OpenSSL
The cryptography and TLS library most of the internet depends on.
What it is
OpenSSL is a robust, full-featured open-source toolkit implementing the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols. It provides cryptographic functions such as encryption, decryption, hashing, key generation, and certificate management.
OpenSSL provides APIs for symmetric and asymmetric encryption, digital signatures, hashing, SSL/TLS communication, and certificate handling. It supports a wide range of cryptographic algorithms including AES, RSA, ECC, SHA, and HMAC.
- Licence
- Apache 2.0 (3.x)
- Watch for
- The 1.1.1 and 3.x APIs differ; check which version an example targets
When to use it
The question documentation cannot answer for you — because it cannot recommend something else.
Reach for it when
- You need TLS, certificate handling or cryptographic primitives in C or C++
- Platform and protocol coverage matters more than API friendliness
Look elsewhere when
- You are implementing your own cryptographic protocol — use a higher-level library and avoid the footguns
- You want a pleasant API; libsodium is dramatically easier to use safely
Installation
sudo apt install libssl-devGetting started
The smallest useful thing you can do with it, and what each part means.
#include <openssl/rsa.h>
#include <openssl/pem.h>
int main() {
RSA *rsa = RSA_generate_key(2048, RSA_F4, NULL, NULL);
FILE *fp = fopen("private.pem", "wb");
PEM_write_RSAPrivateKey(fp, rsa, NULL, NULL, 0, NULL, NULL);
fclose(fp);
RSA_free(rsa);
return 0;
}#include <openssl/sha.h>
#include <stdio.h>
#include <string.h>
int main() {
unsigned char digest[SHA256_DIGEST_LENGTH];
char str[] = "Hello, OpenSSL!";
SHA256((unsigned char*)str, strlen(str), digest);
for(int i = 0; i < SHA256_DIGEST_LENGTH; i++)
printf("%02x", digest[i]);
printf("\n");
return 0;
}Advanced usage
Where the library earns its place over a simpler alternative.
#include <openssl/evp.h>
#include <string.h>
#include <stdio.h>
int main() {
unsigned char key[32] = "01234567890123456789012345678901";
unsigned char iv[16] = "0123456789012345";
unsigned char plaintext[] = "Hello, OpenSSL AES!";
unsigned char ciphertext[128];
int len, ciphertext_len;
EVP_CIPHER_CTX *ctx = EVP_CIPHER_CTX_new();
EVP_EncryptInit_ex(ctx, EVP_aes_256_cbc(), NULL, key, iv);
EVP_EncryptUpdate(ctx, ciphertext, &len, plaintext, strlen((char*)plaintext));
ciphertext_len = len;
EVP_EncryptFinal_ex(ctx, ciphertext + len, &len);
ciphertext_len += len;
EVP_CIPHER_CTX_free(ctx);
printf("Encrypted text length: %d\n", ciphertext_len);
return 0;
}#include <openssl/rsa.h>
#include <openssl/pem.h>
#include <openssl/err.h>
#include <openssl/sha.h>
int main() {
// Load private key
FILE *fp = fopen("private.pem", "r");
RSA *rsa = PEM_read_RSAPrivateKey(fp, NULL, NULL, NULL);
fclose(fp);
unsigned char msg[] = "Hello";
unsigned char sig[256];
unsigned int sig_len;
SHA256(msg, strlen((char*)msg), sig);
RSA_sign(NID_sha256, sig, SHA256_DIGEST_LENGTH, sig, &sig_len, rsa);
RSA_free(rsa);
printf("Signature length: %u\n", sig_len);
return 0;
}#include <openssl/ssl.h>
#include <openssl/err.h>
int main() {
SSL_library_init();
SSL_CTX *ctx = SSL_CTX_new(TLS_client_method());
SSL *ssl = SSL_new(ctx);
// connect socket code omitted for brevity
SSL_connect(ssl);
SSL_shutdown(ssl);
SSL_free(ssl);
SSL_CTX_free(ctx);
return 0;
}Errors and fixes
The failures you are most likely to hit, and what actually resolves them.
- NULL pointer or allocation failure
- Check function return values and handle memory allocation errors.
- SSL handshake failure
- Verify certificates, protocols, and cipher suites are compatible.
- Digest or signature function fails
- Ensure correct key size, padding, and hash algorithm usage.
Best practices
- Always check return values for errors to ensure cryptographic operations succeed.
- Use updated and recommended algorithms (e.g., AES, SHA-256, RSA-2048+).
- Securely store private keys and sensitive data in memory or protected files.
- Use random number generators from OpenSSL for key generation.
- Keep OpenSSL library updated to patch security vulnerabilities.
Alternatives
Comparable options, and the reason you would pick one over the other.
libsodium
Modern, opinionated crypto with an API designed to be hard to misuse
mbedTLS
Small footprint TLS for embedded targets
Background
Why it exists, and what it was reacting to.
OpenSSL was originally developed in 1998 and has become the de facto standard library for implementing secure communications in C/C++ applications. It is widely used in web servers, email servers, VPNs, and many security-sensitive software systems for encryption and certificate management.
