diff --git a/INSTALL b/INSTALL
index 77656b2c..78390d5 100644
--- a/INSTALL
+++ b/INSTALL
@@ -66,10 +66,10 @@
   (1) TUN and/or TAP driver to allow user-space programs to control
       a virtual point-to-point IP or Ethernet device.
       See TUN/TAP Driver References section below for more info.
-  (2a) OpenSSL library, necessary for encryption, version 1.1.0 or higher
+  (2a) OpenSSL library, necessary for encryption, version 1.1.1 or higher
       required, available from https://www.openssl.org/
       or
-  (2b) mbed TLS library, an alternative for encryption, version 2.0 or higher
+  (2b) mbed TLS library, an alternative for encryption, version 3.2.1 or higher
       required, available from https://tls.mbed.org/
   (3) on Linux, "libnl-gen" is required for kernel netlink support
   (4) on Linux, "libcap-ng" is required for Linux capability handling
diff --git a/configure.ac b/configure.ac
index 188f8fa..1aec805 100644
--- a/configure.ac
+++ b/configure.ac
@@ -776,7 +776,7 @@
 		# if the user did not explicitly specify flags, try to autodetect
 		PKG_CHECK_MODULES(
 			[OPENSSL],
-			[openssl >= 1.1.0],
+			[openssl >= 1.1.1],
 			[have_openssl="yes"],
 			[AC_MSG_WARN([OpenSSL not found by pkg-config ${pkg_config_found}])] # If this fails, we will do another test next
 		)
@@ -799,7 +799,7 @@
 				]],
 				[[
 /*	     Version encoding: MNNFFPPS - see opensslv.h for details */
-#if OPENSSL_VERSION_NUMBER < 0x10100000L
+#if OPENSSL_VERSION_NUMBER < 0x10101000L
 #error OpenSSL too old
 #endif
 				]]
diff --git a/src/openvpn/openssl_compat.h b/src/openvpn/openssl_compat.h
index b61bcbf..098bdd5 100644
--- a/src/openvpn/openssl_compat.h
+++ b/src/openvpn/openssl_compat.h
@@ -26,9 +26,9 @@
  * OpenSSL compatibility stub
  *
  * This file provide compatibility stubs for the OpenSSL libraries
- * prior to version 1.1. This version introduces many changes in the
- * library interface, including the fact that various objects and
- * structures are not fully opaque.
+ * prior to the current major version. Newer versions may introduce changes
+ * in the library interface, including replacing functions or enforcing
+ * various objects and structures as fully opaque.
  */
 
 #ifndef OPENSSL_COMPAT_H_
@@ -62,11 +62,6 @@
 #endif
 
 
-/* Functionality missing in 1.1.0 */
-#if OPENSSL_VERSION_NUMBER < 0x10101000L && !defined(ENABLE_CRYPTO_WOLFSSL)
-#define SSL_CTX_set1_groups SSL_CTX_set1_curves
-#endif
-
 /* Functionality missing in LibreSSL before 3.5 */
 #if defined(LIBRESSL_VERSION_NUMBER) && LIBRESSL_VERSION_NUMBER < 0x3050000fL
 #define EVP_CTRL_AEAD_SET_TAG EVP_CTRL_GCM_SET_TAG
diff --git a/src/openvpn/ssl_openssl.c b/src/openvpn/ssl_openssl.c
index ef99b22..32b13db 100644
--- a/src/openvpn/ssl_openssl.c
+++ b/src/openvpn/ssl_openssl.c
@@ -200,42 +200,12 @@
 
 /*
  * Return maximum TLS version supported by local OpenSSL library.
- * Assume that presence of SSL_OP_NO_TLSvX macro indicates that
- * TLSvX is supported.
+ * We only support OpenSSL versions that support TLS 1.3.
  */
 int
 tls_version_max(void)
 {
-#if defined(TLS1_3_VERSION)
-    /* If this is defined we can safely assume TLS 1.3 support */
     return TLS_VER_1_3;
-#elif OPENSSL_VERSION_NUMBER >= 0x10100000L
-    /*
-     * If TLS_VER_1_3 is not defined, we were compiled against a version that
-     * did not support TLS 1.3.
-     *
-     * However, the library we are *linked* against might be OpenSSL 1.1.1
-     * and therefore supports TLS 1.3. This needs to be checked at runtime
-     * since we can be compiled against 1.1.0 and then the library can be
-     * upgraded to 1.1.1.
-     * We only need to check this for OpenSSL versions that can be
-     * upgraded to 1.1.1 without recompile (>= 1.1.0)
-     */
-    if (OpenSSL_version_num() >= 0x1010100fL)
-    {
-        return TLS_VER_1_3;
-    }
-    else
-    {
-        return TLS_VER_1_2;
-    }
-#elif defined(TLS1_2_VERSION) || defined(SSL_OP_NO_TLSv1_2)
-    return TLS_VER_1_2;
-#elif defined(TLS1_1_VERSION) || defined(SSL_OP_NO_TLSv1_1)
-    return TLS_VER_1_1;
-#else /* if defined(TLS1_3_VERSION) */
-    return TLS_VER_1_0;
-#endif
 }
 
 /** Convert internal version number to openssl version number */
@@ -256,22 +226,7 @@
     }
     else if (ver == TLS_VER_1_3)
     {
-        /*
-         * Supporting the library upgraded to TLS1.3 without recompile
-         * is enough to support here with a simple constant that the same
-         * as in the TLS 1.3, so spec it is very unlikely that OpenSSL
-         * will change this constant
-         */
-#ifndef TLS1_3_VERSION
-        /*
-         * We do not want to define TLS_VER_1_3 if not defined
-         * since other parts of the code use the existance of this macro
-         * as proxy for TLS 1.3 support
-         */
-        return 0x0304;
-#else
         return TLS1_3_VERSION;
-#endif
     }
     return 0;
 }
@@ -491,8 +446,8 @@
      */
     if (strlen(ciphers) >= (len - 1))
     {
-        msg(M_FATAL, "Failed to set restricted TLS 1.3 cipher list, too long (>%d).",
-            (int)(len - 1));
+        msg(M_FATAL, "Failed to set restricted TLS 1.3 cipher list, too long (>%zd).",
+            len - 1);
     }
 
     strncpy(openssl_ciphers, ciphers, len);
@@ -511,17 +466,11 @@
 {
     if (ciphers == NULL)
     {
-        /* default cipher list of OpenSSL 1.1.1 is sane, do not set own
+        /* default cipher list of OpenSSL is sane, do not set own
          * default as we do with tls-cipher */
         return;
     }
 
-#if !defined(TLS1_3_VERSION)
-    crypto_msg(M_WARN,
-               "Not compiled with OpenSSL 1.1.1 or higher. "
-               "Ignoring TLS 1.3 only tls-ciphersuites '%s' setting.",
-               ciphers);
-#else
     ASSERT(NULL != ctx);
 
     char openssl_ciphers[4096];
@@ -531,14 +480,12 @@
     {
         crypto_msg(M_FATAL, "Failed to set restricted TLS 1.3 cipher list: %s", openssl_ciphers);
     }
-#endif
 }
 
 void
 tls_ctx_set_cert_profile(struct tls_root_ctx *ctx, const char *profile)
 {
-#if OPENSSL_VERSION_NUMBER > 0x10100000L                                            \
-    && (!defined(LIBRESSL_VERSION_NUMBER) || LIBRESSL_VERSION_NUMBER > 0x3060000fL) \
+#if (!defined(LIBRESSL_VERSION_NUMBER) || LIBRESSL_VERSION_NUMBER > 0x3060000fL) \
     && !defined(OPENSSL_IS_AWSLC)
     /* OpenSSL does not have certificate profiles, but a complex set of
      * callbacks that we could try to implement to achieve something similar.
@@ -565,7 +512,7 @@
     {
         msg(M_FATAL, "ERROR: Invalid cert profile: %s", profile);
     }
-#else  /* if OPENSSL_VERSION_NUMBER > 0x10100000L */
+#else
     if (profile)
     {
         msg(M_WARN,
@@ -573,7 +520,7 @@
             "support --tls-cert-profile, ignoring user-set profile: '%s'",
             profile);
     }
-#endif /* if OPENSSL_VERSION_NUMBER > 0x10100000L */
+#endif
 }
 
 void
@@ -2597,14 +2544,12 @@
         crypto_msg(M_FATAL, "Cannot create SSL_CTX object");
     }
 
-#if defined(TLS1_3_VERSION)
     if (tls13)
     {
         SSL_CTX_set_min_proto_version(tls_ctx.ctx, TLS1_3_VERSION);
         tls_ctx_restrict_ciphers_tls13(&tls_ctx, cipher_list);
     }
     else
-#endif
     {
         SSL_CTX_set_max_proto_version(tls_ctx.ctx, TLS1_2_VERSION);
         tls_ctx_restrict_ciphers(&tls_ctx, cipher_list);
@@ -2618,7 +2563,7 @@
         crypto_msg(M_FATAL, "Cannot create SSL object");
     }
 
-#if OPENSSL_VERSION_NUMBER < 0x1010000fL || defined(OPENSSL_IS_AWSLC) || defined(ENABLE_CRYPTO_WOLFSSL)
+#if defined(OPENSSL_IS_AWSLC) || defined(ENABLE_CRYPTO_WOLFSSL)
     STACK_OF(SSL_CIPHER) *sk = SSL_get_ciphers(ssl);
 #else
     STACK_OF(SSL_CIPHER) *sk = SSL_get1_supported_ciphers(ssl);
@@ -2646,9 +2591,7 @@
             printf("%s\n", pair->iana_name);
         }
     }
-#if (OPENSSL_VERSION_NUMBER >= 0x1010000fL)
     sk_SSL_CIPHER_free(sk);
-#endif
     SSL_free(ssl);
     SSL_CTX_free(tls_ctx.ctx);
 }
diff --git a/tests/unit_tests/openvpn/test_ncp.c b/tests/unit_tests/openvpn/test_ncp.c
index 29365db..99e1aac 100644
--- a/tests/unit_tests/openvpn/test_ncp.c
+++ b/tests/unit_tests/openvpn/test_ncp.c
@@ -110,7 +110,7 @@
     assert_string_equal(mutate_ncp_cipher_list("AES-256-GCM:?AES-128-CCM:AES-128-GCM", &gc),
                         aes_ciphers);
 
-    /* For testing that with OpenSSL 1.1.0+ that also accepts ciphers in
+    /* For testing that with OpenSSL that also accepts ciphers in
      * a different spelling the normalised cipher output is the same */
     bool have_chacha_mixed_case = cipher_valid("ChaCha20-Poly1305");
     if (have_chacha_mixed_case)
