The state of SSL stacks
Willy Tarreau and William Lallemand have posted an extensive whitepaper examining the landscape of the available SSL implementations.
OpenSSL 3.0 performs significantly worse than alternative SSLlibraries, forcing organizations to provision more hardware just tomaintain existing throughput. This raises important questions aboutperformance, energy efficiency, and operational costs.Examining alternatives-BoringSSL, LibreSSL, WolfSSL, andAWS-LC-reveals a landscape of trade-offs. Each offers differentapproaches to API compatibility, performance optimization, and QUICsupport. For developers navigating the modern SSL ecosystem,understanding these trade-offs is crucial for optimizingperformance, maintaining compatibility, and future-proofing theirinfrastructure.