<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[wolfSSL - Embedded SSL Library — wolfProvider 1.1.0: Major Release with Enhanced Features and Extensive]]></title>
		<link>https://www.wolfssl.com/forums/topic2409-wolfprovider-110-major-release-with-enhanced-features-and-extensive.html</link>
		<atom:link href="https://www.wolfssl.com/forums/feed-rss-topic2409.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in wolfProvider 1.1.0: Major Release with Enhanced Features and Extensive.]]></description>
		<lastBuildDate>Tue, 04 Nov 2025 21:20:57 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[wolfProvider 1.1.0: Major Release with Enhanced Features and Extensive]]></title>
			<link>https://www.wolfssl.com/forums/post8590.html#p8590</link>
			<description><![CDATA[<p>wolfSSL is proud to announce the release of <a href="https://github.com/wolfSSL/wolfProvider/releases/tag/v1.1.0">wolfProvider 1.1.0</a>. This major release represents a significant milestone in our commitment to providing robust OpenSSL 3.x compatibility with FIPS 140-3 validated cryptography. wolfProvider 1.1.0 has been developed according to wolfSSL’s rigorous development and QA process and has successfully passed our quality criteria.</p><p>wolfProvider is designed for customers who want FIPS-validated cryptography but are already invested in using OpenSSL. The provider delivers drop-in replacements for cryptographic algorithms used by OpenSSL, leveraging the wolfCrypt engine underneath, which is FIPS 140-3 certified.</p><p><span class="bbu"><strong>New Cryptographic Features</strong></span><br />This release introduces several important cryptographic capabilities:<br /></p><ul><li><p><strong>KBKDF (Key-Based Key Derivation Function)</strong>: Implementation of NIST SP 800-108 key derivation for secure key generation from existing key material.</p></li></ul><ul><li><p><strong>KRB5KDF (Kerberos 5 Key Derivation Function)</strong>: Support for Kerberos cryptographic operations, enabling enterprise authentication scenarios.</p></li></ul><ul><li><p><strong>AES-CTS (Ciphertext Stealing)</strong>: Additional AES cipher mode for applications requiring specific padding behavior.</p></li></ul><ul><li><p><strong>RSA No-Padding Operations</strong>: Raw RSA encrypt/decrypt operations for applications with custom padding schemes.</p></li></ul><p><span class="bbu"><strong>Replace-Default Provider Mode</strong></span><br />A groundbreaking feature in this release is the ability to replace OpenSSL’s default provider entirely with wolfProvider. This mode makes wolfProvider the primary cryptographic implementation system-wide, allowing existing OpenSSL applications to transparently use wolfSSL’s FIPS-validated cryptography without any code modifications. This feature includes comprehensive testing to ensure the default swap works as expected across various scenarios.</p><p><span class="bbu"><strong>Enhanced Testing and Quality Assurance</strong></span><br />wolfProvider 1.1.0 significantly expands our integration testing with real-world open-source applications. We’ve added automated CI/CD workflows for over 40 popular applications, ensuring wolfProvider works seamlessly with:</p><p><strong>Network Infrastructure</strong>: gRPC, OpenSSH, libssh2, OpenSC/PKCS11, OpenLDAP, IPMItool, Stunnel, socat, SSSD, net-snmp, liboauth2, tnftp, systemd, X11VNC, sscep, TPM2 tools, libcryptsetup, libtss2, KRB5, bind9, hostap<br /><strong>Development Tools</strong>: Python3 NTP, libeac, xmlsec, Qt5 Network, rsync, libwebsockets, tcpdump, cjose, iperf, libfido2, ppp, pam-pkcs11, kmod, libnice</p><p>This extensive testing demonstrates wolfProvider’s production-readiness and compatibility with the broader OpenSSL ecosystem.</p><p><span class="bbu"><strong>Command-Line Integration</strong></span><br />New command-line integration tests validate wolfProvider’s compatibility with OpenSSL command-line tools for AES, RSA, RSA-PSS, Hash, and ECC operations. This ensures that scripts and automation tools using OpenSSL commands work correctly with wolfProvider.</p><p><span class="bbu"><strong>Debian Package Support</strong></span><br />This release includes comprehensive Debian packaging support, making deployment on Debian-based systems straightforward. The packaging includes proper dependency management and integration with the system OpenSSL configurations.</p><p><span class="bbu"><strong>Bug Fixes and Stability Improvements</strong></span><br />wolfProvider 1.1.0 includes over 100 bug fixes addressing issues across all cryptographic operations:<br />AES Improvements: Fixed AES-GCM streaming bugs, authentication tag handling, IV management, and CBC consecutive call handling.<br /><strong>RSA Enhancements</strong>: Resolved RSA PSS decoding issues, key import edge cases, keygen retry logic, certificate display formatting, and parameter handling.<br /><strong>ECC Fixes</strong>: Corrected public key validation, parameter handling, private key operations, signing restrictions, and encoding issues.<br /><strong>DH Corrections</strong>: Fixed FIPS build compatibility, parameter handling, private key operations, and decoder registrations.<br /><strong>General Stability</strong>: Improved locking around signature operations, NULL reinit handling, core libctx management, and OpenSSL patching detection.</p><p><span class="bbu"><strong>Looking Forward</strong></span><br />wolfProvider 1.1.0 represents a major step forward in providing FIPS-validated cryptography to the OpenSSL ecosystem. The extensive integration testing, new cryptographic features, and replace-default mode make this release suitable for production deployment in enterprise environments requiring FIPS compliance.</p><p>Refer to the <a href="https://github.com/wolfSSL/wolfProvider/blob/master/README.md">README.md</a> found in the release for usage instructions. We also maintain a <a href="https://github.com/wolfSSL/wolfProvider/blob/master/ChangeLog.md">ChangeLog.md</a> for a complete list of changes in each release.</p><p>If you have questions about any of the above, please contact us at <a href="mailto:facts@wolfssl.com">facts@wolfssl.com</a> or call us at +1 425 245 8247.</p><p><strong><a href="https://www.wolfssl.com/download/">Download</a> wolfSSL Now</strong></p>]]></description>
			<author><![CDATA[null@example.com (shizuka)]]></author>
			<pubDate>Tue, 04 Nov 2025 21:20:57 +0000</pubDate>
			<guid>https://www.wolfssl.com/forums/post8590.html#p8590</guid>
		</item>
	</channel>
</rss>
