Commit 9e97c88359 for openssl.org
commit 9e97c88359e5d820c1da0775fbb22e402a675cb4
Author: Eugene Syromiatnikov <esyr@openssl.org>
Date: Tue Sep 8 17:49:42 2026 +0200
CHANGES.md: wording changes, formatting fixes
Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Wed Sep 9 11:10:37 2026
Merged-from: https://github.com/openssl/openssl/pull/32758
diff --git a/CHANGES.md b/CHANGES.md
index 0fa4bc2aa0..06bc436b4c 100644
--- a/CHANGES.md
+++ b/CHANGES.md
@@ -32,76 +32,76 @@ OpenSSL 4.1
### Changes between 4.0 and 4.1 [xx XXX xxxx]
- * Refactored remaining cipher `OSSL_PARAM` name parsing so that
- automatically generated parsers are used instead of
- `OSSL_PARAM_locate()` calls. This should ensure that the list
- of acceptable parameters better matches those which are actually
- processed. It should also provide a small performance improvement,
- because repeated iteration over passed parameter arrays is avoided.
+ * Refactored remaining cipher `OSSL_PARAM` name parsing so that automatically
+ generated parsers are used instead of `OSSL_PARAM_locate()` calls.
+ This should ensure that the list of acceptable parameters better matches
+ those which are actually processed. It should also provide a small
+ performance improvement, because repeated iteration over passed parameter
+ arrays is avoided.
*Dr Paul Dale*
- * Added a `seed_strict` option to the `random` configuration section
+ * Added a `seed_strict` option to the `random` configuration section,
which makes the configured random seed source strictly enforced when
a provider (such as the FIPS provider) requests entropy or a nonce.
- When a provider requests seeding material before the primary DRBG has
- been created, the request falls back to the operating system entropy
+ When a provider requests seeding material before the primary DRBG
+ has been created, the request falls back to the operating system entropy
sources, because the seed source only comes into existence as a side
effect of creating the primary DRBG. Whether a configured seed source
- is used therefore depends on operation order. With `seed_strict`
- enabled, the seed source is instead instantiated on demand and an
- error is reported if it cannot be used. The option is off by default
- with two exceptions: the `JITTER` seed source seeds strictly unless
- the option disables it and `enable-fips-jitter` builds always seed
- strictly. Additionally, the property query used to fetch the default
- seed source can now be set at build time with
- `-DOPENSSL_DEFAULT_SEED_PROPQ`.
+ is used therefore depends on operation order. With `seed_strict` enabled,
+ the seed source is instead instantiated on demand and an error is reported
+ if it cannot be used. The option is off by default with two exceptions:
+ the `JITTER` seed source seeds strictly unless the option disables it,
+ and `enable-fips-jitter` builds always seed strictly. Additionally,
+ the property query used to fetch the default seed source can now be set
+ at build time with `-DOPENSSL_DEFAULT_SEED_PROPQ`.
*Jakub Zelenka*
* Fixed a bug where a TLS 1.3 session ticket could retain a stale ALPN
- protocol from an earlier connection after a resumption negotiated a
- different protocol (or none), on both the server and the client,
+ protocol from an earlier connection after a resumption negotiated
+ a different protocol (or none), on both the server and the client,
which could otherwise affect a later 0-RTT decision.
*Daniel Kubec and Viktor Dukhovni*
- * Implement extended support of metadata for symmetric key objects (EVP_SKEY).
+ * Implemented extended support of metadata for symmetric key objects
+ (`EVP_SKEY`).
*Dmitry Belyavskiy*
- * Declare support for AArch64 Guarded Control Stack (GCS) in assembly code.
+ * Declared support for AArch64 Guarded Control Stack (GCS) in assembly code.
When building with compilers that support GCS (Clang 18+, GCC 15+),
- assembly modules are marked as compatible when branch protection is
- enabled (e.g. -mbranch-protection=standard). No functional changes to
- the assembly implementations are required, but compliance ensures
+ assembly modules are marked as compatible when branch protection
+ is enabled (e.g. `-mbranch-protection=standard`). No functional changes
+ to the assembly implementations are required, but compliance ensures
correct operation with shadow stack enforcement.
- *Guillaume Gardet*
- *Gowtham Suresh Kumar*
+ *Guillaume Gardet and Gowtham Suresh Kumar*
- * Added support for DTLS 1.3 (RFC 9147). Refer to the ossl-guide-dtlsv13(7)
- manpage for details.
+ * Added support for DTLS 1.3 ([RFC 9147]).
+ Refer to the `ossl-guide-dtlsv13(7)` manual page for details.
*Frederik Wedel-Heinen and Ryan Hooper*
- * Added DTLS support to the SSL listener API. SSL_new_listener() can now
+ * Added DTLS support to the SSL listener API. `SSL_new_listener()` can now
create a DTLS listener that demultiplexes incoming datagrams into per-peer
- connections accepted with SSL_accept_connection(). The listener performs
- address validation (HelloVerifyRequest for DTLS 1.0/1.2, HelloRetryRequest
- cookie for DTLS 1.3) by default; pass SSL_LISTENER_FLAG_NO_VALIDATE to
- disable it. Refer to the SSL_new_listener(3) manpage for details.
+ connections accepted with `SSL_accept_connection()`. The listener performs
+ address validation (`HelloVerifyRequest` for DTLS 1.0/1.2,
+ `HelloRetryRequest` cookie for DTLS 1.3) by default; pass
+ `SSL_LISTENER_FLAG_NO_VALIDATE` to disable it. Refer
+ to the `SSL_new_listener(3)` manual page for details.
*Ryan Hooper*
- * Added configurable values for DTLS listeners, accessed via
- SSL_get_value_uint() / SSL_set_value_uint():
- SSL_VALUE_DTLS_LISTENER_MAX_PENDING_CONNS,
- SSL_VALUE_DTLS_LISTENER_PENDING_TIMEOUT and
- SSL_VALUE_DTLS_LISTENER_MAX_DGRAM_SIZE. Refer to the SSL_get_value_uint(3)
- manpage for details.
+ * Added configurable values for DTLS listeners, accessed
+ via `SSL_get_value_uint()`/`SSL_set_value_uint()`:
+ `SSL_VALUE_DTLS_LISTENER_MAX_PENDING_CONNS`,
+ `SSL_VALUE_DTLS_LISTENER_PENDING_TIMEOUT`,
+ and `SSL_VALUE_DTLS_LISTENER_MAX_DGRAM_SIZE`. Refer
+ to the `SSL_get_value_uint(3)` manual page for details.
*Ryan Hooper*
@@ -113,58 +113,58 @@ OpenSSL 4.1
*Mounir IDRASSI*
* Fixed QUIC child objects to inherit the effective flags of their explicit
- event domain. `SSL_get0_domain()` now reports that domain for connections
+ event domain. `SSL_get0_domain()` now reports that domain for connections
and streams in the hierarchy.
*Mounir IDRASSI*
* Fixed TLS 1.3 clients to encrypt 0-RTT early data with the first offered
- PSK identity (RFC 9846 section 4.3.10) when a 0-RTT-capable resumption
+ PSK identity ([RFC 9846 Section 4.3.10]) when a 0-RTT-capable resumption
ticket has aged out and an external PSK is offered in its place. The early
- data was being encrypted with the retired ticket's secret rather than the
- external PSK's, causing the server to reject it with a bad record MAC.
+ data was being encrypted with the retired ticket's secret, rather than
+ the external PSK's, causing the server to reject it with a bad record MAC.
*Viktor Dukhovni*
* Fixed TLS 1.3 servers to reject early data when a resumed PSK's
- ticket age is outside tolerance, per RFC 9846, instead of accepting
+ ticket age is outside tolerance, per [RFC 9846], instead of accepting
0-RTT data from a ticket that has aged out.
*Daniel Kubec*
- * TLS clients no longer send the TLS padding extension (RFC 7685). It was
- only ever sent when `SSL_OP_TLSEXT_PADDING` was set, to work around a
- ClientHello-length bug in F5 middleboxes; the fix shipped long ago and
- the affected hardware is long out of support, so nothing should still
+ * TLS clients no longer send the TLS padding extension ([RFC 7685]). It was
+ only ever sent when `SSL_OP_TLSEXT_PADDING` was set, to work around
+ a `ClientHello` length bug in F5 middleboxes; the fix shipped long ago
+ and the affected hardware is long out of support, so nothing should still
be running the problematic version.
- `SSL_OP_TLSEXT_PADDING` is now a no-op retained for compatibility, and
- is no longer included in `SSL_OP_ALL`.
