OpenSSL is the go-to command-line tool for creating private keys, certificate signing requests (CSRs), self-signed certificates, and checking TLS connections. The OpenSSL project publishes source code only, so on Windows 11 you install a trusted prebuilt package instead. This guide covers the easiest options (winget, a Windows installer, or the copy bundled with Git), how to add OpenSSL to your PATH, and a few commands to get started.
Quick Answer
Open Terminal and run winget install ShiningLight.OpenSSL.Light. Close and reopen Terminal, then run openssl version. If Windows says the command isn’t recognized, add C:\Program Files\OpenSSL-Win64\bin to your Path environment variable.

Method 1: Install with winget (Recommended)
- Right-click Start and choose Terminal.
- Run
winget search opensslto see available packages. The Shining Light builds (listed on the OpenSSL project’s binaries page) are the most common. - Install the light version:
winget install ShiningLight.OpenSSL.Light. Developers who need headers and libraries for compiling can installShiningLight.OpenSSL.Devinstead. - Close Terminal and open a new window.
- Run
openssl version.
Method 2: Use the Windows Installer
- Visit the Shining Light Productions “Win32/Win64 OpenSSL” page (linked from the OpenSSL wiki’s binaries list).
- Download the latest Win64 OpenSSL v3.x Light MSI (or EXE) installer.
- Run it and accept the default location, C:\Program Files\OpenSSL-Win64.
- When asked where to copy OpenSSL DLLs, choose The OpenSSL binaries (/bin) directory.
- Finish setup, then add the bin folder to PATH (next section).
Add OpenSSL to PATH
- Search Start for Edit the system environment variables and open it.
- Click Environment Variables.
- Under User variables, select Path and click Edit.
- Click New and enter
C:\Program Files\OpenSSL-Win64\bin. - Click OK on each window, then open a new Terminal and run
openssl version.
Method 3: Use the OpenSSL Included with Git for Windows
If you already have Git for Windows, it includes OpenSSL. Open Git Bash and run openssl version, or add C:\Program Files\Git\usr\bin to PATH to use it elsewhere. This version may lag behind the latest release. See our guide to installing Git on Windows 11.
Method 4: WSL
If you use the Windows Subsystem for Linux, OpenSSL is usually preinstalled in Ubuntu. Run openssl version in your WSL terminal, or install it with sudo apt install openssl.
Useful OpenSSL Commands
- Create a private key:
openssl genrsa -out private.key 2048 - Create a CSR:
openssl req -new -key private.key -out request.csr - Self-signed certificate (1 year):
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365 -nodes - View a certificate:
openssl x509 -in cert.pem -text -noout - Test a website’s TLS:
openssl s_client -connect example.com:443 - Convert PEM to PFX:
openssl pkcs12 -export -out cert.pfx -inkey key.pem -in cert.pem
Troubleshooting
- “openssl is not recognized”: open a new Terminal after installing, and confirm the bin folder is in PATH.
- Wrong version runs: another program’s OpenSSL (for example, Git’s) is earlier in PATH. Run
where.exe opensslto see which copies exist and reorder PATH entries. - “Can’t open config file” warnings: set the
OPENSSL_CONFvariable to the openssl.cfg file in the install folder, or reinstall with defaults. - Avoid random download sites: use winget, the binaries list on the OpenSSL wiki, or a trusted package manager.
Frequently Asked Questions
Is OpenSSL free?
Yes. OpenSSL is open source under the Apache 2.0 license.
Light vs. full version: which do I need?
The Light version is enough for command-line use. The full (Dev) version adds headers and libraries for compiling software.
How do I update OpenSSL?
Run winget upgrade ShiningLight.OpenSSL.Light, or download the latest installer.
Summary
- Install with
winget install ShiningLight.OpenSSL.Lightor the Win64 installer. - Add C:\Program Files\OpenSSL-Win64\bin to PATH if needed.
- Verify with
openssl version. - Use Git’s or WSL’s OpenSSL as alternatives.

Kermit Matthews is a freelance writer based in Philadelphia, Pennsylvania with more than a decade of experience writing technology guides. He has a Bachelor’s and Master’s degree in Computer Science and has spent much of his professional career in IT management.
He specializes in writing content about iPhones, Android devices, Microsoft Office, and many other popular applications and devices.