7919.

    API and behavior changes that affect integrators

    ASN1_STRING has been made opaque. Signatures across a range of API functions, including those used in X.509 processing, now include const qualifiers where applicable. The functions X509_cmp_time(), X509_cmp_current_time(), and X509_cmp_timeframe() have been deprecated in favor of X509_check_certificate_times().

    libcrypto no longer cleans up globally allocated data via atexit(). OPENSSL_cleanup() now runs in a global destructor, or not at all by default. BIO_f_reliable() has been removed with no replacement, having been broken since the 3.0 release.

    When X509_V_FLAG_X509_STRICT is set, AKID verification checks are now enforced, and the CRL verification process has received additional checks. Lower bounds checks are now enforced when using PKCS5_PBKDF2_HMAC with the FIPS provider.

    Build and tooling changes

    Support for deprecated elliptic curves in TLS per RFC 8422 and support for explicit EC curves are both disabled at compile time by default, with configuration options available to re-enable each. Build targets for darwin-i386 and darwin-ppc variants have been dropped.

    The c_rehash script has been removed in favor of openssl rehash. FIPS self-tests can now be deferred using the -defer_tests option of openssl fipsinstall. On Windows, the release adds support for choosing between static and dynamic Visual C++ runtime linkage.

    OpenSSL 4.0.0 is available on GitHub.

    Must read:

    Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!

    4.0.0 cuts deprecated Gains OpenSSL PostQuantum protocols release Support
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleQuantum developments put focus on authentication
    Next Article How to watch The Dark Wizard online from anywhere
    admin
    • Website

    Related Posts

    Sweden Blames Pro-Russian Group for Cyberattack Last Year on Its Energy Infrastructure

    April 15, 2026

    Microsoft, Salesforce Patch AI Agent Data Leak Flaws

    April 15, 2026

    Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover

    April 15, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Sweden Blames Pro-Russian Group for Cyberattack Last Year on Its Energy Infrastructure

    April 15, 2026

    The automation drift and how to correct course

    April 15, 2026

    Posts in your Shorts? What to expect from YouTube’s experiment

    April 15, 2026

    Microsoft, Salesforce Patch AI Agent Data Leak Flaws

    April 15, 2026
    Categories
    • Blogging (63)
    • Cybersecurity (1,329)
    • Privacy & Online Earning (167)
    • SEO & Digital Marketing (814)
    • Tech Tools & Mobile / Apps (1,590)
    • WiFi / Internet & Networking (224)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Sweden Blames Pro-Russian Group for Cyberattack Last Year on Its Energy Infrastructure

    April 15, 2026

    The automation drift and how to correct course

    April 15, 2026

    Posts in your Shorts? What to expect from YouTube’s experiment

    April 15, 2026
    Most Popular
    • Sweden Blames Pro-Russian Group for Cyberattack Last Year on Its Energy Infrastructure
    • The automation drift and how to correct course
    • Posts in your Shorts? What to expect from YouTube’s experiment
    • Microsoft, Salesforce Patch AI Agent Data Leak Flaws
    • Why ChatGPT Cites One Page Over Another (Study of 1.4M Prompts)
    • I Tried Binge, the Letterboxd Alternative That I Now Like More Than Letterboxd
    • How Endpoint Network Monitoring Enables Remote Work
    • Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.