<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[wolfSSL - Embedded SSL Library — FIPS 140-3 Announcement to the world]]></title>
		<link>https://www.wolfssl.com/forums/topic2142-fips-1403-announcement-to-the-world.html</link>
		<atom:link href="https://www.wolfssl.com/forums/feed-rss-topic2142.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in FIPS 140-3 Announcement to the world.]]></description>
		<lastBuildDate>Wed, 17 Jul 2024 21:19:43 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[FIPS 140-3 Announcement to the world]]></title>
			<link>https://www.wolfssl.com/forums/post7768.html#p7768</link>
			<description><![CDATA[<p>Original blog announcement: <a href="https://www.wolfssl.com/fips-140-3-announcement-to-the-world/">https://www.wolfssl.com/fips-140-3-anno … the-world/</a></p><p>wolfSSL Inc. is very pleased to announce our wolf pack has successfully hunted down and captured the ever elusive FIPS 140-3 certificate! The world’s first automated submission (SP800-140Br1) FIPS 140-3 validated <strong>certificate #4718</strong> [1] posted to the NIST website on July 11th 2024, valid through July 10th, 2029!</p><p>“wolfSSL remains focused on enhancing our technologies and expanding capabilities. We are dedicated to continuous innovation in security. The advancements in our FIPS 140-3 module highlight our commitment to delivering state-of-the-art cryptographic solutions that meet the rigorous demands of today’s cybersecurity landscape.” Stated wolfSSL CTO, Todd Ouska.</p><p>We are thrilled to work with ÆGISOLVE, INC. on this journey. The wolfSSL team is grateful for the ÆGISOLVE staff’s hard-work and dedication in realizing the <strong>very first SP800-140Br1 140-3 certificate in the world</strong>! A note from the ÆGISOLVE team:</p><div class="quotebox"><blockquote><p>“AEGISOLVE is pleased to announce the world’s first SP800-140Br1 compliant FIPS 140-3 Validation Certificate for wolfSSL’s wolfCrypt module&quot; reported Travis Spann, Founder and President of AEGISOLVE (NVLAP Lab Code: 200802-0).</p><p>&quot;As a first of its kind, this is a tremendous achievement and a huge step forward for the next generation of FIPS 140-3 Validated Cryptographic Modules. Congratulations, wolfSSL!&quot;</p></blockquote></div><p><strong>Highlights</strong></p><ul><li><p>Boot Times<br />&nbsp; - wolfCrypt FIPS 140-2, power-on times could be slower due to mandatory self-tests<br />&nbsp; - wolfCrypt FIPS 140-3 requires self-tests only at the first algorithm use or during a slower event cycle<br />&nbsp; &nbsp; + faster boot times<br />&nbsp; &nbsp; + optimal power and resource consumption with careful planning!</p></li><li><p>Design<br />&nbsp; - The wolfCrypt FIPS 140-3 validated module is the only commercial FIPS solution tailored for embedded<br />&nbsp; - Emphasis on a minimal footprint, low resource use, reduced power consumption, and high performance for standard and real time systems<br />&nbsp; - Design leads to superior scalability across devices, from mobile to server<br />&nbsp; - 2-3 times more connections per device at 15-20% better performance than competing solutions.</p></li><li><p>OpenSSL Replacement<br />&nbsp; - Compatibility [2]<br />&nbsp; - Engine [3]<br />&nbsp; - Provider [4]</p></li><li><p>Embeddability<br />&nbsp; - Embedded Systems (Medical, networking, sensors, security systems, etc.)<br />&nbsp; - Extended Battery life and high performance<br />&nbsp; - Hardware Encryption Support<br />&nbsp; - Assembly Acceleration</p></li></ul><p><strong>Changes from the historic wolfCrypt FIPS 140-2 cert #3389 to the active wolfCrypt FIPS 140-3 cert #4718:</strong></p><ul><li><p>CAST (conditional algo self tests)</p></li><li><p>KDF-TLS, TLS v1.2 KDF and TLSv1.3 KDF</p></li><li><p>SSH KDF</p></li><li><p>AES-OFB mode</p></li><li><p>RSA 3072, 4096 and PSS</p></li><li><p>New Degraded mode of operation in the event of a CAST failure other algorithm services will remain available.</p></li></ul><p><strong>For more about what FIPS is please checkout these blogs:</strong></p><p>What is FIPS (long version): <a href="https://www.wolfssl.com/fips-long-version/">https://www.wolfssl.com/fips-long-version/</a><br />What is FIPS (short version): <a href="https://www.wolfssl.com/fips-short-version/">https://www.wolfssl.com/fips-short-version/</a><br />Webinar: Everything You Need To Know About FIPS 140-3: <a href="https://www.wolfssl.com/live-webinar-everything-you-need-to-know-about-fips-140-3/">https://www.wolfssl.com/live-webinar-ev … ips-140-3/</a></p><p>For information on transitioning from 140-2 to 140-3 please checkout our blog: What is the difference between FIPS 140-2 and FIPS 140-3? (<a href="https://www.wolfssl.com/difference-fips-140-2-fips-140-3/">https://www.wolfssl.com/difference-fips … ips-140-3/</a>)</p><p>Algo cert Link: <a href="https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=36918">https://csrc.nist.gov/projects/cryptogr … tion=36918</a><br />Security Policy Link: <a href="https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp4718.pdf">https://csrc.nist.gov/CSRC/media/projec … sp4718.pdf</a><br />Ref: Section 2.5 Algorithms<br />Ref: Section 2.2 Table 6 “Tested Operational Environments – Software, Firmware, Hybrid”<br />Cert #4718 Link: <a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4718">https://csrc.nist.gov/projects/cryptogr … icate/4718</a></p><p>For questions, comments or feedback please contact the wolfSSL team anytime at fips@wolfssl.com.</p><p>[1] <a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4718">https://csrc.nist.gov/projects/cryptogr … icate/4718</a><br />[2] <a href="https://www.wolfssl.com/documentation/manuals/wolfssl/chapter13.html">https://www.wolfssl.com/documentation/m … ter13.html</a><br />[3] <a href="https://www.wolfssl.com/documentation/manuals/wolfengine/">https://www.wolfssl.com/documentation/m … olfengine/</a><br />[4] <a href="https://www.wolfssl.com/openssl-3-0-provider-solution-fips-2/">https://www.wolfssl.com/openssl-3-0-pro … on-fips-2/</a></p>]]></description>
			<author><![CDATA[null@example.com (chrisc)]]></author>
			<pubDate>Wed, 17 Jul 2024 21:19:43 +0000</pubDate>
			<guid>https://www.wolfssl.com/forums/post7768.html#p7768</guid>
		</item>
	</channel>
</rss>
