* Refactor meta-wolfssl: modularize feature enablement and centralize helpers in bbclass Refactored layer.conf to unconditionally include all recipes, moved feature-specific configuration into modular .inc files, created wolfssl-helper.bbclass with reusable do_wolfssl_autogen and do_wolfssl_check_package tasks, updated all recipes to use the new pattern, and standardized commercial license variables to be recipe-specific. Use a virtual wolfssl to make library switching easier for fips vs non fips or other wolfSSL packages Set wolfssl libraries as the deafualt weak Preferred_Provider option for packages * Merged refactor and new test changes * Combine refactor changes and add replace default and fips modes * Add working and tested fips, replace default, non-fips, non-replace-default work * Add FIPS replace default to layers and test all options * Refactor bbappends to be more yocto like * Add overide to openssl configure * Address comment concerns * Only do neccesary simlinks * Only do neccesary simlinks * Convert wolfprovider test bbappend to inc file * Add Image minimals for all wolfprovider modes * Fully tested images * Get conf files from source * Fix FIPS package issues * Fixes 7z extraction issues, mostly around using password when the password has already been stripped out * Fixes autoreconf and configure issues with the FIPS package * Fixes wolfcrypttest and wolfcryptbenchmark not being isntalled with FIPS when they are selected * Fix unstable meta data for fips package * Fix the execution command for QEMU The execution of QEMU to get the hash would fail when cross-compiling to a different CPU target. This fixes it. * gnutls-wolfssl layers Added 3 layers - gnutls: gnutls fork patched to use wolfssl as cryptographic provider - wolfssl: wolfssl configured to work against gnutls - wolfssl-gnutls-wrapper: shim layer that gets called by gnutls applications when linked against gnutls-wolfssl - gnutls-wolfssl-tests: tests from the wolfssl-gnutls-wrapper folder installed under /usr/lib/wolfssl-gnutls-wrapper/ Everything gets installed under /usr ovverriding the system installed recipes, the wrapper is symlinked in /opt. Fips currently not supported. * fips support * Removed hmac generation and installation since this step is already happening on the base recipe * gnutls layers (from https://github.com/wolfSSL/meta-wolfssl/pull/111/) rebased against the new staging branch (refactor-meta-wolfssl) * - added gnutls-image-minimal; - update layer.conf to conditionally include gnutls-image-minimal if included in the WOLFSSL_DEMOS; - minor update to inc/gnutls/gnutls-enable-wolfssl.inc to by pass the fuzzing binaries from the base recipes; * added do_configure[network] = "1" to the inc file (fixes networking issues on some builds) * Add support for GCP and tarballs The commercial package can now be retrieved from GCP and can be a tarball without password protection. * fix stamp.h in append rather than main .bb * Update wolfprovider include files with local changes * Add messages for debug files * Follow Debian convention for provider config in openssl.cnf - Install provider*.conf files to /etc/ssl/openssl.cnf.d/ instead of /opt - Remove OPENSSL_CONF environment variable approach - Add .include directive to openssl.cnf automatically in explicit load mode - This allows OpenSSL to automatically load the provider configuration - Update script output to reflect the new approach * Append conf fil * Don't use fixed version for FIPS User can use any FIPS wolfSSL package * Fix naming for new fips rename * Add final wolfprovider refactor changes * Benchmark and GPG Error Patch to resolve build issues and disable benchmarking due to length of time it takes to run AES GCM in current port * Fixes for when GNUPG is needed * Update wolfProvider images to match other demo images, add to bbclass to ensure configurations are not added to reciepes automatically. * Fips Image for reference * Fix openssl target detection This was not working properly on an ARM64 build. * Add symlink in ossl-modules, install provider.conf from main module * Remove debug for wolfprovider * Add fix for loading conf in wolfproviderenv * linuxkm: add non-FIPS kernel module recipe and initramfs integration class This introduces support for building the wolfSSL Linux kernel module (linuxkm) in non-FIPS configurations and adds a generic bbclass for including the module in any initramfs image. Key additions: - New recipe: wolfssl-linuxkm.bb (non-FIPS) * Builds linuxkm against the target kernel * Installs libwolfssl.ko into /lib/modules/.../extra * Adds auto-load entry under /etc/modules-load.d/ * Tracks upstream wolfSSL master at commit 3062d1524 - New class: wolfssl-initramfs.bbclass * Allows any initramfs image to include the linuxkm module * Intended to be inherited from BSP/distro override layers This prepares the layer for future FIPS/non-FIPS split support and provides a clean mechanism for systems that need early-boot availability of the wolfSSL kernel module. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> * Add openssl ptest patch * Fix openssl patch * linuxkm: update to latest commit to include randomness changes for Tegra kernel Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> * Add wolfssl-kernel-random.bbclass for kernel randomness patches Bbclass to apply wolfSSL DRBG callback hooks to Linux kernel. Fetches patches from wolfSSL GitHub, works with any kernel flavor. Usage in kernel bbappend: inherit wolfssl-kernel-random WOLFSSL_KERNEL_RANDOM_PATCH = "5.17-ubuntu-jammy-tegra" Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> * Add curl ptest patch * Make RD and FIPS detection more robust * Refactor to handle all cases * Wrong file location for curl .inc * - Updated gnutls to point to the 3.8.11 branch to get the 3.8.11 version of gnutls-wolfssl (https://github.com/wolfSSL/gnutls/tree/gnutls-wolfssl-3.8.11); - added nettle 3.10 recipe, gnutls depends on nettle to be >= 3.10; - removed conditional bbappends in favor of the demo image and recipes-core + inc configuration setup; * Add fix for wolfProvider curl FIPS * Add openssh ptest patch for wolfprovider * Fix location of openSSH patch to point to upstream osp * linuxkm-fips: add Yocto recipe Add commercial FIPS LinuxKM recipe. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> Signed-off-by: Zackery Backman <zackery@wolfssl.com> * Wolfprovider patch fix and other cleanup * Add librelp ptest patch for FIPS * Add support for wolfProvider RD unit test * Add replace default method for fips image * Update rev for wolfProvider * Update wolfProvider ref * Update ref version for pr 347 * fixing compatability and file layout for .incs porting * fix pathing for gcrypt patch file * FIPS-off gnutls recipes + minimal fips-off image. * Update ref version for cmd test specific commit to pr 347 * fix buggy paths in meta-wolfssl * Fix issue with missing config script and also add gcs to linuxkm recipe * Move commercial bundle evaluation outside of recipes and into bbclass * Cleanup to readmes * remove the need for the librelp patch * Update emails to point at support email * add Gnutls images to the main readme * Fix typo in example for wolfprovider meta-data and update licensing to point to 2024/correct md5sum --------- Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> Signed-off-by: Zackery Backman <zackery@wolfssl.com> Co-authored-by: Aidan Garske <aidan@wolfssl.com> Co-authored-by: Andrew Hutchings <andrew@linuxjedi.co.uk> Co-authored-by: Reda Chouk <reda@wolfssl.com> Co-authored-by: Paul Adelsbach <paul.adelsbach@wolfssl.com> Co-authored-by: Sameeh Jubran <sameeh@wolfssl.com> Co-authored-by: Andrew Hutchings <andrew@wolfssl.com> |
||
|---|---|---|
| .. | ||
| README.md | ||
| libgcrypt_%.bbappend | ||
| wolfssl-fips.bbappend | ||
README.md
libgcrypt with wolfSSL Backend
This directory provides integration for running libgcrypt with wolfSSL/wolfCrypt as the cryptographic backend, enabling FIPS-validated cryptography through libgcrypt's standard API.
Overview
libgcrypt is a general-purpose cryptographic library used by many Linux applications (GnuPG, systemd, etc.). By configuring it to use wolfSSL's FIPS-validated wolfCrypt as the backend, you can provide FIPS 140-3 validated cryptography to all applications using libgcrypt.
Files
libgcrypt_%.bbappend
Conditionally enables wolfSSL backend when:
libgcryptis inWOLFSSL_FEATURES, ANDwolfssl-fipsis thePREFERRED_PROVIDER
Uses the wolfssl-osp-support class for conditional configuration.
wolfssl-fips.bbappend
Configures wolfssl-fips with additional features needed by libgcrypt when libgcrypt is in WOLFSSL_FEATURES.
Configuration Files
inc/libgcrypt/libgcrypt-enable-wolfssl.inc
Configures libgcrypt to use the wolfSSL-enabled fork:
- Changes source to
github.com/wolfSSL/libgcrypt-wolfssl - Updates to version 1.11.0
- Adds wolfSSL dependencies
- Configures with
--enable-wolfssl-fips
inc/wolfssl-fips/wolfssl-enable-libgcrypt.inc
Configures wolfssl-fips with features required by libgcrypt:
--enable-fips=v5- FIPS 140-3 validation--enable-keygen- Key generation support- Additional compile flags for libgcrypt compatibility
Usage
Method 1: Using WOLFSSL_FEATURES (Recommended)
# In build/conf/local.conf
WOLFSSL_FEATURES = "libgcrypt"
require /path/to/meta-wolfssl/conf/wolfssl-fips.conf
# Add to your image
IMAGE_INSTALL:append = " libgcrypt"
Method 2: Using Demo Image
# In build/conf/local.conf
WOLFSSL_DEMOS = "wolfssl-image-minimal libgcrypt-image-minimal"
require /path/to/meta-wolfssl/conf/wolfssl-fips.conf
# Build the demo image
bitbake libgcrypt-image-minimal
Testing
The demo image includes ptest support:
# In QEMU
ptest-runner libgcrypt
This runs the libgcrypt test suite to verify the wolfSSL backend is working correctly.
Requirements
- wolfssl-fips: This integration only works with wolfSSL FIPS builds
- FIPS Bundle: You must have a valid wolfSSL FIPS commercial bundle
- libgcrypt 1.11.0+: The wolfSSL fork is based on libgcrypt 1.11.0
Architecture
┌─────────────────────────────────┐
│ Applications (GnuPG, systemd) │
└───────────────┬─────────────────┘
│ libgcrypt API
┌───────────────▼─────────────────┐
│ libgcrypt 1.11.0 │
│ (wolfSSL-enabled fork) │
└───────────────┬─────────────────┘
│ wolfCrypt API
┌───────────────▼─────────────────┐
│ wolfSSL FIPS (wolfCrypt Core) │
│ FIPS 140-3 Validated │
└─────────────────────────────────┘
More Information
- Demo Image: recipes-core/images/libgcrypt-image-minimal/README.md
- Main Layer README: ../../README.md
- libgcrypt-wolfssl: https://github.com/wolfSSL/libgcrypt-wolfssl