How to Install OpenSSL in Windows 10

The OpenSSL project publishes source code, not Windows installers, so on Windows 10 you install OpenSSL from a third-party build, from a tool that already includes it, or inside WSL. The quickest route is the Windows Package Manager: open Terminal and run winget search openssl, then install the build you choose with winget install --id <ID>. The OpenSSL project lists known Windows builds on its binary distributions page, but doesn’t endorse any of them, so check the publisher before installing.

Ways to install OpenSSL on Windows 10
Use winget, Git for Windows or WSL. This is a drawing, not a screenshot.

Option 1: Install with winget

  1. Right-click Start and open Windows PowerShell or Terminal.
  2. Run winget search openssl to list available packages and their publishers.
  3. Choose a well-known, maintained build and run winget install --id <ID> with the ID from the list.
  4. Close and reopen the terminal so the new PATH is picked up.
  5. Run openssl version to confirm it works.

If the command isn’t found, the installer didn’t add OpenSSL to PATH. Add its bin folder (often inside C:\Program Files\OpenSSL-Win64) to your Path variable. See how to set environment variables in Windows 10.

Option 2: Use the copy in Git for Windows

If Git for Windows is installed, you already have OpenSSL. Open Git Bash and run openssl version. From Command Prompt, the file is usually at C:\Program Files\Git\usr\bin\openssl.exe. This is a good option if you only need OpenSSL occasionally for certificates or hashes.

Option 3: Use WSL

If you work with Linux tools, install WSL and Ubuntu (see how to install WSL on Windows 10), then run sudo apt update && sudo apt install openssl. OpenSSL runs inside Linux and can still read your Windows files under /mnt/c.

Check the version

Run openssl version -a to see the version, build date and where OpenSSL looks for its configuration. The OpenSSL documentation explains each field. Use a currently supported release line, such as 3.5 (a long-term support release), and keep it updated, since older versions stop receiving security fixes.

Common commands

TaskCommand
Show the versionopenssl version
Create a private key and self-signed certificateopenssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes
Create a certificate signing requestopenssl req -new -key key.pem -out request.csr
Read a certificateopenssl x509 -in cert.pem -text -noout
SHA-256 hash of a fileopenssl dgst -sha256 file.zip
Test an HTTPS connectionopenssl s_client -connect example.com:443

On Windows, PowerShell’s Get-FileHash also computes hashes without OpenSSL.

Troubleshooting

“openssl is not recognized as an internal or external command”

OpenSSL isn’t on your PATH, or the terminal was open before you installed it. Reopen the terminal, then check the Path variable.

“Can’t open openssl.cnf”

Some builds don’t set the configuration path. Set it for the session with set OPENSSL_CONF=C:\path\to\openssl.cnf in Command Prompt, using your build’s actual path.

Two different versions run

Several programs bundle their own OpenSSL. Run where openssl to see which one Windows finds first, and reorder or remove Path entries if needed.

Frequently asked questions

Is there an official OpenSSL installer for Windows?

No. The project only distributes source code and lists third-party builds for convenience.

Do I need OpenSSL for Python or Node.js?

No. They include their own TLS libraries. See how to install Python and how to install Node.js on Windows 10.

Summary

  • OpenSSL has no official Windows installer.
  • Use winget search openssl and install a trusted build.
  • Or use the copy in Git for Windows, or install it in WSL.
  • Confirm with openssl version.

Get Our Free Newsletter

How-to guides and tech deals

You may opt out at any time.
Read our Privacy Policy