Skip to content

OpenSSL default security level changed to 2 in Node.js 24.5 but docs still say it's 1 #59715

Description

@carey

Affected URL(s)

https://nodejs.org/docs/latest/api/tls.html#openssl-security-level

Description of the problem

Although the OpenSSL documentation does not mention it, the default security level was changed in OpenSSL 3.2 from 1 to 2; see openssl/openssl@b3a33da. This change was included in Node.js 24.5, but the Node.js "OpenSSL security levels" documentation was not updated.

This was an undocumented breaking change for me, though that's my responsibility for using the Current version. It should be clearly documented if the LTS version is upgraded to OpenSSL 3.5, though, or that version be forced to stay at security level 1.

Activity

  1. added
    docIssues and PRs related to Node.js documentation.
    on Sep 2, 2025
  2. carey commented on Sep 2, 2025

    @carey
    Author

    In case it helps, here's a small function that can demonstrate that the OpenSSL default security level has changed. When run with Node.js 24.4.1, this returns successfully, but when run with Node.js 24.7 it fails with ERR_SSL_EE_KEY_TOO_SMALL. In the latter case, the failure can be worked around by changing ciphers: 'DEFAULT' to ciphers: 'DEFAULT@SECLEVEL=1'.

    export function testRSA1024Certificate() {
        const cert = `\
    -----BEGIN CERTIFICATE-----
    MIICCDCCAXGgAwIBAgIUZtwgcn39NWKzln0vATpxThbZ/48wDQYJKoZIhvcNAQEL
    BQAwFjEUMBIGA1UEAwwLZXhhbXBsZS5jb20wHhcNMjUwOTAyMDEzMjU2WhcNMzUw
    ODMxMDEzMjU2WjAWMRQwEgYDVQQDDAtleGFtcGxlLmNvbTCBnzANBgkqhkiG9w0B
    AQEFAAOBjQAwgYkCgYEAqeZpWA39dEjJmlg85MlKyIQIsxvk/a+6hG1NVmoLguLj
    qKIuHE2WGlM38F13u8oi9Yp4gMxkow4L+ulQ/qOvV67sHs1ivMo5bB70u9yvLByd
    Awz4AMn+UplaNA/QeJVMG8bCYx1kVxNbZoTW0r66xYsEUACw7JblEmDYp70DdA0C
    AwEAAaNTMFEwHQYDVR0OBBYEFBuvrmRphCSTez1A2kyJYqNJq4OpMB8GA1UdIwQY
    MBaAFBuvrmRphCSTez1A2kyJYqNJq4OpMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZI
    hvcNAQELBQADgYEAfyX0J2POn9+HKOrqoTlE121OwhG54VQsUiNJwpatqtK/9LeN
    nQaj4DsmcTZvUHrs6Z5vdJ4UzlNU+C0JWpEjoqAf85pXmom6KUb4PvkX+OCYsEnv
    Bfdk6Ji1fR3hLBz0o7bxWVEnkt2+Ax/efs//a7+LBWk7Y2+sjwh56wKOMOQ=
    -----END CERTIFICATE-----`;
        const key = `\
    -----BEGIN PRIVATE KEY-----
    MIICdQIBADANBgkqhkiG9w0BAQEFAASCAl8wggJbAgEAAoGBAKnmaVgN/XRIyZpY
    POTJSsiECLMb5P2vuoRtTVZqC4Li46iiLhxNlhpTN/Bdd7vKIvWKeIDMZKMOC/rp
    UP6jr1eu7B7NYrzKOWwe9LvcrywcnQMM+ADJ/lKZWjQP0HiVTBvGwmMdZFcTW2aE
    1tK+usWLBFAAsOyW5RJg2Ke9A3QNAgMBAAECgYBsCMiJpnO5IqOXUm5+KIU2FccW
    ZTFqIvjeRkZ8IXhqZO3QiDf75VYCLVKPtE9ziOhL7B4OAGopyL/Tb9MB6IGQnVUk
    dFWHeJkJaeIKb4ejt4GeR+fG3chz/UyOP8QrSRvM+tudjcKYpIJ8MA+F5l4mf0FS
    DX7cb0zWmLYyJKtRHQJBANx+4BrV6g5sPoe/EMQNDfqE34KbHRAkQjZ3sbzjizTe
    mQMFadlHuavPFxcH1psKhtTID24BVIwV2ih3GijceusCQQDFQetO/VDywRUS/VjE
    /SNUTj+OSCIvbAfiwvxSwDxy0dByHiRmflxhJW8njuaT8lCBffstB+5/rfrouBQ6
    ux7nAkALyEPVa0TcjHAy9MTClSgAEQWYhw1ghW98VZ0LyOTxaEuo26syTyDey2wi
    cOrI0iEuUZpxeGS6L5i+vM6LDG0NAkAuGJh3jgTjpbFaDbA34HvoEJ0Tj9HFSTaS
    jERQxjGaF2Phtx+EgBTwcsIF+YPyoNalXB5dSJQ4bBzNU28OxnmTAkA5aGFZD+3a
    D0mLlpmz9DV1fZYu0NOxVo6Af9VHBoIUHdcm0PbMZAKjKSqH+f63zDsZPtvm7b6j
    OI16OsDUXMHi
    -----END PRIVATE KEY-----`;
        return createSecureContext({ cert, key, ciphers: 'DEFAULT', minVersion: 'TLSv1.2' });
    }
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    docIssues and PRs related to Node.js documentation.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions