The NXP CAAM (Cryptographic Accelerator and Assurance Module) supports offloading cryptographic operations for acceleration along with heightened security. wolfSSL supports accessing the hardware acceleration in many different operating environments, such as with QNX or NXP’s Yocto Linux builds. For QNX builds wolfSSL has targeted specific i.MX devices, check with our manual or support channel to […]
Read MoreMore TagCategory: wolfSSL/ wolfCrypt
wolfSSL Intel QuickAssist (QAT) Performance Improvements
wolfSSL’s asynchronous crypto offloads public-key, cipher, and hashing work to Intel QuickAssist (QAT) hardware. This update (PR #10772) makes that offload use every QAT device in a multi-adapter system, and hardens it for multi-process and CI use. The problem: idle devices Each worker thread binds to one QAT crypto instance, and the driver hands back […]
Read MoreMore TagwolfSSL TLS with Hardware-Bound Keys on the RealTek RTL8735B (AmebaPro2)
The RealTek RTL8735B (AmebaPro2) is an Arm Cortex-M33 AIoT SoC with a hardware crypto engine and, importantly, a per-device Hardware Unique Key (HUK) fused into the silicon. The HUK never leaves the chip and cannot be read by software. That makes it an ideal root from which to derive keys that are bound to one […]
Read MoreMore TagTightening OCSP Responder Authorization for RFC 6960 Compliance
wolfSSL has removed CheckOcspResponderChain(), a non-compliant chain walk that authorized any OCSP responder certificate issued by any ancestor of the target certificate’s issuer as of version 5.9.2. RFC 6960 §4.2.2.2 requires that an OCSP response be signed directly by the CA that issued the certificate in question or a delegated responder appointed by that exact […]
Read MoreMore TagwolfSSL Improves TLS 1.3 Alert Compliance for Missing SNI
wolfSSL now sends the correct alert when a TLS 1.3 server requires the Server Name Indication (SNI) extension and the client fails to include it. Previously, the server sent a generic handshake_failure alert; it now sends the missing_extension alert defined by RFC 8446 for exactly this case. TLS 1.2 and earlier keep the existing handshake_failure […]
Read MoreMore TagwolfSSL Relaxes Serial Number Validation for Root CA Certificates
wolfSSL has refined its X.509 serial number validation to better handle real-world trust stores. Previously, wolfSSL rejected any certificate with a serial number of 0. While RFC 5280 requires CAs to issue certificates with positive serial numbers, some long-standing self-signed root CA certificates in circulation were created with serial 0, and rejecting them caused otherwise […]
Read MoreMore TagwolfSSL Now Available for Zephyr’s Secure Sockets Layer
We’re pleased to announce that wolfSSL can now be integrated directly into the secure sockets layer of the Zephyr RTOS. The required patches are available now in our Open Source Project (OSP) repository. What This Means These patches let you swap out mbedTLS and use wolfSSL as the TLS provider behind Zephyr’s native socket API. […]
Read MoreMore TagA Quantum Safety Net for TLS 1.3: Mandatory PSKs with Certificate Authentication
TLS 1.3 normally forces a choice: authenticate with certificates or with a pre-shared key, but not both in the same handshake. Combining them gives you a second, independent root of trust that survives even if the first one falls — and wolfSSL now supports both doing this and requiring it. The foundation is RFC 8773, […]
Read MoreMore TagStateful Hash-Based Signatures (LMS and XMSS) in X.509 Certificates
wolfSSL now supports the stateful hash-based signature schemes LMS/HSS and XMSS/XMSS^MT in X.509 certificates, following RFC 9802. What’s New Both sides of the certificate lifecycle are covered: Generation – Sign certificates and CSRs with an LMS/HSS or XMSS/XMSS^MT key, encoded exactly as RFC 9802 specifies. Verification – Parse and verify certificate chains that use these […]
Read MoreMore TagwolfCrypt on the TI C2000 C28x: PQC ML-DSA/ML-KEM on a 16-bit-byte DSP
We’re excited to share that wolfCrypt now runs a full modern crypto suite on Texas Instruments’ C2000 C28x – the NIST post-quantum schemes ML-DSA (FIPS 204) and ML-KEM (FIPS 203), plus RSA, Diffie-Hellman, AES, ChaCha20-Poly1305, HMAC/HKDF, the Curve25519/Ed25519, Curve448/Ed448, and NIST P-256 elliptic-curve schemes, and the SHA-1/2/3 and SHAKE hash families – all validated on […]
Read MoreMore Tag
