{"id":101224,"date":"2021-09-08T16:23:07","date_gmt":"2021-09-08T14:23:07","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vypusk-kriptograficheskoj-biblioteki-openssl-3-0-0"},"modified":"2021-09-08T16:23:07","modified_gmt":"2021-09-08T14:23:07","slug":"vypusk-kriptograficheskoj-biblioteki-openssl-3-0-0","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/vypusk-kriptograficheskoj-biblioteki-openssl-3-0-0","title":{"rendered":"Uscita della libreria crittografica OpenSSL 3.0.0","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dopo tre anni di sviluppo e 19 versioni di prova, \u00e8 stato rilasciato OpenSSL 3.0.0, che implementa i protocolli SSL\/TLS e vari algoritmi di crittografia. Questa nuova versione introduce modifiche che rompono la compatibilit\u00e0 retroattiva a livello di API e ABI, ma tali modifiche non influenzeranno il funzionamento della maggior parte delle applicazioni, per le quali \u00e8 sufficiente ricompilare dopo aver utilizzato OpenSSL 1.1.1. Il supporto per la vecchia versione OpenSSL 1.1.1 continuer\u00e0 fino a settembre 2023.    <\/p>\n<p>\u0417\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u043e\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u043d\u043e\u043c\u0435\u0440\u0430 \u0432\u0435\u0440\u0441\u0438\u0438 \u0441\u0432\u044f\u0437\u0430\u043d\u043e \u0441 \u043f\u0435\u0440\u0435\u0445\u043e\u0434\u043e\u043c \u043d\u0430   \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u0443\u044e \u043d\u0443\u043c\u0435\u0440\u0430\u0446\u0438\u044e &#171;Major.Minor.Patch&#187;. \u041f\u0435\u0440\u0432\u0430\u044f \u0446\u0438\u0444\u0440\u0430 (Major) \u0432 \u043d\u043e\u043c\u0435\u0440\u0435 \u0432\u0435\u0440\u0441\u0438\u0438 \u043e\u0442\u043d\u044b\u043d\u0435 \u0431\u0443\u0434\u0435\u0442 \u043c\u0435\u043d\u044f\u0442\u044c\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u0440\u0438 \u043d\u0430\u0440\u0443\u0448\u0435\u043d\u0438\u0438 \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u043e\u0441\u0442\u0438 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 API\/ABI, \u0430 \u0432\u0442\u043e\u0440\u0430\u044f (Minor) \u043f\u0440\u0438 \u043d\u0430\u0440\u0430\u0449\u0438\u0432\u0430\u043d\u0438\u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u0438 \u0431\u0435\u0437 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f API\/ABI. \u041a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0435 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0431\u0443\u0434\u0443\u0442 \u043f\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0442\u044c\u0441\u044f \u0441 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435\u043c \u0442\u0440\u0435\u0442\u044c\u0435\u0439 \u0446\u0438\u0444\u0440\u044b (Patch). \u041d\u043e\u043c\u0435\u0440  3.0.0 \u0441\u0440\u0430\u0437\u0443 \u043f\u043e\u0441\u043b\u0435 1.1.1 \u0432\u044b\u0431\u0440\u0430\u043d \u0434\u043b\u044f \u0438\u0437\u0431\u0435\u0436\u0430\u043d\u0438\u044f \u043f\u0435\u0440\u0435\u0441\u0435\u0447\u0435\u043d\u0438\u0439 \u0441 \u043d\u0430\u0445\u043e\u0434\u044f\u0449\u0438\u043c\u0441\u044f \u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0435 FIPS-\u043c\u043e\u0434\u0443\u043b\u0435\u043c \u043a OpenSSL, \u0434\u043b\u044f \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u043b\u0430\u0441\u044c \u043d\u0443\u043c\u0435\u0440\u0430\u0446\u0438\u044f 2.x.      <\/p>\n<p>Una delle modifiche pi\u00f9 significative per il progetto \u00e8 stata la transizione da una licenza doppia (OpenSSL e SSLeay) alla licenza Apache 2.0. La precedente licenza proprietaria di OpenSSL si basava sul testo di una licenza Apache 1.0 obsoleta e richiedeva di menzionare esplicitamente OpenSSL nei materiali pubblicitari quando si utilizzavano le librerie OpenSSL, nonch\u00e9 di aggiungere una nota speciale nel caso di fornitura di OpenSSL come parte di un prodotto. Tali requisiti rendevano la vecchia licenza incompatibile con la GPL, creando difficolt\u00e0 nell'utilizzo di OpenSSL in progetti con licenza GPL. Per aggirare questa incompatibilit\u00e0, i progetti GPL erano costretti a utilizzare specifici accordi di licenza, in cui il testo principale della GPL era integrato con una clausola che autorizzava esplicitamente il collegamento dell'applicazione con la libreria OpenSSL e menzionava che i requisiti della GPL non si applicano al collegamento con OpenSSL.         <\/p>\n<p>Rispetto al ramo OpenSSL 1.1.1, in OpenSSL 3.0.0 sono stati introdotti oltre 7500 cambiamenti, preparati da 350 sviluppatori. Le principali novit\u00e0 di OpenSSL 3.0.0:  <\/p>\n<ul>\n<li class=\"l\"> \u00c8 stato proposto un nuovo modulo FIPS che include l'implementazione di algoritmi crittografici conformi allo standard di sicurezza FIPS 140-2 (il processo di certificazione del modulo inizier\u00e0 questo mese, con l'ottenimento del certificato FIPS 140-2 previsto per l'anno prossimo). Il nuovo modulo \u00e8 significativamente pi\u00f9 semplice da usare e la sua integrazione con molte applicazioni non sar\u00e0 pi\u00f9 complessa rispetto alla modifica del file di configurazione. Per impostazione predefinita, il modulo FIPS \u00e8 disattivato e richiede l'indicazione dell'opzione enable-fips per l'attivazione.\n<li class=\"l\"> In libcrypto \u00e8 stata implementata la concettualizzazione di provider plug-in, che sostituisce la vecchia concezione degli engine (l'API ENGINE \u00e8 considerata obsoleta). Con i provider \u00e8 possibile aggiungere implementazioni personalizzate degli algoritmi per operazioni come crittografia, decrittografia, generazione di chiavi, calcolo di MAC, creazione e verifica di firme digitali. \u00c8 possibile sia collegare nuovi provider che creare implementazioni alternative di algoritmi gi\u00e0 supportati (per impostazione predefinita, ora viene utilizzato il provider integrato in OpenSSL per ogni algoritmo).\n<li class=\"l\"> \u00c8 stata aggiunta la supporto per il protocollo di gestione dei certificati CMP (Certificate Management Protocol, RFC 4210), che pu\u00f2 essere utilizzato per richiedere certificati da <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/dts-los-angeles\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3745\">server<\/a> un'autorit\u00e0 di certificazione, per l'aggiornamento dei certificati e per la revoca dei certificati. L'interazione con CMP avviene tramite il nuovo strumento openssl-cmp, che include anche il supporto per il formato CRMF (RFC 4211) e per l'invio di richieste tramite HTTP\/HTTPS (RFC 6712).\n<li class=\"l\"> \u00c8 stato implementato un client completo per i protocolli HTTP e HTTPS, che supporta i metodi GET e POST, la redirezione delle richieste, l'utilizzo attraverso proxy, la codifica ASN.1 e la gestione dei timeout.\n<li class=\"l\"> \u00c8 stato aggiunto un nuovo API EVP_MAC (Message Authentication Code API), che semplifica l'aggiunta di nuove implementazioni delle firme.\n<li class=\"l\"> \u041f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d \u043d\u043e\u0432\u044b\u0439 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u043d\u044b\u0439 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441 \u0434\u043b\u044f \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043b\u044e\u0447\u0435\u0439 &#8212; EVP_KDF (Key Derivation Function API), \u0443\u043f\u0440\u043e\u0449\u0430\u044e\u0449\u0438\u0439 \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043d\u043e\u0432\u044b\u0445 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0439 KDF \u0438 PRF. \u0421\u0442\u0430\u0440\u044b\u0439 API  EVP_PKEY, \u0447\u0435\u0440\u0435\u0437 \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u044b scrypt, TLS1 PRF \u0438 HKDF, \u043f\u0435\u0440\u0435\u0440\u0430\u0431\u043e\u0442\u0430\u043d \u0432 \u0444\u043e\u0440\u043c\u0435 \u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0438,  \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u043f\u043e\u0432\u0435\u0440\u0445 API EVP_KDF \u0438 EVP_MAC.\n<li class=\"l\"> \u0412 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430 TLS \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0430 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u044f \u0432\u0441\u0442\u0440\u043e\u0435\u043d\u043d\u044b\u0445 \u0432 \u044f\u0434\u0440\u043e Linux \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 TLS \u0434\u043b\u044f \u0443\u0441\u043a\u043e\u0440\u0435\u043d\u0438\u044f \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u0439.  \u0414\u043b\u044f \u0437\u0430\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u0438\u044f \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c\u043e\u0439 \u044f\u0434\u0440\u043e\u043c Linux \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 TLS \u0442\u0440\u0435\u0431\u0443\u0435\u0442\u0441\u044f \u0432\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0435 \u043e\u043f\u0446\u0438\u0438 &#171;SSL_OP_ENABLE_KTLS&#187; \u0438\u043b\u0438 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 &#171;enable-ktls&#187;.\n<li class=\"l\"> \u00c8 stata aggiunta la supporto a nuovi algoritmi:\n<ul>\n<li class=\"l\"> \u0410\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u044b \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043b\u044e\u0447\u0435\u0439 (KDF) &#8212; &#171;SINGLE STEP&#187; \u0438 &#171;SSH&#187;.\n<li class=\"l\"> \u0410\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u044b \u0438\u043c\u0438\u0442\u043e\u0432\u0441\u0442\u0430\u0432\u043e\u043a (MAC) &#8212; &#171;GMAC&#187; \u0438 &#171;KMAC&#187;.\n<li class=\"l\"> \u0410\u043b\u0433\u043e\u0440\u0438\u0442\u043c \u0438\u043d\u043a\u0430\u043f\u0441\u0443\u043b\u044f\u0446\u0438\u0438 \u043a\u043b\u044e\u0447\u0435\u0439 RSA (KEM)  &#171;RSASVE&#187;.\n<li class=\"l\"> \u0410\u043b\u0433\u043e\u0440\u0438\u0442\u043c \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f &#171;AES-SIV&#187; (RFC-8452).\n<li class=\"l\"> \u0412 API EVP \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u044b \u0432\u044b\u0437\u043e\u0432\u044b \u0441 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u043e\u0439 \u0438\u043d\u0432\u0435\u0440\u0441\u0438\u0432\u043d\u044b\u0445 \u0448\u0438\u0444\u0440\u043e\u0432,  \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0445  \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c AES \u0434\u043b\u044f \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043b\u044e\u0447\u0435\u0439 (Key Wrap): &#171;AES-128-WRAP-INV&#187;, &#171;AES-192-WRAP-INV&#187;, &#171;AES-256-WRAP-INV&#187;, &#171;AES-128-WRAP-PAD-INV&#187;, &#171;AES-192-WRAP-PAD-INV&#187; \u0438 &#171;AES-256-WRAP-PAD-INV&#187;.\n<li class=\"l\"> \u0412 API EVP \u0434\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u0430 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432 \u0437\u0430\u0438\u043c\u0441\u0442\u0432\u043e\u0432\u0430\u043d\u0438\u0435 \u0448\u0438\u0444\u0440\u043e\u0442\u0435\u043a\u0441\u0442\u0430 (CTS): &#171;AES-128-CBC-CTS&#187;, &#171;AES-192-CBC-CTS&#187;, &#171;AES-256-CBC-CTS&#187;, &#171;CAMELLIA-128-CBC-CTS&#187;, &#171;CAMELLIA-192-CBC-CTS&#187; \u0438 &#171;CAMELLIA-256-CBC-CTS&#187;.\n<li class=\"l\"> \u00c8 stata aggiunta la supporto per le firme digitali CAdES-BES (RFC 5126).\n<li class=\"l\"> In AES_GCM \u00e8 stato implementato il parametro AuthEnvelopedData (RFC 5083), che consente di crittografare e decrittografare messaggi autenticati e crittografati utilizzando la modalit\u00e0 AES GCM.  <\/ul>\n<li class=\"l\"> Nell'API pubblica sono state messe a disposizione le funzioni PKCS7_get_octet_string e PKCS7_type_is_other.\n<li class=\"l\"> \u0412 API PKCS#12  \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u044b, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u044b\u0435 \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e \u0432 \u0444\u0443\u043d\u043a\u0446\u0438\u0438 PKCS12_create(), \u0437\u0430\u043c\u0435\u043d\u0435\u043d\u044b \u043d\u0430 PBKDF2 \u0438 AES, \u0430 \u0434\u043b\u044f \u0440\u0430\u0441\u0447\u0451\u0442\u0430   MAC  \u0437\u0430\u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u043d \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c SHA-256. \u0414\u043b\u044f \u0432\u043e\u0441\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0448\u043b\u043e\u0433\u043e \u043f\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043f\u0440\u0435\u0434\u0443\u0441\u043c\u043e\u0442\u0440\u0435\u043d\u0430 \u043e\u043f\u0446\u0438\u044f  &#171;-legacy&#187;. \u0414\u043e\u0431\u0430\u0432\u043b\u0435\u043d\u043e \u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u0447\u0438\u0441\u043b\u043e \u043d\u043e\u0432\u044b\u0445 \u0440\u0430\u0441\u0448\u0438\u0440\u0435\u043d\u043d\u044b\u0445 \u0432\u044b\u0437\u043e\u0432\u043e\u0432 PKCS12_*_ex, PKCS5_*_ex \u0438  PKCS8_*_ex, \u0442\u0430\u043a\u0438\u0445 \u043a\u0430\u043a PKCS12_add_key_ex().PKCS12_create_ex()  \u0438 PKCS12_decrypt_skey_ex().\n<li class=\"l\"> Per la piattaforma Windows \u00e8 stata aggiunta la possibilit\u00e0 di sincronizzare i thread utilizzando il meccanismo SRWLock.\n<li class=\"l\"> \u00c8 stata aggiunta una nuova API per il tracciamento, attivabile tramite il parametro enable-trace.\n<li class=\"l\"> \u00c8 stata ampliata la gamma di chiavi supportate nelle funzioni EVP_PKEY_public_check() e EVP_PKEY_param_check(): RSA, DSA, ED25519, X25519, ED448 e X448.\n<li class=\"l\"> \u00c8 stato rimosso il sottosistema RAND_DRBG, per il quale \u00e8 stata proposta l'API EVP_RAND. Sono state rimosse le funzioni FIPS_mode() e FIPS_mode_set().\n<li class=\"l\"> \u0417\u0430\u043c\u0435\u0442\u043d\u0430\u044f \u0447\u0430\u0441\u0442\u044c API \u043f\u0435\u0440\u0435\u0432\u0435\u0434\u0435\u043d\u0430 \u0432 \u0440\u0430\u0437\u0440\u044f\u0434 \u0443\u0441\u0442\u0430\u0440\u0435\u0432\u0448\u0438\u0445 &#8212; \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 \u0443\u0441\u0442\u0430\u0440\u0435\u0432\u0448\u0438\u0445 \u0432\u044b\u0437\u043e\u0432\u043e\u0432 \u0432 \u043a\u043e\u0434\u0435 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432 \u0431\u0443\u0434\u0435\u0442 \u043f\u0440\u0438\u0432\u043e\u0434\u0438\u0442\u044c \u0432 \u0432\u044b\u0432\u043e\u0434\u0443 \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0436\u0434\u0435\u043d\u0438\u044f \u043f\u0440\u0438 \u043a\u043e\u043c\u043f\u0438\u043b\u044f\u0446\u0438\u0438. \u0412 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u0440\u0435\u0432\u0448\u0438\u043c\u0438 \u043e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0431\u044a\u044f\u0432\u043b\u0435\u043d\u044b \u043d\u0438\u0437\u043a\u043e\u0443\u0440\u043e\u0432\u043d\u0435\u0432\u044b\u0435 API, \u043f\u0440\u0438\u0432\u044f\u0437\u0430\u043d\u043d\u044b\u0435 \u0441 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u044b\u043c \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u043c \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, AES_set_encrypt_key \u0438 AES_encrypt). \u041e\u0444\u0438\u0446\u0438\u0430\u043b\u044c\u043d\u0430\u044f \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 \u0432 OpenSSL 3.0.0 \u0442\u0435\u043f\u0435\u0440\u044c \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043b\u044f \u0432\u044b\u0441\u043e\u043a\u043e\u0443\u0440\u043e\u0432\u043d\u0435\u0432\u044b\u0445 API EVP, \u0430\u0431\u0441\u0442\u0440\u0430\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043e\u0442 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0445 \u0442\u0438\u043f\u043e\u0432 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432 (\u043a \u0434\u0430\u043d\u043d\u043e\u043c\u0443 API \u043e\u0442\u043d\u043e\u0441\u044f\u0442\u0441\u044f, \u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u0444\u0443\u043d\u043a\u0446\u0438\u0438  EVP_EncryptInit_ex, EVP_EncryptUpdate \u0438 EVP_EncryptFinal). \u0412 \u043e\u0434\u043d\u043e\u043c \u0438\u0437 \u0441\u043b\u0435\u0434\u0443\u044e\u0449\u0438\u0445 \u0437\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0445 \u0432\u044b\u043f\u0443\u0441\u043a\u043e\u0432 \u0443\u0441\u0442\u0430\u0440\u0435\u0432\u0448\u0438\u0435 API \u0431\u0443\u0434\u0443\u0442 \u0443\u0434\u0430\u043b\u0435\u043d\u044b. \u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438  \u0443\u0441\u0442\u0430\u0440\u0435\u0432\u0448\u0438\u0445 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432, \u0442\u0430\u043a\u0438\u0445 \u043a\u0430\u043a MD2 \u0438 DES, \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u044b\u0445 \u0447\u0435\u0440\u0435\u0437 API EVP, \u043f\u0435\u0440\u0435\u043d\u0435\u0441\u0435\u043d\u044b \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0439 \u043c\u043e\u0434\u0443\u043b\u044c &#171;legacy&#187;, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043e\u0442\u043a\u043b\u044e\u0447\u0451\u043d \u043f\u043e \u0443\u043c\u043e\u043b\u0447\u0430\u043d\u0438\u044e.\n<li class=\"l\"> \u00c8 stata significativamente ampliata la documentazione e l'insieme di test. Rispetto al ramo 1.1.1, il volume della documentazione \u00e8 aumentato del 94% e le dimensioni del codice del set di test del 54%.  <\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55760\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e\u0441\u043b\u0435 \u0442\u0440\u0451\u0445 \u043b\u0435\u0442 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0438 19 \u0442\u0435\u0441\u0442\u043e\u0432\u044b\u0445 \u0432\u044b\u043f\u0443\u0441\u043a\u043e\u0432 \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 OpenSSL 3.0.0 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432 SSL\/TLS \u0438 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u041d\u043e\u0432\u0430\u044f \u0432\u0435\u0442\u043a\u0430 \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u0442 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f, \u043d\u0430\u0440\u0443\u0448\u0430\u044e\u0449\u0438\u0435 \u043e\u0431\u0440\u0430\u0442\u043d\u0443\u044e \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u043e\u0441\u0442\u044c \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 API \u0438 ABI, \u043d\u043e \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u043d\u0435 \u043f\u043e\u0432\u043b\u0438\u044f\u044e\u0442 \u043d\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0430 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0432\u043e\u0434\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441 OpenSSL 1.1.1 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043f\u0435\u0440\u0435\u0441\u0431\u043e\u0440\u043a\u0438. \u041f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u0432\u0435\u0442\u043a\u0438 OpenSSL 1.1.1 \u0431\u0443\u0434\u0435\u0442 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-101224","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0442\u0440\u0451\u0445 \u043b\u0435\u0442 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0438 19 \u0442\u0435\u0441\u0442\u043e\u0432\u044b\u0445 \u0432\u044b\u043f\u0443\u0441\u043a\u043e\u0432 \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 OpenSSL 3.0.0 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432 SSL\/TLS \u0438 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u041d\u043e\u0432\u0430\u044f \u0432\u0435\u0442\u043a\u0430 \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u0442 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f, \u043d\u0430\u0440\u0443\u0448\u0430\u044e\u0449\u0438\u0435 \u043e\u0431\u0440\u0430\u0442\u043d\u0443\u044e \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u043e\u0441\u0442\u044c \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 API \u0438 ABI, \u043d\u043e \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u043d\u0435 \u043f\u043e\u0432\u043b\u0438\u044f\u044e\u0442 \u043d\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0430 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0432\u043e\u0434\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441 OpenSSL 1.1.1 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043f\u0435\u0440\u0435\u0441\u0431\u043e\u0440\u043a\u0438. \u041f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u0432\u0435\u0442\u043a\u0438 OpenSSL 1.1.1 \u0431\u0443\u0434\u0435\u0442\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/vypusk-kriptograficheskoj-biblioteki-openssl-3-0-0\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043a\u0440\u0438\u043f\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 OpenSSL 3.0.0 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0442\u0440\u0451\u0445 \u043b\u0435\u0442 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0438 19 \u0442\u0435\u0441\u0442\u043e\u0432\u044b\u0445 \u0432\u044b\u043f\u0443\u0441\u043a\u043e\u0432 \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 OpenSSL 3.0.0 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432 SSL\/TLS \u0438 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u041d\u043e\u0432\u0430\u044f \u0432\u0435\u0442\u043a\u0430 \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u0442 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f, \u043d\u0430\u0440\u0443\u0448\u0430\u044e\u0449\u0438\u0435 \u043e\u0431\u0440\u0430\u0442\u043d\u0443\u044e \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u043e\u0441\u0442\u044c \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 API \u0438 ABI, \u043d\u043e \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u043d\u0435 \u043f\u043e\u0432\u043b\u0438\u044f\u044e\u0442 \u043d\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0430 