wolfSSL is adding RFC 9338 COSE Countersignature support to wolfCOSE, letting a second party sign over an already-signed, encrypted, or MAC’d COSE message. Countersignatures matter for notarization, timestamping, and multi-party workflows, proving that a message existed and was endorsed by an additional authority after the fact, and making wolfCOSE a fit for supply-chain and attestation […]
Read MoreMore TagMonth: September 2026
What We’ve Been Building: A wolfMQTT Update
Since the wolfMQTT 2.1.0 release back in July, the team has been busy working on some major upgrades. Whether you’re running a client or a broker, there’s a lot to dig into in the current master branch on GitHub. We’ve focused on smoothing out the developer experience, tightening up protocol compliance, and, most importantly, a […]
Read MoreMore TagBringing wolfSSL in line with RFC 9846
RFC 9846, published in July 2026, obsoletes RFC 8446 as the specification for TLS 1.3. It is a minor revision in that it is backward compatible, but it tightens a number of requirements that were previously advisory. At wolfSSL, we are working hard on implementing the specification. No KeyUpdate while sending early data. Section 5.5 […]
Read MoreMore TagOpenBao FIPS 140-3 Support with wolfProvider
OpenBao is an open-source secrets management platform used to store, manage, and distribute credentials, encryption keys, and certificates. wolfSSL is evaluating OpenBao with wolfProvider to verify operation with wolfCrypt FIPS. OpenBao can use FIPS 140-3 validated cryptography through wolfProvider with no code changes to OpenBao and potentially no code changes to applications using it, provided […]
Read MoreMore TagwolfBoot now supports booting FAT32 and ext4 Filesystems
wolfBoot can now read a signed firmware image from a file on a filesystem. This applies to the disk boot path, which covers SD cards, eMMC, SATA and NVMe targets. The feature is read only, optional, and off by default. What it does wolfBoot has supported MBR and GPT partition tables on disk targets for […]
Read MoreMore TagwolfSSL Advances Embedded Security with wolfIP, New Post-Quantum Capabilities and AURIX™ TC4xx Support
wolfSSL announced three advances for embedded systems: the deterministic wolfIP TCP/IP stack, broader post-quantum support spanning NIST-validated algorithms and native Falcon and FrodoKEM implementations, and wolfHSM support for the Infineon AURIX™ TC4xx. Together, these capabilities support predictable networking, the transition to post-quantum cryptography, and isolated cryptographic services for automotive systems. EDMONDS, Wash., Sept. 21, 2026 […]
Read MoreMore TagwolfSSL at the Toradex Booth: Post-Quantum the SMARC iMX95 SoM
Heading to Embedded World North America (September 22–24)? Stop by Toradex at Booth 6222 to see wolfSSL’s live Post-Quantum Cryptography (PQC) demo on the Toradex SMARC iMX95 module. Afterward, visit the wolfSSL booth (#6027) to say hi and talk with our team. The Demo at a Glance We demonstrate post-quantum security across both halves of […]
Read MoreMore TagLive Webinar: Rock-Solid curl: Long-Term Support for Stable Deployments
Products with long deployment lifecycles must continue receiving curl security fixes. Moving through frequent curl releases, however, can introduce unrelated features and behavioral changes, requiring additional integration and regression testing. Join this webinar to learn how Rock-Solid curl supports a stable curl and libcurl release branch for five years. See how security and selected stability […]
Read MoreMore TagAnnouncing wolfCOSE v2.0.0
We are excited to announce wolfCOSE 2.0.0, a major update to wolfSSL’s complete, zero-allocation C implementation of CBOR (RFC 8949) and COSE (RFC 9052) built on wolfCrypt. This release adds standardized HSS/LMS stateful hash-based signatures, RFC 9338 countersignatures, RFC 9783 PSA/EAT attestation, RFC 9864 fully specified signature algorithms, delegated signing, and experimental COSE-HPKE, while preserving […]
Read MoreMore TagTop 10 Things to Reduce wolfSSL Code Size
wolfSSL is one of the smallest commercial TLS / crypto libraries available. Pulling the right configuration levers is the biggest challenge. This post is a short tour of the ten biggest knobs. Two ways to configure the build Every define and flag below can be supplied through either of these paths: Autoconf / configure(./configure): Pass […]
Read MoreMore Tag
