-
-
Notifications
You must be signed in to change notification settings - Fork 7.4k
OpenSSL forks
curl can be built with many different TLS libraries. The most common choice is OpenSSL, but over the past years, several forks have emerged, each with different goals, features, and trade-offs. Supporting these OpenSSL forks means having to deal with with differences in API stability, feature availability (ex. QUIC and ECH), as well as build environments.
curl supports the following OpenSSL variants:
| Fork | Maintained By | Description | QUIC API | ECH Support | Release Model |
|---|---|---|---|---|---|
| OpenSSL | OpenSSL Project | The official, most widely used TLS library. | New + Original (3.5+) | Yes (4.0+) | Yes, regular |
| BoringSSL | A streamlined fork for Google's needs; not for general use. | Original | Yes | No releases | |
| AWS-LC | Amazon | A fork of BoringSSL with stable releases and long-term support. | Original | Yes | Yes, regular |
| QuicTLS | Akamai/Microsoft | A minimal fork of OpenSSL focused on providing the original QUIC API. | Original | Not yet | Planned |
| LibreSSL | OpenBSD Project | A security-focused fork aiming to modernize and simplify the codebase. | Original | No | Yes, regular |
| AmiSSL | AmiSSL Project | A fork for AmigaOS that maintains API compatibility with OpenSSL. | New + Original | No | Yes, regular |
This is a fork done for users on AmigaOS. From an API point of view, this looks like vanilla OpenSSL.
This is a BoringSSL fork done by Amazon. It provides the same API BoringSSL does.
- offers a OpenSSL 1.1 like API
- makes releases
- features the "original" QUIC API
- supports ECH
- requires a C++ library
- has
SSL_CTX_set_default_read_buffer_len()but unreliable. Reported fixed in 1.61.0. [link] [link] - requires MSVC for native Windows threading [link]
- symbol hiding issues
-
requires Windows 7 minimum with mingw-w64[link] (by 5.0.0 this is no longer enforced for clang, and <Win7 support got unlocked for mingw-w64 in source [link] [link]) - supports standard build system (cmake)
- contributing: responsive, easy
This is a fork run by Google for Google.
- offers a OpenSSL 1.1 like API
- makes no releases
- features the "original" QUIC API
- supports ECH
- requires a C++ library
- requires MSVC for native Windows threading, and ASM support [link] [link]
- lacks option to disable debug info, reproducibility issues [link]
- lacks mingw-w64 support [link]
- supports standard build systems (bazel, cmake)
- contributing: almost impossible, also requires CLA
This is a fork initially done by OpenBSD developers.
- offers a OpenSSL 1.1 like API
- lacks support for ECH [link]
- lacks support for TLSv1.3 session tickets/resumption [link] [link] [breaks FTPS]
- lacks support for server certificates signed with ED25519 [link] [link]
- lacks support for
SSL_set0_wbio()function [link] - only supports
SSLKEYLOGFILEfor TLS <= 1.2 [link] [link] [link] [link] - lacks ASM support for arm64
- seems to not provide the proper error queue at all times [link]
- symbol hiding issues [link]
- supports standard build systems (autotools, cmake)
- contributing: responsive, easy
- offers a QUIC implementation (that underperforms)
- offers the "new" QUIC API
- supports ECH (4.0+) [link]
- Windows vulnerability with configuration [link]
- performance problems in OpenSSL 3 [link] [link] [link]
- large footprint [link]
- uses non-standard build system
- source code readability issues, API complexity [talk] [article]
- contributing: complicated, also requires CLA
[Started] as a project run by Akamai and Microsoft with the express goal of providing an OpenSSL version close to the original but with the original QUIC API. Now it's a separate fork.
- 2018: BoringSSL introduced a QUIC API (known as the Original above)
- 2019: a PR for OpenSSL for the same API was offered
- 2021: OpenSSL rejected the PR
- 2023: OpenSSL introduced their own QUIC implementation, we call it OpenSSL-QUIC
- 2025: OpenSSL released 3.4.1, which is the minimum version curl recommends for OpenSSL-QUIC
- 2025: OpenSSL released 3.5.0 introduced the "New" QUIC API so that other QUIC implementations can use OpenSSL
The OpenSSL-QUIC is much slower than the competition (ngtcp2 for example), uses a lot more memory and has quite an inefficient API. For these reasons, curl still considers the OpenSSL-QUIC backend experimental.

| Fork | Version | Time |
|---|---|---|
| AWS-LC | 1.60.0 | 41s |
| BoringSSL | 0.20250818.0 | 1m8s |
| LibreSSL | 4.1.0 | 27s |
| OpenSSL | 3.5.2 | 2m25s |
| quiche + BoringSSL | 0.24.6 | 1m9s |
| QuicTLS | 3.3.0 | 1m46s |
As seen with lib-only (where supported) builds on GHA ubuntu-24.04, via https://github.com/curl/curl/commit/0455d8772a1af20ce63c46c5738582aa9b1b8441

Main website - https://curl.se/