OpenSSL 3.2.0 official release, client QUIC support / certificate compression / support for the original public key, etc.
Thanks to CTOnews.com netizens Alejandro86 and Coje_He for the clue delivery! CTOnews.com November 26, OpenSSL is a powerful secure socket layer cipher library that includes major cryptographic algorithms, commonly used key and certificate encapsulation management functions, and SSL protocols, and provides rich applications for testing or other purposes.
OpenSSL 3.2.0 is now released, which is the first general release of the OpenSSL 3.2 series and includes many new features. CTOnews.com lists some important updates:
The default SSL / TLS security level is changed from 1 to 2.
Client-side QUIC support, including support for multiple streams (RFC 9000)
Certificate compression in TLS (RFC 8879), including support for zlib, zstd, and Brotli
Deterministic ECDSA (RFC 6979)
In addition to existing support for Ed25519 and Ed448, Ed25519ctx, Ed25519ph, Ed448ph (RFC 8032) is now supported
Support for AES-GCM-SIV (RFC 8452)
Support for Argon2 (RFC 9106) and thread pool functionality
HPKE (RFC 9180)
Ability to use the original public key in TLS (RFC 7250)
Support for TCP Fast Open (RFC 7413)
Supports the use of provider-based pluggable signature schemes in TLS, allowing third-party post-quantum and other algorithm providers to use algorithms with TLS.
Support the use of Brainpool curves in TLS 1.3.
Support for SM4-XTS
Support the use of the Windows system certificate store as the source of trusted root certificates. It is not enabled by default and must be activated through the environment variable. It may be enabled by default in future feature releases.