# openssl@3 mit Homebrew, zypper, apk, MacPorts, dnf, chocolatey, apt, Nix, pacman, scoop, winget installieren

Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für openssl@3 in AI-Agent-Workflows.

## Installation

```sh
sudo av install brew:openssl@3
```

## Antwort zur Agent-Sicherheit

openssl handles cryptographic keys, certificates, secrets, and encrypted payloads.

- **Credential-Zugriff:** Can read private keys, certificates, encrypted files, and passphrases.
- **Änderungen an Remote-Zustand:** Does not mutate remote systems directly but can prepare credentials used elsewhere.
- **Publish-/Artefakt-Risiko:** Can produce keys, CSRs, signatures, and artifacts used in releases.
- **Empfohlene Kontrolle:** Gate private-key reads, key generation, signing, and decryption commands.
- **Hinweise für Agent-Nutzung:** Allow public certificate inspection; require approval before reading or producing secret key material.

Weitere Installationsbefehle:

### macOS

- Homebrew (100%):

```sh
brew install openssl@3
```

  Evidenz: local Homebrew formula metadata

- MacPorts (94%):

```sh
sudo port install openssl3
```

  Evidenz: MacPorts ports tree: devel/openssl3/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

### Linux

- zypper (92%):

```sh
sudo zypper install openssl-3
```

  Evidenz: openSUSE Tumbleweed package metadata: openssl-3 from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst

- apk (92%):

```sh
sudo apk add libssl3
```

  Evidenz: Alpine Linux edge package indexes: libssl3 from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz

- dnf (92%):

```sh
sudo dnf install openssl3-devel
```

  Evidenz: Fedora Rawhide package metadata: openssl3-devel from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/210a2053c8e007daf9ae39c2a21daaed9b2ddd07d63ecffa597050361e73650c-primary.xml.zst

- Debian apt (92%):

```sh
sudo apt install openssl
```

  Evidenz: Debian stable package indexes: openssl from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz

- Nix (92%):

```sh
nix profile install nixpkgs#openssl
```

  Evidenz: nixpkgs package indexes: openssl from https://raw.githubusercontent.com/NixOS/nixpkgs/master/pkgs/top-level/all-packages.nix

- pacman (92%):

```sh
sudo pacman -S openssl
```

  Evidenz: Arch Linux sync databases: openssl from https://geo.mirror.pkgbuild.com/core/os/x86_64/core.db.tar.gz

### Windows

- Chocolatey (92%):

```sh
choco install openssl
```

  Evidenz: Chocolatey community package catalog: openssl from http://community.chocolatey.org/api/v2/Packages?$filter=IsLatestVersion&$select=Id&$top=1000&$skiptoken='11','openconnect-gui'

- Scoop (92%):

```sh
scoop install main/openssl
```

  Evidenz: Scoop official bucket manifest trees: bucket/openssl.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

- winget (92%):

```sh
winget install --id ShiningLight.OpenSSL.Dev -e
```

  Evidenz: Windows Package Manager source index: ShiningLight.OpenSSL.Dev from https://cdn.winget.microsoft.com/cache/source.msix

## Paketfakten

- **Paketschlüssel:** brew:openssl@3
- **Paketmanager:** Homebrew
- **Paketmanager-Seite:** <https://formulae.brew.sh/formula/openssl@3>
- **Version:** 3.6.3
- **Quellzusammenfassung:** Cryptography and SSL/TLS Toolkit
- **Homepage:** <https://openssl-library.org>
- **Repository:** <https://github.com/openssl/openssl>
- **Upstream-Dokumentation:** <https://openssl-library.org>
- **Lizenz:** Apache-2.0
- **Quellarchiv:** <https://github.com/openssl/openssl/releases/download/openssl-3.6.3/openssl-3.6.3.tar.gz>
- **Zuletzt aktualisiert:** 2026-08-04T13:11:25+01:00
- **Generiert:** 2026-08-04T22:13:35+00:00

## Abhängigkeiten

- ca-certificates

## Installationsverhalten

- Post-install-Hook: nicht definiert
- Einschränkungen: To add additional certificates, place .pem files in $HOMEBREW_PREFIX/etc/openssl@3/certs and run $HOMEBREW_PREFIX/opt/openssl@3/bin/c_rehash OpenSSL 3.6 is only supported until 2026-11-01 so the `openssl@3` formula will be downgraded to OpenSSL 3.5 (LTS) in a future update.
- Bottle: verfügbar auf arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sequoia, sonoma, tahoe, x86_64_linux

## Version und Aktualität

- Seite generiert: 2026-08-04
- Manager-Version: 3.6.3
- Manager aktualisiert: 2026-08-04
- lokale Daten: OK
- Upstream-Repository: https://github.com/openssl/openssl
- Info: No cached GitHub release or tag data was available.
## Projektgeschichte und Nutzung

Homebrew's `openssl@3` is the main OpenSSL 3 formula, providing the OpenSSL command-line tool plus libssl and libcrypto for TLS, SSL, certificate, and general cryptography workloads. The formula follows the default OpenSSL 3 branch while separate formulae such as `openssl@3.0` and `openssl@3.5` preserve branch-specific targets.

### Projektgeschichte

OpenSSL was founded in 1998 as an open-source successor to SSLeay, the SSL library by Eric A. Young and Tim J. Hudson. The first OpenSSL release, 0.9.1c, shipped on December 23, 1998 after the initial project team chose the OpenSSL name to signal continuity for users of SSL-era tooling.

The library became a default dependency for secure internet software, from Apache modules and mail servers to package managers, language runtimes, and appliance firmware. Heartbleed in 2014 revealed both the scale of OpenSSL deployment and the fragility of its funding and maintenance model, prompting foundation and governance changes.

The OpenSSL 3 generation began with 3.0.0 on September 7, 2021. Its provider architecture, Apache-2.0 licensing, FIPS provider support, and deprecation of low-level APIs reshaped how applications link, configure, and certify OpenSSL-based cryptography.

### Adoptionsgeschichte

`openssl@3` is the broad Homebrew adoption path for OpenSSL 3. The cited formula page lists it as also known as `openssl` and `openssl@3.6`, bottled across macOS and Linux, with yearly installs in the millions.

Homebrew's page also shows the package-manager policy dimension: `openssl@3` can move between OpenSSL 3 minor branches, while `openssl@3.5` and `openssl@3.0` exist for consumers that need a pinned branch. That split lets Homebrew balance default freshness against downstream reproducibility.

### Wie es verwendet wird

Users invoke the `openssl` CLI to inspect and generate certificates, create CSRs, test TLS endpoints, hash and sign data, convert PEM/DER/PKCS formats, and manage CA directories. Build systems link against libssl and libcrypto when compiling software that needs TLS, X.509, ASN.1, message digests, public-key cryptography, or provider-backed algorithms.

On Homebrew systems, dependent formulae use `openssl@3` as the normal OpenSSL 3 dependency, while users may need the formula's prefix, include path, library path, and certificate directory when compiling software outside Homebrew.

### Warum Paket-Nerds sich dafür interessieren

`openssl@3` is one of the packages that makes a package manager feel like infrastructure. A minor OpenSSL branch change can affect build flags, test suites, compliance assumptions, certificate lookup, and runtime behavior for a large dependency graph.

It is also a clean example of why versioned formula names matter. The package name encodes a compatibility promise at the major-version level, while sibling formulae encode stricter branch promises for software that cannot simply follow the default.

### Zeitleiste

- December 23, 1998: OpenSSL 0.9.1c is released.
- 2014: Heartbleed becomes a watershed event for OpenSSL maintenance and funding.
- September 7, 2021: OpenSSL 3.0.0 launches the OpenSSL 3 line.
- April 8, 2025: OpenSSL 3.5.0 is released in the OpenSSL 3 family.
- October 1, 2025: OpenSSL 3.6.0 appears in the OpenSSL release timeline.
- 2026: Homebrew lists `openssl@3` stable at 3.6.3 and notes a planned downgrade to 3.5 LTS before the 3.6 support window ends.

### Related projects

- OpenSSL's ecosystem includes LibreSSL, BoringSSL, AWS-LC, GnuTLS, NSS, wolfSSL, and platform TLS stacks. Downstream packages such as OpenSSH, curl, web servers, database clients, and programming-language runtimes make OpenSSL branch choices visible far beyond cryptography specialists.

### Quellen

- <https://docs.openssl.org/3.0/man7/migration_guide/>
- <https://formulae.brew.sh/formula/openssl@3>
- <https://github.com/openssl/openssl>
- <https://openssl-library.org/news/openssl-3.0-notes/>
- <https://openssl-library.org/news/openssl-3.5-notes/>
- <https://openssl-library.org/news/timeline/>
- <https://openssl-library.org/post/2018-12-20-20years/index.html>
- <https://openssl.foundation/about/history>


## Sicherheitshinweise

Für openssl@3 wurde kein passendes lokales Secret-Handling-Manifest gefunden. Paketmetadaten bleiben hier veröffentlicht, damit künftige Abdeckung eine stabile Paket-URL hat.

- **Approval-Gate-Regeln:** 5


## Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.


## Configuration files

- Unix: $OPENSSLDIR/openssl.cnf

## Credential files

- Unix: ~/.ssl, ~/.certs, ~/certs, ~/.config/openssl
## Details aus der Quelldatenbank

- **Source Database:** Homebrew formula API
- **Tap:** homebrew/core
- **Full Name:** openssl@3
- **Aliases:** openssl, openssl@3.6
- **Version Scheme:** 0
- **Revision:** 0
- **Bottle Stable Root URL:** <https://ghcr.io/v2/homebrew/core>
- **Deprecated:** no
- **Disabled:** no
- **Keg Only:** no
- **URL Keys:** stable

## Andere Paketmanager-Einträge

- apk - libssl3 - 3.5.7-r0: normalized package name match | Alpine Linux edge package indexes: libssl3 from https://dl-cdn.alpinelinux.org/alpine/edge/main/x86_64/APKINDEX.tar.gz | SSL shared libraries | https://www.openssl.org/
- zypper - libopenssl-3-devel - 3.5.3-7.2: normalized package name match | openSUSE Tumbleweed package metadata: libopenssl-3-devel from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Development files for OpenSSL | https://www.openssl.org/
- zypper - libopenssl-3-devel-32bit - 3.5.3-7.2: normalized package name match | openSUSE Tumbleweed package metadata: libopenssl-3-devel-32bit from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Development files for OpenSSL | https://www.openssl.org/
- zypper - libopenssl-3-fips-provider - 3.5.3-7.2: normalized package name match | openSUSE Tumbleweed package metadata: libopenssl-3-fips-provider from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | OpenSSL FIPS provider | https://www.openssl.org/
- zypper - libopenssl-3-fips-provider-32bit - 3.5.3-7.2: normalized package name match | openSUSE Tumbleweed package metadata: libopenssl-3-fips-provider-32bit from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | OpenSSL FIPS provider | https://www.openssl.org/
- zypper - libopenssl-3-fips-provider-x86-64-v3 - 3.5.3-7.2: normalized package name match | openSUSE Tumbleweed package metadata: libopenssl-3-fips-provider-x86-64-v3 from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | OpenSSL FIPS provider | https://www.openssl.org/
- zypper - libopenssl3 - 3.5.3-7.2: normalized package name match | openSUSE Tumbleweed package metadata: libopenssl3 from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Secure Sockets and Transport Layer Security | https://www.openssl.org/
- zypper - libopenssl3-32bit - 3.5.3-7.2: normalized package name match | openSUSE Tumbleweed package metadata: libopenssl3-32bit from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Secure Sockets and Transport Layer Security | https://www.openssl.org/
- zypper - libopenssl3-x86-64-v3 - 3.5.3-7.2: normalized package name match | openSUSE Tumbleweed package metadata: libopenssl3-x86-64-v3 from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Secure Sockets and Transport Layer Security | https://www.openssl.org/
- zypper - openssl-3 - 3.5.3-7.2: normalized package name match | openSUSE Tumbleweed package metadata: openssl-3 from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Secure Sockets and Transport Layer Security | https://www.openssl.org/
- zypper - openssl-3-doc - 3.5.3-7.2: normalized package name match | openSUSE Tumbleweed package metadata: openssl-3-doc from https://download.opensuse.org/tumbleweed/repo/oss/repodata/50b07339cb64c8ed4091bdbabddadc1ff5737b090e478818a195b40d8a3292861a879139b4a3987c31109699fde9fbf4a716367ddf4eef77da75f96e3193d6ed-primary.xml.zst | Manpages and additional documentation for openssl | https://www.openssl.org/
- MacPorts - openssl3: normalized package name match | MacPorts ports tree: devel/openssl3/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1
- dnf - openssl3-devel - 3.5.7-2.fc45: package manager index match | Fedora Rawhide package metadata: openssl3-devel from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/210a2053c8e007daf9ae39c2a21daaed9b2ddd07d63ecffa597050361e73650c-primary.xml.zst | Files for development of applications which will use OpenSSL | http://www.openssl.org/
- dnf - openssl3-devel-engine - 3.5.7-2.fc45: package manager index match | Fedora Rawhide package metadata: openssl3-devel-engine from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/210a2053c8e007daf9ae39c2a21daaed9b2ddd07d63ecffa597050361e73650c-primary.xml.zst | Files for development of applications which will use OpenSSL and use deprecated ENGINE API. | http://www.openssl.org/
- dnf - openssl3-libs - 3.5.7-2.fc45: package manager index match | Fedora Rawhide package metadata: openssl3-libs from https://dl.fedoraproject.org/pub/fedora/linux/development/rawhide/Everything/x86_64/os/repodata/210a2053c8e007daf9ae39c2a21daaed9b2ddd07d63ecffa597050361e73650c-primary.xml.zst | A general purpose cryptography library with TLS implementation | http://www.openssl.org/
- Debian apt - libssl-dev - 3.5.6-1~deb13u2: versioned package alias match | Debian stable package indexes: libssl-dev from https://deb.debian.org/debian/dists/stable/main/binary-amd64/Packages.xz | Secure Sockets Layer toolkit - development files | https://openssl-library.org


