<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[wolfSSL - Embedded SSL Library — wolfCLU 0.2.0 release]]></title>
	<link rel="self" href="https://www.wolfssl.com/forums/feed-atom-topic2523.xml" />
	<updated>2026-05-29T19:34:05Z</updated>
	<generator>PunBB</generator>
	<id>https://www.wolfssl.com/forums/topic2523-wolfclu-020-release.html</id>
		<entry>
			<title type="html"><![CDATA[wolfCLU 0.2.0 release]]></title>
			<link rel="alternate" href="https://www.wolfssl.com/forums/post8819.html#p8819" />
			<content type="html"><![CDATA[<p><a href="https://www.wolfssl.com/products/wolfclu/">wolfCLU release 0.2.0</a> is now available. Major feature additions were added; dual-algorithm certificates, a full OCSP client/responder, a cross-platform test suite, and a large round of security hardening.</p><p><strong>Highlights:</strong><br /></p><ul><li><p>Chimera (dual-algorithm) certificates. wolfCLU can now generate Chimera certificates carrying both a conventional and a post-quantum signature on a single X.509 cert, so one certificate satisfies both classical and PQC-aware verifiers. (<a href="https://github.com/wolfSSL/wolfCLU/pull/182">PR 182</a>, @Yu-Ma28051503)</p></li></ul><ul><li><p>OCSP client and responder. New OCSP client and responder, both with HTTP and SCGI transports. SCGI lets the responder be fronted by nginx in production. (<a href="https://github.com/wolfSSL/wolfCLU/pull/200">PR 200</a>, @julek-wolfssl)</p></li></ul><ul><li><p>Cross-platform Python tests. The shell-based test suite was ported to Python (unittest), so it now runs on Windows in addition to Linux and macOS. (<a href="https://github.com/wolfSSL/wolfCLU/pull/215">PR 215</a>, @julek-wolfssl)</p></li></ul><ul><li><p>Explicit key files for enc. The enc command now accepts an explicit key file instead of deriving the key from a password. (<a href="https://github.com/wolfSSL/wolfCLU/pull/224">PR 224</a>, @embhorn)</p></li></ul><p><strong>Security Hardening:</strong><br />A large set of fixes from static analysis using wolfSSL internal Fenrir project: out-of-bounds writes in argv processing, a stack buffer overflow in encryption setup, a shell command injection, a use-after-free, a potential double-free, a heap buffer over-read, plus numerous null-pointer and sanity-check fixes across command and init paths. (PRs 202–223; @miyazakh, @aidangarske, @JacobBarthelmeh, @yosuke-wolfssl, and others)</p><p><strong>Other Changes:</strong><br />ML-DSA sign/verify now passes a context for OpenSSL interop (<a href="https://github.com/wolfSSL/wolfCLU/pull/195">PR 195</a>), the post-quantum groups list was updated to match the latest wolfSSL (<a href="https://github.com/wolfSSL/wolfCLU/pull/209">PR 209</a>), and there were assorted fixes to the enc, pkey, req, and ECC sign/verify paths along with expanded test coverage and README updates. See the full commit log for details.</p><p><a href="https://www.wolfssl.com/download/">Download</a> wolfCLU now and contact <a href="mailto:facts@wolfssl.com">facts@wolfssl.com</a> for any questions.</p><p>If you have questions about any of the above, please contact us at <a href="mailto:facts@wolfssl.com ">facts@wolfssl.com </a>or call us at +1 425 245 8247.</p><p><strong><a href="https://www.wolfssl.com/download/">Download</a> wolfSSL Now</strong></p>]]></content>
			<author>
				<name><![CDATA[shizuka]]></name>
				<uri>https://www.wolfssl.com/forums/user5631.html</uri>
			</author>
			<updated>2026-05-29T19:34:05Z</updated>
			<id>https://www.wolfssl.com/forums/post8819.html#p8819</id>
		</entry>
</feed>
