Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Application Security

OpenSSL 3.0 Released After 3 Years of Development

OpenSSL 3.0 released

The OpenSSL Project last week announced the official release of OpenSSL 3.0, a version that has been under development for the past 3 years.

OpenSSL 3.0 released

The OpenSSL Project last week announced the official release of OpenSSL 3.0, a version that has been under development for the past 3 years.

OpenSSL 3.0 is the successor of version 1.1.1. The latest version is the result of more than 7,500 commits and contributions made by over 350 individuals, and it took 17 alpha releases and two beta releases to prepare OpenSSL 3.0 for its official release.

The full-time engineers working on OpenSSL 3.0 have been aided by many users who have been testing the new release to ensure that it works with a wide range of applications in real world environments.

The OpenSSL Project lists well over 200 changes between version 1.1.1 and 3.0. A migration guide that details the most significant changes has been made available.

“OpenSSL 3.0 is a major release and not fully backwards compatible with the previous release,” explained the OpenSSL Project’s Matt Caswell. “Most applications that worked with OpenSSL 1.1.1 will still work unchanged and will simply need to be recompiled (although you may see numerous compilation warnings about using deprecated APIs). Some applications may need to make changes to compile and work correctly, and many applications will need to be changed to avoid the deprecations warnings.”

Users have been advised to take action to prevent potential problems introduced by deprecated API functions.

Advertisement. Scroll to continue reading.

They have also been informed about “a number of new concepts” and a new FIPS (Federal Information Processing Standard) module.

“Using the new FIPS module in your applications can be as simple as making some configuration file changes, although many applications will need to make other changes,” Caswell said.

The OpenSSL Project has also informed users that OpenSSL 3.0 has switched to Apache License 2.0.

OpenSSL 3.0 is available for download from GitHub and the project’s own Git repository. Users are encouraged to report any issues they encounter. OpenSSL 1.1.1 is the long term support (LTS) version and it will continue to be supported until September 11, 2023.

The open source TLS library has evolved a great deal in terms of security since the disclosure of the Heartbleed vulnerability back in 2014, with only a handful of high-severity flaws being identified in the past few years. The most recent high-severity issue, patched last month, can allow an attacker to change an application’s behavior or cause the app to crash.

Related: OpenSSL Vulnerability Can Be Exploited to Change Application Data

Related: Evolution of OpenSSL Security After Heartbleed

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

David Cass has joined Grayscale Investments as Chief Risk Officer.

Thomas Dager has been appointed Vice President and Chief Information Security Officer at The Goodyear Tire & Rubber Company.

Alex Stamos has become Chief Information Security Officer at Cognition.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.