Repository navigation
OpenSSL default security level changed to 2 in Node.js 24.5 but docs still say it's 1 #59715
Copy link
Copy link
Closed
Labels
docIssues and PRs related to Node.js documentation.Issues and PRs related to Node.js documentation.
Description
Activity
- addeddocIssues and PRs related to Node.js documentation.Issues and PRs related to Node.js documentation.
on Sep 2, 2025 In case it helps, here's a small function that can demonstrate that the OpenSSL default security level has changed. When run with Node.js 24.4.1, this returns successfully, but when run with Node.js 24.7 it fails with
ERR_SSL_EE_KEY_TOO_SMALL. In the latter case, the failure can be worked around by changingciphers: 'DEFAULT'tociphers: 'DEFAULT@SECLEVEL=1'.export function testRSA1024Certificate() { const cert = `\ -----BEGIN CERTIFICATE----- MIICCDCCAXGgAwIBAgIUZtwgcn39NWKzln0vATpxThbZ/48wDQYJKoZIhvcNAQEL BQAwFjEUMBIGA1UEAwwLZXhhbXBsZS5jb20wHhcNMjUwOTAyMDEzMjU2WhcNMzUw ODMxMDEzMjU2WjAWMRQwEgYDVQQDDAtleGFtcGxlLmNvbTCBnzANBgkqhkiG9w0B AQEFAAOBjQAwgYkCgYEAqeZpWA39dEjJmlg85MlKyIQIsxvk/a+6hG1NVmoLguLj qKIuHE2WGlM38F13u8oi9Yp4gMxkow4L+ulQ/qOvV67sHs1ivMo5bB70u9yvLByd Awz4AMn+UplaNA/QeJVMG8bCYx1kVxNbZoTW0r66xYsEUACw7JblEmDYp70DdA0C AwEAAaNTMFEwHQYDVR0OBBYEFBuvrmRphCSTez1A2kyJYqNJq4OpMB8GA1UdIwQY MBaAFBuvrmRphCSTez1A2kyJYqNJq4OpMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZI hvcNAQELBQADgYEAfyX0J2POn9+HKOrqoTlE121OwhG54VQsUiNJwpatqtK/9LeN nQaj4DsmcTZvUHrs6Z5vdJ4UzlNU+C0JWpEjoqAf85pXmom6KUb4PvkX+OCYsEnv Bfdk6Ji1fR3hLBz0o7bxWVEnkt2+Ax/efs//a7+LBWk7Y2+sjwh56wKOMOQ= -----END CERTIFICATE-----`; const key = `\ -----BEGIN PRIVATE KEY----- MIICdQIBADANBgkqhkiG9w0BAQEFAASCAl8wggJbAgEAAoGBAKnmaVgN/XRIyZpY POTJSsiECLMb5P2vuoRtTVZqC4Li46iiLhxNlhpTN/Bdd7vKIvWKeIDMZKMOC/rp UP6jr1eu7B7NYrzKOWwe9LvcrywcnQMM+ADJ/lKZWjQP0HiVTBvGwmMdZFcTW2aE 1tK+usWLBFAAsOyW5RJg2Ke9A3QNAgMBAAECgYBsCMiJpnO5IqOXUm5+KIU2FccW ZTFqIvjeRkZ8IXhqZO3QiDf75VYCLVKPtE9ziOhL7B4OAGopyL/Tb9MB6IGQnVUk dFWHeJkJaeIKb4ejt4GeR+fG3chz/UyOP8QrSRvM+tudjcKYpIJ8MA+F5l4mf0FS DX7cb0zWmLYyJKtRHQJBANx+4BrV6g5sPoe/EMQNDfqE34KbHRAkQjZ3sbzjizTe mQMFadlHuavPFxcH1psKhtTID24BVIwV2ih3GijceusCQQDFQetO/VDywRUS/VjE /SNUTj+OSCIvbAfiwvxSwDxy0dByHiRmflxhJW8njuaT8lCBffstB+5/rfrouBQ6 ux7nAkALyEPVa0TcjHAy9MTClSgAEQWYhw1ghW98VZ0LyOTxaEuo26syTyDey2wi cOrI0iEuUZpxeGS6L5i+vM6LDG0NAkAuGJh3jgTjpbFaDbA34HvoEJ0Tj9HFSTaS jERQxjGaF2Phtx+EgBTwcsIF+YPyoNalXB5dSJQ4bBzNU28OxnmTAkA5aGFZD+3a D0mLlpmz9DV1fZYu0NOxVo6Af9VHBoIUHdcm0PbMZAKjKSqH+f63zDsZPtvm7b6j OI16OsDUXMHi -----END PRIVATE KEY-----`; return createSecureContext({ cert, key, ciphers: 'DEFAULT', minVersion: 'TLSv1.2' }); }
- added a commit that references this issue
on Sep 2, 2025 - added a commit that references this issue
on Sep 8, 2025 - added a commit that references this issue
on Sep 9, 2025
Metadata
Metadata
Assignees
Labels
docIssues and PRs related to Node.js documentation.Issues and PRs related to Node.js documentation.
Affected URL(s)
https://nodejs.org/docs/latest/api/tls.html#openssl-security-level
Description of the problem
Although the OpenSSL documentation does not mention it, the default security level was changed in OpenSSL 3.2 from 1 to 2; see openssl/openssl@b3a33da. This change was included in Node.js 24.5, but the Node.js "OpenSSL security levels" documentation was not updated.
This was an undocumented breaking change for me, though that's my responsibility for using the Current version. It should be clearly documented if the LTS version is upgraded to OpenSSL 3.5, though, or that version be forced to stay at security level 1.