The Transport Layer Security (TLS) protocol provides the ability to secure communications across or inside networks. This comparison of TLS implementations compares several of the most notable libraries. There are several TLS implementations which are free software and open source.

All comparison categories use the stable version of each implementation listed in the overview section. The comparison is limited to features that directly relate to the TLS protocol.

Overview

ImplementationDeveloped byOpen sourceSoftware licenseCopyright holderWritten inLatest stable version, release dateOrigin
BotanJack LloydJack LloydC++US (Vermont)
BoringSSLGoogleEric Young, Tim Hudson, Sun, OpenSSL project, Google, and othersC, C++, Go, assemblyNo stable releases[1]Australia/EU[citation needed]
Bouncy CastleThe Legion of the Bouncy Castle Inc.Legion of the Bouncy Castle Inc.Java, C#Australia
BSAFEDell, formerly RSA SecurityDellJava, C, assemblySSL-J Micro Edition SuiteAustralia
cryptlibPeter Gutmannand commercial licensePeter GutmannCNZ
GnuTLSGnuTLS projectFree Software FoundationCEU (Greece and Sweden)
Java Secure Socket Extension (JSSE)Oracleand commercial licenseOracleJavaUS
LibreSSLOpenBSD ProjectEric Young, Tim Hudson, Sun, OpenSSL project, OpenBSD Project, and othersC, assemblyCanada
MatrixSSL[2]PeerSec Networksand commercial licensePeerSec NetworksCUS
Mbed TLS (previously PolarSSL)Armand commercial licenseArm HoldingsCEU (Netherlands)
Network Security Services (NSS)Mozilla, AOL, Red Hat, Sun, Oracle, Google and othersNSS contributorsC, assemblyUS
OpenSSLOpenSSL project[a]Eric Young, Tim Hudson, Sun, OpenSSL project, and othersC, assemblyAustralia/EU
RustlsJoe Birr-Pixton, Dirkjan Ochtman, Daniel McCarney, Josh Aas, and open source contributorsOpen source contributorsRustUnited Kingdom
s2nAmazonand commercial licenseAmazon.com, Inc.CContinuousUS
SchannelMicrosoftMicrosoft CorporationWindows 11, 2021-10-05US
Secure TransportApple Inc.Apple Inc.57337.20.44 (OS X 10.11.2), 2015-12-08US
wolfSSL (previously CyaSSL)wolfSSL[3]and commercial licensewolfSSL Inc.[4]C, assemblyUS
Erlang/OTP SSL applicationEricssonEricssonErlangOTP-21, 2018-06-19Sweden
ImplementationDeveloped byOpen sourceSoftware licenseCopyright ownerWritten inLatest stable version, release dateOrigin
  1. ^ openssl-licenses
  2. ^ bsafe-sslj-tls10
  3. ^ ssl20-client-hello
  4. ^ NSS-3.24
  5. ^ secure-transport-osx
  6. ^ otp-22
  7. ^ otp-23
  8. ^ "Erlang OTP SSL application TLS 1.3 compliance table"
  9. ^ Not supported for ECDHE key exchange, as per rustls::crypto::aws_lc_rs::kx_group.
  10. ^ These elliptic curves were "Disabled by Default" in current JDK families as part of JDK-8236730.[242]
  11. ^ These elliptic curves were subsequently removed in JDK 16+ as part of JDK-8252601.[243]
  12. ^ JSSEDisableEC
  13. ^ JSSERemoveEC
  14. ^ Pure Java implementations relies on JVM processor optimization capabilities, such as OpenJDK support for AES-NI[244]
  15. ^ BSAFE SSL-J can be configured to run in native mode, using BSAFE Crypto-C Micro Edition to benefit from processor optimization.[245]

TLS/SSL protocol version support

Several versions of the TLS protocol exist. SSL 2.0 is a deprecated[5] protocol version with significant weaknesses. SSL 3.0 (1996) and TLS 1.0 (1999) are successors with two weaknesses in CBC-padding that were explained in 2001 by Serge Vaudenay.[6] TLS 1.1 (2006) fixed only one of the problems, by switching to random initialization vectors (IV) for CBC block ciphers, whereas the more problematic use of mac-pad-encrypt instead of the secure pad-mac-encrypt was addressed with RFC 7366.[7] A workaround for SSL 3.0 and TLS 1.0, roughly equivalent to random IVs from TLS 1.1, was widely adopted by many implementations in late 2011.[8] In 2014, the POODLE vulnerability of SSL 3.0 was discovered, which takes advantage of the known vulnerabilities in CBC, and an insecure fallback negotiation used in browsers.[9]

TLS 1.2 (2008) introduced a means to identify the hash used for digital signatures. While permitting the use of stronger hash functions for digital signatures in the future (rsa,sha256/sha384/sha512) over the SSL 3.0 conservative choice (rsa,sha1+md5), the TLS 1.2 protocol change inadvertently and substantially weakened the default digital signatures and provides (rsa,sha1) and even (rsa,md5).[10]

Datagram Transport Layer Security (DTLS or Datagram TLS) 1.0 is a modification of TLS 1.1 for a packet-oriented transport layer, where packet loss and packet reordering have to be tolerated. The revision DTLS 1.2 based on TLS 1.2 was published in January 2012.[11]

TLS 1.3 (2018) specified in RFC 8446 includes major optimizations and security improvements. QUIC (2021) specified in RFC 9000 and DTLS 1.3 (2022) specified in RFC 9147 builds on TLS 1.3. The publishing of TLS 1.3 and DTLS 1.3 obsoleted TLS 1.2 and DTLS 1.2.

Note that there are known vulnerabilities in SSL 2.0 and SSL 3.0. In 2021, IETF published RFC 8996 also forbidding negotiation of TLS 1.0, TLS 1.1, and DTLS 1.0 due to known vulnerabilities. NIST SP 800-52 requires support of TLS 1.3 by January 2024. Support of TLS 1.3 means that two compliant nodes will never negotiate TLS 1.2.

ImplementationSSL 2.0 (insecure)[12]SSL 3.0 (insecure)[13]TLS 1.0 (deprecated)[14]TLS 1.1 (deprecated)[15]TLS 1.2[16]TLS 1.3DTLS 1.0 (deprecated)[17]DTLS 1.2[11]DTLS 1.3
Botan[18]
BoringSSL
Bouncy Castle
BSAFE SSL-J[19][b][b]
cryptlib
GnuTLS[c][20][21]
JSSE[c][22][23][23]
LibreSSL[24][25][26]
MatrixSSL[27]
Mbed TLS[28][28][28]
(experimental)
[29][29]
NSS[d][30][31][32][33][31][34]
OpenSSL[35][36][36][37]
Rustls[38][38][38][38][38][38]
s2n[39]
Schannel XP, 2003[40]
Schannel Vista[41]
Schannel 2008[41]
Schannel 7, 2008R2[42][43][43]
Schannel 8, 2012[42]
Schannel 8.1, 2012R2, 10 RTM & v1511[42]
Schannel 10 v1607 / 2016[44]
Schannel 11 / 2022[45]
Secure Transport OS X 10.2–10.7, iOS 1–4
Secure Transport OS X 10.8–10.10, iOS 5–8[e][e][e][e]
Secure Transport OS X 10.11, iOS 9[e]
Secure Transport OS X 10.13, iOS 11[e]
(draft version)[46]
wolfSSL[47][48]
Erlang/OTP SSL application[49][f][g][f][f][h][f]
ImplementationSSL 2.0 (insecure)[12]SSL 3.0 (insecure)[13]TLS 1.0 (deprecated)[14]TLS 1.1 (deprecated)[15]TLS 1.2[16]TLS 1.3DTLS 1.0 (deprecated)[17]DTLS 1.2[11]DTLS 1.3

NSA Suite B Cryptography

Required components for NSA Suite B Cryptography (RFC 6460) are:

Per CNSSP-15, the 256-bit elliptic curve (specified in FIPS 186-2), SHA-256, and AES with 128-bit keys are sufficient for protecting classified information up to the Secret level, while the 384-bit elliptic curve (specified in FIPS 186-2), SHA-384, and AES with 256-bit keys are necessary for the protection of Top Secret information.

ImplementationTLS 1.2 Suite B
Botan
Bouncy Castle
BSAFE[19]
cryptlib
GnuTLS
JSSE[50]
LibreSSL
MatrixSSL
Mbed TLS
NSS[51]
OpenSSL[37]
Rustls[38]
S2n
Schannel[52]
Secure Transport
wolfSSL
ImplementationTLS 1.2 Suite B

Certifications

Note that certain certifications have received serious negative criticism from people who are actually involved in them.[53]

ImplementationFIPS 140-1, FIPS 140-2[54]FIPS 140-3
Level 1Level 2[disputed – discuss]Level 1
Botan[55]
Bouncy Castle
BSAFE SSL-J[56]
cryptlib[57]
GnuTLS[58]
JSSE
LibreSSL[24]no support
MatrixSSL[59]
Mbed TLS[60]
NSS[61]
OpenSSL[62]
Rustls
Schannel[63]
Secure Transport
wolfSSL[64]
ImplementationLevel 1Level 2Level 1
FIPS 140-1, FIPS 140-2FIPS 140-3

Key exchange algorithms (certificate-only)

This section lists the certificate verification functionality available in the various implementations.

ImplementationRSA[16]RSA-EXPORT (insecure)[16]DHE-RSA (forward secrecy)[16]DHE-DSS (forward secrecy)[16]ECDH-ECDSA[65]ECDHE-ECDSA (forward secrecy)[65]ECDH-RSA[65]ECDHE-RSA (forward secrecy)[65]GOST R 34.10-94, 34.10-2001[66]
Botan
BSAFE
cryptlib
GnuTLS[20]
JSSE
LibreSSL[24][67]
MatrixSSL
Mbed TLS
NSS[68][69][70]
OpenSSL[35][35][71]
Rustls[38][38]
Schannel XP/2003[72]
Schannel Vista/2008[73][72]
Schannel 8/2012[74][75][76][73][72]
Schannel 7/2008R2, 8.1/2012R2[73][72]
Schannel 10[73][72]
Secure Transport OS X 10.6
Secure Transport OS X 10.8-10.10
Secure Transport OS X 10.11
wolfSSL
Erlang/OTP SSL application
ImplementationRSA[16]RSA-EXPORT (insecure)[16]DHE-RSA (forward secrecy)[16]DHE-DSS (forward secrecy)[16]ECDH-ECDSA[65]ECDHE-ECDSA (forward secrecy)[65]ECDH-RSA[65]ECDHE-RSA (forward secrecy)[65]GOST R 34.10-94, 34.10-2001[66]

Key exchange algorithms (alternative key-exchanges)

ImplementationSRP[77]SRP-DSS[77]SRP-RSA[77]PSK-RSA[78]PSK[78]DHE-PSK (forward secrecy)[78]ECDHE-PSK (forward secrecy)[79]KRB5[80]DH-ANON[16] (insecure)ECDH-ANON[65] (insecure)
Botan
BSAFE SSL-J[81]
cryptlib
GnuTLS
JSSE
LibreSSL[82][82][82]
MatrixSSL
Mbed TLS
NSS[83][83][83][84][84][84][84][85][86]
OpenSSL[87][88][88]
Rustls
Schannel
Secure Transport
wolfSSL[89]
Erlang/OTP SSL application
ImplementationSRP[77]SRP-DSS[77]SRP-RSA[77]PSK-RSA[78]PSK[78]DHE-PSK (forward secrecy)[78]ECDHE-PSK (forward secrecy)[79]KRB5[80]DH-ANON[16] (insecure)ECDH-ANON[65] (insecure)

Certificate verification methods

ImplementationApplication-definedPKIX path validation[90]CRL[91]OCSP[92]DANE (DNSSEC)[93][94]CT[95]
Botan
Bouncy Castle
BSAFE
cryptlib
GnuTLS
JSSE
LibreSSL
MatrixSSL[96]
Mbed TLS[97]
NSS[98]
OpenSSL
Rustls
s2n[99][100][101]
Schannel[102][102]
Secure Transport
wolfSSL
Erlang/OTP SSL application
ImplementationApplication-definedPKIX path validationCRLOCSPDANE (DNSSEC)CT

Encryption algorithms

ImplementationBlock cipher with mode of operationStream cipherNone
AES GCM
[103]
AES CCM
[104]
AES CBCCamellia GCM
[105]
Camellia CBC
[106][105]
ARIA GCM
[107]
ARIA CBC
[107]
SEED CBC
[108]
3DES EDE CBC
(insecure)[109]
GOST 28147-89 CNT
(proposed)
[66][n 1]
ChaCha20-Poly1305
[110]
Null
(insecure)
[n 2]
Botan[111]
BoringSSL
BSAFE SSL-J
cryptlib
GnuTLS[20][112][113]
JSSE[114][115]
LibreSSL[24][67][24][67][24]
MatrixSSL[116]
Mbed TLS[117][118][118][28][119]
NSS[120][121][n 3][122][123][69][70][124]
OpenSSL[125][35][35][126][35][35][71][35]
Rustls[38][38]
Schannel XP/2003[127][72]
Schannel Vista/2008, 2008R2, 2012[72]
Schannel 7, 8, 8.1/2012R2
[74][75]
[72]
Schannel 10[128][72]
Secure Transport OS X 10.6 - 10.10
Secure Transport OS X 10.11
wolfSSL
Erlang/OTP SSL application
ImplementationBlock cipher with mode of operationStream cipherNone
AES GCM
[103]
AES CCM
[104]
AES CBCCamellia GCM
[105]
Camellia CBC
[106][105]
ARIA GCM
[107]
ARIA CBC
[107]
SEED CBC
[108]
3DES EDE CBC
(insecure)[109]
GOST 28147-89 CNT
(proposed)
[66][n 1]
ChaCha20-Poly1305
[110]
Null
(insecure)
[n 2]
Notes
  1. ^ IDEA and DES have been removed from TLS 1.2.[246]

Obsolete algorithms

ImplementationBlock cipher with mode of operationStream cipher
IDEA CBC
["n" 1](insecure)[129]
DES CBC
(insecure)
[n 4]
DES-40 CBC
(EXPORT, insecure)
[n 5]
RC2-40 CBC
(EXPORT, insecure)
[n 5]
RC4-128
(insecure)
[n 6]
RC4-40
(EXPORT, insecure)
[n 7][n 5]
Botan[130]
BoringSSL
BSAFE SSL-J
cryptlib
GnuTLS[20]
JSSE[131]
LibreSSL[24][24][24]
MatrixSSL
Mbed TLS[29]
NSS[132][133]
OpenSSL[35][35][35][35]
Rustls
Schannel XP/2003
Schannel Vista/2008
Schannel 7/2008R2[134]
Schannel 8/2012
Schannel 8.1/2012R2[134]
Schannel 10[128][134]
Secure Transport OS X 10.6
Secure Transport OS X 10.7
Secure Transport OS X 10.8-10.9
Secure Transport OS X 10.10-10.11
Secure Transport macOS 10.12
wolfSSL[135]
Erlang/OTP SSL application
ImplementationBlock cipher with mode of operationStream cipher
IDEA CBC
[n 4](insecure)[129]
DES CBC
(insecure)
[n 4]
DES-40 CBC
(EXPORT, insecure)
[n 5]
RC2-40 CBC
(EXPORT, insecure)
[n 5]
RC4-128
(insecure)
[n 6]
RC4-40
(EXPORT, insecure)
[n 7][n 5]
Notes

Supported elliptic curves

This section lists the supported elliptic curves by each implementation.

Defined curves in RFC 8446 (for TLS 1.3) and RFC 8422, 7027 (for TLS 1.2 and earlier)

applicable TLS versionTLS 1.3 and earlierTLS 1.2 and earlier
Implementationsecp256r1
prime256v1
NIST P-256
(0x0017,[136] 23[137])
secp384r1
NIST P-384
(0x0018,[136] 24[137])
secp521r1
NIST P-521
(0x0019,[136] 25[137])
X25519
(0x001D,[136] 29[137])
X448
(0x001E,[136] 30[137])
brainpoolP256r1
(26)[138]
brainpoolP384r1
(27)[138]
brainpoolP512r1
(28)[138]
Botan[111][139][139][139]
BoringSSL(disabled by default)
BSAFE
GnuTLS[140][141]
JSSE
x25519: JDK 13+[142]
Ed25519:JDK 15+[143]

x448: JDK 13+[142]
Ed448: JDK 15+[143]
LibreSSL[144][24][24][24]
MatrixSSL[145]
Mbed TLS[146][147][148][148][148]
NSS[149][150][151][152][152][152]
OpenSSL[153][154][155][156][37][37][37]
Rustls[157][i]
Schannel Vista/2008, 7/2008R2, 8/2012, 8.1/2012R2, 10
Secure Transport
wolfSSL[158][159]
Erlang/OTP SSL application
Implementationsecp256r1
prime256v1
NIST P-256
(0x0017, 23)
secp384r1
NIST P-384
(0x0018, 24)
secp521r1
NIST P-521
(0x0019, 25)
X25519
(0x001D, 29)
X448
(0x001E, 30)
brainpoolP256r1
(26)
brainpoolP384r1
(27)
brainpoolP512r1
(28)

Deprecated curves in RFC 8422

Implementationsect163k1
NIST K-163
(1)[65]
sect163r1
(2)[65]
sect163r2
NIST B-163
(3)[65]
sect193r1
(4)[65]
sect193r2
(5)[65]
sect233k1
NIST K-233
(6)[65]
sect233r1
NIST B-233
(7)[65]
sect239k1
(8)[65]
sect283k1
NIST K-283
(9)[65]
sect283r1
NIST B-283
(10)[65]
sect409k1
NIST K-409
(11)[65]
sect409r1
NIST B-409
(12)[65]
sect571k1
NIST K-571
(13)[65]
sect571r1
NIST B-571
(14)[65]
Botan
BoringSSL
BSAFE
GnuTLS
JSSE[j][k][l][m][l][m][l][m][l][m][l][m][l][m][l][m][l][m][l][m][l][m][l][m][l][m][l][m]
LibreSSL
MatrixSSL
Mbed TLS
NSS
OpenSSL
Rustls
Schannel Vista/2008, 7/2008R2, 8/2012, 8.1/2012R2, 10
Secure Transport
wolfSSL
Erlang/OTP SSL application
Implementationsect163k1
NIST K-163
(1)
sect163r1
(2)
sect163r2
NIST B-163
(3)
sect193r1
(4)
sect193r2
(5)
sect233k1
NIST K-233
(6)
sect233r1
NIST B-233
(7)
sect239k1
(8)
sect283k1
NIST K-283
(9)
sect283r1
NIST B-283
(10)
sect409k1
NIST K-409
(11)
sect409r1
NIST B-409
(12)
sect571k1
NIST K-571
(13)
sect571r1
NIST B-571
(14)
Implementationsecp160k1
(15)[65]
secp160r1
(16)[65]
secp160r2
(17)[65]
secp192k1
(18)[65]
secp192r1
prime192v1
NIST P-192
(19)[65]
secp224k1
(20)[65]
secp224r1
NIST P-244
(21)[65]
secp256k1
(22)[65]
arbitrary prime curves
(0xFF01)[65][160]
arbitrary char2 curves
(0xFF02)[65][160]
Botan
BoringSSL
BSAFE
GnuTLS
JSSE[l][m][l][m][l][m][l][m][l][m][l][m][l][m][l][m]
LibreSSL
MatrixSSL
Mbed TLS
NSS
OpenSSL
Rustls
Schannel Vista/2008, 7/2008R2, 8/2012, 8.1/2012R2, 10
Secure Transport
wolfSSL
Erlang/OTP SSL application
Implementationsecp160k1
(15)
secp160r1
(16)
secp160r2
(17)
secp192k1
(18)
secp192r1
prime192v1
NIST P-192
(19)
secp224k1
(20)
secp224r1
NIST P-244
(21)
secp256k1
(22)
arbitrary prime curves
(0xFF01)
arbitrary char2 curves
(0xFF02)
Notes

Data integrity

ImplementationHMAC-MD5HMAC-SHA1HMAC-SHA256/384AEADGOST 28147-89 IMIT
[66]
GOST R 34.11-94
[66]
Botan
BSAFE
cryptlib
GnuTLS
JSSE
LibreSSL
[67]

[67]
MatrixSSL
Mbed TLS
NSS
[69][70]

[69][70]
OpenSSL
[71]

[71]
Rustls
Schannel XP/2003, Vista/2008
[161]

[72]

[72]
Schannel 7/2008R2, 8/2012, 8.1/2012R2
[74][75][76]

[72]

[72]
Schannel 10
[128]

[72]

[72]
Secure Transport
wolfSSL
Erlang/OTP SSL application
ImplementationHMAC-MD5HMAC-SHA1HMAC-SHA256/384AEADGOST 28147-89 IMITGOST R 34.11-94

Compression

Note the CRIME security exploit takes advantage of TLS compression, so conservative implementations do not enable compression at the TLS level. HTTP compression is unrelated and unaffected by this exploit, but is exploited by the related BREACH attack.

ImplementationDEFLATE[162]
(insecure)
Botan
BSAFE[19]
cryptlib
GnuTLS
JSSE
LibreSSL[24]
MatrixSSL
Mbed TLS
NSS
OpenSSL
Rustls
Schannel
Secure Transport
wolfSSL
Erlang/OTP SSL application
ImplementationDEFLATE

Extensions

In this section the extensions each implementation supports are listed. Note that the Secure Renegotiation extension is critical for HTTPS client security [citation needed]. TLS clients not implementing it are vulnerable to attacks, irrespective of whether the client implements TLS renegotiation.

ImplementationSecure Renegotiation
[163]
Server Name Indication
[164]
ALPN
[165]
Certificate Status Request
[164]
OpenPGP
[166]
Supplemental Data
[167]
Session Ticket
[168]
Keying Material Exporter
[169]
Maximum Fragment Length
[164]
Encrypt-then-MAC
[7]
TLS Fallback SCSV
[170]
Extended Master Secret
[171]
ClientHello Padding
[172]
Raw Public Keys
[173]
Botan[174][175][176]
BSAFE SSL-J
cryptlib[177]
GnuTLS[178][179][20][180][20][181][182]
JSSE[50][50]
LibreSSL[183]??[184]
MatrixSSL[185][116][116][116]
Mbed TLS[186][187][187][187]
NSS[188][189][190][191][192][188]
OpenSSL[37]?[193][35][194][195]
Rustls[196]
Schannel XP/2003
Schannel Vista/2008[197]
Schannel 7/2008R2[197]
Schannel 8/2012[198][197]
Schannel 8.1/2012R2, 10[198][197]
Secure Transport
wolfSSL[135][199][200]
Erlang/OTP SSL application
ImplementationSecure RenegotiationServer Name IndicationALPNCertificate Status RequestOpenPGPSupplemental DataSession TicketKeying Material ExporterMaximum Fragment LengthEncrypt-then-MACTLS Fallback SCSVExtended Master SecretClientHello PaddingRaw Public Keys

Assisted cryptography

This section lists the known ability of an implementation to take advantage of CPU instruction sets that optimize encryption, or utilize system specific devices that allow access to underlying cryptographic hardware for acceleration or for data separation.

ImplementationPKCS #11 deviceIntel AES-NIVIA PadLockARMv8-AIntel SHANXP CAAMTPM 2.0NXP SE050Microchip ATECCSTMicro STSAFEMaxim MAXQ
Botan[201][202]
BSAFE SSL-J [n][o][203]
cryptlib
Crypto++
GnuTLS[204][205]
JSSE[206]
LibreSSL
MatrixSSL
Mbed TLS[207][208][209]
NSS[210][211][212]
OpenSSL[213][214][215][216][217][218][208][219]
Rustls
Schannel
Secure Transport[220][221]
wolfSSL[222][223][224][225][226][227][228]
ImplementationPKCS #11 deviceIntel AES-NIVIA PadLockARMv8-AIntel SHANXP CAAMTPM 2.0NXP SE050Microchip ATECCSTMicro STSAFEMaxim MAXQ

System-specific backends

This section lists the ability of an implementation to take advantage of the available operating system specific backends, or even the backends provided by another implementation.

Implementation/dev/cryptoaf_algWindows CSPCommonCryptoOpenSSL engine
Botan
BSAFE
cryptlib
GnuTLS
JSSE
LibreSSL[229]
MatrixSSL
Mbed TLS
NSS
OpenSSL
Rustls[230]
Schannel
Secure Transport
wolfSSL[231]
Erlang/OTP SSL application
Implementation/dev/cryptoaf_algWindows CSPCommonCryptoOpenSSL engine

Cryptographic module/token support

ImplementationTPM supportHardware token supportObjects identified via
Botan[176]
BSAFE SSL-J
cryptlibUser-defined label
GnuTLSRFC 7512 PKCS #11 URLs[232]
JSSE
LibreSSLCustom method
MatrixSSL
Mbed TLSCustom method
NSS
OpenSSL[233]RFC 7512 PKCS #11 URLs[232]
Rustls[234]Custom method
SchannelUUID, User-defined label
Secure Transport
wolfSSL
ImplementationTPM supportHardware token supportObjects identified via

Code dependencies

ImplementationDependenciesOptional dependencies
BotanC++20SQLite
zlib (compression)
bzip2 (compression)
liblzma (compression)
boost
trousers (TPM)
GnuTLSlibc
nettle
gmp
zlib (compression)
p11-kit (PKCS #11)
trousers (TPM)
libunbound (DANE)
JSSEJava
MatrixSSLnonezlib (compression)
MatrixSSL-openlibc or newlib
Mbed TLSlibclibpkcs11-helper (PKCS #11)
zlib (compression)
NSSlibc
libnspr4
libsoftokn3
libplc4
libplds4
zlib (compression)
Rustlsrust core libraryrust std library
zlib-rs (compression)
brotli (compression)
ring (cryptography)
aws-lc-rs (cryptography)
OpenSSLlibczlib (compression)
brotli (compression)
zstd (compression)
wolfSSLNonelibc
zlib (compression)
Erlang/OTP SSL applicationlibcrypto (from OpenSSL), Erlang/OTP and its public_key, crypto and asn1 applicationsErlang/OTP -inets (http fetching of CRLs)
ImplementationDependenciesOptional dependencies

Development environment

ImplementationNamespaceBuild toolsAPI manualCrypto back-endOpenSSL compatibility Layer[clarification needed]
BotanBotan::TLSMakefileSphinxIncluded (pluggable)
Bouncy Castleorg.bouncycastleJava Development EnvironmentProgrammers reference manual (PDF)Included (pluggable)
BSAFE SSL-Jcom.rsa.asn1
com.rsa.certj
com.rsa.jcp
com.rsa.jsafe
com.rsa.ssl
com.rsa.jsse
Java class loaderJavadoc, Developer's guide (HTML)Included
cryptlibcrypt*makefile, MSVC project workspacesProgrammers reference manual (PDF), architecture design manual (PDF)Included (monolithic)
GnuTLSgnutls_*Autoconf, automake, libtoolManual and API reference (HTML, PDF)External, libnettle(limited)
JSSEjavax.net.ssl
sun.security.ssl
MakefileAPI Reference (HTML) +Java Cryptography Architecture,
Java Cryptography Extension
MatrixSSLmatrixSsl_*
ps*
Makefile, MSVC project workspaces, Xcode projects for OS X and iOSAPI Reference (PDF), Integration GuideIncluded (pluggable)(Subset: SSL_read, SSL_write, etc.)
Mbed TLSmbedtls_ssl_*
mbedtls_sha1_*
mbedtls_md5_*
mbedtls_x509*
...
Makefile, CMake, MSVC project workspaces, yottaAPI Reference + High Level and Module Level Documentation (HTML)Included (monolithic)
NSSCERT_*
SEC_*
SECKEY_*
NSS_*
PK11_*
SSL_*
...
MakefileManual (HTML)Included, PKCS#11 based[235](separate package called nss_compat_ossl[236])
OpenSSLSSL_*
SHA1_*
MD5_*
EVP_*
...
MakefileMan pagesIncluded (monolithic)
Rustlsrustls::cargoAPI reference and design manualring, aws-lc-rs included. Pluggable with OpenSSL, BoringSSL, Microsoft SymCrypt, wolfCrypt, Mbed TLS, Graviola, and RustCrypto.[237][238][239] (subset)
wolfSSLwolfSSL_*
CyaSSL_*
SSL_*
Autoconf, automake, libtool, MSVC project workspaces, XCode projects, CodeWarrior projects, MPLAB X projects, Keil, IAR, Clang, GCC, e2StudioManual and API Reference (HTML, PDF)Included (monolithic)(about 60% of API)
ImplementationNamespaceBuild toolsAPI manualCrypto back-endOpenSSL compatibility layer

API

Portability concerns

ImplementationPlatform requirementsNetwork requirementsThread safetyRandom seedAble to cross-compileNo OS (bare metal)Supported operating systems
BotanC++11NonePlatform-dependentWindows, Linux, macOS, Android, iOS, FreeBSD, OpenBSD, Solaris, AIX, HP-UX, QNX, BeOS, IncludeOS
BSAFE SSL-JJavaJava SE network componentsDepends on java.security.SecureRandomFreeBSD, Linux, macOS, Microsoft Windows, Android, AIX, Solaris
cryptlibC89POSIX send() and recv(). API to supply your own replacementPlatform-dependent, including hardware sourcesAMX, BeOS, ChorusOS, DOS, eCos, FreeRTOS/OpenRTOS, uItron, MVS, OS/2, Palm OS, QNX Neutrino, RTEMS, Tandem NonStop, ThreadX, uC/OS II, Unix (AIX, FreeBSD, HPUX, Linux, macOS, Solaris, etc.), VDK, VM/CMS, VxWorks, Win16, Win32, Win64, WinCE/PocketPC/etc, XMK
GnuTLSC89POSIX send() and recv(). API to supply your own replacement.Platform dependentGenerally any POSIX platforms or Windows, commonly tested platforms include Linux, Win32/64, macOS, Solaris, OpenWRT, FreeBSD, NetBSD, OpenBSD.
JSSEJavaJava SE network componentsDepends on java.security.SecureRandomJava based, platform-independent
MatrixSSLC89NonePlatform dependentAll
Mbed TLSC89POSIX read() and write(). API to supply your own replacement.Random seed set through entropy poolKnown to work on: Win32/64, Linux, macOS, Solaris, FreeBSD, NetBSD, OpenBSD, OpenWRT, iPhone (iOS), Xbox, Android, eCos, SeggerOS, RISC OS
NSSC89, NSPR[240]NSPR[240] PR_Send() and PR_Recv(). API to supply your own replacement.Platform dependent[241](but cumbersome)AIX, Android, FreeBSD, NetBSD, OpenBSD, BeOS, HP-UX, IRIX, Linux, macOS, OS/2, Solaris, OpenVMS, Amiga DE, Windows, WinCE, Sony PlayStation
RustlsRust (programming language)NonePlatform dependentAll supported by Rust (programming language)
OpenSSLC89NonePlatform dependentUnix-like, DOS (with djgpp), Windows, OpenVMS, NetWare, eCos
wolfSSLC89POSIX send() and recv(). API to supply your own replacement.Random seed set through wolfCryptWin32/64, Linux, macOS, Solaris, ThreadX, VxWorks, FreeBSD, NetBSD, OpenBSD, embedded Linux, Yocto Project, OpenEmbedded, WinCE, Haiku, OpenWRT, iPhone (iOS), Android, Nintendo Wii and GameCube through DevKitPro, QNX, MontaVista, NonStop, TRON/ITRON/μITRON, eCos, Micrium μC/OS-III, FreeRTOS, SafeRTOS, NXP/Freescale MQX, Nucleus, TinyOS, HP/UX, AIX, ARC MQX, Keil RTX, TI-RTOS, uTasker, embOS, INtime, Mbed, uT-Kernel, RIOT, CMSIS-RTOS, FROSTED, Green Hills INTEGRITY, TOPPERS, PetaLinux, Apache mynewt
ImplementationPlatform requirementsNetwork requirementsThread safetyRandom seedAble to cross-compileNo OS (bare metal)Supported operating systems

See also

  • SCTP — with DTLS support
  • DCCP — with DTLS support
  • SRTP — with DTLS support (DTLS-SRTP) and Secure Real-Time Transport Control Protocol (SRTCP)

References

  1. ^ "BoringSSL README.md". boringssl.googlesource.com. Retrieved 2025-11-11.
  2. ^ The features listed are for the closed source version
  3. ^ "wolfSSL product description". Retrieved 2016-05-03.
  4. ^ "wolfSSL Embedded SSL/TLS". Retrieved 2016-05-03.
  5. ^ "Prohibiting Secure Sockets Layer (SSL) Version 2.0"
  6. ^ Vaudenay, Serge (2001). "CBC-Padding: Security Flaws in SSL, IPsec, WTLS,..."
  7. ^ "Encrypt-then-MAC for Transport Layer Security (TLS) and Datagram Transport Layer Security"
  8. ^ "Rizzo/Duong BEAST Countermeasures". Archived from the original on 2016-03-11.
  9. ^ Möller, Bodo; Duong, Thai; Kotowicz, Krzysztof (September 2014). "This POODLE Bites: Exploiting The SSL 3.0 Fallback". Archived from the original on 15 October 2014. Retrieved 15 October 2014.
  10. ^ "1.2". "The Transport Layer Security (TLS) Protocol Version 1.2"
  11. ^
  12. ^ Elgamal, Taher & Hickman, Kipp E. B. (19 April 1995). "The SSL Protocol"
  13. ^
  14. ^
  15. ^
  16. ^
  17. ^
  18. ^ "Version 1.11.13, 2015-01-11 — Botan". 2015-01-11. Archived from the original on 2015-01-09. Retrieved 2015-01-16.
  19. ^ "RSA BSAFE Technical Specification Comparison Tables". Archived from the original on 2015-09-24. Retrieved 2015-01-09.
  20. ^ "[gnutls-devel] GnuTLS 3.4.0 released". 2015-04-08. Retrieved 2015-04-16.
  21. ^ "[gnutls-devel] GnuTLS 3.6.3". 2018-07-16. Retrieved 2018-09-16.
  22. ^ "Java SE Development Kit 8, Update 31 Release Notes". Retrieved 2024-01-14.
  23. ^ "Release Note: Disable TLS 1.0 and 1.1". Retrieved 2024-01-14.
  24. ^ "OpenBSD 5.6 Released". 2014-11-01. Retrieved 2015-01-20.
  25. ^ "LibreSSL 2.3.0 Released". 2015-09-23. Retrieved 2015-09-24.
  26. ^ "LibreSSL 3.3.3 Released". 2021-05-04. Retrieved 2021-05-04.
  27. ^ "MatrixSSL - News". Archived from the original on 2015-02-14. Retrieved 2014-11-09.
  28. ^ "Mbed TLS 3.0.0 branch released". GitHub. 2021-07-07. Retrieved 2021-08-13.
  29. ^ "mbed TLS 2.0.0 released". 2015-07-10. Retrieved 2015-07-14.
  30. ^ "NSS 3.19 release notes". Mozilla Developer Network. Mozilla. Archived from the original on 2015-06-05. Retrieved 2015-05-06.
  31. ^ "NSS 3.14 release notes". Mozilla Developer Network. Mozilla. Archived from the original on 2013-01-17. Retrieved 2012-10-27.
  32. ^ "NSS 3.15.1 release notes". Mozilla Developer Network. Mozilla. Retrieved 2013-08-10.
  33. ^ "NSS 3.39 release notes". Mozilla Developer Network. Mozilla. 2018-08-31. Archived from the original on 2021-12-07. Retrieved 2018-09-15.
  34. ^ "NSS 3.16.2 release notes". Mozilla Developer Network. Mozilla. 2014-06-30. Archived from the original on 2021-12-07. Retrieved 2014-06-30.
  35. ^ "OpenSSL 1.1.0 Series Release Notes". www.openssl.org. Archived from the original on 2018-03-17. Retrieved 2016-09-03.
  36. ^ "Major changes between OpenSSL 1.0.0h and OpenSSL 1.0.1 [14 Mar 2012]". 2012-03-14. Archived from the original on December 5, 2014. Retrieved 2015-01-20.
  37. ^ "Major changes between OpenSSL 1.0.1l and OpenSSL 1.0.2 [22 Jan 2015]". Archived from the original on September 4, 2014. Retrieved 2015-01-22.
  38. ^ "rustls implemented and unimplemented features documentation". Retrieved 2024-08-28.
  39. ^ "S2N Readme". GitHub. 2019-12-21.
  40. ^ "TLS Cipher Suites (Windows)". msdn.microsoft.com. 14 July 2023.
  41. ^ "TLS Cipher Suites in Windows Vista (Windows)". msdn.microsoft.com. 25 October 2021.
  42. ^ "Cipher Suites in TLS/SSL (Schannel SSP) (Windows)". msdn.microsoft.com. 14 July 2023.
  43. ^ "An update is available that adds support for DTLS in Windows 7 SP1 and Windows Server 2008 R2 SP1". Microsoft. Retrieved 13 November 2012.
  44. ^ "Protocols in TLS/SSL (Schannel SSP)". Microsoft. 2022-05-25. Retrieved 2023-11-18.
  45. ^ "Protocols in TLS/SSL (Schannel SSP)". 25 May 2022. Retrieved 6 November 2022.
  46. ^ "@badger: the 1.3 stuff is apparently in iOS 11 and macOS 10.13.". 2018-03-09. Retrieved 2018-03-09.
  47. ^ "[wolfssl] wolfSSL 3.6.6 Released". 2015-08-20. Retrieved 2015-08-24.
  48. ^ "[wolfssl] wolfSSL 3.13.0 Released". 2017-12-21. Retrieved 2022-01-17.
  49. ^ "Erlang -- Standards Compliance"
  50. ^ "Security Enhancements in JDK 8". docs.oracle.com
  51. ^ "Bug 663320 - (NSA-Suite-B-TLS) Implement RFC6460 (NSA Suite B profile for TLS)". Mozilla. Retrieved 2014-05-19.
  52. ^ "Introducing Compliance to Suite B Cryptography". 18 September 2012.
  53. ^ "Speeds and Feeds › Secure or Compliant, Pick One". Archived from the original on December 27, 2013.
  54. ^ "Search - Cryptographic Module Validation Program - CSRC". csrc.nist.gov. Archived from the original on 2014-12-26. Retrieved 2014-03-18.
  55. ^ ""Is botan FIPS 140 certified?" Frequently Asked Questions — Botan". Archived from the original on 2014-11-29. Retrieved 2014-11-16.
  56. ^ "Search - Cryptographic Module Validation Program - CSRC". csrc.nist.gov. 11 October 2016.
  57. ^ "cryptlib". 11 October 2013. Archived from the original on 11 October 2013.
  58. ^ "B.5 Certification". GnuTLS 3.7.7. Retrieved 26 September 2022.
  59. ^ "Matrix SSL Toolkit"
  60. ^ "Is mbed TLS FIPS certified? - Mbed TLS documentation". Mbed TLS documentation
  61. ^ "FIPS Validation - MozillaWiki". wiki.mozilla.org
  62. ^ "OpenSSL and FIPS 140-2". Archived from the original on 2013-05-28. Retrieved 2014-11-15.
  63. ^ "Microsoft FIPS 140 Validated Cryptographic Modules"
  64. ^ "wolfCrypt FIPS 140-2 Information - wolfSSL Embedded SSL/TLS Library"
  65. ^
  66. ^ "GOST 28147-89 Cipher Suites for Transport Layer Security (TLS)"
  67. ^ "LibreSSL 2.1.2 released". 2014-12-09. Retrieved 2015-01-20.
  68. ^ "NSS 3.20 release notes". Mozilla. 2015-08-19. Archived from the original on 2021-12-07. Retrieved 2015-08-20.
  69. ^ Mozilla.org. "Bug 518787 - Add GOST crypto algorithm support in NSS". Retrieved 2014-07-01.
  70. ^ Mozilla.org. "Bug 608725 - Add Russian GOST cryptoalgorithms to NSS and Thunderbird". Retrieved 2014-07-01.
  71. ^ "OpenSSL: CVS Web Interface". Archived from the original on 2013-04-15. Retrieved 2014-11-12.
  72. ^ Extensions to support GOST in Schannel might be available.[citation needed]
  73. ^ "Microsoft Security Advisory 3174644". 14 October 2022.
  74. ^ "Microsoft Security Bulletin MS14-066 - Critical (Section Update FAQ)". Microsoft. November 11, 2014. Retrieved 11 November 2014.
  75. ^ Thomlinson, Matt (November 11, 2014). "Hundreds of Millions of Microsoft Customers Now Benefit from Best-in-Class Encryption". Microsoft Security. Retrieved 11 November 2014.
  76. ^ "Update adds new TLS cipher suites and changes cipher suite priorities in Windows 8.1 and Windows Server 2012 R2". support.microsoft.com
  77. ^
  78. ^
  79. ^
  80. ^
  81. ^ "RSA BSAFE SSL-J 6.2.4 Release Notes". 2018-09-05. Archived from the original on 2018-09-10.
  82. ^ "LibreSSL 2.0.4 released". Retrieved 2014-08-04.
  83. ^ "Bug 405155 - add support for TLS-SRP, rfc5054". Mozilla. Retrieved 2014-01-25.
  84. ^ "Bug 306435 - Mozilla browsers should support the new IETF TLS-PSK protocol to help reduce phishing". Mozilla. Retrieved 2014-01-25.
  85. ^ "Bug 1170510 - Implement NSS server side support for DH_anon". Mozilla. Retrieved 2015-06-03.
  86. ^ "Bug 236245 - Update ECC/TLS to conform to RFC 4492". Mozilla. Retrieved 2014-06-09.
  87. ^ "Changes between 0.9.6h and 0.9.7 [31 Dec 2002]". Retrieved 2016-01-29.
  88. ^ "Changes between 0.9.8n and 1.0.0 [29 Mar 2010]". Retrieved 2016-01-29.
  89. ^ "wolfSSL (Formerly CyaSSL) Release 3.9.0 (03/18/2016)". 2016-03-18. Retrieved 2016-04-05.
  90. ^
  91. ^
  92. ^
  93. ^
  94. ^
  95. ^ Laurie, B.; Langley, A.; Kasper, E. (June 2013). "Certificate Transparency". IETF. ISSN 2070-1721. Retrieved 2020-08-31.
  96. ^ "MatrixSSL 3.8.3". Archived from the original on 2017-01-19. Retrieved 2017-01-18.
  97. ^ "mbed TLS 2.0 defaults implement best practices". Retrieved 2017-01-18.
  98. ^ "Bug 672600 - Use DNSSEC/DANE chain stapled into TLS handshake in certificate chain validation". Mozilla. Retrieved 2014-06-18.
  99. ^ "CRL Validation · Issue #3499 · aws/s2n-tls". GitHub. Retrieved 2022-11-01.
  100. ^ "OCSP digest support for SHA-256 · Issue #2854 · aws/s2n-tls · GitHub". GitHub. Retrieved 2022-11-01.
  101. ^ "[RFC 6962] s2n Client can Validate Signed Certificate Timestamp TLS Extension · Issue #457 · aws/s2n-tls · GitHub". GitHub. Retrieved 2022-11-01.
  102. ^ "How Certificate Revocation Works". Microsoft TechNet. Microsoft. March 16, 2012. Retrieved July 10, 2013.
  103. ^ * *
  104. ^ RFC 6655, RFC 7251
  105. ^
  106. ^
  107. ^
  108. ^
  109. ^ "Sweet32: Birthday attacks on 64-bit block ciphers in TLS and OpenVPN". sweet32.info
  110. ^
  111. ^ "Version 1.11.12, 2015-01-02 — Botan". 2015-01-02. Retrieved 2015-01-09.
  112. ^ "gnutls 3.6.0". 2017-09-21. Retrieved 2018-01-07.
  113. ^ "gnutls 3.4.12". 2016-05-20. Archived from the original on 2016-10-13. Retrieved 2016-05-29.
  114. ^ "Java SE DevelopmentK Kit 10 - 10.0.1 Release Notes". 2018-04-17. Retrieved 2024-01-14.
  115. ^ "JDK 12 Release Notes". Retrieved 2024-01-14.
  116. ^ "Changes in 3.8.3". GitHub. Retrieved 2016-06-19.[dead link]
  117. ^ "PolarSSL 1.3.8 release notes". Archived from the original on 2014-07-14.
  118. ^ "Mbed TLS 2.11.0, 2.7.4 and 2.1.13 released". Retrieved 2018-08-30.
  119. ^ "Mbed TLS 2.12.0, 2.7.5 and 2.1.14 released". Retrieved 2018-08-30.
  120. ^ "NSS 3.25 release notes". Mozilla Developer Network. Mozilla. Archived from the original on 2021-12-07. Retrieved 2016-07-01.
  121. ^ "Bug 940119 - libssl does not support any TLS_ECDHE_*_CAMELLIA_*_GCM cipher suites". Mozilla. Retrieved 2013-11-19.
  122. ^ "NSS 3.12 is released". Retrieved 2013-11-19.
  123. ^ "NSS 3.12.3 Release Notes". Mozilla Developer Network. Mozilla. Archived from the original on 2023-04-02. Retrieved 2023-04-01.
  124. ^ "NSS 3.23 release notes". Mozilla Developer Network. Mozilla. Archived from the original on 2021-04-14. Retrieved 2016-03-09.
  125. ^ "openssl/CHANGES at OpenSSL_1_0_1-stable · openssl/openssl". GitHub. Retrieved 2015-01-20.
  126. ^ "OpenSSL 1.1.1 Series Release Notes". www.openssl.org. Archived from the original on 2024-01-16.
  127. ^ "Cipher Suites in TLS/SSL (Schannel SSP) - Win32 apps". docs.microsoft.com. 14 July 2023.
  128. ^ "Qualys SSL Labs - Projects / User Agent Capabilities: IE 11 / Win 10 Preview". dev.ssllabs.com. Archived from the original on 2023-07-14.
  129. ^ "Sweet32: Birthday attacks on 64-bit block ciphers in TLS and OpenVPN"
  130. ^ "Version 1.11.15, 2015-03-08 — Botan". 2015-03-08. Retrieved 2015-03-11.
  131. ^ "Java Cryptography Architecture Oracle Providers Documentation". docs.oracle.com
  132. ^ "NSS 3.15.3 release notes". Mozilla Developer Network. Mozilla. Archived from the original on 2014-06-05. Retrieved 2014-07-13.
  133. ^ "MFSA 2013-103: Miscellaneous Network Security Services (NSS) vulnerabilities". Mozilla. Retrieved 2014-07-13.
  134. ^ "RC4 is now disabled in Microsoft Edge and Internet Explorer 11 - Microsoft Edge Dev BlogMicrosoft Edge Dev Blog". blogs.windows.com. 2016-08-09.
  135. ^ "wolfSSL (Formerly CyaSSL) Release 3.7.0 (10/26/2015)". 2015-10-26. Retrieved 2015-11-19.
  136. ^ RFC 8446
  137. ^ RFC 8422
  138. ^ RFC 7027
  139. ^ "Version 1.11.5, 2013-11-10 — Botan". 2013-11-10. Retrieved 2015-01-23.
  140. ^ "An overview of the new features in GnuTLS 3.5.0". 2016-05-02. Retrieved 2016-12-09.
  141. ^ "gnutls 3.6.12". 2020-02-01. Retrieved 2021-08-31.
  142. ^ "JDK 13 Early-Access Release Notes". Archived from the original on 2020-04-01. Retrieved 2019-06-20.
  143. ^ "JEP 339: Edwards-Curve Digital Signature Algorithm (EdDSA)". Retrieved 2024-01-14.
  144. ^ "LibreSSL 2.5.1 release notes". OpenBSD. 2017-01-31. Retrieved 2017-02-23.
  145. ^ "MatrixSSL 4.0 changelog". GitHub. Retrieved 2018-09-18.
  146. ^ "PolarSSL 1.3.3 released". 2013-12-31. Archived from the original on 2014-01-07. Retrieved 2015-01-23.
  147. ^ "Mbed TLS 2.9.0, 2.7.3 and 2.1.12 released". Retrieved 2018-08-30.
  148. ^ "PolarSSL 1.3.1 released". 2013-10-15. Archived from the original on 2015-01-23. Retrieved 2015-01-23.
  149. ^ "Bug 957105 - Add support for curve25519 Key Exchange and UMAC MAC support for TLS". Mozilla. Retrieved 2017-02-23.
  150. ^ "Bug 1305243 - Support for X448". Mozilla. Retrieved 2022-08-04.
  151. ^ "Bug 1597057 - Curve448 or named Ed448-Goldilocks support needed (both X448 key exchange and Ed448 signature algorithm )". Mozilla. Retrieved 2022-08-04.
  152. ^ "Bug 943639 - Support for Brainpool ECC Curve (rfc5639)". Mozilla. Retrieved 2014-01-25.
  153. ^ "OpenSSL 1.1.0x Release Notes". 25 August 2016. Archived from the original on 18 May 2018. Retrieved 18 May 2018.
  154. ^ "OpenSSL GitHub Issue #487 Tracker". GitHub. 2 December 2015. Retrieved 18 May 2018.
  155. ^ "OpenSSL CHANGES". 1 May 2018. Archived from the original on 18 May 2018. Retrieved 18 May 2018.
  156. ^ "OpenSSL GitHub Issue #5049 Tracker". GitHub. 9 January 2018. Retrieved 18 May 2018.
  157. ^ "RusTLS Changelog". github.com. 12 September 2024. pp. 0.14.0. Retrieved 9 March 2026. When using aws-lc-rs as the crypto provider, NIST P-521 signatures are now supported.
  158. ^ "wolfSSL (Formerly CyaSSL) Release 3.4.6 (03/30/2015)". 2015-03-30. Retrieved 2015-11-19.
  159. ^ "wolfSSL Release 4.4.0 (04/22/2020)". 2020-04-22. Retrieved 2022-10-18.
  160. ^ Negotiation of arbitrary curves has been shown to be insecure for certain curve sizes Mavrogiannopoulos, Nikos and Vercautern, Frederik and Velichkov, Vesselin and Preneel, Bart (2012). A cross-protocol attack on the TLS protocol. Proceedings of the 2012 ACM conference on Computer and communications security. Association for Computing Machinery. pp. 62–72. doi:10.1145/2382196.2382206. ISBN 978-1-4503-1651-4.
  161. ^ "SHA2 and Windows". Retrieved 2024-12-25.
  162. ^ RFC 3749
  163. ^ RFC 5746
  164. ^ RFC 6066
  165. ^ RFC 7301
  166. ^ RFC 6091
