News: 0001626819

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

OpenSSL 4.0 Released With Encrypted Client Hello, RFC 8998 Support

([Free Software] 3 Hours Ago OpenSSL 4.0)


OpenSSL 4.0 was just released as a big update for this widely-used SSL/TLS and crypto library.

OpenSSL 4.0 delivers better privacy with Encrypted Client Hello (ECH) support to encrypt the initial TLS handshake and hide the Server Name Indication. OpenSSL 4.0 also drops legacy SSLv3 and other old protocol/engine support, improves post-quantum cryptography support with RFC 8998 support, ML-DSA-MU, and tls-hybrid-sm2-mlkem post-quantum group.

OpenSSL 4.0 also makes use of the major version bump to introduce other incompatible changes like removing SSLv2 Client Hello and dropping support for engines as well as removing the Darwin i386 and PowerPC/PPC64 targets.

More details on the OpenSSL 4.0 release via [1]GitHub .



[1] https://github.com/openssl/openssl/releases/tag/openssl-4.0.0



As I argued in "Beloved Son", a book about my son Brian and the subject
of religious communes and cults, one result of proper early instruction
in the methods of rational thought will be to make sudden mindless
conversions -- to anything -- less likely. Brian now realizes this and
has, after eleven years, left the sect he was associated with. The
problem is that once the untrained mind has made a formal commitment to
a religious philosophy -- and it does not matter whether that philosophy
is generally reasonable and high-minded or utterly bizarre and
irrational -- the powers of reason are surprisingly ineffective in
changing the believer's mind.
-- Steve Allen, comedian, from an essay in the book "The Courage of
Conviction", edited by Philip Berman