Scope: the full wolfCrypt algorithm suite vs MbedTLS, measured the same way on four platforms (Intel x86_64, a Raspberry Pi 5 (ARMv8-A Cortex-A76), a bare-metal STM32H563 Cortex-M33, and a Microchip PolarFire SoC RISC-V U54), plus the post-quantum and extended-algorithm coverage MbedTLS does not have. wolfSSL v5.9.1, MbedTLS 3.6.6, June 2026. Method: identical sources built from […]
Read MoreMore TagCategory: Uncategorized
Firmware TPM 2.0 (fTPM) on Microchip PolarFire SoC
We just opened a PR adding a wolfTPM Firmware TPM (fTPM) example for the Microchip PolarFire SoC, validated end-to-end on the MPFS250T Video Kit. It runs a full TPM 2.0 service on a dedicated RISC-V hart, isolated from Linux, with no discrete TPM chip and no third-party TEE. Why this matters Most TPM integrations need […]
Read MoreMore Tagcurl/libcurl FIPS 140-3 Tested & Available with wolfCrypt FIPS
curl and libcurl are widely used tools and libraries for transferring data using protocols such as HTTPS, FTP, SFTP, and MQTT. FIPS 140-3 support is available for curl/libcurl with wolfCrypt FIPS, tested for use with curl/libcurl environments. wolfCrypt FIPS provides a lightweight cryptographic module for security focused deployments. This helps organizations secure data transfers, API […]
Read MoreMore TagMaintaining FIPS Validation: Shifting from BitLocker to VeraCrypt with wolfCrypt
In September of 2026, the Cryptographic Module Validation Program (CMVP) will move all remaining FIPS 140-2 certificates to the Historical List, including the modules powering Windows BitLocker. For organizations navigating FIPS, CMMC, and FedRAMP, this is an immediate critical stop, as NIST guidance states federal agencies “should not include” Historical-status modules in new procurements, and […]
Read MoreMore TagFIPS with Statically-Linked wolfSSL
Many FIPS deployments of wolfSSL’s FIPS 140-3 validated wolfCrypt module use dynamic linking to load the shared object / DLL. However, sometimes it is necessary for some types of projects to statically link the libwolfssl.a static archive directly into an executable or firmware image. This post explains why static linking takes a little extra care, […]
Read MoreMore TagCUPS FIPS 140-3 Tested & Available with wolfCrypt FIPS
CUPS (Common UNIX Printing System) is a printing system that manages print services and network printing on Linux, macOS, and UNIX-based operating systems. FIPS 140-3 support is available for CUPS with wolfCrypt FIPS, tested for use with CUPS environments. wolfCrypt FIPS provides a lightweight cryptographic module for security focused deployments. This helps organizations secure print […]
Read MoreMore TagSSH Host Keys That Never Leave the TPM with wolfSSH and wolfTPM
Many embedded devices generate their SSH server host key in RAM on every boot, then hand it to the SSH stack as a DER buffer. It works, but the private key lives in memory where firmware bugs, cold-boot attacks, or a careless core dump can leak it. For a safety-critical or long-lived product, the host […]
Read MoreMore TagIntroducing wolfHAL: A Lightweight Hardware Abstraction Layer for Embedded Systems
We are excited to announce wolfHAL, a new open-source project from wolfSSL. wolfHAL is a lightweight, OS-agnostic, compiler-agnostic hardware abstraction layer (HAL) for embedded targets, written in portable C. It sits between your application and the silicon, exposing a clean, uniform API for talking to peripherals such as GPIO, UART, SPI, I2C, DMA, flash, timers, […]
Read MoreMore TagwolfBoot Microchip PolarFire SoC support for full HSS replacement
wolfBoot can now boot a Microchip PolarFire SoC (MPFS250T) entirely on its own — no Hart Software Services (HSS) required — and bring up 4-CPU SMP Linux from a signed, verified image. One bootloader, one root of trust wolfBoot can now run in M-Mode directly on the E51 hart out of eNVM and handles all […]
Read MoreMore TagwolfCrypt as a FIPS 140-3 Crypto Provider for VPP
wolfSSL has lab-demoed wolfCrypt as a crypto provider for VPP. VPP (Vector Packet Processing) is FD.io’s user-space networking data plane. wolfCrypt plugs into VPP’s crypto dispatch and handles IPsec traffic. VPP has no FIPS 140-3 validated crypto path today. The built-in crypto has no validation. The OpenSSL path carries whatever FIPS posture OpenSSL has; on […]
Read MoreMore Tag
