OpenSSL version 4.1.0-alpha1 released

11 views
Skip to first unread message

Tomas Mraz

unread,
Sep 9, 2026, 9:40:12 AMSep 9
to openssl-project, openssl-users
OpenSSL version 4.1 alpha 1 released
====================================

OpenSSL - The Open Source toolkit for SSL/TLS
https://www.openssl-library.org/

OpenSSL 4.1 is currently in alpha.

OpenSSL 4.1 alpha 1 has now been made available.

Note: This OpenSSL pre-release has been provided for testing ONLY.
It should NOT be used for security critical purposes.

The alpha release is available for download at:

   * https://github.com/openssl/openssl/releases

Please download and check this alpha release as soon as possible.
To report a bug, open an issue on GitHub:

* https://github.com/openssl/openssl/issues


Release notes
=============

OpenSSL 4.1.0-alpha1 is a feature release adding significant new functionality to OpenSSL.

This release incorporates the following potentially significant or incompatible
changes:

* Added `VC-WIN32-MSVC2013` and `VC-WIN64A-MSVC2013` build targets to provide
internal functions for bridging the gaps in C99 standard support
that are present in MSVC 2013.

* Added optimized ML-DSA and ML-KEM NTT operations on `ppc64le`;
optimized ML-DSA operations on `s390x`, and `x86_64`;
AVX-512-optimized SHAKE x4 operations for ML-DSA on `x86_64`;
AVX-512 and VAES optimizations for AES-CBC decryption on `x86_64`.

* Changed `tsget` utility to use `Net::Curl::Easy` (from the `Net-Curl` CPAN
distribution) instead of the abandoned `WWW::Curl::Easy`. Users who rely
on `tsget` should install `Net::Curl::Easy` before upgrading.

* Dropped Windows-on-Itanium (`VC-WIN64I`) and Windows CE (`VC-CE`) targets
from Configurations.

* Dropped `no-ecdsa` and `no-ecdh` options from `Configure`, as these options
did not really disable the implementations. Use `no-ec` to disable
the elliptic curve support.

This release adds the following new features:

* Support for DTLS 1.3 ([RFC 9147]).
Refer to the `ossl-guide-dtlsv13(7)` manual page for details.

* Support for [RFC 8701] GREASE (Generate Random Extensions And Sustain
Extensibility).

* DTLS support in the SSL listener API.

* Support for IKEV2 KDF.

* Initial support for the Elbrus2000 (`e2k`) architecture.

[RFC 9147]: https://datatracker.ietf.org/doc/html/rfc9147
[RFC 8701]: https://datatracker.ietf.org/doc/html/rfc8701

Yours,

The OpenSSL Project Team.
signature.asc
Reply all
Reply to author
Forward
0 new messages