Release of OpenSSL cryptographic library 3.3.0

After five months of development, the release of the OpenSSL 3.3.0 library has been completed, implementing SSL/TLS protocols and various cryptographic algorithms. Support for OpenSSL 3.3 will continue until April 2026. Support for previous branches OpenSSL 3.2, 3.1, and 3.0 LTS will last until November 2025, March 2025, and September 2026, respectively. The project's code is distributed under the Apache 2.0 license.

Key innovations in OpenSSL 3.3.0:

  • Continued integration of support for the QUIC protocol (RFC 9000), which is built on top of the UDP protocol and is used as the transport in HTTP/3. In this release:
    • Support for QUIC connection tracing through diagnostic logging in the qlog format has been added.
    • Support for non-blocking polling mode for QUIC connections and stream objects has been added.
    • The ability to optimize stream-ending frame generation for QUIC connections has been implemented.
    • The option to disable QUIC event handling during API calls is now available.
    • Support for configuring inactivity timeouts for QUIC has been added.
    • An API has been added to query the size and fill level of the write buffer for QUIC streams.
  • Certificates Management Protocol (CMP) extensions have been implemented, defined in RFC 9480 (definition of CMPv3) and RFC 9483 (lightweight profile for low-power devices).
  • The option to disable the use of the atexit function at the build stage has been added.
  • A variant of the SSL_SESSION API that is not subject to the 2038 problem has been added: SSL_SESSION_get_time_ex() and SSL_SESSION_set_time_ex() functions, utilizing a 64-bit time_t type on 32-bit systems.
  • The EVP_PKEY_fromdata function has been enhanced to automatically obtain parameters for the Chinese Remainder Theorem (CRT).
  • The ability to ignore unknown signature algorithm names specified in the TLS SignatureAlgorithms and ClientSignatureAlgorithms configuration parameters has been added.
  • The option to prioritize PSK key usage in server TLS 1.3 during session recovery has been added.
  • The EVP_DigestSqueeze() function has been added, allowing for the reduction in the size of SHAKE hashes (removing the upper bits) by using several iterations with different output sizes.
  • Support for exporting build files for CMake on Unix-like systems and Windows has been added (in addition to pkg-config based export).
  • Performance optimizations have been made: The AES-GCM algorithm has been optimized for devices with Microsoft Azure Cobalt 100 chips. AES-CTR implementation now supports acceleration using ARM Neoverse V1 and V2 extensions. AES and SHA3 optimizations have been included for Apple systems with M3 chips. Vector extensions of RISC-V have been utilized in various cryptographic functions. An assembly implementation of md5 for Loongarch64 CPUs has been added.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster