Read OpenSSL Build Details with openssl version
You will finish with a reproducible OpenSSL report: the version your shell runs, the library it loads, its build date, installation directories, compiler flags and platform settings. The openssl version command only reports information, so these checks do not alter keys, certificates, services or configuration.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about five minutes. You need a shell and the OpenSSL executable you want to inspect. No elevated privileges are required. The examples use the command found by your current PATH, which matters when a distribution copy and a manually installed copy coexist.
Checkpoint: identify the executable
- Find the command that your shell will run.
command -v openssl
readlink -f "$(command -v openssl)"
The first line prints the selected command path. The second resolves a symlink when the platform provides readlink. If the command is missing, install OpenSSL using your operating system's normal package method, then repeat this check. Do not assume that a manpage and an executable with the same name came from the same installation.
Checkpoint: read the short version report
- Print the version of the executable and the library it is using.
openssl version
On the machine used for this guide, the result is:
OpenSSL 3.6.1 27 Jan 2026 (Library: OpenSSL 3.6.1 27 Jan 2026)
The exact version and date will differ elsewhere. The parenthesised library value is useful because the command can be one installation while its shared library comes from another. If the two versions differ, stop before diagnosing a package or application. Check the executable path, your dynamic library search path, and the process environment first.
Checkpoint: collect the full diagnostic
- Ask for every report category in one command.
openssl version -a
This is the report normally worth attaching to an OpenSSL bug report. It combines the individual switches:
-vprints the current OpenSSL version.-bprints the build date.-oprints internal option information.-fprints compiler flags.-pprints the target platform.-dprints theOPENSSLDIRsetting.-eprints the engines directory.-mprints the modules directory.-rprints random seeding source settings.-cprints CPU settings information.
These values describe how this copy was built and where it expects supporting files. They are not instructions to edit those directories. In particular, do not delete, replace or recursively change anything under OPENSSLDIR, the engines directory or the modules directory merely because a path looks unexpected. Those changes can break applications or alter cryptographic provider behaviour.
Inspect one detail at a time
Use a single switch when a script or a support request needs one field. The following commands are read-only:
openssl version -v
openssl version -b
openssl version -p
openssl version -d
openssl version -e
openssl version -m
openssl version -r
openssl version -c
For example, the local executable reports a build platform of linux-x86_64 and an OPENSSLDIR of /home/linuxbrew/.linuxbrew/etc/openssl@3. Treat paths as output, not portable constants. A Debian package may use different directories, and a container or virtual environment may intentionally use its own installation.
The -o and -f fields are especially useful when comparing two builds. Compiler options can explain performance, portability or hardening differences, but they do not by themselves prove that an application is loading this library. If the problem occurs in a service, inspect that service's actual executable and environment as well.
Check the interface before copying examples
- Display the options supported by the executable you are about to script.
openssl version -help
OpenSSL 3.6.1 lists -a, -v, -b, -o, -f, -p, -d, -e, -m, -r and -c. The installed manpage is dated for the system's OpenSSL 3.0.13 package, while the executable selected in this shell is OpenSSL 3.6.1 from Linuxbrew. That mismatch is a useful warning: read the help for the executable you will run, and record both versions when reporting a problem.
Do not parse the human-readable full report by assuming that every line exists on every release. If automation needs a stable value, use the smallest supported command and validate its output for the specific OpenSSL versions in your fleet. Keep the command's standard output and exit status in your diagnostic record.
Common traps
Wrong installation: openssl version answers for the first matching executable in PATH. Use command -v and an absolute path when comparing installations.
Confusing package and library versions: a package manager's version describes its package, not necessarily the binary selected by the current shell. Record the package query and command path separately.
Sharing sensitive output: the report is usually safe as a build diagnostic, but paths can reveal usernames, deployment layout or custom directories. Review it before posting publicly. Never paste private keys, passphrases or certificate files alongside it.
Expecting a repair: this command does not update OpenSSL, reload a daemon or fix a provider. If you need to change a package or service, take a separate backup and change-management step. There is nothing to undo from the examples above because they make no state changes.
Done means
- You know which
opensslexecutable your shell selected. openssl versionreports the executable and library versions.openssl version -ahas captured the build and directory details.openssl version -helphas confirmed the options supported by that executable.- You have kept package metadata, command paths and OpenSSL output distinct.