NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #352 most downloaded on crates.io
A wrapper over a platform's native TLS implementation
Last release 7 months ago
18 Feb 2026
Ships fairly regularly
a new release about every 8 months
Most releases are documented
notes for 18 of 24 stable releases
1 version withdrawn
withdrawn after publishing
10 years old
25 releases · first in 2016
Fixed min/max protocol selection fallback for very old OpenSSL versions.
Added ALPN support to TlsAcceptor by @matszpk in #229 and @JohnGu9 in #363
Full Changelog: v0.2.16...v0.2.17
One column per quarter.
Added TLS 1.3 as an option on non-Apple platforms #353
Security.framework #357stack_from_pem by @Keruspe in #168openssl-probe and Security.framework bindings #349cfg()s to support all non-macOS Apple platforms.Full Changelog: v0.2.15...v0.2.16
Security.framework.stack_from_pem (except iOS).openssl-probe.Security.framework bindings.cfg()s to support all non-macOS Apple platforms.Upgrade to Edition 2021 by @kornelski in #341
Full Changelog: v0.2.14...v0.2.15
Cache openssl cert lookup and don't bail on error by @sfackler in #324
Full Changelog: v0.2.13...v0.2.14
Stop using deprecated openssl-probe APIs by @sfackler in #316
Use SPDX license format by @jbtrystram in #247
lazy_static with once_cell by @daxpedda in #267once_cell by @tamird in #279Full Changelog: v0.2.11...v0.2.12
Removed an unused build dependency.
### Fixed * Fixed the build for iOS.
### Added * Added Identity::from_pkcs8.
Identity::from_pkcs8.Fixed an off by one error in the schannel backend's handling of max_protocol_version.
Added support for ALPN in client APIs flagged under the alpn Cargo feature.
alpn Cargo feature.### Fixed * Fixed compilation on iOS.
Added TlsConnectorBuilder::disable_built_in_roots to only trust root certificates explicitly added to the builder.
TlsConnectorBuilder::disable_built_in_roots to only trust root certificates explicitly
added to the builder.Added a Clone implementation for Identity.
Clone implementation for Identity.Adding an already-trusted certificate to the root certificate set no longer triggers an error with OpenSSL.
Failure to load a root certificate on Android now logs a message rather than producing an error.
The vendored Cargo feature will cause the crate to compile and statically link to a vendored copy of OpenSSL on platforms that use that backend.
vendored Cargo feature will cause the crate to compile and statically link to a vendored
copy of OpenSSL on platforms that use that backend.The openssl_probe crate is now used with the OpenSSL backend so that trusted root certificates will automatically be detected when statically linking
openssl_probe crate is now used with the OpenSSL backend so that trusted root certificates
will automatically be detected when statically linking to OpenSSL.Certificate::to_der to serialize an X509 certificate to DER.TlsConnectorBuilder::danger_accept_invalid_certs to disable certificate verification.TlsAcceptor::new and TlsConnector::new to easily create an acceptor/connector with
default settings.TlsStream::peer_certificate to obtain the peer's leaf certificate.TlsStream::tls_server_end_point to retrieve RFC 5929 tls-server-end-point channel binding
data.openssl 0.10 and security-framework 0.2.Pkcs12 has been renamed to Identity, and Pkcs12::from_der has been renamed to
Identity::from_pkcs12.HandshakeError::Interrupted has been renamed to HandshakeError::WouldBlock.TlsConnectorBuilder and TlsAcceptorBuilder are now "traditional"-style builders. Their methods
are now infallible and return &mut Self to allow them to be chained together.supported_protocols has been replaced by min_protocol_version and max_protocol_version on
TlsConnectorBuilder and TlsAcceptorBuilder.TlsConnectorBuilder::use_sni and
TlsConnectorBuilder::danger_accept_invalid_hostnames. They replace the
TlsConnector::danger_connect_without_providing_domain_for_certificate_verification_and_server_name_indication
method, which has been removed.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →