* Refactor meta-wolfssl: modularize feature enablement and centralize helpers in bbclass Refactored layer.conf to unconditionally include all recipes, moved feature-specific configuration into modular .inc files, created wolfssl-helper.bbclass with reusable do_wolfssl_autogen and do_wolfssl_check_package tasks, updated all recipes to use the new pattern, and standardized commercial license variables to be recipe-specific. Use a virtual wolfssl to make library switching easier for fips vs non fips or other wolfSSL packages Set wolfssl libraries as the deafualt weak Preferred_Provider option for packages * Merged refactor and new test changes * Combine refactor changes and add replace default and fips modes * Add working and tested fips, replace default, non-fips, non-replace-default work * Add FIPS replace default to layers and test all options * Refactor bbappends to be more yocto like * Add overide to openssl configure * Address comment concerns * Only do neccesary simlinks * Only do neccesary simlinks * Convert wolfprovider test bbappend to inc file * Add Image minimals for all wolfprovider modes * Fully tested images * Get conf files from source * Fix FIPS package issues * Fixes 7z extraction issues, mostly around using password when the password has already been stripped out * Fixes autoreconf and configure issues with the FIPS package * Fixes wolfcrypttest and wolfcryptbenchmark not being isntalled with FIPS when they are selected * Fix unstable meta data for fips package * Fix the execution command for QEMU The execution of QEMU to get the hash would fail when cross-compiling to a different CPU target. This fixes it. * gnutls-wolfssl layers Added 3 layers - gnutls: gnutls fork patched to use wolfssl as cryptographic provider - wolfssl: wolfssl configured to work against gnutls - wolfssl-gnutls-wrapper: shim layer that gets called by gnutls applications when linked against gnutls-wolfssl - gnutls-wolfssl-tests: tests from the wolfssl-gnutls-wrapper folder installed under /usr/lib/wolfssl-gnutls-wrapper/ Everything gets installed under /usr ovverriding the system installed recipes, the wrapper is symlinked in /opt. Fips currently not supported. * fips support * Removed hmac generation and installation since this step is already happening on the base recipe * gnutls layers (from https://github.com/wolfSSL/meta-wolfssl/pull/111/) rebased against the new staging branch (refactor-meta-wolfssl) * - added gnutls-image-minimal; - update layer.conf to conditionally include gnutls-image-minimal if included in the WOLFSSL_DEMOS; - minor update to inc/gnutls/gnutls-enable-wolfssl.inc to by pass the fuzzing binaries from the base recipes; * added do_configure[network] = "1" to the inc file (fixes networking issues on some builds) * Add support for GCP and tarballs The commercial package can now be retrieved from GCP and can be a tarball without password protection. * fix stamp.h in append rather than main .bb * Update wolfprovider include files with local changes * Add messages for debug files * Follow Debian convention for provider config in openssl.cnf - Install provider*.conf files to /etc/ssl/openssl.cnf.d/ instead of /opt - Remove OPENSSL_CONF environment variable approach - Add .include directive to openssl.cnf automatically in explicit load mode - This allows OpenSSL to automatically load the provider configuration - Update script output to reflect the new approach * Append conf fil * Don't use fixed version for FIPS User can use any FIPS wolfSSL package * Fix naming for new fips rename * Add final wolfprovider refactor changes * Benchmark and GPG Error Patch to resolve build issues and disable benchmarking due to length of time it takes to run AES GCM in current port * Fixes for when GNUPG is needed * Update wolfProvider images to match other demo images, add to bbclass to ensure configurations are not added to reciepes automatically. * Fips Image for reference * Fix openssl target detection This was not working properly on an ARM64 build. * Add symlink in ossl-modules, install provider.conf from main module * Remove debug for wolfprovider * Add fix for loading conf in wolfproviderenv * linuxkm: add non-FIPS kernel module recipe and initramfs integration class This introduces support for building the wolfSSL Linux kernel module (linuxkm) in non-FIPS configurations and adds a generic bbclass for including the module in any initramfs image. Key additions: - New recipe: wolfssl-linuxkm.bb (non-FIPS) * Builds linuxkm against the target kernel * Installs libwolfssl.ko into /lib/modules/.../extra * Adds auto-load entry under /etc/modules-load.d/ * Tracks upstream wolfSSL master at commit 3062d1524 - New class: wolfssl-initramfs.bbclass * Allows any initramfs image to include the linuxkm module * Intended to be inherited from BSP/distro override layers This prepares the layer for future FIPS/non-FIPS split support and provides a clean mechanism for systems that need early-boot availability of the wolfSSL kernel module. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> * Add openssl ptest patch * Fix openssl patch * linuxkm: update to latest commit to include randomness changes for Tegra kernel Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> * Add wolfssl-kernel-random.bbclass for kernel randomness patches Bbclass to apply wolfSSL DRBG callback hooks to Linux kernel. Fetches patches from wolfSSL GitHub, works with any kernel flavor. Usage in kernel bbappend: inherit wolfssl-kernel-random WOLFSSL_KERNEL_RANDOM_PATCH = "5.17-ubuntu-jammy-tegra" Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> * Add curl ptest patch * Make RD and FIPS detection more robust * Refactor to handle all cases * Wrong file location for curl .inc * - Updated gnutls to point to the 3.8.11 branch to get the 3.8.11 version of gnutls-wolfssl (https://github.com/wolfSSL/gnutls/tree/gnutls-wolfssl-3.8.11); - added nettle 3.10 recipe, gnutls depends on nettle to be >= 3.10; - removed conditional bbappends in favor of the demo image and recipes-core + inc configuration setup; * Add fix for wolfProvider curl FIPS * Add openssh ptest patch for wolfprovider * Fix location of openSSH patch to point to upstream osp * linuxkm-fips: add Yocto recipe Add commercial FIPS LinuxKM recipe. Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> Signed-off-by: Zackery Backman <zackery@wolfssl.com> * Wolfprovider patch fix and other cleanup * Add librelp ptest patch for FIPS * Add support for wolfProvider RD unit test * Add replace default method for fips image * Update rev for wolfProvider * Update wolfProvider ref * Update ref version for pr 347 * fixing compatability and file layout for .incs porting * fix pathing for gcrypt patch file * FIPS-off gnutls recipes + minimal fips-off image. * Update ref version for cmd test specific commit to pr 347 * fix buggy paths in meta-wolfssl * Fix issue with missing config script and also add gcs to linuxkm recipe * Move commercial bundle evaluation outside of recipes and into bbclass * Cleanup to readmes * remove the need for the librelp patch * Update emails to point at support email * add Gnutls images to the main readme * Fix typo in example for wolfprovider meta-data and update licensing to point to 2024/correct md5sum --------- Signed-off-by: Sameeh Jubran <sameeh@wolfssl.com> Signed-off-by: Zackery Backman <zackery@wolfssl.com> Co-authored-by: Aidan Garske <aidan@wolfssl.com> Co-authored-by: Andrew Hutchings <andrew@linuxjedi.co.uk> Co-authored-by: Reda Chouk <reda@wolfssl.com> Co-authored-by: Paul Adelsbach <paul.adelsbach@wolfssl.com> Co-authored-by: Sameeh Jubran <sameeh@wolfssl.com> Co-authored-by: Andrew Hutchings <andrew@wolfssl.com> |
||
|---|---|---|
| .. | ||
| wolfprovider-image-minimal | ||
| wolfprovider-replace-default-image-minimal | ||
| README.md | ||
README.md
wolfProvider Minimal Images
Minimal demo images showcasing wolfProvider integration with OpenSSL 3.x in various configurations.
Overview
These images demonstrate different wolfProvider configurations for OpenSSL 3.x integration. Each image is self-contained and requires no local.conf configuration (except FIPS images which require wolfssl-fips.conf).
Available Images
1. wolfprovider-image-minimal
Standalone mode, non-FIPS
- wolfProvider configured as an additional provider alongside OpenSSL's default
- Applications can explicitly load wolfProvider or use it alongside the default provider
- Includes test utilities and unit tests
Configuration:
# Enable demo images
WOLFSSL_DEMOS = "wolfprovider-image-minimal"
if enabling fips add:
# In build/conf/local.conf:
require /path/to/meta-wolfssl/conf/wolfssl-fips.conf
Build:
bitbake wolfprovider-image-minimal
2. wolfprovider-replace-default-image-minimal
Replace-default mode
- wolfProvider replaces OpenSSL's default provider
- All OpenSSL operations automatically use wolfProvider
- No code changes needed - transparent drop-in replacement
Configuration:
# Enable demo images
WOLFSSL_DEMOS = "wolfprovider-replace-default-image-minimal"
if enabling fips add:
# In build/conf/local.conf:
require /path/to/meta-wolfssl/conf/wolfssl-fips.conf
Build:
bitbake wolfprovider-replace-default-image-minimal
What's Included
All images include:
- Everything from
wolfssl-image-minimal - wolfSSL (or wolfSSL FIPS) with wolfProvider support
- OpenSSL 3.x with wolfProvider backend
- wolfProvider environment setup tools (
wolfproviderenv,wolfprovidercmd) - Unit tests (standalone mode images only)
Testing
Inside QEMU, test wolfProvider:
# Run wolfProvider environment setup (standalone mode only)
wolfprovidertest
# Run wolfProvider command-line tests
wolfprovidercmd
# Run wolfProvider environment setup
wolfproviderenv
# Verify provider configuration (replace-default images)
openssl list -providers
How It Works
Each image directory contains bbappend files that automatically configure packages:
- wolfssl_%.bbappend or wolfssl-fips_%.bbappend: Configures wolfSSL with wolfProvider support
- openssl_%.bbappend: Configures OpenSSL to support wolfProvider (standalone or replace-default)
- wolfprovider_%.bbappend: Enables unit tests (standalone mode only)
All configurations use conditional functions (wolfssl_osp_include_if_provider) that automatically detect the provider and include the appropriate configuration files.
Mode Comparison
Standalone Mode
- wolfProvider is an additional provider
- Applications must explicitly load wolfProvider
- OpenSSL's default provider remains available
- Useful for testing and selective adoption
Replace-Default Mode
- wolfProvider replaces OpenSSL's default provider
- All OpenSSL operations automatically use wolfProvider
- No application code changes needed
- Useful for system-wide deployment
Requirements
- FIPS images: Valid wolfSSL FIPS commercial bundle and
wolfssl-fips.confconfiguration - Non-FIPS images: No additional requirements
More Information
- Main README: ../../../README.md
- wolfProvider: ../../../recipes-wolfssl/wolfprovider/README.md
- wolfSSL FIPS: ../../../recipes-wolfssl/wolfssl/README-fips.md