The OpenSSL project publishes source code, not Windows installers, so on Windows 10 you install OpenSSL from a third-party build, from a tool that already includes it, or inside WSL. The quickest route is the Windows Package Manager: open Terminal and run winget search openssl, then install the build you choose with winget install --id <ID>. The OpenSSL project lists known Windows builds on its binary distributions page, but doesn’t endorse any of them, so check the publisher before installing.

Option 1: Install with winget
- Right-click Start and open Windows PowerShell or Terminal.
- Run
winget search opensslto list available packages and their publishers. - Choose a well-known, maintained build and run
winget install --id <ID>with the ID from the list. - Close and reopen the terminal so the new PATH is picked up.
- Run
openssl versionto confirm it works.
If the command isn’t found, the installer didn’t add OpenSSL to PATH. Add its bin folder (often inside C:\Program Files\OpenSSL-Win64) to your Path variable. See how to set environment variables in Windows 10.
Option 2: Use the copy in Git for Windows
If Git for Windows is installed, you already have OpenSSL. Open Git Bash and run openssl version. From Command Prompt, the file is usually at C:\Program Files\Git\usr\bin\openssl.exe. This is a good option if you only need OpenSSL occasionally for certificates or hashes.
Option 3: Use WSL
If you work with Linux tools, install WSL and Ubuntu (see how to install WSL on Windows 10), then run sudo apt update && sudo apt install openssl. OpenSSL runs inside Linux and can still read your Windows files under /mnt/c.
Check the version
Run openssl version -a to see the version, build date and where OpenSSL looks for its configuration. The OpenSSL documentation explains each field. Use a currently supported release line, such as 3.5 (a long-term support release), and keep it updated, since older versions stop receiving security fixes.
Common commands
| Task | Command |
|---|---|
| Show the version | openssl version |
| Create a private key and self-signed certificate | openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes |
| Create a certificate signing request | openssl req -new -key key.pem -out request.csr |
| Read a certificate | openssl x509 -in cert.pem -text -noout |
| SHA-256 hash of a file | openssl dgst -sha256 file.zip |
| Test an HTTPS connection | openssl s_client -connect example.com:443 |
On Windows, PowerShell’s Get-FileHash also computes hashes without OpenSSL.
Troubleshooting
“openssl is not recognized as an internal or external command”
OpenSSL isn’t on your PATH, or the terminal was open before you installed it. Reopen the terminal, then check the Path variable.
“Can’t open openssl.cnf”
Some builds don’t set the configuration path. Set it for the session with set OPENSSL_CONF=C:\path\to\openssl.cnf in Command Prompt, using your build’s actual path.
Two different versions run
Several programs bundle their own OpenSSL. Run where openssl to see which one Windows finds first, and reorder or remove Path entries if needed.
Frequently asked questions
Is there an official OpenSSL installer for Windows?
No. The project only distributes source code and lists third-party builds for convenience.
Do I need OpenSSL for Python or Node.js?
No. They include their own TLS libraries. See how to install Python and how to install Node.js on Windows 10.
Summary
- OpenSSL has no official Windows installer.
- Use
winget search openssland install a trusted build. - Or use the copy in Git for Windows, or install it in WSL.
- Confirm with
openssl version.

Matt Jacobs has been working as an IT consultant for small businesses since receiving his Master’s degree in 2003. While he still does some consulting work, his primary focus now is on creating technology support content for SupportYourTech.com.
His work can be found on many websites and focuses on topics such as Microsoft Office, Apple devices, Android devices, Photoshop, and more.