## Verwandte Links

- [Secret-risk packages](https://pkg.so/de/secret-risk-packages/) - Has protected-tool coverage, approval-gate, or non-low Geiger security signals.
- [Terminal utility packages](https://pkg.so/de/terminal-utilities/) - Matched terminal and command-line workflow metadata.
- [Networking and protocol packages](https://pkg.so/de/networking-protocol-tools/) - Matched network, protocol, or remote-service metadata.
- [Security and crypto packages](https://pkg.so/de/security-crypto-tools/) - Matched security, identity, cryptography, password, signing, or certificate metadata.
- [node](https://pkg.so/de/brew/node/) - Popular package that depends on this formula.
- [python@3.14](https://pkg.so/de/brew/python-3-14/) - Popular package that depends on this formula.
- [awscli](https://pkg.so/de/brew/awscli/) - Popular package that depends on this formula.
- [ffmpeg](https://pkg.so/de/brew/ffmpeg/) - Popular package that depends on this formula.
- [python@3.13](https://pkg.so/de/brew/python-3-13/) - Popular package that depends on this formula.
- [unbound](https://pkg.so/de/brew/unbound/) - Popular package that depends on this formula.
- [krb5](https://pkg.so/de/brew/krb5/) - Popular package that depends on this formula.
- [openssl@4](https://pkg.so/de/brew/openssl-4/) - Package name indicates the same formula family.
- [openssl@3.5](https://pkg.so/de/brew/openssl-3-5/) - Package name indicates the same formula family.
- [openssl@3.0](https://pkg.so/de/brew/openssl-3-0/) - Package name indicates the same formula family.
- [gnutls](https://pkg.so/de/brew/gnutls/) - Shares pkgdb curated category or tags: cli, cryptography, security, ssl, tls.
- [mbedtls](https://pkg.so/de/brew/mbedtls/) - Shares pkgdb curated category or tags: cli, cryptography, security, ssl, tls.
- [libressl](https://pkg.so/de/brew/libressl/) - Shares pkgdb curated category or tags: cli, cryptography, security, ssl, tls.
- [cfssl](https://pkg.so/de/brew/cfssl/) - Shares pkgdb curated category or tags: certificates, cli, cryptography, security, tls.
- [wolfssl](https://pkg.so/de/brew/wolfssl/) - Shares pkgdb curated category or tags: cli, cryptography, security, ssl, tls.

## Combined YAML source

View the package source record on GitHub. [combined/openssl@3.yml](https://github.com/mxcl/pkgdb/blob/main/combined/openssl@3.yml)


## Quellen

- pkg.so package database
- approval-gate seed metadata
- package-page enrichment
- curated configuration and credential file locations
- curated package history
- package version freshness
- pkgdb category and tag curation
- package relationship graph
- external package-manager database matches
- cross-ecosystem install command graph
- curated agent safety answer
