OpenSSL is an open-source cryptographic library and command-line toolkit, originally derived from SSLeay in 1998 and now governed by the OpenSSL Software Foundation under an Apache 2.0 licence (since version 3.0). It is the default cryptographic substrate for the majority of Linux server software: Apache httpd, nginx, curl, wget, PostgreSQL, MySQL, Postfix, OpenLDAP, and hundreds of other projects link against libssl and libcrypto by default. It implements TLS (all versions from 1.2 through 1.3), X.509 certificate parsing and validation, PKI operations (CSR generation, certificate signing, CRL and OCSP processing), and the full range of cryptographic primitives — symmetric ciphers (AES-GCM, ChaCha20-Poly1305), hash functions (SHA-2, SHA-3, SHAKE), RSA, ECC (ECDSA, ECDH, Ed25519, X25519), HMAC, HKDF, and key derivation functions. The library has two primary components: libcrypto, the algorithm library, and libssl, the TLS protocol layer built on top of it. The openssl command-line tool exposes both as a single swiss-army interface for certificate management, key generation, encryption, hashing, benchmarking, and protocol testing.
OpenSSL’s versioning history is operationally important. Versions 0.9.x through 1.0.2 are end-of-life and contain known vulnerabilities including Heartbleed (CVE-2014-0160, 2014 — an out-of-bounds read in the TLS heartbeat extension that exposed up to 64 KB of server memory per request, including private keys, and triggered a global certificate revocation event). Version 1.1.1 reached end-of-life in September 2023; version 3.0 was the transition that restructured the library into a provider architecture — a plugin model where algorithm implementations are supplied by provider modules (the built-in default provider, the legacy provider for deprecated algorithms, and the fips provider). OpenSSL 3.x is the current supported branch, with 3.0 LTS (end-of-life 2026) and 3.4+ as the actively developed line. The FIPS provider for OpenSSL 3.x has received FIPS 140-3 validation, making OpenSSL 3.x+FIPS the production path for US federal and compliance-mandated deployments. OpenSSL 3.4 added initial support for ML-KEM (FIPS 203) and ML-DSA (FIPS 204) via the default provider, with SLH-DSA (FIPS 205) following in 3.5 — making OpenSSL 3.4+ the primary PQC migration path for the Linux ecosystem. The hybrid TLS 1.3 key exchange group X25519MLKEM768 is supported from OpenSSL 3.4, enabling the already-deployed Chrome interoperability without additional patching.
The openssl CLI is the universal screwdriver for certificate and key operations in the Linux ecosystem, and knowing its most operationally important commands is essential for anyone managing PKI or TLS infrastructure. openssl req -newkey ec -pkeyopt ec_paramgen_curve:P-256 -keyout key.pem -out csr.pem generates an ECDSA P-256 private key and CSR. openssl x509 -in cert.pem -noout -text decodes and displays a certificate’s full contents including SANs, validity, and extensions. openssl verify -CAfile ca-bundle.pem cert.pem validates a certificate chain against a trust store. openssl s_client -connect host:443 -showcerts opens a TLS connection and displays the full certificate chain presented by the server — the most reliable way to diagnose certificate chain issues in production. openssl pkeyutl -sign and openssl dgst handle signing and hashing from scripts. openssl speed benchmarks algorithm performance on the local hardware, producing reference numbers for algorithm selection decisions. For LUKS users, cryptsetup uses libgcrypt rather than OpenSSL, but the conceptual mapping of operations is the same. For cert-manager and Vault, OpenSSL’s algorithm support matrix defines what the underlying certificate operations can produce; the addition of ML-DSA to OpenSSL 3.4 is therefore the dependency that unblocks those tools’ PQC certificate issuance. BoringSSL (Google’s fork) and LibreSSL (OpenBSD’s fork) provide API-compatible alternatives with narrower, more conservative algorithm sets; AWS-LC (Amazon’s fork of BoringSSL) adds FIPS 140-3 validation and ML-KEM/ML-DSA support and is the default in AWS SDK and Rust aws-lc-rs deployments.
