OpenSSL 3.0 End of Life
The OpenSSL 3.0 series has reached its End of Life (EOL). As such it will no longer receive publicly available security fixes.
OpenSSL 3.0 was released on 7 September 2021 as a long term support (LTS) release. Per the library’s release strategy, LTS releases receive 5 years of public support. OpenSSL 3.0 has reached its EOL as of 7 September 2026.
If you are still using OpenSSL 3.0 then it is time to upgrade to a more recent version. Our most recent version is OpenSSL 4.0 which will be supported until 14 May 2027. Also available is OpenSSL 3.5 which is a long term support (LTS) release and will be supported until 8 April 2030.
If your deployment relies on the OpenSSL FIPS Provider on 3.0, note that the remaining FIPS 140-2 certificates move to the CMVP Historical List on 21 September 2026. For more details, see the OpenSSL Corporation blog.
Another option is to purchase a support contract which offers extended support (i.e. ongoing access to security fixes) for releases beyond their public EOL date. There is no defined end date for this extended support and we intend to continue to provide it for as long as it remains commercially viable for us to do so (i.e. for the foreseeable future). Further information is available on our support contracts page.