-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathblog.xhtml
More file actions
404 lines (404 loc) · 38.8 KB
/
Copy pathblog.xhtml
File metadata and controls
404 lines (404 loc) · 38.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
<!DOCTYPE html>
<html lang="en" xmlns="http://www.w3.org/1999/xhtml" xml:lang="en">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1" />
<title>TaurusTLS Blog</title>
<meta name="description" content="This page is a blog from the TaurusTLS Developers with information about current development." />
<meta name="apple-mobile-web-app-title" content="TaurusTLS" />
<meta property="fb:app_id" content="1074308038263684" />
<meta property="og:title" content="TaurusTLS Developers' Blog" />
<meta property="og:url" content="https://taurustls.org/" />
<meta property="og:description" content="This page is a blog from the TaurusTLS Developers with information about current development." />
<meta property="og:image" content="https://taurustls.org/gfx/200x200px-bullshead.png" />
<link rel="icon" type="image/png" href="/gfx/favicon-96x96.png" sizes="96x96" />
<link rel="icon" type="image/svg+xml" href="/gfx/favicon.svg" />
<link rel="shortcut icon" href="/gfx/favicon.ico" />
<link rel="apple-touch-icon" sizes="180x180" href="/gfx/apple-touch-icon.png" />
<link rel="manifest" href="/gfx/site.webmanifest" />
<link rel="canonical" href="https://taurustls.org/blog.xhtml" />
<link rel="stylesheet" href="css/screen.css" media="screen" />
<link rel="stylesheet" href="css/print.css" media="print" />
</head>
<body>
<header>
<a class="skip" href="#main">Skip to main content</a>
<nav class="navbar" title="Main Menu">
<ul class="nav-links">
<li><img loading="lazy" class="logo" src="gfx/TaurusTLS.png" height="77" width="77" alt="TaurusTLS" /></li>
<li>
<a href="index.xhtml">About</a>
</li>
<li>
<a href="download.xhtml">Download TaurusTLS</a>
</li>
<li>
<a href="deployapps.xhtml">Deployment</a>
</li>
<li>
<a href="donate.xhtml">Donate</a>
</li>
<li><span>Blog</span></li>
<li>
<a href="contactus.xhtml">Contact Us</a>
</li>
<li>
<a href="links.xhtml">Links</a>
</li>
</ul>
<div class="hamburger">
<span></span> <span></span> <span></span>
</div>
</nav>
</header>
<main id="main">
<h1>TaurusTLS Developer's Blog</h1>
<article id="September_29_OpenSSL_Released">
<h2>OpenSSL 3.4.8, 3.5.9, 3.6.5, and 3.6.5 Released</h2>
<p class="post-meta">Published on September 29, 2026 by J. Peter Mugaas</p>
<p>The OpenSSL project has released updated versions of its core library (3.4.8, 3.5.9, 3.6.5, and 4.0.3). Thanks to our automated build pipeline, these updates have already been compiled, packaged, and made available in all supported formats across our target platforms.</p>
<p>The new binaries are now available for download on our <a href="https://github.com/TaurusTLS-Developers/OpenSSL-Distribution/releases">OpenSSL Release Distribution</a> page.</p>
<p>As these updates contain important security patches, we highly recommend updating your software distributions with these latest binaries at your earliest convenience to ensure continued security and stability.</p>
</article>
<article id="September_27_NTLM_Protocol_Enabled">
<h2>NTLM Protocol Support Restored in TaurusTLS</h2>
<p class="post-meta">Published on September 27, 2026 by J. Peter Mugaas</p>
<p><strong>Updated on October 3, 2026:</strong> Revised for recent changes to source code.</p>
<p>Thanks to Clayton Arends (zencode1), NTLM protocol support has been restored to TaurusTLS via the <code>TaurusTLS_NTLM</code> unit. This support is intended solely for interoperability with legacy systems.</p>
<p>Because NTLM relies on obsolete cryptographic algorithms like DES and MD4, OpenSSL 3.x and 4.x isolate these routines inside their <code>legacy</code> provider. As a result, components relying on NTLM previously failed to initialize properly under OpenSSL 3.x+ unless the legacy provider was explicitly loaded.</p>
<p>TaurusTLS now correctly initializes these legacy hooks upon loading OpenSSL. To enable support in your applications, call the <code>LoadLegacyProvider</code> method in the <code>TaurusTLS_LegacyProviders</code> unit and ensure you deploy the OpenSSL <code>Providers</code> directory alongside your application binary.</p>
</article>
<article id="September_24_TIdC_TIMET">
<h2><code>TOSSL_TIMET</code> (<code>time_t</code>) replaces <code>TIdC_TIMET</code></h2>
<p class="post-meta">Published on September 23, 2026 by J. Peter Mugaas</p>
<p><strong>Updated on September 25, 2026:</strong> Additional research into the platform-specific <code>time_t</code> ABI has clarified this change.</p>
<p>TaurusTLS now uses the TaurusTLS-specific <code>TOSSL_TIMET</code> and <code>POSSL_TIMET</code> types instead of Indy's <code>TIdC_TIMET</code> and <code>PIdC_TIMET</code> for OpenSSL declarations involving <code>time_t</code>.</p>
