OpenSSL 3.4 Alpha 1 Released with New Features
phoronix.com
phoronix.com
The v3.4 roadmap entry PR mentions QUIC (which HTTP/3 requires)? https://github.com/openssl/web/pull/481/files
Someday there will probably be a TLS1.4/2.0 with PQ, and also FIPS-140 -4?
Are there additional ways to implement NIST PQ finalist algos with openssl?
open-quantum-safe/oqs-provider: https://github.com/open-quantum-safe/oqs-provider :
openssl list -signature-algorithms -provider oqsprovider
openssl list -kem-algorithms -provider oqsprovider
openssl list -tls-signature-algorithms- Added FIPS indicators to the FIPS provider as part of FIPS 140-3 requirements.
- A new random seed source RNG JITTER using a statically-linked jitterentropy library.
- The "openssl list" command can now retrieve configured TLS signature algorithms.
- Improved Base64 BIO correctness and error reporting.
- Support for HMAC hardware acceleration on the IBM s390x architecture.
- RFC 9579 (PBMAC1) implementation in PKCS#12
- Support for directly-fetched composite signature algorithms like RSA-SHA2-256.
- Support for RFC 9150 with integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3
- Attribute Certificate (RFC 5755) support.
- OpenSSL now supports building Position Independent Executables (PIE) with a new "enable-pie" configuration option to support Address Space Layout Randomization (ASL)R with the OpenSSL executable.