NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #314 most downloaded on crates.io
OpenSSL bindings
Last release 3 months ago
12 Jun 2026
Release timing varies
gaps range from 2 weeks to 5 months
Nearly every release is documented
notes for 59 of the last 60 stable releases
3 versions withdrawn
withdrawn after publishing
12 years old
174 releases · first in 2014
Fixed overly conservatifve buffer size checks in Crypter when using stream ciphers.
Crypter when using stream ciphers.PkeyRef::size.Added CmsContentInfo::from_der and CmsContentInfo::encrypt.
CmsContentInfo::from_der and CmsContentInfo::encrypt.X509Ref::verify and X509ReqRef::verify.PartialEq and Eq for MessageDigest.MessageDigest::type_ and EcGroupRef::curve_name.One column per quarter.
The openssl-sys build script now logs the values of environment variables.
ERR_PACK to openssl-sys.ERR_* functions in openssl-sys are const functions when building against newer Rust versions.Clone for Dsa.SslContextRef::add_session and SslContextRef::remove_session.SslSessionRef::time, SslSessionRef::timeout, and SslSessionRef::protocol_version.SslContextBuilder::set_session_cache_size and SslContextRef::session_cache_size.Fixed the return type of ssl::cipher_name.
ssl::cipher_name.Implemented AsRef and AsRef<[u8]> for OpenSslString.
AsRef<str> and AsRef<[u8]> for OpenSslString.Asn1Integer::from_bn.RsaRef::check_key.Asn1Time::from_str and Asn1Time::from_str_x509.Rsa::generate_with_e.Cipher::des_ede3_cfb64.SslCipherRef::standard_name and ssl::cipher_name.Added SHA3 and SHAKE to MessageDigest.
MessageDigest.rand::keep_random_devices_open.Implemented DoubleEndedIterator for stack iterators.
DoubleEndedIterator for stack iterators.Made some accidentally exposed internal functions private.
vendored feature has been upgraded from 1.1.0 to 1.1.1.Fixed a double-free in the SslContextBuilder::set_get_session_callback API.
SslContextBuilder::set_get_session_callback API.SslContextBuilder::set_client_hello_callback.EcdsaSig::from_der and EcdsaSig::to_der.Fixed handling of SNI callbacks during renegotiation.
SslRef::get_shutdown and SslRef::set_shutdown.SslContextBuilder::set_psk_callback has been renamed to SslContextBuilder::set_psk_client_callback and deprecated.
vendored cargo feature will cause openssl-sys to compile and statically link to a
vendored copy of OpenSSL.SslContextBuilder::set_psk_server_callback.DsaRef::pub_key and DsaRef::priv_key.Dsa::from_private_components and Dsa::from_public_components.X509NameRef::entries.SslContextBuilder::set_psk_callback has been renamed to
SslContextBuilder::set_psk_client_callback and deprecated.Added SslContextBuilder::set_ciphersuites.
SslRef::set_alpn_protos.SslContextBuilder::set_ciphersuites.X509Ref::fingerprint has been deprecated in favor of X509Ref::digest.
CmsContentInfo::sign.SslRef::servername now returns None rather than panicking on a non-UTF8 name.MessageDigest::from_nid.Nid::signature_algorithms, Nid::long_name, and Nid::short_name.SslRef::verified_chain.SslRef::servername_raw which returns a &[u8] rather than &str.SslRef::finished and SslRef::peer_finished.X509Ref::digest to replace X509Ref::fingerprint.X509StoreBuilder and X509Store now implement Sync and Send.X509Ref::fingerprint has been deprecated in favor of X509Ref::digest.openssl-sys will now detect Homebrew-installed OpenSSL when installed to a non-default directory.
openssl-sys will now detect Homebrew-installed OpenSSL when installed to a non-default
directory.X509_V_ERR_INVALID_CALL, X509_V_ERR_STORE_LOOKUP, and
X509_V_ERR_PROXY_SUBJECT_NAME_VIOLATION constants in openssl-sys are now only present when
building against 1.1.0g and up rather than 1.1.0.SslContextBuilder::max_proto_version and SslContextBuilder::min_proto_version are only present
when building against 1.1.0g and up rather than 1.1.0.CmsContentInfo::sign.Clone and ToOwned implementations to Rsa and RsaRef respectively.min_proto_version and max_proto_version methods are available when linking against
LibreSSL 2.6.1 and up in addition to OpenSSL.X509VerifyParam is available when linking against LibreSSL 2.6.1 and up in addition to OpenSSL.Stack and StackRef are now Sync and Send.…being built against. The other variables are deprecated.
X509Req::public_key and X509Req::extensions.RsaPrivateKeyBuilder to allow control over initialization of optional components of an RSA
private key.SslSession.DEP_OPENSSL_VERSION_NUMBER and
DEP_OPENSSL_LIBRESSL_VERSION_NUMBER environment variables to downstream build scripts which
contains the hex-encoded version number of the OpenSSL or LibreSSL distribution being built
against. The other variables are deprecated.Fixed PKey::private_key_from_der to return a PKey rather than a PKey . This is technically a breaking change but the function was pretty useless previ…
SslOptions::ENABLE_MIDDLEBOX_COMPAT.Sync and Send implementations.PKeyRef::id.Padding::PKCS1_PSS.Signer::set_rsa_pss_saltlen, Signer::set_rsa_mgf1_md, Signer::set_rsa_pss_saltlen, and
Signer::set_rsa_mgf1_mdX509StoreContextRef::verify to directly verify certificates.EcKey::from_private_components.X509Ref::serial_number.Asn1IntegerRef::to_bn.PKey::private_key_from_der to return a PKey<Private> rather than a PKey<Public>. This
is technically a breaking change but the function was pretty useless previously.X509CheckFlags::FLAG_NO_WILDCARDS has been renamed to X509CheckFlags::NO_WILDCARDS and the old
name deprecated.SslRef::version has been deprecated. Use SslRef::version_str instead.
ErrorStack's Display implementation no longer writes an empty string if it contains no errors.SslRef::version2.Cipher::des_ede3_cbc.SslRef::export_keying_material.Error or ErrorStack back onto OpenSSL's error stack. Various
callback bindings use this to propagate errors properly.SslContextBuilder::set_cookie_generate_cb and SslContextBuilder::set_cookie_verify_cb.SslContextBuilder::set_max_proto_version, SslContextBuilder::set_min_proto_version,
SslContextBuilder::max_proto_version, and SslContextBuilder::min_proto_version.SslConnector's default cipher list to match Python's.SslRef::version has been deprecated. Use SslRef::version_str instead.Added Rsa::public_key_from_pem_pkcs1.
Rsa::public_key_from_pem_pkcs1.SslOptions::NO_TLSV1_3. (OpenSSL 1.1.1 only)SslVersion.SslSessionCacheMode and SslContextBuilder::set_session_cache_mode.SslContextBuilder::set_new_session_callback,
SslContextBuilder::set_remove_session_callback, and
SslContextBuilder::set_get_session_callback.SslContextBuilder::set_keylog_callback. (OpenSSL 1.1.1 only)SslRef::client_random and SslRef::server_random. (OpenSSL 1.1.0+ only)SslAcceptorBuilder::mozilla_modern constructor now disables TLSv1.0 and TLSv1.1 in
accordance with Mozilla's recommendations.OpenSSL is now automatically detected on FreeBSD systems.
GeneralName accessors for rfc822Name and uri variants.X509StoreBuilder::add_cert.Added ConnectConfiguration::set_use_server_name_indication and ConnectConfiguration::set_verify_hostname for use in contexts where you don't have owne
ConnectConfiguration::set_use_server_name_indication and
ConnectConfiguration::set_verify_hostname for use in contexts where you don't have ownership
of the ConnectConfiguration.Added a From for ssl::Error implementation.
From<ErrorStack> for ssl::Error implementation.All deprecated APIs have been removed.
ssl::select_next_proto function can be used to easily implement the ALPN selection callback
in a "standard" way.fips module.X509VerifyResult can now be set in the certificate verification callback via
X509StoreContextRef::set_error.All constants have been moved to associated constants of their type. For example, bn::MSB_ONE
is now bn::MsbOption::ONE.
Asymmetric key types are now parameterized over what they contain. In OpenSSL, the same type is used for key parameters, public keys, and private keys. Unfortunately, some APIs simply assume that certain components are present and will segfault trying to use things that aren't there.
The pkey module contains new tag types named Params, Public, and Private, and the
Dh, Dsa, EcKey, Rsa, and PKey have a type parameter set to one of those values. This
allows the Signer constructor to indicate that it requires a private key at compile time for
example. Previously, Signer would simply segfault if provided a key without private
components.
ALPN support has been changed to more directly model OpenSSL's own APIs. Instead of a single
method used for both the server and client sides which performed everything automatically, the
SslContextBuilder::set_alpn_protos and SslContextBuilder::set_alpn_select_callback handle
the client and server sides respectively.
SslConnector::danger_connect_without_providing_domain_for_certificate_verification_and_server_name_indication
has been removed in favor of new methods which provide more control. The
ConnectConfiguration::use_server_name_indication method controls the use of Server Name
Indication (SNI), and the ConnectConfiguration::verify_hostname method controls the use of
hostname verification. These can be controlled independently, and if both are disabled, the
domain argument to ConnectConfiguration::connect is ignored.
Shared secret derivation is now handled by the new derive::Deriver type rather than
pkey::PKeyContext, which has been removed.
ssl::Error is now no longer an enum, and provides more direct access to the relevant state.
SslConnectorBuilder::new has been moved and renamed to SslConnector::builder.
SslAcceptorBuilder::mozilla_intermediate and SslAcceptorBuilder::mozilla_modern have been
moved to SslAcceptor and no longer take the private key and certificate chain. Install those
manually after creating the builder.
X509VerifyError is now X509VerifyResult and can now have the "ok" value in addition to error
values.
x509::X509FileType is now ssl::SslFiletype.
Asymmetric key serialization and deserialization methods now document the formats that they correspond to, and some have been renamed to better indicate that.
SslRef::compression has been removed.ssl::SslOptions flags have been removed as they no longer do anything.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →