<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[wolfSSL - Embedded SSL Library — wolfProvider 1.2.2 Now Available]]></title>
	<link rel="self" href="https://www.wolfssl.com/forums/feed-atom-topic2570.xml" />
	<updated>2026-08-31T18:20:04Z</updated>
	<generator>PunBB</generator>
	<id>https://www.wolfssl.com/forums/topic2570-wolfprovider-122-now-available.html</id>
		<entry>
			<title type="html"><![CDATA[wolfProvider 1.2.2 Now Available]]></title>
			<link rel="alternate" href="https://www.wolfssl.com/forums/post8926.html#p8926" />
			<content type="html"><![CDATA[<p><a href="https://www.wolfssl.com/products/wolfprovider/">wolfProvider version 1.2.2</a> is now available. As an OpenSSL 3.x provider, wolfProvider routes cryptographic operations through the wolfCrypt FIPS 140-3 module, allowing existing OpenSSL applications to gain a FIPS-validated cryptographic core without modifying any application code. This release introduces native Windows support, PKCS#8 private-key encryption, FIPS build hardening, and a high severity security fix for <strong>AES-GCM</strong> in TLS 1.2.</p><p><span class="bbu"><strong>Windows and Visual Studio 2022 Support</strong></span><br />wolfProvider now compiles natively on Windows using Visual Studio 2022, building libwolfprov.dll against OpenSSL 3.x and wolfSSL configured via user_settings.h. Both non-FIPS and FIPS configurations are fully supported, bringing the same integration Linux users rely on directly to Windows environments.</p><p><span class="bbu"><strong>PKCS#8 Private-Key Encryption</strong></span><br />The PKCS#8 encoder now encrypts private keys whenever a cipher is assigned on the PrivateKeyInfo encoder. This ensures encrypted PKCS#8 output works smoothly through the provider as callers expect. This update also tightens PKCS#8 feature guards and expands cipher-rejection test coverage.</p><p><span class="bbu"><strong>FIPS and Interoperability Enhancements</strong></span><br /></p><ul><li><p>Restored the default FIPS policy mask in WOLFSSL_USER_SETTINGS builds, added portable FIPS CAST-mutex initialization, and balanced wolfCrypt init and cleanup calls.</p></li></ul><ul><li><p>Stopped advertising <strong>SHA-512/224</strong> and <strong>SHA-512/256</strong> in FIPS and self-test builds.</p></li></ul><ul><li><p>Matched OpenSSL’s <strong>ML-KEM</strong> NULL output handling.</p></li></ul><ul><li><p>Expanded hostap smoke tests and EAP test coverage in CI.</p></li></ul><p>Additional fixes, including <strong>X25519</strong> public-key length validation and buffer sizing for <strong>ECX/ECC</strong> get_params, can be found in the included ChangeLog.</p><p><span class="bbu"><strong>Security Fixes</strong></span><br /><strong>CVE-2026-81019, AES-GCM Explicit Nonce Reuse on TLS 1.2 and DTLS 1.2</strong></p><p>Severity, High. Affects wolfProvider 1.0.0 through 1.2.1.<br />The 8-byte explicit nonce was generated when setting up the fixed IV, but it did not increment for subsequent records. Because successive <strong>AES-GCM</strong> records within the same encryption context reused the exact same key and nonce pair, confidentiality was weakened by repeated keystreams and integrity was vulnerable to authentication tag forgery. TLS 1.3, and non-TLS uses of <strong>AES-GCM</strong> are unaffected. This impacts wolfProvider versions 1.0.0 through 1.2.1 across both FIPS and non-FIPS builds.</p><p><span class="bbu"><strong>Download and Upgrade</strong></span><br />Anyone running TLS 1.2 or DTLS 1.2 with <strong>AES-GCM</strong> through wolfProvider should update to 1.2.2 immediately.</p><p>You can find the release on GitHub at <a href="https://github.com/wolfSSL/wolfProvider">https://github.com/wolfSSL/wolfProvider</a> alongside the full ChangeLog.</p><p>For questions on wolfProvider, FIPS 140-3, or commercial licensing, reach out to <a href="mailto:facts@wolfssl.com">facts@wolfssl.com</a>. For direct technical assistance, contact <a href="mailto:support@wolfssl.com">support@wolfssl.com</a>.</p><p><strong><a href="https://www.wolfssl.com/download/">Download</a> wolfSSL Now</strong></p>]]></content>
			<author>
				<name><![CDATA[shizuka]]></name>
				<uri>https://www.wolfssl.com/forums/user5631.html</uri>
			</author>
			<updated>2026-08-31T18:20:04Z</updated>
			<id>https://www.wolfssl.com/forums/post8926.html#p8926</id>
		</entry>
</feed>
