RFC 9846, published in July 2026, obsoletes RFC 8446 as the specification for TLS 1.3. It is a minor revision in that it is backward compatible, but it tightens a number of requirements that were previously advisory. At wolfSSL, we are working hard on implementing the specification. No KeyUpdate while sending early data. Section 5.5 […]
Read MoreMore TagCategory: wolfSSL/ wolfCrypt
wolfSSL at the Toradex Booth: Post-Quantum the SMARC iMX95 SoM
Heading to Embedded World North America (September 22–24)? Stop by Toradex at Booth 6222 to see wolfSSL’s live Post-Quantum Cryptography (PQC) demo on the Toradex SMARC iMX95 module. Afterward, visit the wolfSSL booth (#6027) to say hi and talk with our team. The Demo at a Glance We demonstrate post-quantum security across both halves of […]
Read MoreMore TagTop 10 Things to Reduce wolfSSL Code Size
wolfSSL is one of the smallest commercial TLS / crypto libraries available. Pulling the right configuration levers is the biggest challenge. This post is a short tour of the ten biggest knobs. Two ways to configure the build Every define and flag below can be supplied through either of these paths: Autoconf / configure(./configure): Pass […]
Read MoreMore TagwolfCrypt on the Silicon Labs EFR32xG25 Secure Element
wolfSSL now supports hardware-accelerated crypto on the Silicon Labs EFR32 Series 2 Secure Element using wolfCrypt crypto callbacks. Simply define WOLFSSL_SILABS_CRYPTOCB. wolfCrypt automatically registers the Secure Element at startup and routes supported operations to hardware, including: Symmetric Ciphers: AES (ECB, CBC, CTR, GCM, CCM), ChaCha20-Poly1305 MAC & KDF: AES-CMAC, HKDF, PBKDF2 Hashing: SHA-2 Asymmetric: ECDSA, […]
Read MoreMore TagTLS 1.3 in 30.8 KB: wolfSSL vs MbedTLS
wolfSSL’s new tinytls13 profile against a parity-matched MbedTLS, measured on Cortex-M33, x86_64, and aarch64. wolfSSL and MbedTLS both target small embedded TLS, but configured and built with parity options they are not the same size. The new tinytls13 profile is a TLS 1.3-only build that strips everything which is not TLS 1.3 and defaults to […]
Read MoreMore TagHardware Crypto Acceleration for NXP QorIQ PowerPC: the SEC engine in wolfCrypt
wolfSSL now supports the SEC security engine on NXP’s QorIQ PowerPC T-series processors. SEC is the QorIQ name for the same CAAM block that wolfSSL has long supported on i.MX, and both are covered here: a new bare-metal port for the T-series, and a Linux user space backend for the existing CAAM driver. AES, AES-GCM, […]
Read MoreMore TagSymmetric vs Asymmetric Cryptography
When it comes to the basics of cryptographic algorithms, one of the most fundamental distinctions is whether an algorithm is symmetric or asymmetric. Symmetric cryptography uses a single shared key for both encryption and decryption for example, AES. The operations are simple, and this makes symmetric algorithms fast and cheap, which is why it’s the […]
Read MoreMore TagDTLS 1.3 vs DTLS 1.2: Why It’s Time to Upgrade
DTLS 1.3, standardized as RFC 9147, is a major leap over DTLS 1.2 for any application securing UDP traffic. It inherits every improvement of TLS 1.3, first among them the only path to post-quantum cryptography, one DTLS 1.2 will never have, and adds datagram-specific advances of its own that make communication safer, faster, more reliable, […]
Read MoreMore TagBare-Metal STM32 Hardware Crypto with wolfCrypt: DHUK and CCB Device-Bound Keys
wolfCrypt now drives STM32 on-chip crypto hardware directly from the registers, with zero STMicroelectronics HAL dependency (wolfSSL PR #10395). On top of the bare drivers, the port adds DHUK and CCB: chip-bound keys that are derived and used entirely inside the silicon and never appear in software. It is validated across ~27 NUCLEO boards spanning […]
Read MoreMore TagwolfSSL is bringing hardware key isolation to the Altera Agilex 5 SoC FPGA
wolfSSL is adding native support for the Secure Device Manager (SDM) hardened crypto services on Altera Agilex 5 devices. The new port connects wolfCrypt directly to the FPGA Crypto Services (FCS) stack, so keys can live where Linux cannot reach them: inside the SDM itself. Applications get that isolation through the same wolfSSL APIs they […]
Read MoreMore Tag
