Release of OpenSSL 3.5.0 cryptographic library

The release of OpenSSL 3.5.0 has been announced, implementing SSL/TLS protocols and various encryption algorithms. OpenSSL 3.5 is classified as a long-term support (LTS) release, with updates provided for 5 years (until April 2030). Support for previous branches OpenSSL 3.3, 3.2, and 3.0 LTS will continue until April 2026, November 2025, and September 2026, respectively. The project's code is distributed under the Apache 2.0 license.

Key innovations:

  • Support for quantum computer-resistant cryptographic algorithms has been added:
    • ML-KEM (CRYSTALS-Kyber) is a key exchange algorithm that utilizes lattice-based cryptography methods, whose solution times are equivalent on both classical and quantum computers.
    • ML-DSA (CRYSTALS-Dilithium) is a digital signature generation algorithm based on lattice theory.
    • SLH-DSA (Sphincs+) is a digital signature generation algorithm that employs hash-based cryptography methods. SLH-DSA lags behind ML-DSA in signature size and speed, but is based on entirely different mathematical principles, meaning it will remain effective even if lattice-based algorithms are compromised.
  • Full support for the QUIC protocol (RFC 9000) has been implemented, which is now available for server applications as well as client applications. QUIC is an extension of the UDP protocol, supporting the multiplexing of multiple connections and providing encryption methods equivalent to TLS. The QUIC protocol is used in HTTP/3 and was created as an alternative to the TCP+TLS combination, addressing issues with long setup and handshake times in TCP, and eliminating delays caused by packet loss during data transmission.
  • The ability to use third-party stacks implementing the QUIC protocol has been added, including stacks that support 0-RTT (0 Round Trip Time) mode, allowing immediate data transmission after sending the connection setup packet.
  • Support for opaque symmetric key objects (EVP_SKEY), which conceal key implementation details, has been added.
  • A 'no-tls-deprecated-ec' parameter has been added to disable support for TLS groups that have been marked as deprecated in RFC-8422.
  • The "enable-fips-jitter" parameter has been added, which enables the use of a jitter-based entropy source in the FIPS provider, implemented using the jitterentropy library. Jitter-based entropy is generated by measuring the timing variations during the repeated execution of a specific set of CPU instructions, which depend on many internal factors and are unpredictable without physical control over the CPU.
  • Support for centralized key generation has been added to CMP (Certificate Management Protocol) (public and private keys for the client are generated on the server side server).
  • Support for providing multiple keysets (keyshares) for a single TLS connection has been added.
  • An API for pipelining has been added, allowing simultaneous processing of several data blocks when using certain ciphers, such as AES-GCM, that support parallel computation.
  • In the req, cms, and smime applications, the default encryption algorithm has been changed from des-ede3-cbc to aes-256-cbc.
  • Hybrid KEM (Key Encapsulation Mechanism) groups, resistant to quantum computing attacks, have been included in the default cipher list for TLS and prioritized.
  • X25519MLKEM768 and X25519 algorithms have been added to the default keysets (keyshares) used in TLS.
  • The functions BIO_meth_get_*() have been deprecated.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster