OpenSSL 3.0.0 ืงืจื™ืคึผื˜ืึธื’ืจืึทืคื™ืง ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืžืขืœื“ื•ื ื’

ื ืึธืš ื“ืจื™ื™ ื™ืึธืจ ืคื•ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ืื•ืŸ 19 ืคึผืจืึธื‘ืข ืจื™ืœื™ืกื™ื–, ื“ื™ OpenSSL 3.0.0 ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืื™ื– ื‘ืืคืจื™ื™ื˜ ืžื™ื˜ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ SSL / TLS ืคึผืจืึธื˜ืึธืงืึธืœืก ืื•ืŸ ืคืึทืจืฉื™ื“ืŸ ืขื ืงืจื™ืคึผืฉืึทืŸ ืึทืœื’ืขืจื™ื“ืึทืžื–. ื“ื™ ื ื™ื™ึทืข ืฆื•ื•ื™ื™ึทื’ ื™ื ืงืœื•ื“ื– ืขื ื“ืขืจื•ื ื’ืขืŸ ื•ื•ืึธืก ื‘ืจืขื›ืŸ ืงืึทืคึผื•ื™ืขืจ ืงืึทืžืคึผืึทื˜ืึทื‘ื™ืœืึทื˜ื™ ื‘ื™ื™ ื“ื™ API ืื•ืŸ ABI ืžื“ืจื’ื”, ืึธื‘ืขืจ ื“ื™ ืขื ื“ืขืจื•ื ื’ืขืŸ ื•ื•ืขืœืŸ ื ื™ืฉื˜ ื•ื•ื™ืจืงืŸ ื“ื™ ืึธืคึผืขืจืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ืจื•ื‘ึฟ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื•ื•ืึธืก ื“ืึทืจืคืŸ ืึท ืจื™ื‘ื™ืœื“ ืฆื• ืžื™ื™ื’ืจื™ื™ื˜ ืคึฟื•ืŸ OpenSSL 1.1.1. ื“ื™ ืคืจื™ืขืจื“ื™ืงืข ืฆื•ื•ื™ื™ึทื’ ืคื•ืŸ OpenSSL 1.1.1 ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขืฉื˜ื™ืฆื˜ ื‘ื™ื– ืกืขืคื˜ืขืžื‘ืขืจ 2023.

ื ื‘ืึทื˜ื™ื™ึทื˜ื™ืง ืขื ื“ืขืจื•ื ื’ ืื™ืŸ ื“ื™ ื•ื•ืขืจืกื™ืข ื ื•ืžืขืจ ืื™ื– ืจืขื›ื˜ ืฆื• ื“ืขืจ ื™ื‘ืขืจื’ืึทื ื’ ืฆื• ื“ื™ ื˜ืจืื“ื™ืฆื™ืื ืขืœืŸ "ืžืึทื“ื–ืฉืึธืจ.ืžื™ื ืึธืจ.ืคึผืึทื˜ืฉ" ื ื•ืžืขืจื™ื ื’. ืคึฟื•ืŸ ืื™ืฆื˜ ืื•ื™ืฃ, ื“ืขืจ ืขืจืฉื˜ืขืจ ืฆื™ืคึฟืขืจ (ืžืึทื“ื–ืฉืึธืจ) ืื™ืŸ ื“ื™ ื•ื•ืขืจืกื™ืข ื ื•ืžืขืจ ื•ื•ืขื˜ ื˜ื•ื™ืฉืŸ ื‘ืœื•ื™ื– ืื•ื™ื‘ ืงืึทืžืคึผืึทื˜ืึทื‘ื™ืœืึทื˜ื™ ืื™ื– ืฆืขื‘ืจืื›ืŸ ืื™ืŸ ื“ื™ API / ABI ืžื“ืจื’ื”, ืื•ืŸ ื“ื™ ืจื’ืข (ืžื™ื™ื ืขืจ) ื•ื•ืขื˜ ื˜ื•ื™ืฉืŸ ื•ื•ืขืŸ ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ืื™ื– ื’ืขื•ื•ืืงืกืŸ ืึธืŸ ื˜ืฉืึทื ื’ื™ื ื’ ื“ื™ API / ABI. ืงืขืจืขืงื˜ื™ื•ื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืื™ื‘ืขืจื’ืขื’ืขื‘ืŸ ืžื™ื˜ ืึท ืขื ื“ืขืจื•ื ื’ ืฆื• ื“ื™ ื“ืจื™ื˜ ืฆื™ืคึฟืขืจ (ืคึผืึทื˜ืฉ). ื“ื™ ื ื•ืžืขืจ 3.0.0 ื’ืœื™ื™ืš ื ืึธืš 1.1.1 ืื™ื– ืื•ื™ืกื“ืขืจื•ื•ื™ื™ืœื˜ ืฆื• ื•ื™ืกืžื™ื™ื“ืŸ ืึธื•ื•ื•ืขืจืœืึทืคึผืก ืžื™ื˜ ื“ื™ ื“ืขืจื•ื•ื™ื™ึทืœ ืื•ื ื˜ืขืจ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ FIPS ืžืึธื“ื•ืœืข ืคึฟืึทืจ OpenSSL, ืคึฟืึทืจ ื•ื•ืึธืก ื“ื™ 2.x ื ื•ืžืขืจื™ื ื’ ืื™ื– ื’ืขื ื™ืฆื˜.

ื“ื™ ืฆื•ื•ื™ื™ื˜ืข ื•ื•ื™ื›ื˜ื™ืง ืขื ื“ืขืจื•ื ื’ ืคึฟืึทืจ ื“ื™ ืคึผืจื•ื™ืขืงื˜ ืื™ื– ื’ืขื•ื•ืขืŸ ื“ื™ ื™ื‘ืขืจื’ืึทื ื’ ืคื•ืŸ ืึท ืฆื•ื•ื™ื™ืขื ื“ื™ืง ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ (OpenSSL ืื•ืŸ SSLeay) ืฆื• ื“ื™ Apache 2.0 ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ. ื“ื™ ืคืจื™ืขืจื“ื™ืงืข ืคึผืจืึทืคึผืจื™ื™ืึทื˜ืขืจื™ OpenSSL ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืื™ื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ื˜ืขืงืกื˜ ืคื•ืŸ ื“ื™ ืœืขื’ืึทื˜ Apache 1.0 ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืื•ืŸ ืคืืจืœืื ื’ื˜ ื™ืงืกืคึผืœื™ืกืึทื˜ ื“ืขืจืžืึธื ืขืŸ ืคื•ืŸ OpenSSL ืื™ืŸ ืคึฟืึทืจืงื•ื™ืฃ ืžืึทื˜ืขืจื™ืึทืœืก ื•ื•ืขืŸ ื ื™ืฆืŸ OpenSSL ืœื™ื™ื‘ืจืขืจื™ื–, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ืึท ืกืคึผืขืฆื™ืขืœ ืึธื ื–ืึธื’ ืื•ื™ื‘ OpenSSL ืื™ื– ื’ืขื•ื•ืขืŸ ืฆื•ื’ืขืฉื˜ืขืœื˜ ื•ื•ื™ ืึท ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ ืคึผืจืึธื“ื•ืงื˜. ื“ื™ ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ ื’ืขืžืื›ื˜ ื“ื™ ืึทืœื˜ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ื™ื ืงืึทืžืคึผืึทื˜ืึทื‘ืึทืœ ืžื™ื˜ ื“ื™ GPL, ืžืื›ืŸ ืขืก ืฉื•ื•ืขืจ ืฆื• ื ื•ืฆืŸ OpenSSL ืื™ืŸ GPL-ืœื™ื™ืกืึทื ืกื˜ ืคึผืจืึทื“ื–ืฉืขืงืก. ืฆื• ื‘ืึทืงื•ืžืขืŸ ืึทืจื•ื ื“ืขื ื™ื ืงืึทืžืคึผืึทื˜ืึทื‘ื™ืœืึทื˜ื™, GPL ืคืจืื™ืขืงื˜ืŸ ื–ืขื ืขืŸ ื’ืขืฆื•ื•ื•ื ื’ืขืŸ ืฆื• ื ื•ืฆืŸ ืกืคึผืขืฆื™ืคื™ืฉ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืึทื’ืจื™ืžืึทื ืฅ ืื™ืŸ ื•ื•ืึธืก ื“ื™ ื”ื•ื™ืคึผื˜ ื˜ืขืงืกื˜ ืคื•ืŸ ื“ื™ GPL ืื™ื– ื’ืขื•ื•ืขืŸ ืกืึทืคึผืœืึทืžืขื ื˜ืึทื“ ืžื™ื˜ ืึท ืคึผื•ื ืงื˜ ื•ื•ืึธืก ื‘ืคื™ืจื•ืฉ ืขืจืœื•ื™ื‘ื˜ ื“ื™ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืฆื• ื–ื™ื™ืŸ ืœื™ื ื’ืงื˜ ืžื™ื˜ ื“ื™ OpenSSL ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืื•ืŸ ื“ืขืจืžืื ื˜ ืึทื– ื“ื™ ื‘ืื“ืขืจืคืขื ื™ืฉืŸ ืคื•ืŸ ื“ื™ GPL ื˜ืึธืŸ ื ื™ื˜. ืฆื•ืœื™ื™ื’ืŸ ืฆื• ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ ืžื™ื˜ OpenSSL.

ืงืึทืžืคึผืขืจื“ ืฆื• ื“ื™ OpenSSL 1.1.1 ืฆื•ื•ื™ื™ึทื’, OpenSSL 3.0.0 ืฆื•ื’ืขื’ืขื‘ืŸ ืžืขืจ ื•ื•ื™ 7500 ืขื ื“ืขืจื•ื ื’ืขืŸ ืงืึทื ื˜ืจื™ื‘ื™ื•ื˜ื™ื“ ื“ื•ืจืš 350 ื“ืขื•ื•ืขืœืึธืคึผืขืจืก. ื”ื•ื™ืคึผื˜ ื™ื ืึธื•ื•ื•ื™ื™ืฉืึทื ื– ืคื•ืŸ OpenSSL 3.0.0:

  • ื ื ื™ื™ึทืข FIPS ืžืึธื“ื•ืœืข ืื™ื– ืคืืจื’ืขืœื™ื™ื’ื˜, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ืงืจื™ืคึผื˜ืึธื’ืจืึทืคื™ืง ืึทืœื’ืขืจื™ื“ืึทืžื– ื•ื•ืึธืก ื ืึธื›ืงื•ืžืขืŸ ืžื™ื˜ ื“ื™ FIPS 140-2 ื–ื™ื›ืขืจื”ื™ื™ื˜ ื ืึธืจืžืึทืœ (ื“ื™ ืกืขืจื˜ืึทืคืึทืงื™ื™ืฉืึทืŸ ืคึผืจืึธืฆืขืก ืคึฟืึทืจ ื“ื™ ืžืึธื“ื•ืœืข ืื™ื– ืกืงืขื“ื–ืฉื•ืœื“ ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ื“ืขื ื—ื•ื“ืฉ, ืื•ืŸ FIPS 140-2 ืกืขืจื˜ืึทืคืึทืงื™ื™ืฉืึทืŸ ืื™ื– ื’ืขืจื™ื›ื˜ ื•ื•ื™ื™ึทื˜ืขืจ ื™ืึธืจ). ื“ื™ ื ื™ื™ึทืข ืžืึธื“ื•ืœืข ืื™ื– ืคื™ืœ ื’ืจื™ื ื’ืขืจ ืฆื• ื ื•ืฆืŸ ืื•ืŸ ืงืึทื ืขืงื˜ื™ื ื’ ืขืก ืฆื• ืคื™ืœืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื•ื•ืขื˜ ื–ื™ื™ืŸ ื ื™ื˜ ืžืขืจ ืฉื•ื•ืขืจ ื•ื•ื™ ื˜ืฉืึทื ื’ื™ื ื’ ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข. ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื“ื™ FIPS ืžืึธื“ื•ืœืข ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜ ืื•ืŸ ืจื™ืงื•ื•ื™ื™ืขืจื– ื“ื™ ื’ืขื‘ืŸ-ืคื™ืคึผืก ืึธืคึผืฆื™ืข ืฆื• ื–ื™ื™ืŸ ืขื ื™ื™ื‘ืึทืœื“.
  • libcrypto ื™ืžืคึผืœืึทืžืึทื ืฅ ื“ืขืจ ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ืคึผืœืึทื’ืึทื‘ืึทืœ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื–, ื•ื•ืึธืก ืจื™ืคึผืœื™ื™ืกื˜ ื“ืขื ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ ืขื ื“ื–ืฉืึทื ื– (ื“ื™ ENGINE API ืื™ื– ื“ื™ืคึผืจื™ืฉื™ื™ื™ื˜ื™ื“). ืžื™ื˜ ื“ื™ ื”ื™ืœืฃ ืคื•ืŸ ืคึผืจืึทื•ื•ื™ื™ื“ืขืจื–, ืื™ืจ ืงืขื ืขืŸ ืœื™ื™ื’ืŸ ื“ื™ื™ืŸ ืื™ื™ื’ืขื ืข ื™ืžืคึผืœืึทืžืึทื ืฅ ืคื•ืŸ ืึทืœื’ืขืจื™ื“ืึทืžื– ืคึฟืึทืจ ืึทื–ืึท ืึทืคึผืขืจื™ื™ืฉืึทื ื– ื•ื•ื™ ืขื ืงืจื™ืคึผืฉืึทืŸ, ื“ืขืงืจื™ืคึผื˜ื™ืึธืŸ, ืฉืœื™ืกืœ ื“ื•ืจ, MAC ื›ืขื–ืฉื‘ืŸ, ืฉืึทืคื•ื ื’ ืื•ืŸ ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ื’ื™ื˜ืึทืœ ืกื™ื’ื ืึทื˜ืฉืขืจื–. ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ื ื™ื™ึทืข ืื•ืŸ ืฉืึทืคึฟืŸ ืึธืœื˜ืขืจื ืึทื˜ื™ื•ื• ื™ืžืคึผืœืึทืžืึทื ืฅ ืคื•ืŸ ืฉื•ื™ืŸ ื’ืขืฉื˜ื™ืฆื˜ ืึทืœื’ืขืจื™ื“ืึทืžื– (ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื“ืขืจ ืฉืคึผื™ื™ึทื–ืขืจ ื’ืขื‘ื•ื™ื˜ ืื™ืŸ OpenSSL ืื™ื– ืื™ืฆื˜ ื’ืขื ื™ืฆื˜ ืคึฟืึทืจ ื™ืขื“ืขืจ ืึทืœื’ืขืจื™ื“ืึทื).
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื“ื™ ืกืขืจื˜ื™ืคื™ืงืึทื˜ ืžืึทื ืึทื’ืขืžืขื ื˜ ืคึผืจืึธื˜ืึธืงืึธืœ (RFC 4210), ื•ื•ืึธืก ืงืขื ืขืŸ ื•ื•ืขืจืŸ ื’ืขื ื•ืฆื˜ ืฆื• ื‘ืขื˜ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืคื•ืŸ ืึท CA ืกืขืจื•ื•ืขืจ, ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืื•ืŸ ืึธืคึผืจื•ืคืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ. ืืจื‘ืขื˜ืŸ ืžื™ื˜ ืงืžืคึผ ืื™ื– ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืžื™ื˜ ื“ื™ ื ื™ื™ึทืข ืึธืคึผืขื ืกืกืœ-ืงืžืคึผ ื ื•ืฆืŸ, ื•ื•ืึธืก ืื•ื™ืš ืฉื˜ื™ืฆื˜ ื“ื™ CRMF ืคึฟืึธืจืžืึทื˜ (RFC 4211) ืื•ืŸ ืฉื™ืงืŸ ืจื™ืงื•ื•ืขืก ื“ื•ืจืš ื”ื˜ื˜ืคึผ / ื”ื˜ื˜ืคึผืก (RFC 6712).
  • ื ืคื•ืœ-ืคืœืขื“ื–ืฉื“ ืงืœื™ืขื ื˜ ืคึฟืึทืจ ื“ื™ ื”ื˜ื˜ืคึผ ืื•ืŸ ื”ื˜ื˜ืคึผืก ืคึผืจืึธื˜ืึธืงืึธืœืก ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“, ืฉื˜ื™ืฆืŸ ื“ื™ GET ืื•ืŸ POST ืžืขื˜ื”ืึธื“ืก, ื‘ืขื˜ืŸ ืจื™ื“ืขืจืขืงืฉืึทืŸ, ืืจื‘ืขื˜ืŸ ื“ื•ืจืš ืึท ืคึผืจืึทืงืกื™, ASN.1 ืงืึธื“ื™ืจื•ื ื’ ืื•ืŸ ื˜ื™ื™ืžืึทื•ื˜ ืคึผืจืึทืกืขืกื™ื ื’.
  • ื ื ื™ื™ึทืข EVP_MAC (Message Authentication Code API) ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ืžืึทื›ืŸ ืขืก ื’ืจื™ื ื’ืขืจ ืฆื• ืœื™ื™ื’ืŸ ื ื™ื™ึทืข ื™ืžืคึผืœืึทืžืึทื ืฅ ืคื•ืŸ ืจื™ื™ืฆื  ื™ื ืกืขืจืฅ.
  • ื ื ื™ื™ึทืข ื•ื•ื™ื™ื›ื•ื•ืืจื’ ืฆื•ื‘ื™ื ื“ ืคึฟืึทืจ ื“ื–ืฉืขื ืขืจื™ื™ื˜ื™ื ื’ ืฉืœื™ืกืœืขืŸ ืื™ื– ืคืืจื’ืขืœื™ื™ื’ื˜ - EVP_KDF (Key Derivation Function API), ื•ื•ืึธืก ืกื™ืžืคึผืœืึทืคื™ื™ื– ื“ื™ ืึทื“ื™ืฉืึทืŸ ืคื•ืŸ ื ื™ื™ึทืข ื™ืžืคึผืœืึทืžืึทื ืฅ ืคื•ืŸ KDF ืื•ืŸ PRF. ื“ื™ ืึทืœื˜ EVP_PKEY API, ื“ื•ืจืš ื•ื•ืึธืก ื“ื™ ืกืงืจื™ืคึผื˜, TLS1 PRF ืื•ืŸ HKDF ืึทืœื’ืขืจื™ื“ืึทืžื– ื–ืขื ืขืŸ ื‘ื ื™ืžืฆื, ืื™ื– ืจื™ื“ื™ื–ื™ื™ื ื“ ืื™ืŸ ื“ื™ ืคืึธืจืขื ืคื•ืŸ ืึท ืฉื™ื›ื˜ืข ื™ืžืคึผืœืึทืžืขื ืึทื“ ืื•ื™ืฃ ืฉืคึผื™ืฅ ืคื•ืŸ ื“ื™ EVP_KDF ืื•ืŸ EVP_MAC APIs.
  • ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ TLS ืคึผืจืึธื˜ืึธืงืึธืœ ื’ื™ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ ื“ื™ TLS ืงืœื™ืขื ื˜ ืื•ืŸ ืกืขืจื•ื•ืขืจ ื’ืขื‘ื•ื™ื˜ ืื™ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ ืฆื• ืคืึทืจื’ื™ื›ืขืจืŸ ืึทืคึผืขืจื™ื™ืฉืึทื ื–. ืฆื• ื’ืขื‘ืŸ ื“ื™ TLS ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืฆื•ื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ, ืื™ืจ ืžื•ื–ืŸ ื’ืขื‘ืŸ ื“ื™ "SSL_OP_ENABLE_KTLS" ืึธืคึผืฆื™ืข ืึธื“ืขืจ ื“ื™ "Enable-ktls" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ.
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื ื™ื™ึทืข ืึทืœื’ืขืจื™ื“ืึทืžื–:
    • ืฉืœื™ืกืœ ื“ื•ืจ ืึทืœื’ืขืจื™ื“ืึทืžื– (KDF) ื–ืขื ืขืŸ "ืื™ื™ืŸ ืฉืจื™ื˜" ืื•ืŸ "ืกืฉ".
    • ืกื™ืžื™ืึทืœื™ื™ื˜ื™ื“ ื™ื ืกืขืจืฉืึทืŸ ืึทืœื’ืขืจื™ื“ืึทืžื– (MAC) ื–ืขื ืขืŸ "GMAC" ืื•ืŸ "KMAC".
    • ืจืกืึท ืฉืœื™ืกืœ ืขื ืงืึทืคึผืกื•ืœืึทื˜ื™ืึธืŸ ืึทืœื’ืขืจื™ื“ืึทื (ืงืขื) "ืจืกืึทืกื•ื•ืข".
    • ืขื ืงืจื™ืคึผืฉืึทืŸ ืึทืœื’ืขืจื™ื“ืึทื "AES-SIV" (RFC-8452).
    • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืจื•ืคื˜ ืฆื• ื“ื™ EVP API ื•ื•ืึธืก ืฉื˜ื™ืฆืŸ ืคืึทืจืงืขืจื˜ ืกื™ืคืขืจืก ื ื™ืฆืŸ ื“ื™ AES ืึทืœื’ืขืจื™ื“ืึทื ืฆื• ืขื ืงืจื™ืคึผื˜ ืฉืœื™ืกืœืขืŸ (ืงื™ื™ ื•ื•ืจืึทืคึผ): "AES-128-WRAP-INV", "AES-192-WRAP-INV", "AES-256-WRAP-INV". ", "AES-128-WRAP-PAD-INV", "AES-192-WRAP-PAD-INV" ืื•ืŸ "AES-256-WRAP-PAD-INV".
    • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืกื™ืคืขืจื˜ืขืงืกื˜ ื‘ืึทืจืึธื•ื™ื ื’ (CTS) ืึทืœื’ืขืจื™ื“ืึทืžื– ืฆื• ื“ื™ EVP API: "AES-128-CBC-CTS", "AES-192-CBC-CTS", "AES-256-CBC-CTS", "CAMELLIA-128-CBC". -CTS", "CAMELLIA-192-CBC-CTS" ืื•ืŸ "CAMELLIA-256-CBC-CTS".
    • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ CAdES-BES ื“ื™ื’ื™ื˜ืึทืœ ืกื™ื’ื ืึทื˜ืฉืขืจื– (RFC 5126).
    • AES_GCM ื™ืžืคึผืœืึทืžืึทื ืฅ ื“ื™ AuthEnvelopedData (RFC 5083) ืคึผืึทืจืึทืžืขื˜ืขืจ ืฆื• ื’ืขื‘ืŸ ืขื ืงืจื™ืคึผืฉืึทืŸ ืื•ืŸ ื“ืขืงืจื™ืคึผื˜ื™ืึธืŸ ืคื•ืŸ ืึทืจื˜ื™ืงืœืขืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ืื•ืŸ ื™ื ืงืจื™ืคึผื˜ื™ื“ ืžื™ื˜ ื“ื™ AES GCM ืžืึธื“ืข.
  • ื“ื™ PKCS7_get_octet_string ืื•ืŸ PKCS7_type_is_other ืคืึทื ื’ืงืฉืึทื ื– ื–ืขื ืขืŸ ืžื•ืกื™ืฃ ืฆื• ื“ื™ ืขืคื ื˜ืœืขืš ืึทืคึผื™.
  • ื“ื™ PKCS #12 API ืจื™ืคึผืœื™ื™ืกื™ื– ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืึทืœื’ืขืจื™ื“ืึทืžื– ื’ืขื ื™ืฆื˜ ืื™ืŸ ื“ื™ PKCS12_create () ืคึฟื•ื ืงืฆื™ืข ืžื™ื˜ PBKDF2 ืื•ืŸ AES, ืื•ืŸ ื ื™ืฆื˜ ื“ื™ SHA-256 ืึทืœื’ืขืจื™ื“ืึทื ืฆื• ืจืขื›ืขื ืขืŸ MAC. ืฆื• ื•ืžืงืขืจืŸ ืคืึทืจื’ืึทื ื’ืขื ื”ื™ื™ื˜ ื ืึทื˜ื•ืจ, ื“ื™ "-ืœืขื’ืึทื˜" ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขืฉื˜ืขืœื˜. ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ื’ืจื•ื™ืก ื ื•ืžืขืจ ืคื•ืŸ ื ื™ื™ึทืข ืขืงืกื˜ืขื ื“ืขื“ ืงืึทืœืœืก ืฆื• PKCS12_*_ex, PKCS5_*_ex ืื•ืŸ PKCS8_*_ex, ืึทื–ืึท ื•ื•ื™ PKCS12_add_key_ex().PKCS12_create_ex() ืื•ืŸ PKCS12_decrypt_skey_ex().
  • ืคึฟืึทืจ ื“ื™ Windows ืคึผืœืึทื˜ืคืึธืจืžืข, ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืคืึธื“ืขื ืกื™ื ื’ืงืจืึทื ืึทื–ื™ื™ืฉืึทืŸ ืžื™ื˜ ื“ื™ SRWLock ืžืขืงืึทื ื™ื–ืึทื ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ.
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืึท ื ื™ื™ึทืข ื˜ืจื™ื™ืกื™ื ื’ ืึทืคึผื™, ืขื ื™ื™ื‘ืึทืœื“ ื“ื•ืจืš ื“ื™ ื’ืขื‘ืŸ-ืฉืคึผื•ืจ ืคึผืึทืจืึทืžืขื˜ืขืจ.
  • ื“ื™ ืงื™ื™ื˜ ืคื•ืŸ ืฉืœื™ืกืœืขืŸ ื’ืขืฉื˜ื™ืฆื˜ ืื™ืŸ ื“ื™ EVP_PKEY_public_check () ืื•ืŸ EVP_PKEY_param_check () ืคืึทื ื’ืงืฉืึทื ื– ืื™ื– ื™ืงืกืคึผืึทื ื“ื™ื“: RSA, DSA, ED25519, X25519, ED448 ืื•ืŸ X448.
  • ื“ื™ RAND_DRBG ืกืึทื‘ืกื™ืกื˜ืขื ืื™ื– ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ, ืจื™ืคึผืœื™ื™ืกื˜ ื“ื•ืจืš ื“ื™ EVP_RAND API. ื“ื™ FIPS_mode () ืื•ืŸ FIPS_mode_set () ืคืึทื ื’ืงืฉืึทื ื– ื–ืขื ืขืŸ ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ.
