wolfssl-examples/crypto/aes-modes
Aidan Garske b41d12c0b8
Add CI that builds and runs every example (#598)
* Regenerate the CRL that expired in September 2025

* Refresh the expired certificates embedded in certloadverifybuffer

* Return 0 from tls servers that returned a wolfSSL_write byte count

* Send a client certificate from client-tls and client-tls13-resume

* Return 0 from certverify instead of WOLFSSL_SUCCESS

* Give the XTS demo key two different halves

* Exit success after ml_dsa prints its parameter table

* Report failure from the custom io file client and server

* Latch failures across every ecc-params curve lookup

* Ignore SIGPIPE in the btle fifo transport

* Fix the dtls rw-threads certificate paths

* Make runall.sh fail when an example fails

* Make openssl-verify.sh actually verify and actually fail

* Raise the generate_ssl.sh common name length limit

* Port the PQ examples to the current wolfSSL API

* Return 0 from csr_w_ed25519_example and rsa-public-decrypt-app

* Build the x509_acert openssl example against the right headers

* Give the examples Makefiles a consistent wolfSSL prefix

* Fix the double free and NULL derefs in the custom io cleanup paths

* Stop forcing the ESP32 examples to include a developer private config

* Add the missing WiFi Kconfig to the DTLS13 station examples

* Use XSTRLCPY in client-dtls13 since wolfSSL has no XSTRCPY

* Make the DTLS13 example ctx static so it stops colliding with libnet80211

* Set SO_REUSEADDR on the tls servers that lacked it

* Give puf the wolfSSL sources and stop building the IDF 4.4 only ENC28J60 examples

* Set SO_REUSEADDR on server-tcp as well

* Exit the can-bus client on EOF and give it real input in CI

* Re-arm the select timeout each pass in the nonblocking dtls server

* Keep the shared memory BIOs alive until both sides are done

* Port the ebpf tracers to the libbpf 1.0 perf_buffer__new signature

* Clone wolfSSL before make builds its graph so uefi-static builds from a clean tree

* Raise wolfcryptjni compileSdk to 32 for the BigInteger API its submodule uses

* Link wolfentropy.o and keep wc_port socket helpers out of the UEFI build

* Track the wolfSSL dilithium.c to wc_mldsa.c rename and drop a stale java import

* Move uefi-library to the wc_MlDsa API after the wolfSSL dilithium rename

* Declare the launcher activity exported, required from API 31

* Configure wolfSSL before make in the fullstack setup script

* Track the wolfSSL io.c to wolfio.c rename in the ndk sample

* Keep glibc headers out of the freestanding uefi-library build

* Track the wolfSSL mlkem.h rename and give RT1060 the SDK name it selects on

* Track the wolfIP struct ll rename and pin wolfIP to its v1.0 release

* Use getaddrinfo in the ndk sample since bionic does not declare gethostbyname

* Cross compile RT1060 with arm-none-eabi and document the SDK value the Makefile matches

* Enable wolfIP HTTP so its httpd.h actually declares the API the example calls

* Define HAVE_NETDB_H so wolfio.c includes the header its getaddrinfo path needs

* Link pkcs12.o, which RT1060 enables by default and wolfcrypt test calls

* Port the ENC28J60 examples to the ESP-IDF 5.x ethernet API

* Compile dtls.c in the ndk sample, which enables WOLFSSL_DTLS

* Define the PHY identifier registers the removed IDF header supplied

* Compile kdf.c in the ndk sample for the TLS PRF

* Give RT1060 a current_time so the benchmark stops needing clock_gettime

* Port the ENC28J60 PHY to the IDF 5.x autonego_ctrl vtable

* Remove the ENC28J60 server's duplicate driver copy that main already builds

* Return the DTLS server to accept on close_notify so a resume is heard

* Run the C# pq client/server pair under mono

* Define WOLFSSL_CERT_REQ so the ndk-gradle app links wolfssljni's X509_REQ calls

* Refresh the expired client ECC DER certificate

* Add CI that builds and runs every example against wolfSSL master and stable

* Sign OCSP staples with a responder intermediate1 actually delegated

* Report a failing PKCS#11 example instead of always exiting 0

* Link the PSA library the README's PSA_LIB_PATH names

* Widen the mynewt pointer prints so they build on a 64 bit native BSP

* Test RSA under UEFI with a 2048 bit key so it clears wolfSSL's minimum

* Left pad the ECDSA r and s so a leading zero cannot shift the signature

* Document the smime and indef flags the pkcs7 examples need

* Fail ecc-verify when the signature does not verify

* Fail ecc-sign when a round produces an invalid signature

* Fail aesgcm-file-encrypt when its sanity test does not pass

* Check that ML-KEM derives the same shared secret on both sides

* Fail ecdh_gen_secret when the two sides derive different secrets

* Return the DH key agreement error instead of always exiting 0

* Retry the fullstack HTTPS probe so a slow sim start does not fail it

* Confirm the custom-io file transfer succeeded so CI can assert it

* Print a success line from the silent file-encrypt and ecc-export examples

* Add device-sims job running ATECC608 STSAFE and TROPIC01 sim wolfcrypt tests

* Extend device-sims to STM32 and PIC32MZ for the full sim fleet

* Mount wolfSSL for the STM32 and PIC32MZ sim wolfcrypt runs

* Accept the zero success return from wolfSSL_CTX_set_max_early_data

* Read the earlydata reply so the client processes the session ticket before resuming

* Read the earlydata reply in the DTLS client so it processes the session ticket

* Run the tls13 and dtls13 earlydata pairs now that the clients process the ticket

* Let expect_fail clear on refs that carry the fix via a fixed_on marker

* Retry the PSA TLS 1.3 handshake so an intermittent ECC reject does not fail CI

* Retry network fetches across CI so a transient blip does not fail a job

* Normalize do_ecc and do_25519 exit codes like do_448 so an error is never masked to 0

* Build and run the merged-in hsm dtls_client example in CI via a dedicated hsm.yml job

* Add a make check target to each applicable example

* Run only the example and lint smoke set on draft PRs

* Only run a per-target workflow when its own example dir changes

* Assert the real se050 wolfcrypt result instead of an early sub-test line

* Size the RSA 2048 key export buffers so the UEFI test does not fail on BUFFER_E

* Call the always-present MLDSA context API from the UEFI driver

* Cross uefi-static and uefi-library with both wolfSSL refs in the matrix

* Give each tpm matrix leg a ref-unique results file and artifact

* Add a codespell spellcheck pass to the lint job

* Run push CI on master only so a PR branch does not double-trigger

* Select valgrind by caller_run_id since event_name is the caller under workflow_call

* Make example check targets catch real failures with pipefail exit checks and inputs

* Wire the harness to run make check for mode check examples starting with ecc

* Migrate the single-entry exec examples to mode check and fold their inputs into the check targets

* Fix four make check assertions that misfired under pipefail

* Give the tpm manifest entry a run step so it asserts output

* Skip uefi-static in the lint make -n loop so it does not clone

* Assert the actual verify result in the pkcs7 and rsa-nb checks

* Return nonzero from pkcs12-create-example on a failed create so the check is not a false pass

* Return nonzero from rsa-kg on any key generate or write failure

* Assert the static memory checks by exit code instead of a pipefail grep that BSD make lacks

* Run pkcs7 signedData stream through make check so it asserts the real verify result

* Check DER certificates and CRLs in the expiry canary too

* Feed the wolfHSM client its stdin so run_client actually exchanges data

* Assert every make check by exit code and captured output instead of a pipefail grep so they hold under BSD make
2026-07-23 10:07:06 -06:00
..
Makefile Add CI that builds and runs every example (#598) 2026-07-23 10:07:06 -06:00
README.md AES modes extravaganza. Makefile, README and misc. files 2025-12-18 10:03:50 -05:00
aes-cbc.c AES modes extravaganza. CBC 2025-12-18 10:16:18 -05:00
aes-ccm.c AES modes extravaganza. CCM 2025-12-18 10:18:53 -05:00
aes-cfb.c AES modes extravaganza. CFB, CFB1, CFB8 2025-12-18 10:24:11 -05:00
aes-cfb1.c AES modes extravaganza. CFB, CFB1, CFB8 2025-12-18 10:24:11 -05:00
aes-cfb8.c AES modes extravaganza. CFB, CFB1, CFB8 2025-12-18 10:24:11 -05:00
aes-ctr.c AES modes extravaganza. CTR 2025-12-18 10:27:06 -05:00
aes-cts.c AES modes extravaganza. CTS 2025-12-18 10:55:53 -05:00
aes-direct.c AES modes extravaganza. direct and keywrap 2025-12-18 11:35:32 -05:00
aes-eax.c AES modes extravaganza. eax and ecb 2025-12-18 11:37:43 -05:00
aes-ecb.c AES modes extravaganza. eax and ecb 2025-12-18 11:37:43 -05:00
aes-gcm.c AES modes extravaganza. gcm and gmac 2025-12-18 11:39:27 -05:00
aes-gmac.c AES modes extravaganza. gcm and gmac 2025-12-18 11:39:27 -05:00
aes-keywrap.c F-1302 F-1303 F-1304 F-1308 F-3471 F-3691 F-4601: fix buffer overflows, malloc/realloc NULL checks, and padding validation in crypto file-encryption examples 2026-07-14 13:33:25 -06:00
aes-ofb.c AES modes extravaganza. ofb, siv, xts 2025-12-18 11:41:40 -05:00
aes-siv.c AES modes extravaganza. ofb, siv, xts 2025-12-18 11:41:40 -05:00
aes-xts.c Add CI that builds and runs every example (#598) 2026-07-23 10:07:06 -06:00
testfile.txt AES modes extravaganza. Makefile, README and misc. files 2025-12-18 10:03:50 -05:00
testfile_direct.txt AES modes extravaganza. Makefile, README and misc. files 2025-12-18 10:03:50 -05:00
testfile_keywrap.txt AES modes extravaganza. Makefile, README and misc. files 2025-12-18 10:03:50 -05:00

README.md

AES Mode Examples

This directory contains examples demonstrating all 16 AES modes supported by wolfSSL's wolfCrypt library. Each example encrypts a file using the one-shot API and decrypts it using the streaming API (where available).

Overview

Each example demonstrates:

  • One-shot encryption using the mode's encrypt function
  • Streaming decryption using Init/Update/Final pattern (if available)
  • Proper key/IV/nonce generation and handling
  • File I/O for practical usage

AES Modes

Mode File Streaming Decrypt Build Flag Description
CBC aes-cbc.c No HAVE_AES_CBC Cipher Block Chaining
CFB aes-cfb.c Yes WOLFSSL_AES_CFB Cipher Feedback (128-bit)
CFB1 aes-cfb1.c Yes WOLFSSL_AES_CFB Cipher Feedback (1-bit)
CFB8 aes-cfb8.c Yes WOLFSSL_AES_CFB Cipher Feedback (8-bit)
OFB aes-ofb.c Yes WOLFSSL_AES_OFB Output Feedback
ECB aes-ecb.c No HAVE_AES_ECB Electronic Codebook
CTR aes-ctr.c Yes WOLFSSL_AES_COUNTER Counter Mode
DIRECT aes-direct.c No WOLFSSL_AES_DIRECT Raw Block Cipher
GCM aes-gcm.c Yes* HAVE_AESGCM Galois/Counter Mode (AEAD)
GMAC aes-gmac.c No HAVE_AESGCM Galois MAC (auth only)
CCM aes-ccm.c No HAVE_AESCCM Counter with CBC-MAC (AEAD)
KEY WRAP aes-keywrap.c No HAVE_AES_KEYWRAP RFC 3394 Key Wrap
XTS aes-xts.c Yes* WOLFSSL_AES_XTS XEX-based Tweaked-codebook
SIV aes-siv.c No WOLFSSL_AES_SIV Synthetic IV (AEAD)
EAX aes-eax.c Yes WOLFSSL_AES_EAX Encrypt-Authenticate-Translate
CTS aes-cts.c No* WOLFSSL_AES_CTS Ciphertext Stealing

*GCM streaming requires WOLFSSL_AESGCM_STREAM, XTS streaming requires WOLFSSL_AESXTS_STREAM, CTS streaming API requires complex internal buffering and is not demonstrated in this example

Building

Prerequisites

wolfSSL must be installed with the required AES modes enabled. To enable all modes:

cd /path/to/wolfssl
./autogen.sh
./configure --enable-aescbc \
            --enable-aescfb \
            --enable-aesofb \
            --enable-aesecb \
            --enable-aesctr \
            --enable-aesgcm \
            --enable-aesccm \
            --enable-aeskeywrap \
            --enable-xts \
            --enable-aessiv \
            --enable-aeseax \
            --enable-aescts \
            --enable-aesgcm-stream \
            --enable-aesxts-stream
make
sudo make install

Building the Examples

make

Usage

All examples follow the same pattern:

./<example> <input_file> <output_file>

The example will:

  1. Read the input file
  2. Encrypt it using the one-shot API
  3. Write encrypted data to a temporary file
  4. Decrypt using streaming API (or one-shot if no streaming available)
  5. Write decrypted data to the output file
  6. Clean up temporary files

Example

# Create a test file
echo "Hello, wolfSSL AES modes!" > test.txt

# Test AES-GCM
./aes-gcm test.txt output.txt
cat output.txt

# Test AES-CTR
./aes-ctr test.txt output.txt
cat output.txt

Notes

Security Considerations

  • These examples use fixed keys for demonstration purposes only
  • In production, use proper key management and secure random key generation
  • ECB mode is not recommended for most use cases due to security weaknesses
  • GMAC provides authentication only (no encryption)

Streaming vs One-Shot

Modes with streaming support allow processing data in chunks, which is useful for:

  • Large files that don't fit in memory
  • Network streams where data arrives incrementally
  • Memory-constrained environments

Modes without streaming support require the entire plaintext/ciphertext to be available before processing.

Minimum Input Sizes

Some modes have minimum input size requirements:

  • XTS: Minimum 16 bytes
  • CTS: Minimum 16 bytes
  • KEY WRAP: Input must be multiple of 8 bytes (padding applied automatically)