<p>The size of <code>time_t</code> is determined by the target platform and C library ABI and is not necessarily the same as the size of Pascal's or C's other integer types. In particular, <code>time_t</code> can be 64-bit on 32-bit platforms. Using a type with the wrong size can result in an ABI mismatch and potentially cause value truncation, incorrect parameter or return-value handling, or memory corruption.</p>
<p><code>TOSSL_TIMET</code> explicitly represents the <code>time_t</code> ABI used by OpenSSL. On 32-bit Linux and Android targets, the <code>OSSL_TIMET_64BIT</code> conditional compilation flag can be used when compiling TaurusTLS against a 64-bit-time C ABI.</p>
<p>This change does not intentionally alter the public TaurusTLS API. The previous <code>TIdC_TIMET</code> and <code>PIdC_TIMET</code> types were used only by OpenSSL declarations.</p>
</article>
<article id="September_24_OpenSSL_4_1_0beta1_Binaries">
<h2>OpenSSL 4.1.0beta1 Binaries Are Released</h2>
<p class="post-meta">Published on September 24, 2026 by J. Peter Mugaas</p>
<p>We are releasing compiled versions of <strong>OpenSSL 4.1.0 Alpha 1</strong>. This is a prerelease from the OpenSSL Developers.</p>
<p>Since this version is a prerelease, it will only be available <strong>temporarily</strong> until a new release is made and there is no automated installer for it.</p>
<p>We make <a href="https://github.com/TaurusTLS-Developers/OpenSSL-Distribution/releases/tag/v4.1.0-beta1">this version available</a> for users that want to test it. We do <strong>NOT recommend</strong> using it in production software.</p>
</article>
<article id="September_14_OpenSSL_4_1_0alpha1_Binaries">
<h2>OpenSSL 4.1.0alpha1 Binaries Are Released</h2>
<p class="post-meta">Published on September 14, 2026 by J. Peter Mugaas</p>
<p>We are releasing compiled versions of <strong>OpenSSL 4.1.0 Alpha 1</strong>. This is a prerelease from the OpenSSL Developers.</p>
<p>Since this version is a prerelease, it will only be available <strong>temporarily</strong> until a new release is made and there is no automated installer for it.</p>
<p>We make this version available for users that want to test it. We do <strong>NOT recommend</strong> using it in production software.</p>
</article>
<article id="September_10_26_TaurusTLS_2_0_Client_Socket_Demo">
<h2>TaurusTLS 2.0: Client SSL Socket and ECH Demo Available</h2>
<p class="post-meta">Published on September 10, 2026 by Alexander Tregubov</p>
<p>We have published a console demonstration showcasing the core <strong><a href="#July_11_26_Announcing_TaurusTLS_2_0">TaurusTLS 2.0</a></strong> Client SSL Socket architecture. This sample illustrates the low-level socket state machine, immutable configuration snapshots (<code>ITaurusTLSSslSocketCtx</code>), and the fluent context builder pattern.</p>
<p>The demo covers multiple client operational modes, including direct IP connections (<code>csmDisabled</code>), standard SNI (<code>csmStandardSNI</code>), ECH GREASE anti-ossification (<code>csmECHGrease</code>), dynamic ECH key discovery with automated reconnection (<code>csmECHGreaseDiscovery</code>), and private ECH with suppressed outer SNI (<code>csmECHNoOuter</code>). Native Windows Certificate Store integration (<code>UseSystemCertStore</code>) and custom CA chaining are also demonstrated.</p>
<p>While high-level <code>IOHandler</code> integration remains in progress, this sample models the exact lifecycle operations executed under the hood. The demo source code is available in the <code>demos\TaurusTLS_2\HTTPCLi</code> path on the <a href="https://github.com/TaurusTLS-Developers/TaurusTLS/tree/TaurusTLS2.0-%40AT">TaurusTLS2.0-@AT branch</a>.</p>
</article>
<article id="September_10_TaurusTLS_1_0_11_53">
<h2>TaurusTLS 1.0.11.53</h2>
<p class="post-meta">Published on September 10, 2026 by J. Peter Mugaas</p>
<p>We are pleased to announce the <a href="https://github.com/TaurusTLS-Developers/TaurusTLS/releases/tag/1.0.11.53">release of TaurusTLS 1.0.11.53</a>. This maintenance release addresses several bugs, including:</p>
<ul>
<li>
<a href="https://github.com/TaurusTLS-Developers/TaurusTLS/issues/258">Issue 258 (Win64 platform missing in D13 packages )</a>
</li>
<li>
<a href="https://github.com/TaurusTLS-Developers/TaurusTLS/issues/251">Issue 251 (Strange client issue)</a>
</li>
<li>
<a href="https://github.com/TaurusTLS-Developers/TaurusTLS/issues/271">Issue 271 (Support <code>SSL_CTX_set_ciphersuites</code>)</a>
</li>
</ul>
<p>This release features a new property, <code>CipherSuites</code> that is used to specify the cipher suites you wish to use with <strong>TLS 1.3</strong>. Do not confuse this with the <code>CipherList</code> property which specifies the ciphers you wish to use with <strong>TLS 1.2 or earlier</strong>.</p>
</article>
<article id="September_7_OpenSSL_30_EOL">
<h2>OpenSSL 3.0 Version Series Reached It's End-Of-Life</h2>
<p class="post-meta">Published on September 7, 2026 by J. Peter Mugaas</p>
