How to Install OpenSSL on Windows 11 (winget, Installer, or Git)

OpenSSL is the go-to command-line tool for creating private keys, certificate signing requests (CSRs), self-signed certificates, and checking TLS connections. The OpenSSL project publishes source code only, so on Windows 11 you install a trusted prebuilt package instead. This guide covers the easiest options (winget, a Windows installer, or the copy bundled with Git), how to add OpenSSL to your PATH, and a few commands to get started.

Quick Answer

Open Terminal and run winget install ShiningLight.OpenSSL.Light. Close and reopen Terminal, then run openssl version. If Windows says the command isn’t recognized, add C:\Program Files\OpenSSL-Win64\bin to your Path environment variable.

Terminal window installing OpenSSL with winget and then running openssl version, with the install command and the version output highlighted
(1) Install OpenSSL with winget; (2) confirm it works with openssl version.

Method 1: Install with winget (Recommended)

  1. Right-click Start and choose Terminal.
  2. Run winget search openssl to see available packages. The Shining Light builds (listed on the OpenSSL project’s binaries page) are the most common.
  3. Install the light version: winget install ShiningLight.OpenSSL.Light. Developers who need headers and libraries for compiling can install ShiningLight.OpenSSL.Dev instead.
  4. Close Terminal and open a new window.
  5. Run openssl version.

Method 2: Use the Windows Installer

  1. Visit the Shining Light Productions “Win32/Win64 OpenSSL” page (linked from the OpenSSL wiki’s binaries list).
  2. Download the latest Win64 OpenSSL v3.x Light MSI (or EXE) installer.
  3. Run it and accept the default location, C:\Program Files\OpenSSL-Win64.
  4. When asked where to copy OpenSSL DLLs, choose The OpenSSL binaries (/bin) directory.
  5. Finish setup, then add the bin folder to PATH (next section).

Add OpenSSL to PATH

  1. Search Start for Edit the system environment variables and open it.
  2. Click Environment Variables.
  3. Under User variables, select Path and click Edit.
  4. Click New and enter C:\Program Files\OpenSSL-Win64\bin.
  5. Click OK on each window, then open a new Terminal and run openssl version.

Method 3: Use the OpenSSL Included with Git for Windows

If you already have Git for Windows, it includes OpenSSL. Open Git Bash and run openssl version, or add C:\Program Files\Git\usr\bin to PATH to use it elsewhere. This version may lag behind the latest release. See our guide to installing Git on Windows 11.

Method 4: WSL

If you use the Windows Subsystem for Linux, OpenSSL is usually preinstalled in Ubuntu. Run openssl version in your WSL terminal, or install it with sudo apt install openssl.

Useful OpenSSL Commands

  • Create a private key: openssl genrsa -out private.key 2048
  • Create a CSR: openssl req -new -key private.key -out request.csr
  • Self-signed certificate (1 year): openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes
  • View a certificate: openssl x509 -in cert.pem -text -noout
  • Test a website’s TLS: openssl s_client -connect example.com:443
  • Convert PEM to PFX: openssl pkcs12 -export -out cert.pfx -inkey key.pem -in cert.pem

Troubleshooting

  • “openssl is not recognized”: open a new Terminal after installing, and confirm the bin folder is in PATH.
  • Wrong version runs: another program’s OpenSSL (for example, Git’s) is earlier in PATH. Run where.exe openssl to see which copies exist and reorder PATH entries.
  • “Can’t open config file” warnings: set the OPENSSL_CONF variable to the openssl.cfg file in the install folder, or reinstall with defaults.
  • Avoid random download sites: use winget, the binaries list on the OpenSSL wiki, or a trusted package manager.

Frequently Asked Questions

Is OpenSSL free?

Yes. OpenSSL is open source under the Apache 2.0 license.

Light vs. full version: which do I need?

The Light version is enough for command-line use. The full (Dev) version adds headers and libraries for compiling software.

How do I update OpenSSL?

Run winget upgrade ShiningLight.OpenSSL.Light, or download the latest installer.

Summary

  1. Install with winget install ShiningLight.OpenSSL.Light or the Win64 installer.
  2. Add C:\Program Files\OpenSSL-Win64\bin to PATH if needed.
  3. Verify with openssl version.
  4. Use Git’s or WSL’s OpenSSL as alternatives.