# Kconfig - Cryptography primitive options for wolfSSL

#
# Copyright (c) 2016 Intel Corporation
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
#     http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#

config ZEPHYR_WOLFSSL_MODULE
        bool
config WOLFSSL_PROMPTLESS
        bool
        help
          Symbol to disable the prompt for WOLFSSL selection.
          This symbol may be used internally in a Kconfig tree to hide the
          wolfSSL menu prompt and instead handle the selection of WOLFSSL from
          dependent sub-configurations and thus prevent stuck symbol behavior.


menuconfig WOLFSSL
	bool "wolfSSL Support" if !WOLFSSL_PROMPTLESS
	help
	  This option enables the wolfSSL cryptography library.

if WOLFSSL

choice WOLFSSL_IMPLEMENTATION
	prompt "Select implementation"
	default WOLFSSL_BUILTIN

config WOLFSSL_BUILTIN
	bool "Enable wolfSSL integrated sources"
	help
	  Link with local wolfSSL sources instead of external library.

config WOLFSSL_LIBRARY
	bool "Enable wolfSSL external library"
	help
	  This option enables wolfSSL library.

endchoice

config WOLFSSL_SETTINGS_FILE
	string "wolfSSL settings file"
	depends on WOLFSSL_BUILTIN
	help
	  Use a specific wolfSSL settings file. The default config file
	  file can be tweaked with Kconfig. The default settings is
	  suitable to communicate with majority of HTTPS servers on the Internet,
	  but has relatively many features enabled. To optimize resources for
	  special TLS usage, use available Kconfig settings, or select an
	  alternative config.

config WOLFSSL_HAS_SETTINGS_FILE
	bool
	default y if WOLFSSL_SETTINGS_FILE != ""
	help
	  Set when the application supplies its own wolfSSL settings file.
	  That file is authoritative, so every option that works by writing a
	  define into the module's user_settings.h depends on this being clear.

config WOLFCRYPT_FIPS
	bool "wolfCrypt FIPS support"
	depends on WOLFSSL_BUILTIN && !WOLFSSL_HAS_SETTINGS_FILE
	help
	  Enable the wolfCrypt FIPS 140-3 module boundary. Requires the wolfSSL
	  FIPS bundle (fips.c, fips_test.c, wolfcrypt_first.c, wolfcrypt_last.c)
	  dropped into wolfcrypt/src/ - the CMake FIPS-boundary block compiles them.
	  Select the version that matches the bundle under "wolfCrypt FIPS version".

choice
	prompt "wolfCrypt FIPS version"
	depends on WOLFCRYPT_FIPS
	default WOLFCRYPT_FIPS_V6
	help
	  Select the FIPS module version. It must match the dropped-in bundle: the
	  in-core integrity check and the in-boundary algorithm set are keyed to the
	  version, so a mismatch fails the power-on self test. Values mirror
	  configure.ac's --enable-fips=VERSION mapping.

config WOLFCRYPT_FIPS_V2
	bool "FIPS 140-2 (Cert #3389)"
	help
	  Legacy FIPS 140-2 validated module (HAVE_FIPS_VERSION 2.0.0).

config WOLFCRYPT_FIPS_V5
	bool "FIPS 140-3 (Cert #4718)"
	help
	  wolfCrypt FIPS 140-3 validated module, Certificate #4718 (version 5.2.1).

config WOLFCRYPT_FIPS_V6
	bool "FIPS 140-3 (SRTP-KDF full submission)"
	help
	  wolfCrypt FIPS 140-3 SRTP-KDF full submission (version 6.0.0).

config WOLFCRYPT_FIPS_V7
	bool "FIPS 140-3 (v7 full submission)"
	help
	  wolfCrypt FIPS 140-3 v7 full submission (version 7.0.0).

config WOLFCRYPT_FIPS_READY
	bool "FIPS Ready (in-tree, uncertified)"
	help
	  FIPS-Ready in-tree sources, feature locked (version 8.0.0 - kept one ahead
	  of the latest submission). Carries the newest in-boundary algorithms but is
	  not yet NIST-certified; use it for pre-certification integration.

endchoice

config WOLFSSL_CRYPTO_CB
  bool "wolfCrypt crypto callbacks"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Enable the crypto callback interface (WOLF_CRYPTO_CB), through which an
    application registers a device with wc_CryptoCb_RegisterDevice() and
    routes wolfCrypt operations to it. Also enables key references
    (WOLF_PRIVATE_KEY_ID), which is what lets a TLS key live on that device
    instead of in the application's memory.

config WOLFSSL_CRYPTO_ONLY
	bool "Build wolfCrypt only (no TLS layer)"
	depends on !WOLFSSL_HAS_SETTINGS_FILE
	depends on WOLFSSL_BUILTIN
	help
	  Define WOLFCRYPT_ONLY: compile only the wolfCrypt crypto library and
	  leave the wolfSSL TLS layer out of the build.

config WOLFSSL_SINGLE_THREADED
	bool "wolfCrypt single-threaded"
	depends on !WOLFSSL_HAS_SETTINGS_FILE
	depends on WOLFSSL_BUILTIN
	default y if !MULTITHREADING
	help
	  Define SINGLE_THREADED: build wolfCrypt without internal locking, for a
	  single-threaded system or when the caller serializes all access. Defaults
	  on when the kernel has no threading (!MULTITHREADING), so consumers such
	  as wolfPSA do not need to select it themselves.

config WOLFSSL_TLS_VERSION_1_2
  bool "TLS 1.2"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  default y
  help
    Enable TLS 1.2. Clearing this and WOLFSSL_TLS_VERSION_1_3 leaves the
    build with no TLS version at all, which only makes sense alongside
    WOLFSSL_CRYPTO_ONLY.

config WOLFSSL_TLS_VERSION_1_3
  bool "TLS 1.3"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  default y
  help
    Enable TLS 1.3 (WOLFSSL_TLS13).

config WOLFSSL_DTLS
  bool "wolfSSL DTLS support"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Enable DTLS support

config WOLFSSL_ALPN
  bool "wolfSSL ALPN support"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Enable ALPN support

config WOLFSSL_PSK
  bool "wolfSSL PSK support"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Enable PSK support

config WOLFSSL_MLKEM
  bool "wolfSSL PQC ML-KEM support"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Enable PQC ML-KEM support for Key Exchange

config WOLFSSL_MLDSA
  bool "wolfSSL PQC ML-DSA support"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Enable PQC ML-DSA (Dilithium) signatures.

config WOLFSSL_LMS
  bool "wolfSSL LMS/HSS hash-based signatures"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Enable LMS/HSS stateful hash-based signature verification (verify-only).

config WOLFSSL_XMSS
  bool "wolfSSL XMSS/XMSS^MT hash-based signatures"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Enable XMSS/XMSS^MT stateful hash-based signature verification (verify-only).

config WOLFSSL_FALCON
  bool "wolfSSL PQC Falcon signatures"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Enable PQC Falcon (FN-DSA) signatures.

config WOLFSSL_RSA
  bool "wolfCrypt RSA support"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  default y
  help
    Enable RSA (define RSA support; NO_RSA when off).

config WOLFSSL_ECC
  bool "wolfCrypt ECC support"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  default y
  help
    Enable ECC (HAVE_ECC). At least one curve must be selected below - a
    build with none is rejected, because wolfCrypt has no curve table to
    size its types from.

if WOLFSSL_ECC

config WOLFSSL_ECC_256
  bool "SECP256R1 (P-256)"
  default y
  help
    Enable the NIST P-256 curve. This is the curve TLS uses by default, so
    leave it on unless you know the whole application avoids it.

config WOLFSSL_ECC_384
  bool "SECP384R1 (P-384)"
  help
    Enable the NIST P-384 curve (HAVE_ECC384 and the SP implementation
    behind WOLFSSL_SP_384).

    Enabling a curve larger than P-256 raises MAX_ECC_BYTES, so every ECC
    key, signature buffer and temporary grows accordingly - including on the
    stack. Size thread stacks for the largest curve selected.

config WOLFSSL_ECC_512
  bool "512-bit curves"
  help
    Enable the 512-bit curve size (HAVE_ECC512). There is no NIST curve at
    this size - it exists for brainpoolP512r1, so it is only useful together
    with WOLFSSL_ECC_BRAINPOOL. SP math has no implementation at this size,
    so selecting it forces the generic SP variant.

config WOLFSSL_ECC_521
  bool "SECP521R1 (P-521)"
  help
    Enable the NIST P-521 curve (HAVE_ECC521 and the SP implementation
    behind WOLFSSL_SP_521). This sets the largest MAX_ECC_BYTES of any
    supported curve.

    Its SP implementation is also the most stack-hungry: a thread signing on
    P-521 overflowed a 16 KB stack during bring-up and needed roughly three
    times that. Raise CONFIG_MAIN_STACK_SIZE and any relevant thread stack,
    or set WOLFSSL_SMALL_STACK to move the intermediates onto the heap.

config WOLFSSL_ECC_BRAINPOOL
  bool "Brainpool curves"
  help
    Enable the Brainpool curve family (HAVE_ECC_BRAINPOOL). Each curve also
    needs its matching size enabled: brainpoolP256r1 needs WOLFSSL_ECC_256,
    brainpoolP384r1 needs WOLFSSL_ECC_384 and brainpoolP512r1 needs
    WOLFSSL_ECC_512.

    Implies WOLFSSL_CUSTOM_CURVES, which wolfCrypt requires for any
    non-prime-field curve, and that moves the whole build onto the generic
    SP variant - slower and larger on the common curves, which is why this
    is opt-in.

endif # WOLFSSL_ECC

# Selected by consumers that must sign an all-zero digest, such as wolfPSA.
# No depends on: settings-file builds select it too.
config WOLFSSL_ECC_ALLOW_ZERO_HASH
  bool

# The v2 and v5 FIPS bundles pin an aes.c that has neither backend in it, and
# a settings file replaces the module defaults that map the choice below.
config WOLFSSL_AES_CONSTANT_TIME_AVAILABLE
  bool
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  default y if !WOLFCRYPT_FIPS_V2 && !WOLFCRYPT_FIPS_V5

config WOLFSSL_AES_CONSTANT_TIME
  bool "Constant-time AES software backend"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  depends on WOLFSSL_AES_CONSTANT_TIME_AVAILABLE
  help
    Build the AES software core so that no memory access depends on a
    secret.

    wolfCrypt's default core indexes precomputed tables with key- and
    state-derived bytes. On a part with a data cache that access pattern is
    observable, so a caller that must be constant time - the PSA Crypto API
    is one - has to turn this on. On a part with no data cache there is
    nothing to observe and the default core is the right choice.

    A subsystem that requires the guarantee defaults this on and leaves the
    implementation below to the target.

    It has no effect when the build uses a hardware AES engine or the
    assembly core: neither compiles a software table.

    Unavailable under FIPS v2 and v5, whose pinned aes.c predates both
    backends and would ignore the macro rather than fail: a build would come
    out with the table core and no sign that the request was dropped. It does
    take effect from FIPS v6 on, where it changes the in-core integrity
    digest, so the module must be rehashed and is no longer the validated
    binary.

choice WOLFSSL_AES_CONSTANT_TIME_IMPL
  prompt "Constant-time AES implementation"
  depends on WOLFSSL_AES_CONSTANT_TIME
  default WOLFSSL_AES_TOUCH_LINES

config WOLFSSL_AES_TOUCH_LINES
  bool "Touch every cache line of the table"
  help
    Define WOLFSSL_AES_TOUCH_LINES. Every table access reads all cache lines
    of the table, so the access pattern carries no secret. sizeof(Aes) is
    unchanged, which is what makes this the affordable choice on a
    constrained target.

config WOLFSSL_AES_BITSLICED
  bool "Bitsliced core"
  help
    Define WC_AES_BITSLICED. Holds the state as bit slices across machine
    words, so there is no table and no secret-indexed load at all.

    It grows every Aes and Cmac quadratically in the word size, so set
    WOLFSSL_AES_BS_WORD_SIZE for the target before selecting it.

endchoice

config WOLFSSL_AES_BS_WORD_SIZE
  int "Bitsliced AES word size"
  depends on WOLFSSL_AES_BITSLICED
  default 16
  help
    Define WC_AES_BS_WORD_SIZE: bits processed per round, and the term that
    dominates the size of every Aes and Cmac. The bitsliced key schedule
    costs 30 * WC_AES_BS_WORD_SIZE^2 bytes, so measured against this
    module's own defaults:

      8    2,248 byte Aes      32   31,048 byte Aes
      16   8,008 byte Aes      64  123,208 byte Aes

    Only 8, 16, 32 and 64 are implemented; wolfCrypt rejects anything else.

    wolfCrypt itself defaults to 64 on a 64-bit build. 16 is the default
    here because these contexts are allocated per live operation, and 64
    puts a single AES operation beyond the whole heap of a typical part.

config WOLFSSL_CHACHA_POLY
  bool "wolfCrypt ChaCha20-Poly1305 support"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  default y
  help
    Enable ChaCha20 and Poly1305 (HAVE_CHACHA, HAVE_POLY1305).

config WOLFSSL_CURVE25519
  bool "wolfCrypt Curve25519 / Ed25519 support"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  default n
  help
    Enable Curve25519 and Ed25519 (HAVE_CURVE25519, HAVE_ED25519).

config WOLFSSL_SNI
  bool "wolfSSL Server Name Indication (SNI)"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  default y
  help
    Enable TLS Server Name Indication (HAVE_SNI).

config WOLFSSL_SESSION_CACHE
  bool "wolfSSL TLS session cache"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  default y
  help
    Enable the TLS session cache (SMALL_SESSION_CACHE; NO_SESSION_CACHE off).

config WOLFSSL_OCSP
  bool "wolfSSL OCSP certificate revocation checking"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Enable OCSP (HAVE_OCSP).

config WOLFSSL_OCSP_STAPLING
  bool "wolfSSL OCSP stapling"
  depends on WOLFSSL_OCSP
  help
    Enable the TLS certificate status request extension
    (HAVE_CERTIFICATE_STATUS_REQUEST), with which a client asks the server
    to staple an OCSP response for its own certificate to the handshake.

config WOLFSSL_SESSION_TICKET
  bool "wolfSSL TLS session tickets"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  default y
  help
    Enable TLS session tickets (HAVE_SESSION_TICKET, TLS 1.3 resumption).

config WOLFSSL_MAX_FRAGMENT
  bool "wolfSSL max_fragment_length extension"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  default y
  help
    Enable the RFC 6066 max_fragment_length extension (HAVE_MAX_FRAGMENT).

config WOLFSSL_SESSION_EXPORT
  bool "wolfSSL session export support"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Enable external session cache (HAVE_EXT_CACHE)

config WOLFSSL_KEEP_PEER_CERT
  bool "wolfSSL keep peer certificate support"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Retain peer certificate after handshake (KEEP_PEER_CERT)

config WOLFSSL_ALWAYS_VERIFY_CB
  bool "wolfSSL always invoke verify callback"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Invoke verify callback on success as well as failure (WOLFSSL_ALWAYS_VERIFY_CB)

config WOLFSSL_OPENSSL_EXTRA_X509_SMALL
  bool "wolfSSL minimal X509 compat APIs"
  depends on !WOLFSSL_HAS_SETTINGS_FILE
  help
    Define OPENSSL_EXTRA_X509_SMALL. Exposes a small subset of X509
    helpers (wolfSSL_X509_free, wolfSSL_get_verify_result, ...) without
    the rest of OPENSSL_EXTRA.

config WOLFCRYPT_ASM
	bool "wolfCrypt assembly optimisations"
	depends on WOLFSSL_BUILTIN && !WOLFSSL_HAS_SETTINGS_FILE
	depends on ARM || ARM64 || X86_64
	help
	  Use the hand-written assembly for the symmetric algorithms (AES,
	  SHA-2, SHA-3, ChaCha20/Poly1305, Curve25519) and, on ARM, for the
	  single-precision math behind RSA, DH and ECC.

	  The port follows the CPU Zephyr reports:

	    ARMv7-M / ARMv8-M mainline  thumb2 symmetric, Cortex-M math
	    ARMv6-M / ARMv8-M baseline  math only, Thumb variant
	    32-bit Cortex-A / Cortex-R  armv8-32 symmetric, ARM32 math
	    AArch64                     armv8 symmetric, ARM64 math
	    x86_64                      symmetric only

	  ARMv6-M and ARMv8-M baseline get no symmetric assembly because the
	  Thumb2 port uses UBFX and LDRD, which those cores lack. On the
	  mainline cores the math assembly prefers UMAAL, part of the DSP
	  extension; a part built without it takes the slower UMAAL-free
	  variant of the same routines.

	  x86_64 gets no single-precision assembly: sp_x86_64_asm.S is AVX
	  throughout and sp_x86_64.c calls it without a CPUID check, while
	  Zephyr's x86 context switch never enables the YMM state. Its
	  symmetric AVX1/AVX2 paths are safe because they are chosen at run
	  time by CPUID, which this module also teaches to check that the OS
	  enabled the vector state.

	  32-bit x86 is not offered: only the AES sources have an
	  implementation at that width, and the rest are guarded to x86_64.

config WOLFCRYPT_SP_SMALL
	bool "Smaller single-precision math"
	depends on WOLFSSL_BUILTIN && !WOLFSSL_HAS_SETTINGS_FILE
	default y
	help
	  Build the space-optimised variant of the single-precision math
	  backend. Turning it off trades a markedly larger image for faster
	  RSA, DH and ECC.

	  Independent of WOLFCRYPT_ASM, which picks the backend while this
	  picks the variant within it: the assembly sources carry both a
	  loop-based and an unrolled form of each routine. Leaving this on
	  therefore keeps the smaller, slower half of the assembly, so
	  turning it off is what makes WOLFCRYPT_ASM pay off on a part with
	  the flash to spare.

config WOLFSSL_NO_HAVE_MIN_MAX
	bool "Force wolfSSL to use its own min/max"
	help
	  Disable this if Zephyr min()/max() macros cause
	  issues. By default wolfSSL defers to Zephyr's
	  min/max on >= 4.3.

config WOLFSSL_DEBUG
	bool "wolfSSL debug activation"
	depends on WOLFSSL_BUILTIN
	help
	  Enable debugging activation for wolfSSL configuration. If you use
	  wolfSSL/Zephyr integration (e.g. net_app), this will activate debug
	  logging (of the level configured by WOLFSSL_DEBUG_LEVEL).

config WOLFSSL_INSTALL_PATH
	string "wolfSSL install path"
	depends on WOLFSSL_LIBRARY
	help
	  This option holds the path where the wolfSSL libraries and headers are
	  installed. Make sure this option is properly set when WOLFSSL_LIBRARY
	  is enabled otherwise the build will fail.

module = WOLFSSL
module-str = wolfssl
source "subsys/logging/Kconfig.template.log_config"

config APP_LINK_WITH_WOLFSSL
	bool "Link 'app' with WOLFSSL"
	default y
	help
	  Add WOLFSSL header files to the 'app' include path. It may be
	  disabled if the include paths for WOLFSSL are causing aliasing
	  issues for 'app'.

endif