<p>OpenSSL 3.0 has reached it's end-of-life (EOL) meaning there will be no further public releases. We discourage users from continuing to use this version. You have the following options:</p>
<ul>
<li><strong>OpenSSL 3.4.x</strong> - This will reach it's end-of-life on October 22, 2026</li>
<li><strong>OpenSSL 3.5.x</strong> - This version series has long-term support until April 8, 2030</li>
<li><strong>OpenSSL 3.6.x</strong> - This will reach its end of life on November 1, 2026</li>
<li><strong>OpenSSL 4.0.x</strong> - This will reach its end-of-life on May 14, 2027</li>
</ul>
<p>For further information, please consult the <a href="https://openssl-library.org/roadmap/">OpenSSL Roadmap</a>.</p>
<p>We recommend that developers upgrade to <strong>OpenSSL 4.0</strong> and eventually to <strong>OpenSSL 4.2</strong> when it is released because OpenSSL 4.2.x will have long-term-support. The OpenSSL 4.x versions are recommended because <a href="#July_11_26_Announcing_TaurusTLS_2_0">TaurusTLS 2.0</a> will feature <a href="#July_12_26_TaurusTLS_2_0_ECH_Support">Encrypted Client Hello (ECH) including GREASE (Generate Random Extensions And Sustain Extensibility)</a>.</p>
</article>
<article id="September_1_MSI_Installer">
<h2>Announcing Windows MSI Installer Releases for OpenSSL</h2>
<p class="post-meta">Published on September 1, 2026 by J. Peter Mugaas & Alexander Tregubov</p>
<p>We are excited to announce the release of official Windows Installer (<strong>MSI</strong>) packages for OpenSSL <strong>3.0.22, 3.4.7, 3.5.8, 3.6.4, and 4.0.2</strong> across <code>x64</code>, <code>x86</code>, and <code>arm64</code> architectures.</p>
<p>Built with <a href="https://www.firegiant.com/wixtoolset/">WiX Toolset</a> v5 and digitally signed with Azure Trusted Signing, these packages are ready for enterprise deployment (GPO, Intune, SCCM) and feature automatic rollback on failure, on-demand repair, and optional 32-bit runtime compatibility on 64-bit Windows.</p>
<p>Download the new MSI installers on our <a href="https://github.com/TaurusTLS-Developers/OpenSSL-Distribution/releases">OpenSSL Distribution Releases</a> page.</p>
</article>
<article id="August_30_26_ARM64X_Release">
<h2>Announcing Windows ARM64X Releases: OpenSSL 3.0.22, 3.4.7, 3.5.8, 3.6.4, and 4.0.2</h2>
<p class="post-meta">Published on August 30, 2026 by J. Peter Mugaas & Alexander Tregubov</p>
<p>We are excited to announce the release of unified <strong>ARM64X</strong> OpenSSL binaries for Windows on ARM, officially replacing our previous standalone <code>arm64ec</code> packages.</p>
<p>By leveraging Microsoft's ARM64X format, these binaries fuse <strong>Native ARM64</strong> and <strong>ARM64EC</strong> into single dual-architecture binaries. This means the <strong>exact same DLLs and import libraries</strong> work seamlessly for both native ARM64 executables and ARM64EC applications, including those compiled with <a href="https://www.embarcadero.com/products/rad-studio" target="_blank" rel="noopener">Embarcadero RAD Studio (Delphi / C++Builder)</a>.</p>
<p>All binaries are built with HybridCRT (eliminating external <code>vcruntime140.dll</code> dependencies) and are digitally signed with Microsoft Azure Trusted Signing.</p>
<p>The new binaries and installers are now available for download on our <a href="https://github.com/TaurusTLS-Developers/OpenSSL-Distribution/releases">OpenSSL Distribution Releases</a> page.</p>
</article>
<article id="August_25_26_OpenSSL_Releases">
<h2>OpenSSL 3.0.22, 3.4.7, 3.5.8, 3.6.4, and 4.0.2 Released</h2>
<p class="post-meta">Published on August 25, 2026 by J. Peter Mugaas</p>
<p>The OpenSSL project has released updated versions of its core library (3.0.22, 3.4.7, 3.5.8, 3.6.4, and 4.0.2). Thanks to our automated build pipeline, these updates have already been compiled, packaged, and made available in all supported formats across our target platforms.</p>
<p>The new binaries are now available for download on our <a href="https://github.com/TaurusTLS-Developers/OpenSSL-Distribution/releases">OpenSSL Release Distribution</a> page.</p>
<p>As these updates contain important security patches, we highly recommend updating your software distributions with these latest binaries at your earliest convenience to ensure continued security and stability.</p>
</article>
<article id="August_21_26_Apps_That_Use_TaurusTLS">
<h2>Do You Use TaurusTLS? Let Us Know!</h2>
<p class="post-meta">Published on August 21, 2026 by J. Peter Mugaas</p>
<p>We are always excited to see how TaurusTLS is being utilized in the wild. If you have developed or released an application—whether it is commercial, freeware, or open source — that relies on TaurusTLS, we would love to hear about it!</p>
<p>By sharing your project, you help us demonstrate the library's real-world impact and guide our future development. We would be proud to feature your product on our official <a href="links.xhtml#SoftwareThatUsesTaurusTLS">Showcase of TaurusTLS-Powered Products</a> page.</p>
