NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #285 most downloaded on crates.io
FFI bindings to OpenSSL
Last release 3 months ago
12 Jun 2026
Release timing varies
gaps range from 2 weeks to 5 months
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
12 years old
183 releases · first in 2014
Deprecate Asn1StringRef::as_utf8 in favor of a NUL-safe to_string by @alex in #2652
Full Changelog: openssl-sys-v0.9.116...openssl-sys-v0.9.117
One column per quarter.
SSL_VERIFY_CLIENT_ONCE and SSL_VERIFY_POST_HANDSHAKE.NID_brainpoolP224r1 and NID_brainpoolP224t1.aws-lc-sys to 0.41.Prefer Homebrew openssl@4 and stop looking for openssl@1.1 by @alex in #2633
Full Changelog: openssl-sys-v0.9.115...openssl-sys-v0.9.116
openssl@4, falls back to openssl@3/openssl@3.0, and no longer looks for openssl@1.1.Bump actions/cache from 5.0.4 to 5.0.5 by @dependabot [bot] in #2610
use libc::*; with targeted imports in openssl-sys by @alex in #2618Full Changelog: openssl-sys-v0.9.114...openssl-sys-v0.9.115
OSSL_PARAM_modified and exposed the OSSL_PARAM struct fields, so callers can detect whether a get-params call wrote into a parameter and read its return_size.EVP_CIPHER_flags / EVP_CIPHER_get_flags, the EVP_CIPH_MODE mask, and the EVP_CIPH_WRAP_MODE constant.Fix Suite B flag assignments in verify.rs by @alex in #2592
Full Changelog: openssl-sys-v0.9.113...openssl-sys-v0.9.114
BIO_get_mem_data as unsafe on AWS-LC -- this matches other backends.X509_NAME_ENTRY_get_data, X509_NAME_ENTRY_get_object, and X509_CRL_get_issuer now return *const pointers under ossl400 to match OpenSSL 4.CI: Hash-pin all action usage, avoid credential persistence in actions/checkout by @woodruffw in #2587
Full Changelog: openssl-sys-v0.9.112...openssl-sys-v0.9.113
EVP_MD_CTX_reset on LibreSSL.aws-lc-sys to 0.39.Bumped aws-lc-sys from 0.27 to 0.38. 0.38 includes security fixes (CVEs).
OSSL_PARAM_BLD_push_int.EVP_PKEY_new_raw_public_key_ex, EVP_PKEY_new_raw_private_key_ex, and EVP_PKEY_is_a.AES_*_OCB.X509_NAME_dup and other *_dup() functions.aws-lc-sys from 0.27 to 0.38. 0.38 includes security fixes (CVEs).ASN1_STRING_data for LibreSSL 4.3.0.X509_VERIFY_PARAM_ID for LibreSSL 4.3.0.ASN1_ENCODING for LibreSSL 4.3.0.Added bindings to EVP_MAC APIs.
EVP_MAC APIs.ASN1_GENERALIZEDTIME_new and ASN1_GENERALIZEDTIME_set_string.Added support for LibreSSL 4.2.0.
__off_t on NetBSD 10.OPENSSL_NO_COMP.OPENSSL_NO_SRTP.Fixed building with vcpkg, a statically linked OpenSSL, and rust 1.87.0.
vcpkg, a statically linked OpenSSL, and rust 1.87.0.Added support for LibreSSL 4.1.x.
Support for building with AWS-LC.
Support building with OPENSSL_NO_RC2.
OPENSSL_NO_RC2.EVP_rc2_cbc and EVP_rc2_40_cbc.Added DTLS_server_method and DTLS_client_method.
DTLS_server_method and DTLS_client_method.Added support for LibreSSL 4.0.x.
EVP_KDF_* and EVP_KDF_CTX_* bindings.EVP_DigestSqueeze.OSSL_PARAM_construct_octet_string.OSSL_set_max_threads and OSSL_get_max_threads.openssl-sys is now a 2021 edition crateCargo.tomlbindgen (optional) dependency from 0.65 to 0.69Added several functions and constants for datagram BIOs.
BIOs.EVP_PKEY_set1_DSA, EVP_PKEY_set1_DH, and EVP_PKEY_set1_EC_KEY.Added support for LibreSSL 3.9.x.
Fixed a bug where, when building with the vendored feature, this crate always needed to be rebuilt.
vendored feature, this crate always needed to be rebuilt.Added OSSL_PARAM, OSSL_PARAM_construct_uint , OSSL_PARAM_construct_end.
OSSL_PARAM, OSSL_PARAM_construct_uint , OSSL_PARAM_construct_end.EVP_PKEY_CTX_set_params and EVP_PKEY_CTX_get_params.X509_alias_get0.EVP_default_properties_enable_fips.On macOS added Homebrew's openssl@3.0 to the list of candidates to build against.
openssl@3.0 to the list of candidates to build against.NID_brainpoolP256r1, NID_brainpoolP320r1, NID_brainpoolP384r1, and NID_brainpoolP512r1 are now available on LibreSSL.X509_PURPOSE is now opaque on LibreSSL 3.9.0+.X509_PURPOSE_get0 now returns a const pointer on LibreSSL 3.9.0+.
RAND_priv_bytes.NID_brainpoolP320r1.X509_PURPOSE_get0 now returns a const pointer on LibreSSL 3.9.0+.X509V3_EXT_add_alias is removed on LibreSSL 3.9.0+.libatomic is no longer dynamically linked for 32 bit ARM targets.
SSL_read_ex, SSL_peek_ex, and SSL_write_ex.EVP_chacha20 is now available on LibreSSL
EVP_chacha20 is now available on LibreSSLEVP_des_ede3_ecb, EVP_des_ede3_cfb8, EVP_des_ede3_ofb, EVP_camellia_128_ofb, EVP_camellia_192_ofb, EVP_camellia_256_ofb, EVP_cast5_ofb, EVP_idea_ofbX509_STORE_get1_all_certsSSL_CTRL_GET_PEER_TMP_KEY, SSL_CTRL_GET_TMP_KEY, SSL_get_peer_tmp_key, SSL_get_tmp_keyFixed the availability of EVP_PKEY_RSA_PSS on OpenSSL
EVP_PKEY_RSA_PSS on OpenSSLNID_chacha20_poly1305X509_ALGOR is now opaque on new LibreSSL releases
X509_ALGOR is now opaque on new LibreSSL releasesOPENSSL_NO_SCRYPTEVP_PKEY_RSA_PSS and EVP_PKEY_DHXEVP_PKEY are now available on LibreSSL.SSL_CTX_set_security_level, SSL_set_security_level, SSL_CTX_get_security_level, SSL_get_security_levelX509_check_host, X509_check_email, X509_check_ip, X509_check_ip_ascThe vendored Cargo feature now builds OpenSSL 3.1, as 1.1.1 is reaching its EOL.
vendored Cargo feature now builds OpenSSL 3.1, as 1.1.1 is reaching its EOL.Expose EVP_chacha20_poly1305 on LibreSSL
EVP_CIPHER_CTX_copyEVP_chacha20_poly1305 on LibreSSLX509_VERIFY_PARAM_set1_emailExpose poly1305_state, CRYPTO_poly1305_init, CRYPTO_poly1305_update, and CRYPTO_poly1305_finish on BoringSSL and LibreSSL.
poly1305_state, CRYPTO_poly1305_init, CRYPTO_poly1305_update, and CRYPTO_poly1305_finish on BoringSSL and LibreSSL.EC_POINT_point2hex and EC_POINT_hex2point.EVP_PKEY_verify_recover_init, EVP_PKEY_verify_recover, and EVP_PKEY_CTX_set_signature_md.EVP_CIPHER_CTX_FLAG_WRAP_ALLOW and EVP_CTX_set_flags.BN_mod_sqrt.Fixed compilation with BoringSSL when building with the bindgen CLI.
Fixed compilation with recent versions of BoringSSL.
OPENSSL_NO_OCB.EVP_PKEY_SM2 and NID_sm2.EVP_PKEY_assign_RSA, EVP_PKEY_assign_DSA, EVP_PKEY_assign_DH, and EVP_PKEY_assign_EC_KEY.EC_GROUP_get_asn1_flag.EC_POINT_get_affine_coordinates on BoringSSL and LibreSSL.EVP_PKEY_derive_set_peer_ex.Added support for the LibreSSL 3.8.0.
OPENSSL_NO_RC4.OBJ_dup.ASN1_TYPE_new, ASN1_TYPE_set, d2i_ASN1_TYPE, and i2d_ASN1_TYPE.SSL_bytes_to_cipher_list, SSL_CTX_get_num_tickets, and SSL_get_num_tickets.GENERAL_NAME_set0_othername.X509_get_pathlen.Added CMAC_CTX_new, CMAC_CTX_free, CMAC_Init, CMAC_Update, CMAC_Final, and CMAC_CTX_copy.
DH_CHECK.CMAC_CTX_new, CMAC_CTX_free, CMAC_Init, CMAC_Update, CMAC_Final, and CMAC_CTX_copy.EVP_default_properties_is_fips_enabled.X509_get0_subject_key_id, X509_get0_authority_key_id, X509_get0_authority_issuer, and X509_get0_authority_serial.NID_poly1305.Fixed BoringSSL support with the latest bindgen release.
Added support for LibreSSL 3.7.x.
Added ASN1_INTEGER_dup and ASN1_INTEGER_cmp.
ASN1_INTEGER_dup and ASN1_INTEGER_cmp.stack_st_X509_NAME_ENTRY.DIST_POINT_NAME, DIST_POINT, stack_st_DIST_POINT, DIST_POINT_free, and DIST_POINT_NAME_free.Fixed version checks for LibreSSL.
i2d_X509_EXTENSION.GENERAL_NAME_new.Added support for LibreSSL 3.7.1.
Fixed builds against OpenSSL built with no-cast.
Fixed builds against OpenSSL built with no-cast.
X509_VERIFY_PARAM_set_auth_level, X509_VERIFY_PARAM_get_auth_level, and X509_VERIFY_PARAM_set_purpose.X509_PURPOSE_* consts.X509_NAME_add_entry.X509_load_crl_file.SSL_set_cipher_list, SSL_set_ssl_method, SSL_use_PrivateKey_file, SSL_use_PrivateKey, SSL_use_certificate, SSL_use_certificate_chain_file, SSL_set_client_CA_list, SSL_add_client_CA, and SSL_set0_verify_cert_store.X509_PURPOSE, X509_STORE_set_purpose, and X509_STORE_set_trust.SSL_CTX_set_num_tickets, SSL_set_num_tickets, SSL_CTX_get_num_tickets, and SSL_get_num_tickets.CMS_verify.Added NO_DEPRECATED_3_0 cfg checks for more APIs.
NO_DEPRECATED_3_0 cfg checks for more APIs.SSL_CTRL_CHAIN_CERT and SSL_add0_chain_cert.EVP_PKEY_get_security_bits and EVP_PKEY_security_bits.OSSL_PROVIDER_set_default_search_path.Added X509_LOOKUP_file and X509_load_cert_file.
EVP_CIPHER_CTX_num.X509_LOOKUP_file and X509_load_cert_file.Added support for LibreSSL 3.6.x.
NID_brainpoolP256r1, NID_brainpoolP384r1, and NID_brainpool512r1.EVP_camellia_128_cfb128, EVP_camellia_128_ecb, EVP_camellia_192_cfb128, EVP_camellia_192_ecb,
EVP_camellia_256_cfb128, and EVP_camellia_256_ecb.EVP_cast5_cfb64 and EVP_cast5_ecb.EVP_idea_cfb64 and EVP_idea_ecb.DSA_SIG, d2i_DSA_SIG, i2d_DSA_SIG, DSA_SIG_new, DSA_SIG_free, DSA_SIG_get0, and DSA_SIG_set0.X509_STORE_set1_param, X509_VERIFY_PARAM_new, X509_VERIFY_PARAM_set_time, and
X509_VERIFY_PARAM_set_depth.Added support for LibreSSL 3.6.0
assume_init.Fixed the deprecation note on SSL_CTX_set_alpn_select_cb.
SSL_get_psk_identity_hint and SSL_get_psk_identity.SSL_OP_PRIORITIZE_CHACHA.X509_REQ_print.EVP_MD_CTX_size and EVP_MD_CTX_get_sizeEVP_MD_CTX_reset.SSL_CTX_set_alpn_select_cb.Added EC_GROUP_set_generator and EC_POINT_set_affine_coordinates_GFp.
EC_GROUP_set_generator and EC_POINT_set_affine_coordinates_GFp.Added X509_V_ERR_INVALID_CA back when building against OpenSSL 3.0.
EVP_MD_block_size.X509V3_EXT_add_alias.X509_V_ERR_INVALID_CA back when building against OpenSSL 3.0.Added support for installations that place libraries in $OPENSSL_DIR/lib64 in addition to $OPENSSL_DIR/lib.
$OPENSSL_DIR/lib64 in addition to $OPENSSL_DIR/lib.X509_issuer_name_hash.ASN1_string_set.X509_CRL_dup, X509_REQ_dup, X509_NAME_dup, and X509_dup.X509_print.Temporarily downgraded the vendored OpenSSL back to 1.1.1 due to significant performance regressions. We will move back to 3.0.0 when a future release
PKCS12_set_mac.EVP_PKEY_sign_init, EVP_PKEY_sign, EVP_PKEY_verify_init, and EVP_PKEY_verify.Fixed linkage to static OpenSSL 3.0.0 libraries on some 32 bit Android targets.
SSL_get_extms_support and SSL_CTRL_GET_EXTMS_SUPPORT.OBJ_create.EVP_CIPHER_CTX_get0_cipher, EVP_CIPHER_CTX_get_block_size, EVP_CIPHER_CTX_get_key_length,
EVP_CIPHER_CTX_get_iv_length, and EVP_CIPHER_CTX_get_tag_length.EVP_CIPHER_free.EVP_CIPHER_CTX_rand_key.OSSL_LIB_CTX_new and OSSL_LIB_CTX_free.EVP_CIPHER_fetch.EVP_MD_fetch and EVP_MD_free.OPENSSL_malloc and OPENSSL_free.EVP_DigestSignUpdate and EVP_DigestVerifyUpdate.Fixed linkage to static 3.0.0 OpenSSL libraries on some 32 bit architectures.
Upgraded the vendored OpenSSL to 3.0.0.
openssl@3 installs.EVP_PKEY_Q_keygen and EVP_EC_gen.Added i2d_X509_NAME and d2i_X509_NAME.
BN_bn2binpad.i2d_X509_NAME and d2i_X509_NAME.BN_FLG_MALLOCED, BN_FLG_STATIC_DATA, BN_FLG_CONSTTIME, and BN_FLG_SECURE.BN_CTX_secure_new, BN_secure_new, BN_set_flags, and BN_get_flags.Added support for LibreSSL 3.4.0
Added EVP_seed_cbc, EVP_seed_cfb128, EVP_seed_ecb, and EVP_seed_ofb.
EVP_seed_cbc, EVP_seed_cfb128, EVP_seed_ecb, and EVP_seed_ofb.OBJ_length and OBJ_get0_data.i2d_PKCS8PrivateKey_bio.Restored the accidentally deleted PEM_read_bio_X509_CRL function.
PEM_read_bio_X509_CRL function.Added support for OpenSSL 3.x.x.
SSL_peek.ERR_LIB_ASN1 and ASN1_R_HEADER_TOO_LONG.d2i_X509_bio.OBJ_nid2obj.RAND_add.SSL_CTX_set_post_handshake_auth.COMP_get_type.X509_get_default_cert_file_env, X509_get_default_cert_file, X509_get_default_cert_dir_env, and
X509_get_default_cirt_dir.Added support for LibreSSL 3.3.x.
Added support for LibreSSL 3.3.2.
DH_set0_key.EC_POINT_get_affine_coordinates.Added support for automatic detection of OpenSSL installations via pkgsrc and MacPorts on macOS.
V_ASN1_* constants.DH_generate_parameters_ex.EC_POINT_is_at_infinity and EC_POINT_is_on_curve.EVP_CIPHER_nid.EVP_sm3.NID_* constants related to SM3.PKCS7_get0_signers.EVP_PKEY_CTX_set0_rsa_oaep_label.ACCESS_DESCRIPTION and ACCESS_DESCRIPTION_free.Added support for the default Homebrew install directory on ARM.
EVP_PKEY_CTX_set_rsa_oaep_md and EVP_PKEY_CTRL_RSA_OAEP_MD.Added support for LibreSSL 3.2.x, 3.3.0, and 3.3.1.
DH_generate_parameters, DH_generate_key, DH_compute_key, and DH_size.NID_X25519, NID_X448, EVP_PKEY_x25519 and EVP_PKEY_x448.OBJ_txt2obj.d2i_PKCS7 and i2d_PKCS7.SRTP_AEAD_AES_128_GCM and SRTP_AEAD_AES_256_GCM.Added support for LibreSSL 3.2.0.
SSL_set_mtu.PEM_read_bio_EC_PUBKEY, PEM_write_bio_EC_PUBKEY, d2i_EC_PUBKEY, and i2d_EC_PUBKEY.EVP_PKEY_encrypt_init, EVP_PKEY_encrypt, EVP_PKEY_decrypt_init, EVP_PKEY_decrypt,
EVP_PKEY_get_raw_public_key, EVP_PKEY_new_raw_public_key, EVP_PKEY_get_raw_private_key,
and EVP_PKEY_new_raw_private_key.OBJ_sn2nid.Your coding agent can read these notes before it upgrades. Set up the MCP server →