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0432\u043e\u0434\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441 OpenSSL 1.1.1 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043f\u0435\u0440\u0435\u0441\u0431\u043e\u0440\u043a\u0438. \u041f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u0432\u0435\u0442\u043a\u0438 OpenSSL 1.1.1 \u0431\u0443\u0434\u0435\u0442\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/vypusk-kriptograficheskoj-biblioteki-openssl-3-0-0\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-09-08T14:23:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-09-08T14:23:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Rilascio della libreria crittografica OpenSSL 3.0.0 | ProHoster","description":"Dopo tre anni di sviluppo e 19 versioni di prova, \u00e8 stata rilasciata la libreria OpenSSL 3.0.0 con implementazione dei protocolli SSL\/TLS e vari algoritmi di crittografia. Questa nuova versione include modifiche che rompono la compatibilit\u00e0 retroattiva a livello di API e ABI, ma tali cambiamenti non influenzeranno il funzionamento della maggior parte delle applicazioni, per le quali la migrazione da OpenSSL 1.1.1 richiede solo una ricompilazione. Il supporto per la precedente versione OpenSSL 1.1.1 sar\u00e0","canonical_url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/vypusk-kriptograficheskoj-biblioteki-openssl-3-0-0","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u043a\u0440\u0438\u043f\u0442\u043e\u0433\u0440\u0430\u0444\u0438\u0447\u0435\u0441\u043a\u043e\u0439 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 OpenSSL 3.0.0 | ProHoster","og:description":"\u041f\u043e\u0441\u043b\u0435 \u0442\u0440\u0451\u0445 \u043b\u0435\u0442 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0438 19 \u0442\u0435\u0441\u0442\u043e\u0432\u044b\u0445 \u0432\u044b\u043f\u0443\u0441\u043a\u043e\u0432 \u0441\u043e\u0441\u0442\u043e\u044f\u043b\u0441\u044f \u0440\u0435\u043b\u0438\u0437 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 OpenSSL 3.0.0 \u0441 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0435\u0439 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u043e\u0432 SSL\/TLS \u0438 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u043e\u0432 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f. \u041d\u043e\u0432\u0430\u044f \u0432\u0435\u0442\u043a\u0430 \u0432\u043a\u043b\u044e\u0447\u0430\u0435\u0442 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f, \u043d\u0430\u0440\u0443\u0448\u0430\u044e\u0449\u0438\u0435 \u043e\u0431\u0440\u0430\u0442\u043d\u0443\u044e \u0441\u043e\u0432\u043c\u0435\u0441\u0442\u0438\u043c\u043e\u0441\u0442\u044c \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 API \u0438 ABI, \u043d\u043e \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u043d\u0435 \u043f\u043e\u0432\u043b\u0438\u044f\u044e\u0442 \u043d\u0430 \u0440\u0430\u0431\u043e\u0442\u0443 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u0430 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0434\u043b\u044f \u043f\u0435\u0440\u0435\u0432\u043e\u0434\u0430 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441 OpenSSL 1.1.1 \u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043f\u0435\u0440\u0435\u0441\u0431\u043e\u0440\u043a\u0438. \u041f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u0432\u0435\u0442\u043a\u0438 OpenSSL 1.1.1 \u0431\u0443\u0434\u0435\u0442","og:url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/vypusk-kriptograficheskoj-biblioteki-openssl-3-0-0","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-09-08T14:23:07+00:00","article:modified_time":"2021-09-08T14:23:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"101224","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-09-08 14:38:48","updated":"2026-02-22 15:30:27"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/101224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=101224"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/101224\/revisions"}],"predecessor-version":[{"id":162273,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/101224\/revisions\/162273"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=101224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=101224"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=101224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}