Release of the cryptographic library wolfSSL 5.0.0

A new release of the compact cryptographic library wolfSSL 5.0.0 is now available, optimized for use on embedded devices with limited CPU and memory resources, such as Internet of Things devices, smart home systems, automotive information systems, routers, and mobile phones. The code is written in C and is distributed under the GPLv2 license.

The library provides high-performance implementations of modern cryptographic algorithms, including ChaCha20, Curve25519, NTRU, RSA, Blake2b, TLS 1.0-1.3, and DTLS 1.2, which, according to the developers, are 20 times more compact than the implementations from OpenSSL. It offers both its simplified API and a layer for compatibility with the OpenSSL API. OCSP (Online Certificate Status Protocol) and CRL (Certificate Revocation List) support is available for certificate revocation checking.

Key innovations of wolfSSL 5.0.0:

  • Support for platforms has been added: IoT-Safe (with TLS support), SE050 (supporting RNG, SHA, AES, ECC, and ED25519), and Renesas TSIP 1.13 (for RX72N microcontrollers).
  • Support for post-quantum cryptography algorithms, resistant to attacks on quantum computers, has been added: NIST Round 3 KEM groups for TLS 1.3 and hybrid NIST ECC groups based on the OQS (Open Quantum Safe, liboqs) project. Quantum-resistant groups have also been added to the compatibility layer. Support for NTRU and QSH algorithms has been discontinued.
  • The Linux kernel module has implemented support for cryptographic algorithms that comply with the FIPS 140-3 security standard. A separate product has been introduced with FIPS 140-3 implementation, and its code is currently in the testing, review, and verification stage.
  • The Linux kernel module has added variants of RSA, ECC, DH, DSA, AES/AES-GCM algorithms, accelerated by x86 CPU vector instructions. Interrupt handlers have also been accelerated using vector instructions. Support for a subsystem for module verification via digital signatures has been added. The possibility to build the embedded cryptographic engine wolfCrypt in "--enable-linuxkm-pie" (position-independent) mode has been provided. The module supports Linux kernels 3.16, 4.4, 4.9, 5.4, and 5.10.
  • Support for libssh2, pyOpenSSL, libimobiledevice, rsyslog, OpenSSH 8.5p1, and Python 3.8.5 has been added to the compatibility layer for integration with other libraries and applications.
  • A large set of new APIs has been added, including EVP_blake2, wolfSSL_set_client_CA_list, wolfSSL_EVP_sha512_256, wc_Sha512*, EVP_shake256, SSL_CIPHER_*, SSL_SESSION_*, and more.
  • Two vulnerabilities that have been classified as non-critical have been fixed: a hang when creating DSA digital signatures with specific parameters and incorrect certificate validation with multiple alternative subject names, when using name-based constraints.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster