On this page
Overview
OpenSSL provides TLS protocol and general-purpose cryptography libraries plus command-line tools. It underpins encrypted application traffic, keys, certificates, signatures, and hashing.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Best fit
Fit TLS-enabled applications and certificate workflows
It suits adding TLS to servers or clients, creating certificate requests, and inspecting self-signed certificates in test environments.
Sources: [1]
Before adoption
Official sources
- [1]OpenSSL README at openssl-4.0.3(2026-10-05)
- [2]OpenSSL INSTALL at openssl-4.0.3(2026-10-05)
- [3]openssl-req manual for 4.0(2026-10-05)
- [4]OpenSSL LICENSE at openssl-4.0.3(2026-10-05)
Supplemental curator note
Build the pinned release instead of assuming an OS compatibility command is OpenSSL, then inspect subject, issuer, and SHA256 fingerprint on a temporary Ed25519 key and one-day self-signed certificate.
Try it in 3 steps
- 1
Fetch the pinned source
On a Unix-like system, install bash or zsh, Git, make, Perl 5 with Text::Template, and a C99 compiler; fetch openssl-4.0.3 and continue in openssl-demo.
git clone --branch openssl-4.0.3 --depth 1 https://github.com/openssl/openssl.git openssl-demo && cd openssl-demo - 2
Build the pinned openssl command
Configure for the host and build the repository apps/openssl binary so an OS-provided compatibility tool such as LibreSSL is not mistaken for this release.
./Configure no-shared && make -j2 apps/openssl - 3
Verify temporary certificate fields
Create an Ed25519 private key and one-day self-signed certificate in an owned temporary directory, inspect subject, issuer, and SHA256 fingerprint without printing the key, then delete both on exit.
(tmp_dir=$(mktemp -d) || exit 1; trap 'rm -rf "$tmp_dir"' EXIT; umask 077; apps/openssl req -x509 -newkey ed25519 -keyout "$tmp_dir/key.pem" -out "$tmp_dir/cert.pem" -noenc -subj '/CN=oss-tanbou-demo' -days 1 && test -s "$tmp_dir/key.pem" && test -s "$tmp_dir/cert.pem" && (set -o pipefail; apps/openssl x509 -in "$tmp_dir/cert.pem" -noout -nameopt RFC2253 -subject -issuer -fingerprint -sha256 | tee "$tmp_dir/cert-info.txt") && grep -F 'subject=CN=oss-tanbou-demo' "$tmp_dir/cert-info.txt" && grep -F 'issuer=CN=oss-tanbou-demo' "$tmp_dir/cert-info.txt" && grep -F 'sha256 Fingerprint=' "$tmp_dir/cert-info.txt")
Growth
Growth trends · Last 30 days
30,891 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 378
- Open PRs
- 531
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- cryptography
- openssl
- encryption
- tls
- ssl
- decryption
- Stars
- 30,891
- Forks
- 11,505
- Watchers
- 1,015
- Open issues
- 995
- Contributors
- 363
- Owner type
- Organization
- Primary language
- C
- License
- Apache-2.0
- Repository last updated
- Oct 5, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- NGINX31,792 Stars
2 shared tag(s) · Same language
run web delivery, reverse proxying, and load balancing while choosing between mainline and stable streams
C - Bitcoin Core90,309 Stars
2 shared tag(s)
Fully validate Bitcoin peer-to-peer blocks and transactions yourself while optionally running wallet and RPC services on the same node
C++ - Tuta Mail7,982 Stars
2 shared tag(s)
Implement open-source clients for encrypted mail, contacts, and calendar across web, desktop, and mobile
TypeScript - Padloc2,925 Stars
2 shared tag(s)
manage passwords and sensitive data with end-to-end encryption for individuals and teams
JavaScript - Eclipse Paho MQTT C2,373 Stars
1 shared tag(s) · 2 shared category(s) · Same language
connect C applications to MQTT 5.0/3.1.1 brokers through synchronous or asynchronous APIs over TCP, TLS, WebSockets, and Unix sockets
C - lwIP1,762 Stars
1 shared tag(s) · 2 shared category(s) · Same language
Embed a lightweight TCP/IP stack in devices with constrained memory
C
Report incorrect information
Tell us if any listing information is incorrect or outdated.