VOOZH about

URL: https://www.phoronix.com/news/OpenSSL-4.0-Alpha-1

⇱ OpenSSL 4.0 Alpha 1 Released With Encrypted Client Hello "ECH" & Other Features - Phoronix


👁 Phoronix

OpenSSL 4.0 Alpha 1 Released With Encrypted Client Hello "ECH" & Other Features

Written by Michael Larabel in Free Software on 10 March 2026 at 12:13 PM EDT. 8 Comments
The first alpha release of OpenSSL 4.0 is now available for testing. With OpenSSL 3.0 they are removing support for SSLv3 that has been deprecated for over one decade while also dropping OpenSSL engines and other removals while also adding in some new features.

OpenSSL 4.0 does away with a lot of old code for this widely used library. On the new feature side, OpenSSL 4.0 is adding support for TLS Encrypted Client Hello (a.k.a. RFC 9849). Encrypted Client Hello is a security feature for TLS that allows encrypting the initial handshake's Client Hello message to hide the Server Name Indication so that destination hostnames are not leaked. ECH is a replacement for Encrypted Server Name Indication (ESNI).

OpenSSL 4.0 is also adding support for the RFC 8998 signature algorithm, cSHAKE function support, ML-DSA-MU digest algorithm support, and support for SNMP KDF and SRTP KDF.

👁 OpenSSL logo


Downloads and more details on today's OpenSSL 4.0 Alpha 1 release via GitHub.

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.