<p>Please let us know about your software by opening a feedback thread on our <a href="https://github.com/orgs/TaurusTLS-Developers/discussions/categories/show-and-tell">GitHub <strong>Show and Tell</strong> Discussion Forum</a> or by reaching out to us directly through our <a href="contactus.xhtml">Contact Us</a> form.</p>
</article>
<article id="August_15_26_OpenSSL_Installers">
<h2>OpenSSL Installers Now Available</h2>
<p class="post-meta">Published on August 15, 2026 by J. Peter Mugaas & Alexander Tregubov</p>
<p>We are pleased to announce that official Windows installers for our OpenSSL distribution are <a href="https://github.com/TaurusTLS-Developers/OpenSSL-Distribution/releases">now available for download</a>. These installers bundle our pre-compiled libraries for <code>x86</code>, <code>x64</code>, and <code>ARM64EC</code> architectures.</p>
<p>To accommodate different deployment scenarios and developer workflows, we have prepared two distinct installer formats:</p>
<ul>
<li>
<strong>Classic Desktop Installer:</strong> A single hybrid executable built with <a href="https://jrsoftware.org/isinfo.php">Inno Setup</a>. It runs seamlessly on both Intel (x86/x64) and ARM64 platforms, automatically detecting the host environment at runtime to deploy the correct architecture-specific binaries.
</li>
<li><strong>UWP Sideloading Packages:</strong> A modern, <code>.msix</code> packages that provides a seamless, one-click installation experience optimized for Universal Windows Platform (UWP) applications.</li>
</ul>
<p>Both kinds of installer packages are fully digitally signed under the name "J. Peter Mugaas" using our Individual Validation (IV) Code Signing Certificate, ensuring secure, tamper-free delivery and a smoother installation process on Windows systems.</p>
</article>
<article id="August_12_26_OpenSSL_Now_Code_Signed">
<h2>OpenSSL Binaries Now Code-Signed</h2>
<p class="post-meta">Published on August 12, 2026 by J. Peter Mugaas</p>
<p>We are pleased to announce that starting today, our distributed OpenSSL 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21 DLLs and the <code>openssl.exe</code> executable are officially code-signed under the name "J. Peter Mugaas".</p>
<p>This digital signature ensures the integrity and authenticity of the binaries, verifying that they have not been altered or tampered with since compilation. Additionally, code-signing should help reduce false-positive warnings from antivirus software and Windows SmartScreen during installation.</p>
<p>We highly recommend updating your software distributions with these newly signed files.</p>
</article>
<article id="August_09_26_TaurusTLS_2_0_OSSL_STORE_API_Wrappers">
<h2>TaurusTLS 2.0 Internals: OpenSSL OSSL_STORE API Wrappers</h2>
<p class="post-meta">Published on August 09, 2026 by Alexander Tregubov</p>
<h3>Introduction</h3>
<p>The OpenSSL context (<code>SSL_CTX</code>) and connection (<code>SSL</code>) structures rely on Public Key Infrastructure (PKI) objects—such as certificates, public and private keys, CRLs (Certificate Revocation Lists), and Diffie-Hellman (DH) or Elliptic Curve (EC) parameters—to establish secure communications. These PKI objects can be packaged in various formats, including Base64-encoded <code>PEM</code> files, raw binary <code>DER</code> files, or <code>PKCS#12</code> containers. Each format has its own distinct structure, encoding scheme, and internal encryption mechanisms.</p>
<p>Historically, OpenSSL implemented distinct sets of routines tailored to each specific format. This introduces significant challenges for developers who need to support multiple PKI formats in their applications, as these legacy routines feature divergent parameter signatures and inconsistent usage patterns. To address this, OpenSSL introduced the <code>OSSL_STORE</code> API in version 1.1.1, which became fully production-ready in OpenSSL 3.0. This API offers a unified interface capable of processing all major PKI formats under a single, cohesive framework.</p>
<h3>How the Original TaurusTLS Handles PKI Objects</h3>
<ul>
<li><strong>Legacy Routines:</strong> The original TaurusTLS implementation relies on legacy OpenSSL APIs to load PKI objects exclusively from disk or the Windows Certificate Store. These old routines do not support the direct ingestion of in-memory PKI data.</li>
<li><strong>Reactive Loading Overhead:</strong> Current <code>IOHandler</code> instances use a reactive loading pattern, resolving PKI objects on demand. For example, a server-side SSL socket reloads the certificate and private key files on every incoming client connection. This results in redundant disk I/O operations and reduces connection throughput (Connections Per Minute / CPM).</li>
</ul>
<h3>How the <code>OSSL_STORE</code> Wrapper Improves Usability and Performance</h3>
<p>The <code>OSSL_STORE</code> API unifies the loading of various PKI formats into a single, cohesive interface. It can ingest data in single or multiple passes and automatically instantiate native OpenSSL types such as <code>X509</code> (certificates) and <code>EVP_PKEY</code> (private/public keys). Crucially, the same wrappers can be used for in-memory buffers, offering developers unprecedented flexibility.</p>
<p>TaurusTLS 2.0 leverages these wrappers to support several advanced integration scenarios:</p>
<ul>
<li><strong>Preloading and Sharing Trusted Certificates:</strong> Trusted certificates can be loaded once and shared across multiple <code>IOHandler</code> instances. This will be exposed via a new <code>Trusted Store</code> component.</li>
<li><strong>Preloaded Server and Client Credentials:</strong> Server-side PKI credentials and client-side certificates can be preloaded into memory, eliminating disk I/O bottlenecks during the TLS handshake.</li>
</ul>
<p>Both approaches will significantly simplify code maintenance and improve overall runtime performance.</p>
<h3>Source Code</h3>
<p>The initial implementation of these <code>OSSL_STORE</code> wrappers is available for review in our <a href="https://github.com/TaurusTLS-Developers/TaurusTLS/blob/TaurusTLS2.0-%40AT/Source/TaurusTLS_SSLStores.pas">Development Branch</a>.</p>
</article>
<article id="July_28_26_TaurusTLS_1_0_10_52">
<h2>TaurusTLS 1.0.10.52</h2>
<p class="post-meta">Published on July 28, 2026 by J. Peter Mugaas</p>
<p>We are pleased to announce the <a href="https://github.com/TaurusTLS-Developers/TaurusTLS/releases/tag/1.0.10.52">release of TaurusTLS 1.0.10.52</a>. This maintenance release addresses several bugs, including:</p>
<ul>
<li>
<a href="https://github.com/TaurusTLS-Developers/TaurusTLS/issues/241">Issue #241 (Error when compiling under C++Builder)</a>
</li>
<li>
<a href="https://github.com/TaurusTLS-Developers/TaurusTLS/issues/251">Issue #251 (Socket unresponsiveness under poor network conditions on POSIX)</a>
</li>
</ul>
<p>As <a href="#July_20_26_The_CppBuilder_Support_Status_Update">previously discussed</a>, this release significantly improves compatibility for C++Builder developers.</p>
</article>
<article id="July_27_26_TaurusTLS_2_0_Status_Update">
<h2>TaurusTLS 2.0 Status Update</h2>
<p class="post-meta">Published on July 27, 2026 by Alexander Tregubov</p>
<p>Recently, we resolved an issue that affected the behavior of <code>TaurusTLSIOHandlerSocket</code> under poor network conditions on POSIX systems. See <a href="https://github.com/TaurusTLS-Developers/TaurusTLS/issues/251">Issue #251 (Strange client issue)</a>. This fix prompted us to review OpenSSL and TCP socket interoperability in <strong>TaurusTLS 2.0</strong>.</p>
<p>We found that OpenSSL enables <code>SSL_MODE_AUTO_RETRY</code> by default. In this mode, OpenSSL prevents read and write operations from returning control to the application while it processes the transmission of internal protocol messages. It only yields control once it has successfully decoded application data records, or when application records are encoded and sent successfully.</p>
<p>However, the SSL/TLS protocols rely on internal control frames—which can be transmitted in the middle of application data—to maintain connection integrity. Losing one or more of these control frames can delay read/write operations and directly impact the responsiveness of <code>TaurusTLSIOHandlerSocket</code>. To improve stability under unstable network conditions, the TaurusTLS team plans to disable <code>SSL_MODE_AUTO_RETRY</code> in <strong>TaurusTLS 2.0</strong>.</p>
<p>We are currently evaluating the implementation complexity and the robust error handling required for this approach.</p>
<p>Stay tuned for more updates.</p>
</article>
<article id="July_21_26_TaurusFTP_Console_Demo_Program">
<h2>The TaurusFTP Console Demo Program</h2>
<p class="post-meta">Published on July 21, 2026 by J. Peter Mugaas</p>
<p>There is an unsung hero in the TaurusTLS distribution that is not given enough credit. That unsung hero is the TaurusFTP Console Demo program that is included with TaurusTLS distributions in the <code>/Demos/TaurusFTPConsole</code> folder. This is not merely a simple demo program, but rather a fully functional console FTP (File Transfer Protocol) client that is completely driven by commands. I consider this program superior to the bundled FTP client included in Windows because:</p>
<ul>
<li>It supports both explicit TLS (as defined by <a href="https://www.rfc-editor.org/info/rfc4217/">RFC 4217: Securing FTP with TLS</a>) and implicit TLS with FTP. In explicit TLS, the connection starts unencrypted using the same port as regular FTP, the client issues an <code>AUTH TLS</code> command, the server sends a response, and TLS negotiation begins. In implicit TLS, the connection is made to port 990 and TLS negotiation happens immediately.
