Skip to content

Post-quantum cryptography

openssl

Maintained by open-quantum-safe

The Open Quantum Safe OpenSSL fork lets teams experiment with hybrid TLS and post-quantum ciphers in familiar OpenSSL workflows.

CBSD-3-ClauseArchive
openssl illustration

Resource snapshot

Category

Post-quantum cryptography

Stars

307

Last pushed

Jan 5, 2026Updated 8mo ago

Open issues

0

What it is

This fork extends OpenSSL with liboqs-backed algorithms so engineers can pilot hybrid key exchange and signing without replacing their entire crypto stack overnight.

Inventory still comes first: know which endpoints depend on legacy RSA/ECDSA before swapping ciphers — Qtangl Assess produces that baseline with CBOM export.

Who it's for

Platform engineers and security architects piloting hybrid TLS or evaluating OpenSSL-based PQC deployment paths.

What you can build or learn

  • Prototype hybrid TLS handshakes with ML-KEM alongside legacy algorithms.
  • Compare OQS OpenSSL behavior against production inventory from /assess.
  • Cross-reference deployment plans with framework guides at /q-day/frameworks/ml-kem and /q-day/frameworks/cmmc.

License

BSD-3-Clause

SPDX identifier detected from the repository metadata or license files.

Q-Day readiness

Open-source PQC libraries support the technical migration. Qtangl supports the operational workflow — inventory, CBOM export, and framework-mapped evidence.

Repository README

Preview from the project README.

Rendered as Markdown inside a scrollable preview. Long READMEs stay contained; expand or open on GitHub for the full document.

~433 words · about 2 min readOpen on GitHub

OpenSSL 1.1.1u 30 May 2023

Copyright (c) 1998-2023 The OpenSSL Project Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson All rights reserved.

DESCRIPTION

The OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, fully featured, and Open Source toolkit implementing the Transport Layer Security (TLS) protocols (including SSLv3) as well as a full-strength general purpose cryptographic library.

OpenSSL is descended from the SSLeay library developed by Eric A. Young and Tim J. Hudson. The OpenSSL toolkit is licensed under a dual-license (the OpenSSL license plus the SSLeay license), which means that you are free to get and use it for commercial and non-commercial purposes as long as you fulfill the conditions of both licenses.

OVERVIEW

The OpenSSL toolkit includes:

libssl (with platform specific naming): Provides the client and server-side implementations for SSLv3 and TLS.

libcrypto (with platform specific naming): Provides general cryptographic and X.509 support needed by SSL/TLS but not logically part of it.

openssl: A command line tool that can be used for: Creation of key parameters Creation of X.509 certificates, CSRs and CRLs Calculation of message digests Encryption and decryption SSL/TLS client and server tests Handling of S/MIME signed or encrypted mail And more...

INSTALLATION

See the appropriate file: INSTALL Linux, Unix, Windows, OpenVMS, ... NOTES.* INSTALL addendums for different platforms

SUPPORT

See the OpenSSL website www.openssl.org for details on how to obtain commercial technical support. Free community support is available through the openssl-users email list (see https://www.openssl.org/community/mailinglists.html for further details).

If you have any problems with OpenSSL then please take the following steps first:

- Download the latest version from the repository
  to see if the problem has already been addressed
- Configure with no-asm
- Remove compiler optimization flags

If you wish to report a bug then please include the following information and create an issue on GitHub:

- OpenSSL version: output of 'openssl version -a'
- Configuration data: output of 'perl configdata.pm --dump'
- OS Name, Version, Hardware platform
- Compiler Details (name, version)
- Application Details (name, version)
- Problem Description (steps that will reproduce the problem, if known)
- Stack Traceback (if the application dumps core)

Just because something doesn't work the way you expect does not mean it is necessarily a bug in OpenSSL. Use the openssl-users email list for this type of query.

HOW TO CONTRIBUTE TO OpenSSL

See CONTRIBUTING

LEGALITIES

A number of nations restrict the use or export of cryptography. If you are potentially subject to such restrictions you should seek competent professional legal advice before attempting to develop or distribute cryptographic code.

Read on GitHub

Activity

Latest release

—

Watchers

27

Python support

—

Learn digest

Get monthly updates when library entries change.

Monthly digest: new library entries, updated flagships, and one editorial pick.

Related resources

Keep exploring nearby tools.

open-quantum-safe

liboqs

C library for prototyping and experimenting with quantum-resistant cryptography

CMITFlagship

2,946 stars · Updated 3mo ago

open-quantum-safe

openssh-portable

Fork of OpenSSH that includes prototype quantum-resistant key exchange and authentication in SSH based on liboqs.

CBSD-3-Clause

232 stars · Updated 5mo ago

PQClean

PQClean

Clean, portable, tested implementations of post-quantum cryptography

C

923 stars · Updated 3mo ago

QISKit

qiskit

Qiskit is an open-source SDK for working with quantum computers at the level of extended quantum circuits, operators, and primitives.

PythonApache-2.0FlagshipQtangl relevant

7,412 stars · Updated 3mo ago

theQRL

QRL

Quantum Resistant Ledger

PythonMIT

463 stars · Updated 6mo ago

Microsoft

QuantumKatas

Tutorials and programming exercises for learning Q# and quantum computing

Jupyter NotebookMITFlagshipArchive

4,862 stars · Updated 2y ago