+ `SSL_OP_TLSEXT_PADDING` is now a no-op retained for compatibility,
+ and is no longer included in `SSL_OP_ALL`.
*Bob Beck*
- * Repeated fields in the `basicConstraints`, `basicAttConstraints`,
- and `policyConstraints` X.509v3 extension configurations are now rejected
- instead of silently using the last value.
+ * Fixed X.509v3 extension configuration parsing to reject repeated fields
+ in the `basicConstraints`, `basicAttConstraints`, and `policyConstraints`
+ X.509v3 extension configurations, instead of silently using the last value.
*Adam Tabak*
- * The `tsget` utility now uses `Net::Curl::Easy` (from the `Net-Curl` CPAN
- distribution) instead of the abandoned `WWW::Curl::Easy`. Users who relied
- on `tsget` must install `Net::Curl::Easy` before upgrading.
+ * Changed `tsget` utility to use `Net::Curl::Easy` (from the `Net-Curl` CPAN
+ distribution) instead of the abandoned `WWW::Curl::Easy`. Users who rely
+ on `tsget` should install `Net::Curl::Easy` before upgrading.
*Shreenidhi Shedi*
- * Added `CMS_add_standard_smimecap_ex()`, which populates an SMIMECapabilities
- list using `EVP_CIPHER_fetch()` and `EVP_MD_fetch()` so that only algorithms
- available in the active providers are advertised. `PKCS7_sign_add_signer()`
- was updated in the same way, so that legacy ciphers such as RC2 and DES are
- no longer included in SMIMECapabilities by default when only the default
- provider is loaded.
+ * Added `CMS_add_standard_smimecap_ex()` API function, which populates
+ an `SMIMECapabilities` list using `EVP_CIPHER_fetch()` and `EVP_MD_fetch()`
+ so that only algorithms available in the active providers are advertised.
+ `PKCS7_sign_add_signer()` was updated in the same way, so that legacy
+ ciphers, such as RC2 and DES, are no longer included in `SMIMECapabilities`
+ by default when only the default provider is loaded.
*Todd Short*
- * Added various optimizations for the Elbrus2000 architecture in the
- cryptographic and BN code.
+ * Added various optimizations for the Elbrus2000 architecture
+ in the cryptographic and BN code.
*Gleb Popov*
@@ -178,22 +178,22 @@ OpenSSL 4.1
*Viktor Dukhovni*
- * Added AVX512 optimized SHAKE x4 operations for ML-DSA on `x86_64`.
+ * Added AVX-512-optimized SHAKE x4 operations for ML-DSA on `x86_64`.
*Marcel Cornu and Tomasz Kantecki*
- * EC key point format simplification.
+ * Simplified EC key point format handling.
The point conversion form (compressed, uncompressed, or hybrid)
is now a single value on the `EC_GROUP` and round-trips
unchanged through import and export of `EC_KEY` objects.
- Freshly generated keys have their public point encoded in
- uncompressed form. A `point-format` supplied at key generation
- time via `OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT` is
- validated (an invalid value is rejected) but otherwise ignored
- on the generated key. EC parameter generation continues to
- honour the requested form on the group's generator; imported
+ Freshly generated keys have their public point encoded
+ in uncompressed form. A `point-format` supplied at key generation
+ time via `OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT`
+ is validated (an invalid value is rejected) but otherwise ignored
+ on the generated key. EC parameter generation continues
+ to honour the requested form on the group's generator; imported
keys keep their form.
The `ec_point_formats` extension no longer affects TLS 1.2
@@ -202,32 +202,33 @@ OpenSSL 4.1
and sends any EC certificate it has regardless of point form.
TLS 1.3 disregards the extension entirely.
- The RFC 4492/8422 section 5.1.2 requirement that the peer's
- point-format list contain "uncompressed" is now enforced on
- both sides (previously client-only), and only when an ECC
- TLS 1.2 ciphersuite is negotiated -- a missing "uncompressed"
- is ignored under TLS 1.3 or with a non-ECC cipher.
+ The [RFC 4492][RFC 4492 Section 5.1.2]/[8422 section 5.1.2][RFC 8422 Section 5.1.2]
+ requirement that the peer's point-format list contain "uncompressed" is now
+ enforced on both sides (previously client-only), and only when an ECC TLS 1.2
+ ciphersuite is negotiated—a missing "uncompressed" is ignored under TLS 1.3
+ or with a non-ECC cipher.
*Viktor Dukhovni*
- * Added unit tests setup activated via `enable-unit-tests` option. This works
+ * Added unit tests setup activated via `enable-unit-tests` option. This works
only on platforms with ld `--wrap` support (Linux, BSD).
*Jakub Zelenka*
* Deprecated the `enable-unit-test` configure option and the
- `SSL_test_functions()` function. Both will be removed in OpenSSL 5.0.
+ `SSL_test_functions()` function. Both will be removed in OpenSSL 5.0.
*Jakub Zelenka*
- * Deprecated BIO_snprintf() and BIO_vsnprintf(). C99 snprintf() is now
- universally available, and the wrappers return -1 on truncation rather
- than the would-have-been length, so callers reaching for the standard
- idiom by reflex produce bugs. Use snprintf() and vsnprintf() directly.
+ * Deprecated `BIO_snprintf()` and `BIO_vsnprintf()`. `snprintf()`, being part
+ of C99 standard, that is the baseline for OpenSSL since version 3.6,
+ is now considered universally available; moreover, the fact that `BIO_*()`
+ functions return -1 on truncation, rather than the would-have-been length,
+ makes their usage error-prone. Use `snprintf()` and `vsnprintf()` directly.
*Bob Beck*
- * Added -testmode option for `s_time` app.
+ * Added `-testmode` option for `openssl s_time` command.
*Jakub Zelenka*
@@ -237,31 +238,31 @@ OpenSSL 4.1
*Mounir IDRASSI*
- * Added support for Ed25519 and Ed448 certificates in DTLS 1.2. Previously,
+ * Added support for Ed25519 and Ed448 certificates in DTLS 1.2. Previously,
these certificate types were only supported in TLS 1.2 and TLS 1.3.
*Adriano Sela Aviles*
- * Add a build target to provide MSVC 2013 hacks in a C99 world.
- The build target adds internal functions to provide C99 functions
- that are not present with MSVC 2013.
+ * Added `VC-WIN32-MSVC2013` and `VC-WIN64A-MSVC2013` build targets to provide
+ internal functions for bridging the gaps in C99 standard support
+ that are present in MSVC 2013.
*Bob Beck*
- * SubjectPublicKeyInfo blobs whose AlgorithmIdentifier uses id-RSAES-OAEP
- (`NID_rsaesOaep`, 1.2.840.113549.1.1.7) with a plain RSAPublicKey body
- are now decoded as RSA keys. This is required for interoperability
- with TPM 1.2 Endorsement Key certificates per TCG Credential Profiles
- V1.2 section 3.2.7. The OAEP AlgorithmIdentifier parameters are not
- interpreted.
+ * Improved interoperability with TPM 1.2 Endorsement Key certificates
+ per [TCG Credential Profiles specification Version 1.2, Section 3.2.7]:
+ `SubjectPublicKeyInfo` blobs whose `AlgorithmIdentifier` uses
+ `id-RSAES-OAEP` (`NID_rsaesOaep`, 1.2.840.113549.1.1.7) with a plain
+ `RSAPublicKey` body are now decoded as RSA keys. The OAEP
+ `AlgorithmIdentifier` parameters are not interpreted.
*Craig Lorentzen*
- * Do not issue TLS1.3 session tickets if the server has explicitly disabled
+ * Do not issue TLS 1.3 session tickets if the server has explicitly disabled
them via `SSL_OP_NO_TICKET` and also turned off the session cache with
`SSL_SESS_CACHE_OFF`. Both conditions together indicate a clear intent to
- suppress resumption, so sending NewSessionTicket messages would be wasteful
- and misleading. TLS1.3 client that does not send the `psk_key_exchange_modes`
+ suppress resumption, so sending `NewSessionTicket` messages would be wasteful
+ and misleading. TLS 1.3 client that does not send the `psk_key_exchange_modes`
extension, or that sends it together with [RFC 9149] parameters such as
`new_session_count = 0` or `resumption_count = 0`, is effectively signaling
no interest in session tickets and session resumption.
@@ -272,77 +273,70 @@ OpenSSL 4.1
*Jakub Zelenka*
- * Windows-on-Itanium (VC-WIN64I) support was dropped - the Itanium
- architecture has been discontinued and the platform is no longer
- supported or tested.
-
- *Bob Beck*
-
- * Windows CE support was dropped - Windows CE has been unsupported since
- 2018 and does not have a modern C99 toolchain.
+ * Dropped Windows-on-Itanium (`VC-WIN64I`) and Windows CE (`VC-CE`) targets
+ from Configurations.
*Bob Beck*
- * Improved DTLS handshake robustness under UDP reordering by buffering and
- replaying early ChangeCipherSpec (CCS) records at the expected state.
+ * Improved DTLS handshake robustness under UDP reordering by buffering
+ and replaying early `ChangeCipherSpec` (CCS) records at the expected state.
*Tong Li*
- * Header files in OpenSSL are being changed to reflect modern development
- practices - Include files should all be guarded for inclusion by a define
- and must be self contained, meaning they include all dependencies they need
- to compile on their own. Headers have been changed to include guards and
- to include the dependencies they require. Doing this will help the
- future use of more modern tooling.
+ * Updated header files to reflect modern development practices: all include
+ files now have header guards and they are self-contained (they include all
+ dependencies they need to be included on their own).
*Bob Beck*
- * `ASN1_STRING_set()` and `ASN1_STRING_length()` have been
- deprecated. The replacement functions `ASN1_STRING_set1_data()` or
- `ASN1_STRING_set1_string()`, and `ASN1_STRING_get_length()` should be
- used in their place. This prepares the ASN1_STRING type to support
- modern size_t length values in the future.
-
- *Bob Beck*
+ * Deprecated `ASN1_STRING_set()` and `ASN1_STRING_length()`. The replacement
+ functions `ASN1_STRING_set1_data()` or `ASN1_STRING_set1_string()`,
+ and `ASN1_STRING_get_length()` should be used in their place. This prepares
+ the `ASN1_STRING` type to support modern `size_t` length values
+ in the future.
- * `EVP_CIPHER_CTX_get_num()` and `EVP_CIPHER_CTX_set_num()' have been deprecated.
+ *Bob Beck*
- Refer to ossl-migration-guide(7) for more info.
+ * Deprecated `EVP_CIPHER_CTX_get_num()` and `EVP_CIPHER_CTX_set_num()`
+ functions. Refer to `ossl-migration-guide(7)` for more info.
*Shane Lontis*
- * The functions `ASN1_BIT_STRING_name_print()`, `ASN1_BIT_STRING_num_asc(),
- and `ASN1_BIT_STRING_set_asc()`, have been deprecated. Refer to the manual
+ * Deprecated `ASN1_BIT_STRING_name_print()`, `ASN1_BIT_STRING_num_asc()`,
+ and `ASN1_BIT_STRING_set_asc()` functions. Refer to the manual
pages for more information.
*Bob Beck*
- * The API functions `CRYPTO_atomic_load_ptr`, `CRYPTO_atomic_store_ptr`, and
- `CRYPTO_atomic_cmp_exch_ptr` have been added to libcrypto.
+ * Added `CRYPTO_atomic_load_ptr`, `CRYPTO_atomic_store_ptr`,
+ and `CRYPTO_atomic_cmp_exch_ptr` functions to `libcrypto`, that implement
+ the respective atomic operations with a locking-based fallback on platforms
+ that do not support them.
*Neil Horman*
- * The `openssl pkeyutl` command now uses memory-mapped I/O when reading
- raw input from a file for oneshot sign/verify operations (such as Ed25519,
- Ed448, and ML-DSA) on platforms that support it (Unix-like). The
- `openssl dgst` command uses the same approach for one-shot sign/verify
- when the input is from a file, removing the previous 16 MB limit for
- file-based input. This improves performance and supports large files
- without doubling memory use. Other platforms and stdin input continue to
- use the existing buffer-based path.
+ * Added ability to utilise memory-mapped I/O when reading raw input
+ from a file for one-shot sign/verify operations (such as Ed25519,
+ Ed448, and ML-DSA) to `openssl pkeyutl` command on platforms
+ that support it (Unix-like). The `openssl dgst` command uses the same
+ approach for one-shot sign/verify when the input is from a file, removing
+ the previous 16 MB limit for file-based input. This improves performance
+ and supports large files without doubling memory use. Other platforms
+ and `stdin` input continue to use the existing buffer-based implementation.
*John Claus*
-* 'X509_check_host()', 'X509_check_email()', 'X509_check_ip()', and 'X509_check_ip_asc()'
- have been deprecated. Applications should migrate to setting a reference identifier
- to check using 'X509_VERIFY_PARAM_set1_host()', 'X509_VERIFY_PARAM_set1_email()', or
- X509_VERIFY_PARAM_set1_ip_asc()', and using 'X509_verify_cert()'.
+ * Deprecated `X509_check_host()`, `X509_check_email()`, `X509_check_ip()`,
+ and `X509_check_ip_asc()` functions. Applications should migrate to setting
+ a reference identifier to check using `X509_VERIFY_PARAM_set1_host()`,
+ `X509_VERIFY_PARAM_set1_email()`, or `X509_VERIFY_PARAM_set1_ip_asc()`,
+ and using `X509_verify_cert()`.
*Bob Beck*
- * The API function `ASN1_STRING_new_not_owned` has been added to the
- libcrypto. It provides the ability to construct an ASN1_STRING with data
- for which ownership is not taken by the created ASN1_STRING object.
+ * Added `ASN1_STRING_new_not_owned()` function to `libcrypto`. It provides
+ the ability to construct an `ASN1_STRING` with data for which ownership
+ is not taken by the created `ASN1_STRING` object.
*Bob Beck*
@@ -352,113 +346,117 @@ OpenSSL 4.1
*John Claus*
- * Added AVX2 optimized ML-DSA NTT operations on `x86_64`.
+ * Added AVX2-optimized ML-DSA NTT operations on `x86_64`.
*Marcel Cornu and Tomasz Kantecki*
- * X509 certificate verification no longer consults the subject
- distinguished name by default. Previously, when a certificate
- contained no subject alternative name of the type being checked,
- the subject commonName (for host name checks) or emailAddress (for
- email checks) was matched instead. The subject dn is now checked
- only when the `X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT` flag is set.
- Correspondingly, during chain verification DNS name constraints are
- applied to the subject commonName of the leaf certificate only when
- that flag is set, rather than whenever the leaf had no DNS subject
- alternative name.
+ * Updated X.509 certificate verification to no longer consult the subject
+ distinguished name (DN) by default. Previously, when a certificate contained
+ no subject alternative name of the type being checked, the subject
+ `commonName` (for host name checks) or `emailAddress` (for email checks)
+ was matched instead. The subject DN is now checked only when
+ the `X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT` flag is set. Correspondingly,
+ during chain verification, DNS name constraints are applied to the subject
+ `commonName` of the leaf certificate only when that flag is set, rather than
+ whenever the leaf had no DNS subject alternative name.
*Bob Beck*
- * Add `CMS_VERIFY_PARTIAL` flag to `CMS_verify()` and `-verify_partial` option
- to `openssl cms -verify`.
-
- If this flag is set, the call is successful also if not all, but at least
- one of the individual signatures can be verified (perhaps due to CAs missing
- from the local store, expired certificates, or unsupported algorithms). The
- application would then call `CMS_get0_signers()` and check if the set of
- valid signatures satisfies its policy.
-
- To access detailed verification results, the new functions
- `CMS_SignerInfo_get_verification_result()` and
- `CMS_SignerInfo_get0_signer_cert()` can be used.
+ * Added `CMS_VERIFY_PARTIAL` flag to `CMS_verify()`, `-verify_partial`
+ option to `openssl cms -verify` operation,
+ and `CMS_SignerInfo_get_verification_result()`
+ and `CMS_SignerInfo_get0_signer_cert()` functions.
+
+ If the `CMS_VERIFY_PARTIAL` flag is set, the `CMS_verify()` call
+ is successful if at least one of the individual signatures can be verified
+ (as opposed to all of them), which may be useful to gracefully handle various
+ situations, like missing CAs, expired certificates, or unsupported
+ algorithms; applications can call `CMS_get0_signers()` to check if the set
+ of valid signatures satisfies its policy, or use
+ `CMS_SignerInfo_get_verification_result()`
+ and `CMS_SignerInfo_get0_signer_cert()` functions to access the detailed
+ verification results.
*Jan Lübbe*
- * Changed the output of the -disabled option for the list command.
- Displaying disabled features, protocols, and algorithms, in relevant sections.
- Disabled features are now generated at configuration time.
+ * Changed the output of the `-disabled` option for the `openssl list` command
+ to display disabled features, protocols, and algorithms, in relevant
+ sections.
*Paul Louvel*
- * Added `CTLOG_STORE_add0_log()` to add individual CT logs to a `CTLOG_STORE`.
+ * Added `CTLOG_STORE_add0_log()` function to add individual CT logs
+ to a `CTLOG_STORE`.
*Tim Perry*
- * Dropped `no-ecdsa` and `no-ecdh` options from `Configure` as these options
- did not really disable the implementations. Use `no-ec` to disable the
- elliptic curve support.
+ * Dropped `no-ecdsa` and `no-ecdh` options from `Configure`, as these options
+ did not really disable the implementations. Use `no-ec` to disable
+ the elliptic curve support.
*Tomáš Mráz*
- * Added `EVP_EC_affine2oct()` that converts the affine coordinates of an
- EC point to an octet string conforming to Sec. 2.3.4 of the SECG SEC 1
- ("Elliptic Curve Cryptography") standard.
+ * Added `EVP_EC_affine2oct()` function, that converts the affine coordinates
+ of an EC point to an octet string conforming
+ to [Section 2.3.4 of SECG SEC 1][SECG SEC 1 Section 2.3.4] ("Elliptic Curve
+ Cryptography") standard.
*Igor Ustinov*
- * Made more QUIC transport parameters configurable via the
- `SSL_get_value_uint`/`SSL_set_value_uint` functions. Now also configurable:
+ * Implemented an ability to configure additional QUIC transport parameters
+ via the `SSL_get_value_uint()`/`SSL_set_value_uint()` functions:
`max_udp_payload_size`, `initial_max_data`,
`initial_max_stream_data_bidi_local`, `initial_max_stream_data_uni`,
- `ack_delay_exponent`, `max_ack_delay`.
+ `ack_delay_exponent`, and `max_ack_delay`.
*Nikolas Gauder*
- * Add new verification error `X509_V_ERR_DUPLICATE_EXTENSION` with descriptive
- message for certificates containing duplicate X.509 extensions, which are
- explicitly prohibited by [RFC 5280].
+ * Added a new verification error, `X509_V_ERR_DUPLICATE_EXTENSION`,
+ with a descriptive message for certificates containing duplicate X.509
+ extensions, which are explicitly prohibited by [RFC 5280].
*Daniel Kubec*
- * Deprecated `CMS_stream()` and `PKCS7_stream()`. These are internal
- plumbing that leaked into the public API, and no longer return a
- streaming boundary. Use `BIO_new_CMS()` or `BIO_new_PKCS7()` to stream
- CMS and PKCS7 content.
+ * Deprecated `CMS_stream()` and `PKCS7_stream()` functions. These are internal
+ plumbing that leaked into the public API, and no longer return a streaming
+ boundary. Use `BIO_new_CMS()` or `BIO_new_PKCS7()` to stream CMS and PKCS#7
+ content.
*Bob Beck*
- * Added `OSSL_CMP_OPT_NONMATCHED_ERROR_NONCES` option for `OSSL_CMP_CTX` and
- a corresponding `-nonmatched_error_nonces` option for the `openssl cmp` command.
+ * Added `OSSL_CMP_OPT_NONMATCHED_ERROR_NONCES` option for `OSSL_CMP_CTX`
+ and a corresponding `-nonmatched_error_nonces` option for the `openssl cmp`
+ command.
This work was sponsored by Siemens AG.
*David von Oheimb*
- * Added support for RFC 8701 GREASE (Generate Random Extensions And Sustain
- Extensibility). When `SSL_OP_GREASE` is set, the TLS client injects
+ * Added support for [RFC 8701] GREASE (Generate Random Extensions And Sustain
+ Extensibility). When `SSL_OP_GREASE` is set, the TLS client injects
reserved GREASE values into cipher suites, supported versions, supported
- groups, signature algorithms, key share, and extensions in the ClientHello
- to prevent ecosystem ossification. The `openssl s_client` command gains a
- `-grease` option to enable this.
+ groups, signature algorithms, key share, and extensions in the `ClientHello`
+ to prevent ecosystem ossification.
+ Added `-grease` option to `openssl s_client` to enable this.
*William McCormack*
- * The undocumented public functions `UTF8_putc()` and `UTF8_getc()`
- were deprecated, and their functionality moved internal to the
- library. No public replacement is planned.
+ * Deprecated undocumented public functions `UTF8_putc()` and `UTF8_getc()`,
+ No public replacement is planned.
*Bob Beck*
- * Added IKEV2 KDF (EVP_KDF-IKEV2KDF) implementation.
+ * Added IKEV2 KDF (`EVP_KDF-IKEV2KDF`) to `EVP_KDF`.
*Helen Zhang*
- * Added AVX-512 and VAES optimizations for AES-CBC decryption. Decryption
+ * Added AVX-512 and VAES optimizations for AES-CBC decryption. Decryption
performance for large inputs (1024 bytes or more) improved by 3.5x to 3.8x.
*Madan Mohan Manokar*
- * Deprecated `ASN1_BIT_STRING_set()` in favour of `ASN1_BIT_STRING_set1()`.
+ * Deprecated `ASN1_BIT_STRING_set()` function in favour
+ of `ASN1_BIT_STRING_set1()`.
*Norbert Pócs*
@@ -472,10 +470,10 @@ OpenSSL 4.1
*Leon Timmermans*
- * Add `FIPS_mode()` as a convenience define to
- `EVP_default_properties_is_fips_enabled(NULL)`, which is
- shorthand to check whether the `fips=yes` property is currently enabled
- in the default library context.
+ * Added `FIPS_mode()` macro as a convenience alias
+ to `EVP_default_properties_is_fips_enabled(NULL)`, which is a shorthand
+ to check whether the `fips=yes` property is currently enabled in the default
+ library context.
*Dimitri John Ledkov*
@@ -24061,17 +24059,27 @@ ndif
[ESV]: https://csrc.nist.gov/Projects/cryptographic-module-validation-program/entropy-validations
[RFC 2578 (STD 58), section 3.5]: https://datatracker.ietf.org/doc/html/rfc2578#section-3.5
[RFC 3211]: https://datatracker.ietf.org/doc/html/rfc3211
+[RFC 4492 Section 5.1.2]: https://datatracker.ietf.org/doc/html/rfc4492#section-5.1.2
+[RFC 5280]: https://datatracker.ietf.org/doc/html/rfc5280
[RFC 5297]: https://datatracker.ietf.org/doc/html/rfc5297
[RFC 7250]: https://datatracker.ietf.org/doc/html/rfc7250
+[RFC 7685]: https://datatracker.ietf.org/doc/html/rfc7685
[RFC 7919]: https://datatracker.ietf.org/doc/html/rfc7919
[RFC 8422]: https://datatracker.ietf.org/doc/html/rfc8422
+[RFC 8422 Section 5.1.2]: https://datatracker.ietf.org/doc/html/rfc8422#section-5.1.2
[RFC 8446]: https://datatracker.ietf.org/doc/html/rfc8446
[RFC 8446 Section 4.6.1]: https://datatracker.ietf.org/doc/html/rfc8446#section-4.6.1
[RFC 8452]: https://datatracker.ietf.org/doc/html/rfc8452
+[RFC 8701]: https://datatracker.ietf.org/doc/html/rfc8701
[RFC 8998]: https://datatracker.ietf.org/doc/html/rfc8998#name-iana-considerations
+[RFC 9147]: https://datatracker.ietf.org/doc/html/rfc9147
[RFC 9149]: https://datatracker.ietf.org/doc/html/rfc9149
+[RFC 9846]: https://datatracker.ietf.org/doc/html/rfc9846
+[RFC 9846 Section 4.3.10]: https://datatracker.ietf.org/doc/html/rfc9846#section-4.3.10
[RFC 9849]: https://datatracker.ietf.org/doc/html/rfc9849
+[SECG SEC 1 Section 2.3.4]: https://www.secg.org/sec1-v2.pdf#subsubsection.2.3.4
[SP 800-132]: https://csrc.nist.gov/pubs/sp/800/132/final
[SP 800-185]: https://csrc.nist.gov/pubs/sp/800/185/final
[SP 800-208]: https://csrc.nist.gov/pubs/sp/800/208/final
+[TCG Credential Profiles specification Version 1.2, Section 3.2.7]: https://trustedcomputinggroup.org/wp-content/uploads/Credential_Profiles_V1.2_Level2_Revision8.pdf#page=35
[tls-hybrid-sm2-mlkem]: https://datatracker.ietf.org/doc/html/draft-yang-tls-hybrid-sm2-mlkem-03#name-iana-considerations