wolfSSL and embedded devices
wolfSSL’s supported key-exchange groups depend on build configuration. Embedded devices also need sufficient resources and interoperable peers to complete the handshake.
Evidence to collect
- Record the deployed firmware, wolfSSL version, and enabled build features.
- Compare supported groups with wolfSSL’s documentation for that release. Do not enable experimental options by copying an old recipe.
- Collect the negotiated group from a test connection and assess memory, message-size, and timeout behavior on the actual device.
Record the scope and result
Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.
Official references
Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.