Definitions of OpenSSL terms follow the project's own glossary where one exists; those entries are marked (OpenSSL). Protocol terms follow RFC 8446.
OSSL_PARAM array. TLS-GROUP and
TLS-SIGALG are the two the TLS layer consumes (§4.3).OSSL_DISPATCH entries pairing function identifiers with function
pointers, terminated by a zero entry. The provider architecture's ABI (§3.2).EVP_MD_fetch(). The returned object is owned by the caller.Extract and
Expand. The basis of the TLS 1.3 key schedule.EVP_sha256(), with an implementation resolved automatically on
first use using default criteria.OSSL_LIB_CTX: a scope within which configuration applies and
providers are activated. Represented by NULL for the default context.| Abbreviation | Expansion |
|---|---|
| AAD | Additional Authenticated Data |
| ABI | Application Binary Interface |
| AEAD | Authenticated Encryption with Associated Data |
| CMVP | Cryptographic Module Validation Program |
| ECDH | Elliptic-Curve Diffie–Hellman |
| GCM | Galois/Counter Mode |
| HKDF | HMAC-based Key Derivation Function |
| HMAC | Keyed-Hash Message Authentication Code |
| IANA | Internet Assigned Numbers Authority |
| KEM | Key Encapsulation Mechanism |
| ML-DSA | Module-Lattice-based Digital Signature Algorithm |
| NID | Numeric Identifier (OpenSSL's internal algorithm numbering) |
| OID | Object Identifier |
| TEE | Trusted Execution Environment |
| TLS | Transport Layer Security |