|Stable release||1.3.4 (January 27, 2014) [±]|
|License||GPLv2 or proprietary|
The PolarSSL SSL library is a dual licensed (GPLv2 or proprietary) implementation of the SSL and TLS protocols and the respective cryptographic algorithms and support code required. Stated on the website is that PolarSSL aims to be "easy to understand, use, integrate and expand".
The PolarSSL SSL library is the official continuation fork of the XySSL SSL library. XySSL was created by the French "white hat hacker" Christophe Devine and was first released on November 1, 2006 under GPL and BSD licenses. In 2008 Christophe Devine was no longer able to support XySSL and allowed Paul Bakker to create the official fork, named PolarSSL.
In 2011 the Dutch government approved an integration between OpenVPN and PolarSSL, which is named OpenVPN-NL. This version of OpenVPN has been approved for use in protecting government communications up to the level of Restricted.
The core SSL library is written in the C programming language and implements the SSL module, the basic cryptographic functions and provides various utility functions. Unlike OpenSSL and other implementations of TLS, PolarSSL is designed to fit on small embedded devices, with the minimum complete TLS stack requiring under 60KB of program space and under 64KB of RAM. It is also highly modular: each component, such as a cryptographic function, can be used independently from the rest of the framework. Versions are also available for Microsoft Windows and Linux. Because PolarSSL is written in the C programming language, without external dependencies, it works on most operating systems and architectures without any trouble.
Later versions of the SSL library (> PolarSSL 1.3.0) add abstraction layers for memory allocation and threading to the core "to support better integration with existing embedded operating systems".
The PolarSSL library expresses a focus on readability of the code, documentation, automated regression tests, a loosely coupled design and portable code.
The following documentation is available for developers:
- High Level Design; This document provides a high level description of the different modules inside the library, with UML diagrams, use cases and interactions in common scenarios.
- API documentation; The API documentation is Doxygen-generated documentation from the header files of the library.
- Source code documentation; The source code of the library is documented to clarify structures, decisions and code constructs.
PolarSSL provides automated testing of the code and of PolarSSL's compatibility as follows:
- A test framework is included with the source code that contains over 5000 automated tests (based on the number of tests in version 1.3.2 of the library) to test for regressions and compatibility on different platforms.
- A continuous integration system based on Buildbot
- A compatibility script (compat.sh) that tests compatibility of SSL communication with OpenSSL.
PolarSSL is used as the SSL component in large open source projects:
Major version releases
- PolarSSL 1.2.10 was released on October 7, 2013
- PolarSSL 1.3.0 was released on October 1, 2013
- PolarSSL 1.2.6 was released on March 15, 2013
- PolarSSL 1.2.5 was released on February 2, 2013
- PolarSSL 1.2.0 was released on October 31, 2012
- PolarSSL 1.1.4 was released on May 31, 2012
- PolarSSL 1.1.0 was released on December 22, 2011
- PolarSSL 1.0.0 was released on August 9, 2011
- PolarSSL 0.14.0 was released on August 16, 2010
- PolarSSL 0.13.1 was released on March 24, 2010
- PolarSSL 0.12.1 was released on October 4, 2009
- PolarSSL 0.12.0 was released on July 28, 2009
- PolarSSL 0.11.0 was released on May 3, 2009
PolarSSL supports a number of different cryptographic algorithms:
- AES, Camellia, DES, RC4, RC5, Triple DES, XTEA, Blowfish
- Cryptographic hash functions
- MD5, MD2, MD4, SHA-1, SHA-2
- Public-key cryptography
- RSA, Diffie-Hellman key exchange, Elliptic curve cryptography (ECC), Elliptic curve Diffie–Hellman (ECDH), Elliptic Curve DSA (ECDSA)
- Transport Layer Security
- Comparison of TLS Implementations
- POSSE project
- Network Security Services
- "Download overview - PolarSSL". 2014-01-27. Retrieved 2014-02-04.