</li>
<li>It supports <a href="https://datatracker.ietf.org/doc/html/draft-preston-ftpext-deflate-04">Deflate transmission mode for FTP</a> or <code>MODE Z</code> if the server supports this.
</li>
<li>It supports passive transfers (<code>PASV</code>) by default instead of relying on active transfers (<code>PORT</code>). Passive transfers tend to be more friendly in firewall/proxy configurations and NATs (Network Address Translators) than active transfers because the PASV response is an IP address and port that the server is listening on. In active transfers, an IP address and port number is sent by the client and the IP address might be local network instead of the Internet.</li>
<li>It supports the <code>EPSV</code> and <code>EPRT</code> commands that allow the client and server to communicate IPv6 addresses as defined by <a href="https://www.rfc-editor.org/info/rfc2428/">RFC 2428: FTP Extensions for IPv6 and NATs</a>.
</li>
<li>It supports <a href="https://www.rfc-editor.org/info/rfc2640/">RFC 2640: Internationalization of the File Transfer Protocol</a>.
</li>
<li>It supports the <code>MLSD</code> command which provides a standardized machine and human-readable directory listing format as specified by <a href="https://www.rfc-editor.org/info/rfc3659/">RFC 3659: Extensions to FTP</a> by default instead of simply using the old standard <code>DIR</code> command which does not specify a format (although the Unix format is a de facto standard).
</li>
</ul>
<p>Using the program is very simple. The program provides a <code>help</code> command that lists the commands and what they do. In addition, you can use the <code>help command</code> function to get help with the command parameters.</p>
</article>
<article id="July_20_26_The_CppBuilder_Support_Status_Update">
<h2>The C++Builder Support Status Update</h2>
<p class="post-meta">Published on July 20, 2026 by J. Peter Mugaas</p>
<p>I have checked in extensive modifications to make TaurusTLS compatible with <a href="https://www.embarcadero.com/products/cbuilder">C++Builder</a>. This resolves issue <a href="https://github.com/TaurusTLS-Developers/TaurusTLS/issues/241">#241 (error when compiling under C++Builder)</a>. These changes will be available in the next release of TaurusTLS.</p>
<p>While we still do not formally support C++Builder due to a lack of dedicated expertise and resources, we are pleased that this update significantly improves the situation for C++Builder developers.</p>
</article>
<article id="July_12_26_TaurusTLS_1_0_9_51">
<h2>TaurusTLS 1.0.9.51 Dedicated to My Late Father</h2>
<p class="post-meta">Published on July 12, 2026 by J. Peter Mugaas</p>
<p>We are <a href="https://github.com/TaurusTLS-Developers/TaurusTLS/releases/tag/1.0.9.51">releasing TaurusTLS 1.0.9.51</a>. This fixes several bugs including:</p>
<ul>
<li>
<a href="https://github.com/TaurusTLS-Developers/TaurusTLS/issues/240">Exception code 13, lazarus x86_64 linux</a>
</li>
<li>
<a href="https://github.com/TaurusTLS-Developers/TaurusTLS/issues/226">Error compiling: Posix not found. TaurusTLS 1.0.8.48 Lazarus 4.6 FPC 3.2.2</a>
</li>
</ul>
<p>This release supports <a href="https://github.com/TaurusTLS-Developers/TaurusTLS/pull/228">bidirectional shutdown</a> through the property <code>UseBidirectionalShutdown</code>.</p>
<p>This release is dedicated to my late father, John N. Mugaas, PhD. who died June 27, 2026. RIP.</p>
</article><!-- Post #4: July 12, 2026 -->
<article id="July_12_26_TaurusTLS_2_0_ECH_Support">
<h2>TaurusTLS 2.0: Encrypted Client Hello (ECH) Support</h2>
<p class="post-meta">Published on July 12, 2026 by Alexander Tregubov</p>
<p>We are excited to share that TaurusTLS 2.0 client (<code>xxxIOHandlerSocket</code>) and server (<code>xxxServerIOHandler</code>) components will feature support for the <strong><a href="https://www.rfc-editor.org/rfc/rfc9849.html">Encrypted Client Hello</a> (ECH)</strong> TLS extension. This critical addition will help protect user privacy by minimizing the metadata exposed during the initial TLS handshake.</p>
<h3>Initial Release Scope</h3>
<p>Our integration of ECH in the initial release of TaurusTLS 2.0 will work as follows:</p>
<ul>
<li><strong>DNS/DoH Queries:</strong> We do not plan to support dynamic retrieval of <code>ECHConfig</code> values via DNS or DNS-over-HTTPS (DoH) queries out-of-the-box on the client side (<code>xxxIOHandlerSocket</code>).</li>
<li><strong>DNS Record Updates:</strong> On the server side (<code>xxxServerIOHandler</code>), there will be no built-in mechanism to dynamically update DNS <code>SVCB</code> or <code>HTTPS</code> resource records with updated <code>ECHConfig</code> parameters.</li>
<li><strong>Developer Flexibility:</strong> To keep the library lightweight, we will instead expose the necessary APIs so that your applications can easily implement these dynamic DNS and DoH lookup tasks independently.</li>
</ul>
<h3>ECH GREASE Support</h3>
<p>To further enhance client privacy, we are also implementing the <strong>ECH GREASE</strong> (<a href="https://www.rfc-editor.org/rfc/rfc8701.html">Generate Random Extensions And Sustain Extensibility</a>) mechanism. This allows your client applications to safely send dummy ECH extensions to prevent network fingerprinting, even if an <code>ECHConfig</code> payload is not yet known (provided the destination server supports GREASE).</p>
<p>Stay tuned for more updates as development progresses!</p>
</article><!-- Post #3: July 11, 2026 -->
<article id="July_11_26_Announcing_TaurusTLS_2_0">
<h2>Announcing TaurusTLS 2.0: A Modernization Initiative</h2>
<p class="post-meta">Published on July 11, 2026 by Alexander Tregubov</p>
<p>The TaurusTLS development team is pleased to announce the launch of a major modernization project for our library, currently codenamed <strong>TaurusTLS 2.0</strong>.</p>
<p>Our primary goals for this next-generation release include:</p>
<ul>
<li><strong>Modern <a href="https://www.openssl.org/">OpenSSL</a> Integration:</strong> We are phasing out legacy OpenSSL 1.x API calls in favor of modern OpenSSL 3.x and newer APIs, procedures, and data structures. This ensures long-term compatibility and stability with upstream OpenSSL development.</li>
<li><strong>Enhanced Multithreading Support:</strong> We are restructuring internal logic to improve concurrency safety and thread performance.</li>
<li><strong>Granular Traffic Control:</strong> We will expand the list of configurable parameters and event handlers, giving developers more options to optimize traffic handling for their specific use cases.</li>
<li><strong><a href="https://www.rfc-editor.org/rfc/rfc9849.html">Encrypted Client Hello</a> (ECH) Support:</strong> We are adding native ECH support to both client and server components (which will require OpenSSL 4.0 or newer).</li>
</ul>
<h3>Backward Compatibility Notice</h3>
<p>Unfortunately, achieving these modernization goals means we will not be able to maintain full backward compatibility with older TaurusTLS components. We sincerely apologize for any inconvenience this may cause.</p>
<p>To ensure a smooth transition, we plan to maintain and support both the current TaurusTLS branch and the new TaurusTLS 2.0 branch in parallel for a reasonable timeframe. This will give you ample time to migrate and adapt your existing applications.</p>
<p>We highly value your feedback and feature requests as we shape TaurusTLS 2.0. Please let us know your thoughts directly on <a href="https://github.com/TaurusTLS-Developers/TaurusTLS/issues">our issue tracker</a>!</p>
</article><!-- Post #2: July 10, 2026 -->
<article id="July_09_26_We_Are_Dropping_C_Builder_Support">
<h2>We Are Dropping C++Builder Support</h2>
<p class="post-meta">Published on July 10, 2026 by J. Peter Mugaas & Alexander Tregubov</p>
<p>We are saddened to announce that we are officially dropping support for C++Builder. Unfortunately, we do not have the specialized expertise or resources required to properly address and resolve C++Builder-specific issues. To ensure the highest quality for our core users, we have decided to focus our efforts entirely on supporting Delphi.</p>
<p>However, if you have strong C++Builder expertise and are interested in helping maintain or resolve issues for this platform, we would highly <a href="https://github.com/TaurusTLS-Developers/TaurusTLS/pulls">welcome your contributions</a>.</p>
</article><!-- Post #1: July 07, 2026 -->
<article id="July_07_26_The_New_Website">
<h2>The New Website</h2>
<p class="post-meta">Published on July 07, 2026 by J. Peter Mugaas</p>
<p>TaurusTLS has a new website. It took several days of coffee-fueled benders to do this. My goals for this website is make information available about TaurusTLS to the people that need it. This involves handicapped accessibility (an extremely personal thing for me), ability to work on mobile devices, and the ability to print the content of this site. This involved a lot of research and testing. The website is completely done by hand using tools such as <a href="https://www.htmlvalidator.com/">CSE-Validator</a>, <a href="https://www.totalvalidator.com/">Total Validator</a>, some online tools, and of course, Google.</p>
<p>I need to thank David Nottage for helping me with the CSS. He did a much better job than I could.</p>
</article>
<aside>
<h2>Recent Posts</h2>
<ul>
<li>
<a href="#September_29_OpenSSL_Released">OpenSSL 3.4.8, 3.5.9, 3.6.5, and 3.6.5 Released</a>
</li>
<li>
<a href="#September_27_NTLM_Protocol_Enabled">The NTLM (NT Lan Manager Protocol) has been Enabled</a>
</li>
<li>
<a href="#September_24_TIdC_TIMET"><code>TOSSL_TIMET</code> (<code>time_t</code>) replaces <code>TIdC_TIMET</code></a>
</li>
<li>
<a href="#September_24_OpenSSL_4_1_0beta1_Binaries">OpenSSL 4.1.0beta1 Binaries Are Released</a>
</li>
<li>
<a href="#September_14_OpenSSL_4_1_0alpha1_Binaries">OpenSSL 4.1.0alpha1 Binaries Are Released</a>
</li>
<li>
<a href="#September_10_26_TaurusTLS_2_0_Client_Socket_Demo">TaurusTLS 2.0: Client SSL Socket and ECH Demo Available</a>
</li>
<li>
<a href="#September_10_TaurusTLS_1_0_11_53">TaurusTLS 1.0.11.53</a>
</li>
<li>
<a href="#September_7_OpenSSL_30_EOL">OpenSSL 3.0 Version Series Reached It's End-Of-Life</a>
</li>
<li>
<a href="#September_1_MSI_Installer">Announcing Windows MSI Installer Release</a>
</li>
<li>
<a href="#August_30_26_ARM64X_Release">Announcing Windows ARM64X Releases: OpenSSL 3.0.22, 3.4.7, 3.5.8, 3.6.4, and 4.0.2</a>
</li>
<li>
<a href="#August_25_26_OpenSSL_Releases">OpenSSL 3.0.22, 3.4.7, 3.5.8, 3.6.4, & 4.0.2 Have Been Released</a>
</li>
<li>
<a href="#August_21_26_Apps_That_Use_TaurusTLS">Do You Use TaurusTLS? Let Us Know!</a>
</li>
<li>
<a href="#August_15_26_OpenSSL_Installers">OpenSSL Installers Now Available</a>
</li>
<li>
<a href="#August_12_26_OpenSSL_Now_Code_Signed">OpenSSL Binaries Now Code-Signed</a>
</li>
<li>
<a href="#August_09_26_TaurusTLS_2_0_OSSL_STORE_API_Wrappers">TaurusTLS 2.0 Internals: OpenSSL OSSL_STORE API Wrappers</a>
</li>
<li>
<a href="#July_28_26_TaurusTLS_1_0_10_52">TaurusTLS 1.0.10.52</a>
</li>
<li>
<a href="#July_27_26_TaurusTLS_2_0_Status_Update">TaurusTLS 2.0 Status Update</a>
</li>
<li>
<a href="#July_21_26_TaurusFTP_Console_Demo_Program">The TaurusFTP Console Demo Program</a>
</li>
<li>
<a href="#July_20_26_The_CppBuilder_Support_Status_Update">The C++Builder Support Status Update</a>
</li>
<li>
<a href="#July_12_26_TaurusTLS_1_0_9_51">TaurusTLS 1.0.9.51 Dedicated to My Late Father</a>
</li>
<li>
<a href="#July_12_26_TaurusTLS_2_0_ECH_Support">TaurusTLS 2.0: Encrypted Client Hello (ECH) Support</a>
</li>
<li>
<a href="#July_11_26_Announcing_TaurusTLS_2_0">Announcing TaurusTLS 2.0: A Modernization Initiative</a>
</li>
<li>
<a href="#July_09_26_We_Are_Dropping_C_Builder_Support">We Are Dropping C++Builder Support</a>
</li>
<li>
<a href="#July_07_26_The_New_Website">The New Website</a>
</li>
</ul>
</aside>
</main>
<footer>
<div class="social-media-links">
<ul>
<li>
<a href="https://github.com/TaurusTLS-Developers" rel="noopener noreferrer"><img src="gfx/github.svg" alt="Visit us on GitHub" class="social-icon" height="16" width="16" /></a>
</li>
<li>
<a href="https://www.facebook.com/people/Taurustls/61582588996953/" rel="noopener noreferrer"><img src="gfx/facebook.svg" alt="Visit Us on Facebook" class="social-icon" height="16" width="16" /></a>
</li>
<li>
<a href="https://www.linkedin.com/company/109619101" rel="noopener noreferrer"><img src="gfx/linkedin.svg" alt="Visit Us on LinkedIn" class="social-icon" height="16" width="16" /></a>
</li>
</ul>
</div>
<p class="copyright">Copyright © 2026 TaurusTLS Developers. All rights reserved</p>
</footer>
<script type="text/javascript" src="js/hamburger.js"></script>
</body>
</html>