Press release
wolfSSL 3.13.0 is now available for download!
wolfSSL 3.13.0 includes bug fixes and new features, including support for TLS 1.3 Draft 21, performance and footprint optimizations, build fixes, updated examples and project files, one vulnerability fix. Continue reading below for a summary of the features and fixes included in this release!Protocol Changes:
Fixes for TLS 1.3, support for Draft 21
TLS 1.0 disabled by default, addition of "-enable-tls10" configure option
Performance and Size Optimizations:
New option to reduce SHA-256 code size at expense of performance (USE_SLOW_SHA256)
New option for memory reduced build (-enable-lowresource)
AES-GCM performance improvements on AVX1 (IvyBridge) and AVX2
SHA-256 and SHA-512 performance improvements using AVX1/2 ASM
SHA-3 size and performance optimizations
Fixes for Intel AVX2 builds on Mac/OSX
Intel assembly for Curve25519 and Ed25519 performance optimizations
Allow adjusting static I/O buffer size with WOLFMEM_IO_SZ
Build Option Updates:
New option to force 32-bit mode with "-enable-32bit"
New option to disable all inline assembly with "-disable-asm"
Ability to override maximum signature algorithms using WOLFSSL_MAX_SIGALGO
Removes 3DES and SHA1 dependencies from PKCS#7
Adds ability to disable PKCS#7 EncryptedData type (NO_PKCS7_ENCRYPTED_DATA)
Feature Additions:
Add ability to get client-side SNI
Expanded OpenSSL compatibility layer
Adds static memory support to the wolfSSL example client
Adds option to wolfCrypt benchmark to benchmark individual algorithms
Adds option to wolfCrypt benchmark to display benchmarks in powers of 10 (-base10)
Updated Project Files:
Updated Visual Studio for ARM builds (for ECC supported curves and SHA-384)
Updated Texas Instruments TI-RTOS build
Updated STM32 CubeMX build with fixes for SHA
Updated IAR EWARM project files
Updated Apple Xcode projects with the addition of a benchmark example project
Build and Feature Fixes:
Fixes for handling of unsupported TLS extensions.
Fixes for compiling AES-GCM code with GCC 4.8.*
Fixes for building without a filesystem
Fix for logging file names with OpenSSL compatibility layer enabled, with WOLFSSL_MAX_ERROR_SZ user-overridable
Fixes for sniffer to use TLS 1.2 client method
Vulnerability Fix:
This release of wolfSSL fixes 1 security vulnerability
wolfSSL is cited in the recent ROBOT Attack by Böck, Somorovsky and Young. The paper notes that wolfSSL only gives a weak oracle without a practical attack but this is still a flaw. This release contains a fix for this report. Please note that wolfSSL has static RSA cipher suites disabled by default as of version 3.6.6 because of the lack of perfect forward secrecy. Only users who have explicitly enabled static RSA cipher suites with WOLFSSL_STATIC_RSA and use those suites on a host are affected. More information will be available at https://wolfssl.com/wolfSSL/security/vulnerabilities.php
Find more about wolfSSL at https://www.wolfssl.com/wolfSSL/Products-wolfssl.html
wolfSSL, founded in 2004, is an Open Source Internet security company with products including the wolfSSL embedded SSL/TLS library, wolfCrypt crypto engine, SSL Inspection, and wolfMQTT. Primary users are programmers building security functionality into applications, devices, and cloud services. wolfSSL employs the dual licensing model, offering products under both the GPLv2 as well as a standard commercial license.
wolfSSL's products are designed to offer optimal embedded performance, rapid integration into existing applications and platforms, the ability to leverage a wide range of hardware crypto solutions, and support for the most current standards. All products are designed for ease-of-use with clean APIs, and are backed by a dedicated and responsive support and development team.
wolfSSL
United States of America Edmonds 10016 Edmonds Way
Larry Stefonic pad@wolfssl.com
This release was published on openPR.
Permanent link to this press release:
Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.
You can edit or delete your press release wolfSSL 3.13.0 is now available for download! here
News-ID: 930556 • Views: …
More Releases from wolfSSL

wolfSSL Announces Qt Framework Support/Integration
wolfSSL, a leading provider of TLS cryptography and the world’s first commercial release of TLS 1.3 announces support for the Qt Framework. Qt is a GUI development framework that traditionally uses OpenSSL in its network layer for security. wolfSSL has expanded its OpenSSL compatibility layer to compile Qt with wolfSSL instead of OpenSSL. There are several reasons that users switch from OpenSSL to wolfSSL, including memory usage, portability, algorithm support,…
Implement Security by Design with an Embedded SSL Library
Software and hardware developers are under constant pressure to make their technologies secure by design, rather than only thinking about security as something that gets tacked on later after everything else is complete. Some of the most vulnerable devices end up being embedded systems, such as IoT smart devices, which often have a single purpose but still handle sensitive data. As such, TLS security is something that every device that…
More Releases for SSL
E-commerce Security Market Top Players - Akamai Technologies (Akamai Web Securit …
InsightAce Analytic Pvt. Ltd. announces the release of a market assessment report on the " E-commerce Security Market - (By Type (Network Security, Application Security, Endpoint Security, Cloud Security, Payment Security), By Application (Retail, Travel & Tourism, Healthcare, Banking & Financial Services, Government), By Solution (Intrusion Detection Systems (IDS), Encryption, Firewalls, Multi-Factor Authentication (MFA), Anti-Malware Solutions), By End-User (B2B, B2C)), Trends, Industry Competition Analysis, Revenue and Forecast To 2031."
According to…
E-commerce Security Market Key Players Analysis - Akamai Technologies (Akamai We …
InsightAce Analytic Pvt. Ltd. announces the release of a market assessment report on the " E-commerce Security Market - (By Type (Network Security, Application Security, Endpoint Security, Cloud Security, Payment Security), By Application (Retail, Travel & Tourism, Healthcare, Banking & Financial Services, Government), By Solution (Intrusion Detection Systems (IDS), Encryption, Firewalls, Multi-Factor Authentication (MFA), Anti-Malware Solutions), By End-User (B2B, B2C)), Trends, Industry Competition Analysis, Revenue and Forecast To 2031."
According to…
SSLWiki.org Launches Free Online SSL Checker Tool to Verify Your SSL Certificate …
SSLWiki.org, a leading online resource for SSL certificates and web security, is proud to announce the launch of its highly anticipated Free SSL Checker Tool. This innovative tool is designed to empower website owners and administrators by providing them with a comprehensive assessment of their SSL certificate and website security, ensuring the highest level of protection for their visitors' data.
In today's digital landscape, ensuring the security and integrity of websites…
The SSL Store is Now Offering a Trio of New Wildcard SSL/TLS Certificates
The world’s biggest SSL/TLS reseller’s product portfolio has increased to include three new premium wildcard options
St. Petersburg, FL – March 22, 2016 – The SSL Store™, the world’s largest SSL/TLS reseller, is excited to announce three new Wildcard SSL offerings along with the Comodo Personal Authentication Certificate (CPAC), which are now available to its valued resellers or for purchase directly. Given the popularity of Wildcard SSL certificates in the SSL/TLS…
Comodo Launches Free Upgrade to EV SSL Certificate with Purchase of Any SSL
JERSEY CITY, NJ, February 1, 2011 - Comodo (comodo.com) has launched a free upgrade of its Comodo Extended Validation Secure Sockets Layer (EV SSL) Certificate, with the purchase of any SSL Certificate for a limited period.
Website owners and operators can now have the advantage of a fully-functioning Comodo EV SSL certificate on their websites for the price of any SSL, a substantial price savings during a limited time offer.
"After just…
Professional SSL certificate management with SSL Manager 2.0 from InterNetX
(REGENSBURG, January 26, 2011) – The Internet Service Provider InterNetX has released innovative software for efficient SSL certificate management with their launch of the new SSL Manager 2.0. The SSL management software now enables users to order certificates and renew validity periods directly via the web interface.
SSL Manager 2.0 is designed to simplify handling and ordering processes for SSL certificates. The progressive software includes a broad range of functions, e.g.…