Repository navigation
Supported Operations
github-actions[bot] edited this page Jun 11, 2026
·
5 revisions
wolfSPDM implements requester-side SPDM operations for session establishment, secure data exchange, attestation, and session maintenance.
| Operation | SPDM area | wolfSPDM API |
|---|---|---|
| Version negotiation | GET_VERSION | wolfSPDM_GetVersion |
| Capability negotiation | GET_CAPABILITIES | wolfSPDM_GetCapabilities |
| Algorithm negotiation | NEGOTIATE_ALGORITHMS | wolfSPDM_NegotiateAlgorithms |
| Certificate digest retrieval | GET_DIGESTS | wolfSPDM_GetDigests |
| Certificate chain retrieval | GET_CERTIFICATE | wolfSPDM_GetCertificate |
| Session key exchange | KEY_EXCHANGE | wolfSPDM_KeyExchange |
| Session finalization | FINISH | wolfSPDM_Finish |
| One-shot full connect | Full handshake | wolfSPDM_Connect |
| Secured app exchange | Secured messages | wolfSPDM_SecuredExchange |
| App send/receive helpers | Secured messages |
wolfSPDM_SendData, wolfSPDM_ReceiveData
|
| Measurements (signed/unsigned) | GET_MEASUREMENTS | wolfSPDM_GetMeasurements |
| Measurement block access | Measurement parsing |
wolfSPDM_GetMeasurementCount, wolfSPDM_GetMeasurementBlock
|
| Sessionless challenge auth | CHALLENGE / CHALLENGE_AUTH | wolfSPDM_Challenge |
| Keep-alive | HEARTBEAT | wolfSPDM_Heartbeat |
| Session key rotation | KEY_UPDATE | wolfSPDM_KeyUpdate |
- SPDM 1.2 (
0x12) - SPDM 1.3 (
0x13) - SPDM 1.4 (
0x14)
Maximum negotiated version can be capped with wolfSPDM_SetMaxVersion.
- Hash: SHA-384
- Asymmetric signature: ECDSA P-384
- DHE: secp384r1
- AEAD: AES-256-GCM
- Key schedule: SPDM key schedule + HKDF-SHA384
When built against a wolfSSL with ML-DSA (FIPS 204), wolfSPDM additionally
advertises ML-DSA-44 / ML-DSA-65 / ML-DSA-87 in the SPDM 1.4 PqcAsymAlgo
field (dual-stack alongside ECDSA P-384). The responder selects exactly one
signature algorithm; wolfSPDM verifies whichever was negotiated. See
Post-Quantum ML-DSA.
Large responses (e.g. an ML-DSA-87 signature that exceeds the negotiated
DataTransferSize) are reassembled with SPDM 1.2 message chunking
(CHUNK_GET); see Message Chunking.
- Requester-only implementation (no responder role)
- Designed for standards-based SPDM peers and DMTF spdm-emu
- Trust anchor support via
wolfSPDM_SetTrustedCAs(single DER CA cert buffer)