Read OpenSSL's Built-in Paths and Runtime Settings with info
You will use openssl info to read the OpenSSL configuration directory, engine and provider module directories, separator characters, random seed sources and CPU settings. The command only reports values, so this workflow does not edit OpenSSL configuration or restart a service. Allow about ten minutes.
The route
Jump straight to the step you need, or tick off Done means at the end.
You need a shell and the openssl command. No elevated privileges are normally required. The examples were checked with the OpenSSL 3.6.1 executable available on this machine. The installed Ubuntu manpage belongs to package openssl 3.0.13-0ubuntu3.15 and is dated 18 August 2026, so confirm both the binary and the manual page when a version-specific result matters.
1. Confirm which OpenSSL you are querying
The info subcommand reports compiled-in information from the executable you run. A machine can have more than one OpenSSL installation, and man openssl-info can describe a distribution package while your shell finds another binary first.
$ command -v openssl
/home/linuxbrew/.linuxbrew/bin/openssl
$ openssl version -a
OpenSSL 3.6.1 27 Jan 2026 (Library: OpenSSL 3.6.1 27 Jan 2026)
...
The version line and path will differ on your host. If you need the distribution copy, invoke its absolute path after locating it, then use that same path for every query. Do not compare a path from one installation with values printed by another.
Checkpoint: record the executable path and version before putting any result into a service unit, build script or bug report.
2. Ask for the available items
Run -help to see the options supported by the binary:
$ openssl info -help
Usage: info [options]
General options:
-help Display this summary
Output options:
-configdir Default configuration file directory
-enginesdir Default engine module directory
-modulesdir Default module directory (other than engine modules)
-dsoext Configured extension for modules
-dirnamesep Directory-filename separator
-listsep List separator character
-seeds Seed sources
-cpusettings CPU settings info
The local 3.0-style manpage documents these eight output options. The newer 3.6.1 executable also lists -windowscontext, which is not present in that local manual. Read the help from the executable you will actually call rather than copying an option from a different OpenSSL release.
3. Query one value at a time
Choose exactly one output option for each invocation. OpenSSL writes the value without a descriptive label, which is useful in scripts but easy to misread at a prompt.
$ openssl info -configdir
/home/linuxbrew/.linuxbrew/etc/openssl@3
$ openssl info -modulesdir
/home/linuxbrew/.linuxbrew/Cellar/openssl@3/3.6.1/lib/ossl-modules
$ openssl info -enginesdir
/home/linuxbrew/.linuxbrew/Cellar/openssl@3/3.6.1/lib/engines-3
$ openssl info -dsoext
.so
These are paths and build settings, not instructions to create directories. The configuration directory is where this build expects its default OpenSSL configuration files. The modules directory is for dynamically loadable modules other than engine modules, while -enginesdir identifies the separate engine location. Do not copy a path from one host into another host's configuration without checking the target installation.
OpenSSL allows only one item per run. If you pass two, the command rejects the request rather than producing two labelled lines:
$ openssl info -configdir -modulesdir
info: only one item may be chosen
info: Use -help for summary.
Use separate command substitutions when a script needs more than one value:
config_dir=$(openssl info -configdir) || exit $?
modules_dir=$(openssl info -modulesdir) || exit $?
printf 'config=%s\nmodules=%s\n' "$config_dir" "$modules_dir"
Do not parse a label from the output. The documented contract is the value itself, followed by a newline.
4. Check separators before building a list
-dirnamesep prints the separator between a directory specification and a filename. -listsep prints the separator used for OpenSSL list values, typically the character used in a PATH-style list. They are different concepts.
$ openssl info -dirnamesep
/
$ openssl info -listsep
:
On this Linux build, a directory and filename are joined with /, while list entries are separated with :. Do not assume those values on another operating system, and do not use -dirnamesep as the separator for a list of module directories.
If you need to show invisible separators clearly, inspect the bytes:
$ openssl info -listsep | od -An -tx1c
3a 0a
: \n
Keep the newline out of a shell variable by using command substitution, as in the previous step. If you construct a list, quote the complete value and preserve the separator returned by OpenSSL.
5. Inspect seed and CPU information
Use -seeds and -cpusettings when diagnosing how this build was configured:
$ openssl info -seeds
os-specific
$ openssl info -cpusettings
OPENSSL_ia32cap=0x7ffaf3ffffebffff:0x00000000029c67af:...
The exact seed description and CPU setting string are build and platform dependent. Treat them as diagnostic output, not as a security verdict. In particular, a seed-source label does not replace checking the operating system's random facility or the application protocol using OpenSSL.
These values can expose installation details in logs. Before sending output to a public issue tracker, review paths, host-specific settings and any surrounding command output. There is no reason to run this command as root.
6. Handle the common mistakes safely
Running openssl info with no item is an error, not a request for a default report:
$ openssl info
info: No items chosen
info: Use -help for summary.
Add one documented option. If an option is rejected, run openssl info -help and check that the shell is using the binary you intended. The OpenSSL project documents that the command was added in OpenSSL 3.0. Current upstream documentation also records that -windowscontext was added in 3.4 and that -enginesdir is removed in OpenSSL 4.0. A script that needs to span those releases should test the supported option set instead of assuming every flag exists.
Most failures here are selection or provenance errors. Do not repair them by editing openssl.cnf, changing environment variables globally or replacing module files. Those actions change system behaviour and need a separate maintenance plan and rollback. For this guide, the recovery is simply to stop, identify the executable, read its help, and rerun one supported query.
Done means
- You recorded the exact OpenSSL executable and version being queried.
- You used one
infooutput option per command. - You can read configuration, engine and module paths without confusing their roles.
- You checked separators before constructing a platform-specific list.
- You treated seed and CPU output as build diagnostics, not proof of overall security.
- No configuration file, module, service or privilege setting was changed.