Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions docs/FIPS_INTEGRATION_GUIDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -206,6 +206,7 @@ cd wolfssl-5.8.4-commercial-fips-ready

./configure --enable-fips=ready \
--enable-opensslcoexist \
--enable-dh \
--prefix=/usr/local/wolfssl-fips \
CPPFLAGS="-I/usr/local/openssl/include -DWOLFSSL_OLD_OID_SUM -DWOLFSSL_DH_EXTRA"
make -j$(nproc)
Expand All @@ -216,6 +217,7 @@ Replace `--enable-fips=ready` with your bundle's tag (see FIPS Check Options abo

**Required flags:**
- `--enable-opensslcoexist` - Prevents symbol conflicts with OpenSSL (mandatory)
- `--enable-dh` - Enables DH, which is off by default in FIPS v7+ bundles (mandatory)
- `-DWOLFSSL_OLD_OID_SUM` - Required for certificate compatibility (mandatory)
- `-DWOLFSSL_DH_EXTRA` - Required for DH key operations (mandatory)
- `-I/usr/local/openssl/include` - Path to your OpenSSL headers (adjust as needed)
Expand Down
4 changes: 2 additions & 2 deletions scripts/utils-wolfssl.sh
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
#!/bin/bash
#
# Copyright (C) 2006-2024 wolfSSL Inc.
# Copyright (C) 2006-2026 wolfSSL Inc.
#
# This file is part of wolfProvider.
#
Expand Down Expand Up @@ -42,7 +42,7 @@ WOLFSSL_SOURCE_DIR=${SCRIPT_DIR}/../wolfssl-source
WOLFSSL_INSTALL_DIR=${SCRIPT_DIR}/../wolfssl-install
WOLFSSL_ISFIPS=${WOLFSSL_ISFIPS:-0}
WOLFSSL_FIPS_VERSION=${WOLFSSL_FIPS_VERSION:-"5.2.4"}
WOLFSSL_FIPS_CONFIG_OPTS=${WOLFSSL_CONFIG_OPTS:-'--enable-opensslcoexist '}
WOLFSSL_FIPS_CONFIG_OPTS=${WOLFSSL_CONFIG_OPTS:-'--enable-opensslcoexist --enable-dh '}
Comment thread
padelsbach marked this conversation as resolved.
WOLFSSL_FIPS_CONFIG_CFLAGS=${WOLFSSL_CONFIG_CFLAGS:-"-I${OPENSSL_INSTALL_DIR}/include -DWOLFSSL_OLD_OID_SUM -DWOLFSSL_DH_EXTRA"}
WOLFSSL_CONFIG_OPTS=${WOLFSSL_CONFIG_OPTS:-'--enable-all-crypto --with-eccminsz=192 --with-max-ecc-bits=1024 --enable-opensslcoexist --enable-sha'}
WOLFSSL_CONFIG_CFLAGS=${WOLFSSL_CONFIG_CFLAGS:-"-I${OPENSSL_INSTALL_DIR}/include -DWC_RSA_NO_PADDING -DWOLFSSL_PUBLIC_MP -DHAVE_PUBLIC_FFDHE -DHAVE_FFDHE_6144 -DHAVE_FFDHE_8192 -DWOLFSSL_PSS_LONG_SALT -DWOLFSSL_PSS_SALT_LEN_DISCOVER -DRSA_MIN_SIZE=1024 -DWOLFSSL_OLD_OID_SUM "}
Expand Down
Loading