  167. ^ RFC 4680
  168. ^
  169. ^
  170. ^
  171. ^ RFC 7627
  172. ^ RFC 7685
  173. ^ RFC 7250
  174. ^ "Version 1.11.16, 2015-03-29 — Botan". 2016-03-29. Retrieved 2016-09-08.
  175. ^ "Version 1.11.10, 2014-12-10 — Botan". 2014-12-10. Retrieved 2014-12-14.
  176. ^ "Version 1.11.26, 2016-01-04 — Botan". 2016-01-04. Retrieved 2016-02-25.
  177. ^ Present, but disabled by default due to lack of use by any implementation.
  178. ^ "gnutls 3.2.0". Archived from the original on 2016-01-31. Retrieved 2015-01-26.
  179. ^ Mavrogiannopoulos, Nikos (August 21, 2017). "[gnutls-help] GnuTLS 3.6.0 released"
  180. ^ "gnutls 3.4.4". Archived from the original on 2017-07-17. Retrieved 2015-08-25.
  181. ^ "%DUMBFW priority keyword". Retrieved 2017-04-30.
  182. ^ "gnutls 3.6.6". 2019-01-25. Retrieved 2019-09-01.
  183. ^ "LibreSSL 2.1.3 released". 2015-01-22. Retrieved 2015-01-22.
  184. ^ "LibreSSL 2.1.4 released". 2015-03-04. Retrieved 2015-03-04.
  185. ^ "MatrixSSL - News". 2014-12-04. Archived from the original on 2015-02-14. Retrieved 2015-01-26.
  186. ^ "Download overview - PolarSSL". 2014-04-11. Archived from the original on 2015-02-09. Retrieved 2015-01-26.
  187. ^ "mbed TLS 1.3.10 released". 2015-02-08. Archived from the original on 2015-02-09. Retrieved 2015-02-09.
  188. ^ "NSS 3.15.5 release notes". Mozilla Developer Network. Mozilla. Archived from the original on January 26, 2015. Retrieved 2015-01-26.
  189. ^ "Bug 961416 - Support RFC6091 - Using OpenPGP Keys for Transport Layer Security Authentication (TLS1.2)". Mozilla. Retrieved 2014-06-18.
  190. ^ "Bug 972145 - Implement the encrypt-then-MAC TLS extension". Mozilla. Retrieved 2014-11-06.
  191. ^ "NSS 3.17.1 release notes". Archived from the original on 2019-04-19. Retrieved 2014-10-17.
  192. ^ "NSS 3.21 release notes". Archived from the original on 2021-12-07. Retrieved 2015-11-14.
  193. ^ "OpenSSL Security Advisory [15 Oct 2014]". 2014-10-15.
  194. ^ "Major changes between OpenSSL 1.0.1f and OpenSSL 1.0.1g [7 Apr 2014]". 2014-04-07. Archived from the original on 2015-01-20. Retrieved 2015-02-10.
  195. ^ "OpenSSL Announces Final Release of OpenSSL 3.2.0". 2023-11-23. Retrieved 2024-10-11.
  196. ^ rustls does not implement earlier versions that would warrant protection against insecure downgrade
  197. ^ "Microsoft Security Bulletin MS15-121". March 2023. Retrieved 2024-04-28.
  198. ^ "What's New in TLS/SSL (Schannel SSP)". 31 August 2016. Retrieved 2024-04-28.
  199. ^ "wolfSSL Version 4.2.0 is Now Available!". 22 October 2019. Retrieved 2021-08-13.
  200. ^ "wolfSSL supports Raw Public Keys". August 2023. Retrieved 2024-10-25.
  201. ^ "Version 1.11.31, 2015-08-30 — Botan". 2016-08-30. Retrieved 2016-09-08.
  202. ^ "Trusted Platform Module (TPM) — Botan"
  203. ^ "Comparison of BSAFE TLS libraries: Micro Edition Suite vs SSL-J | Dell Malaysia"
  204. ^ Mavrogiannopoulos, Nikos (October 9, 2016). "[gnutls-devel] gnutls 3.5.5"
  205. ^ "Trusted Platform Module (GnuTLS 3.8.4)"
  206. ^ "Java SSL provider with AES-NI support". stackoverflow.com
  207. ^ "PolarSSL 1.3.3 released". 2013-12-31. Archived from the original on 2014-01-07. Retrieved 2014-01-07. We've incorporated support for AES-NI in our AES and GCM modules.
  208. ^ "NXP/Plug-and-trust". GitHub
  209. ^ "ARMmbed/Mbed-os-atecc608a". GitHub
  210. ^ Normally NSS's libssl performs all operations via the PKCS#11 interface, either to hardware or software tokens
  211. ^ "Bug 706024 - AES-NI enhancements to NSS on Sandy Bridge systems". Retrieved 2013-09-28.
  212. ^ "Bug 479744 - RFE : VIA Padlock ACE support (hardware RNG, AES, SHA1 and SHA256)". Retrieved 2014-04-11.
  213. ^ "Подключаем Рутокен ЭЦП к OpenSSL" (in Russian). 16 December 2011.
  214. ^ "Поддержка Рутокен ЭЦП в OpenSSL (Страница 1) — Рутокен и Open Source — Форум Рутокен" (in Russian)
  215. ^ "OpenSSL ГОСТ" (in Russian). Archived from the original on 2018-06-23.
  216. ^ "git.openssl.org Git - openssl.git/commitdiff". git.openssl.org
  217. ^ "Tpm2-software/Tpm2-openssl". GitHub
  218. ^ "Provider - OpenSSL Documentation"
  219. ^ "STSW-STSA110-SSL - STSAFE-A integration within OpenSSL security stack". STMicroelectronics
  220. ^
  221. ^ "Crypto Officer Role Guide for FIPS 140-2 Compliance OS X Mountain Lion v10.8". Apple Inc. 2013.
  222. ^ "CAAM support in wolfSSL". 10 March 2020.
  223. ^ "wolfTPM Portable TPM 2.0 Library"
  224. ^ "Announcing wolfSSL TPM support for the Espressif ESP32". 20 June 2024.
  225. ^ "WolfSSL SSL/TLS Support for NXP SE050 – wolfSSL". 22 February 2024.
  226. ^ "WolfSSL support for the ATECC608 Crypto Coprocessor – wolfSSL". 13 October 2021.
  227. ^ "WolfSSL support for STSAFE-A100 crypto coprocessor – wolfSSL". 20 September 2018.
  228. ^ "Support for MAXQ1065 in wolfSSL – wolfSSL". 29 November 2022.
  229. ^ "LibreSSL 2.2.1 Released". 2015-07-08. Retrieved 2016-01-30.
  230. ^ "ktls integration for rustls". GitHub. Retrieved 2024-08-29.
  231. ^ "wolfProvider". 2021-11-10. Retrieved 2022-01-17.
  232. ^ "The PKCS #11 URI Scheme"
  233. ^ "libp11: PKCS#11 wrapper library". 19 January 2018. – via GitHub.
  234. ^ "Windows CNG bridge for rustls". GitHub. Retrieved 2024-08-29.
  235. ^ On the fly replaceable/augmentable.
  236. ^ "Nss compat ossl - Fedora Project Wiki". fedoraproject.org
  237. ^ "Struct CryptoProvider". docs.rs/rustls. Retrieved 9 March 2026.
  238. ^ "rustls". crates.io. 24 February 2026. Retrieved 10 March 2026.
  239. ^ "rustls-openssl compatibility layer". GitHub. Retrieved 2024-08-29.
  240. ^ "NSPR". Mozilla Developer Network
  241. ^ For Unix/Linux it uses /dev/urandom if available, for Windows it uses CAPI. For other platforms it gets data from clock, and tries to open system files. NSS has a set of platform dependent functions it uses to determine randomness.
  242. ^ "Release Note: Weak Named Curves in TLS, CertPath, and Signed JAR Disabled by Default". JDK Bug System (JBS). Retrieved 25 December 2024.
  243. ^ "Release Note: Removal of Legacy Elliptic Curves". JDK Bug System (JBS). Retrieved 25 December 2024.
  244. ^ "JEP 164: Leverage CPU Instructions for AES Cryptography". openjdk.org
  245. ^ "RSA SecurID PASSCODE Request". sso.rsasecurity.com
  246. ^ RFC 5469
  1. ^ This algorithm is not defined yet as TLS cipher suites in RFCs, is proposed in drafts.
  2. ^ authentication only, no encryption
  3. ^ This algorithm is implemented in an NSS fork used by Pale Moon.
  4. ^ removal_from_tls1.2
  5. ^ 40 bits strength of cipher suites were designed to operate at reduced key lengths in order to comply with US regulations about the export of cryptographic software containing certain strong encryption algorithms (see Export of cryptography from the United States). These weak suites are forbidden in TLS 1.1 and later.
  6. ^ The RC4 attacks weaken or break RC4 used in SSL/TLS. Use of RC4 is prohibited by RFC 7465.
  7. ^ The RC4 attacks weaken or break RC4 used in SSL/TLS.