  • ื ื‘ืึทื˜ื™ื™ื˜ื™ืง ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ API ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึทืจืขืœื˜ืขืจื˜ - ื ื™ืฆืŸ ืคืึทืจืขืœื˜ืขืจื˜ ืงืึทืœืœืก ืื™ืŸ ืคึผืจื•ื™ืขืงื˜ ืงืึธื“ ื•ื•ืขื˜ ืจืขื–ื•ืœื˜ืึทื˜ ืื™ืŸ ื•ื•ืึธืจื ื™ื ื’ื– ื‘ืขืฉืึทืก ื–ืึทืžืœื•ื ื’. ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ื ื™ื“ืขืจื™ืง-ืžื“ืจื’ื” ืึทืคึผื™ืก ื˜ื™ื™ื“ ืฆื• ื–ื™ื›ืขืจ ื™ืžืคึผืœืึทืžืึทื ืฅ ืคื•ืŸ ืึทืœื’ืขืจื™ื“ืึทืžื– (ืœืžืฉืœ, AES_set_encrypt_key ืื•ืŸ AES_encrypt) ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืึทืคื™ืฉืึทืœื™ ื“ืขืจืงืœืขืจื˜ ืคืึทืจืขืœื˜ืขืจื˜. ื‘ืึทืึทืžื˜ืขืจ ืฉื˜ื™ืฆืŸ ืื™ืŸ OpenSSL 3.0.0 ืื™ื– ืื™ืฆื˜ ื‘ืœื•ื™ื– ืฆื•ื’ืขืฉื˜ืขืœื˜ ืคึฟืึทืจ ื”ื•ื™ืš-ืžื“ืจื’ื” EVP ืึทืคึผื™ืก ื•ื•ืึธืก ื–ืขื ืขืŸ ืึทื‘ืกื˜ืจืึทืงื˜ื™ื“ ืคื•ืŸ ื™ื—ื™ื“ ืึทืœื’ืขืจื™ื“ืึทื ื˜ื™ื™ืคึผืก (ื“ืขื ืึทืคึผื™ ื›ื•ืœืœ, ืœืžืฉืœ, ื“ื™ EVP_EncryptInit_ex, EVP_EncryptUpdate ืื•ืŸ EVP_EncryptFinal ืคืึทื ื’ืงืฉืึทื ื–). ื“ื™ืคึผืจื™ืฉื™ื™ื™ื˜ื™ื“ ืึทืคึผื™ืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ืื™ืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ื•ื•ื™ื™ึทื˜ืขืจ ื”ื•ื™ืคึผื˜ ืจื™ืœื™ืกื™ื–. ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทื ื– ืคื•ืŸ ืœืขื’ืึทื˜ ืึทืœื’ืขืจื™ื“ืึทืžื– ืึทื–ืึท ื•ื•ื™ MD2 ืื•ืŸ DES, ื‘ื ื™ืžืฆื ื“ื•ืจืš ื“ื™ EVP API, ื–ืขื ืขืŸ ืืจื™ื‘ืขืจื’ืขืคืืจืŸ ืฆื• ืึท ื‘ืึทื–ื•ื ื“ืขืจ "ืœืขื’ืึทื˜" ืžืึธื“ื•ืœืข, ื•ื•ืึธืก ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜.
  • ื“ื™ ื“ืึทืงื™ื•ืžืขื ื˜ื™ื™ืฉืึทืŸ ืื•ืŸ ืคึผืจื•ื‘ื™ืจืŸ ืกื•ื•ื™ื˜ ื–ืขื ืขืŸ ื‘ืื˜ื™ื™ื˜ื™ืง ื™ืงืกืคึผืึทื ื“ื™ื“. ืงืึทืžืคึผืขืจื“ ืฆื• ืฆื•ื•ื™ื™ึทื’ 1.1.1, ื“ื™ ื‘ืึทื ื“ ืคื•ืŸ ื“ืึทืงื™ื•ืžืขื ื˜ื™ื™ืฉืึทืŸ ืื™ื– ื’ืขื•ื•ืืงืกืŸ ืžื™ื˜ 94%, ืื•ืŸ ื“ื™ ื’ืจื™ื™ืก ืคื•ืŸ ื“ื™ ืคึผืจืึธื‘ืข ืกื•ื•ื™ื˜ ืงืึธื“ ืื™ื– ื’ืขื•ื•ืืงืกืŸ ืžื™ื˜ 54%.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’